{
  "data": {
    "similar": [
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/plaid.json",
        "name": "Plaid",
        "score": 69.8,
        "shared": [
          "bank.accounts",
          "bank.transactions",
          "bank.identity",
          "bank.consent"
        ],
        "slug": "plaid"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/belvo.json",
        "name": "Belvo",
        "score": 63.5,
        "shared": [
          "bank.accounts",
          "bank.transactions",
          "bank.identity",
          "bank.consent"
        ],
        "slug": "belvo"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/mx.json",
        "name": "MX Platform API",
        "score": 62.5,
        "shared": [
          "bank.accounts",
          "bank.transactions",
          "bank.identity",
          "bank.consent"
        ],
        "slug": "mx"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/tink.json",
        "name": "Tink",
        "score": 62.5,
        "shared": [
          "bank.accounts",
          "bank.transactions",
          "bank.consent",
          "bank.identity"
        ],
        "slug": "tink"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/truelayer.json",
        "name": "TrueLayer",
        "score": 62.1,
        "shared": [
          "bank.accounts",
          "bank.transactions",
          "bank.identity",
          "bank.consent"
        ],
        "slug": "truelayer"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/yapily.json",
        "name": "Yapily",
        "score": 57.6,
        "shared": [
          "bank.accounts",
          "bank.transactions",
          "bank.identity",
          "bank.consent"
        ],
        "slug": "yapily"
      }
    ],
    "tool": {
      "slug": "akoya",
      "name": "Akoya",
      "vendor": "Akoya LLC",
      "vendorUrl": "https://akoya.com",
      "kind": "http-api",
      "category": "banking-data",
      "summary": "Akoya runs a US data access network through which consumers permit apps to read their bank and brokerage accounts. Data recipients call FDX-based REST APIs for accounts, balances, transactions, customer details, statements and consent, after an OAuth consent flow.",
      "url": "https://www.anchorterminal.com/tools/akoya",
      "markdownUrl": "https://www.anchorterminal.com/tools/akoya.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/akoya.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/akoya.json",
      "license": "Proprietary service under the Akoya Terms of Use and a signed data access agreement",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://products.ddp.akoya.com",
      "packages": [],
      "auth": "oauth",
      "authNotes": "OAuth 2.0 authorisation code grant with OpenID Connect. A person requests a Data Recipient Hub account (MFA is mandatory), registers an app and receives a client ID and secret. The consumer signs in at their own institution, picks the accounts to share, and the app exchanges the code at `/token` for an ID token and a refresh token. The ID token is the bearer token for data calls. The only scopes are `openid profile offline_access`, and what an app can read is set by its product subscriptions and the consumer's account selection. The service APIs take a 24-hour service token from separate credentials. Sandbox access is self-service. Production needs a questionnaire, a security review and a signed agreement.",
      "pricing": "paid",
      "pricingNotes": "No price is published. The pricing page names Standard (fewer than 10,000 monthly connections, self-service onboarding) and Enterprise (10,000 or more, custom pricing) without figures, and its FAQ says a set-up or implementation fee may apply. The sandbox is free and self-service with test data, so an agent's owner can start without a contract. Live data needs production approval (https://akoya.com/pricing, checked 2026-10-08).",
      "priceSummary": "Paid",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the OpenAPI specifications or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.akoya.com",
      "openapi": "https://docs.akoya.com/guides/akoya-apis-3-0-0-spec",
      "capabilities": [
        "bank.accounts",
        "bank.transactions",
        "bank.identity",
        "bank.consent"
      ],
      "tags": [
        "hosted",
        "oauth",
        "openapi",
        "fdx",
        "us-only",
        "sandbox",
        "webhooks",
        "sales-led",
        "closed-source",
        "soc2"
      ],
      "lastRelease": "2026-08-05",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 48.3,
        "grade": "D",
        "agentReady": false,
        "rank": 623,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 8,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 67,
          "maintenance": 33,
          "payments": 10,
          "reliability": 28,
          "schema": 70,
          "security": 64,
          "transparency": 58
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 28,
            "points": 5.6,
            "reason": "Graded as a hosted service. No public status page was found. status.akoya.com did not connect, and the docs place network availability and provider outages inside the Data Recipient Hub, behind a login (0). No readable incident history (5). The only number is a recommended maximum of 5 calls a second on the Apps Management API, with none for the data APIs (5 of 15). The docs name 429 with code 1207 and say to slow bulk requests, and advise three retries with exponential backoff on 5xx. No Retry-After header and no idempotency key for app creation were found (8 of 15). No SLA is published. The home page's 99.9%+ network availability is a vendor claim, not a commitment (0). The v3 data APIs have been in production since 23 February 2026, with only the Tax product marked beta (10). Total 28."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 70,
            "points": 11.38,
            "reason": "OpenAPI 3.1 specifications are published for all six APIs, as YAML code blocks to copy from docs pages with no raw file address (20 of 25). No `llms.txt` or Markdown docs. docs.akoya.com/llms.txt returns the HTML docs page (0). Each endpoint states its purpose, and guides say which product fits a use case, such as preferring customer information over `/contacts` (14 of 20). Parameters are typed and the data spec carries 73 enums, but `limit` is typed as a string and the docs warn that providers may return unknown enum values (10 of 15). The spec carries response examples, and an error reference lists codes with causes (13 of 15). The major version is in the path, with a version timeline and a changelog of eight entries since early 2025 (13 of 15). Total 70."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 67,
            "points": 10.89,
            "reason": "Responses can be sized with `limit` (default 50), `offset`, `startTime`, `endTime` and an `accountIds` filter. No field selection was found (17 of 25). Link-based pagination through `links.next.href`, though a small number of providers return no `prev` link (17 of 20). Errors carry a stable `code`, a `message` and an optional `debugMessage`, with causes documented. Code 602 covers both an expired token and missing consent (15 of 20). Every data endpoint is a GET, so calls are safe to repeat, and retry advice is documented. App creation has no idempotency key (14 of 20). v3 needs two or three custom headers and a provider ID on every call, the ID token stands in for an access token, and there is no SDK, only a Postman workspace (4 of 15). Total 67."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 64,
            "points": 11.2,
            "reason": "OAuth 2.0 authorisation code grant with OpenID Connect. Tokens are issued per consumer and per app, ID tokens last 15 minutes to 24 hours, refresh tokens rotate, and `/revoke` ends a grant. Scopes are fixed, and access is narrowed by product subscriptions and the consumer's account selection (26 of 30). The data APIs are read-only, and the Hub has admin and viewer roles with mandatory MFA (17 of 20). The APIs return bank-written transaction descriptions, and no guidance on treating them as untrusted was found (7 of 15). Each response carries `x-akoya-interaction-id` for tracing. No per-call log for the operator was found (4 of 15). The security page states SOC 2 Type 2 and a security review of every participant. No security.txt, disclosure policy or bug bounty was found (10 of 20). Total 64."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 10,
            "points": 1.25,
            "reason": "No x402, MPP or L402 (0). The pricing page names Standard and Enterprise plans by monthly connections with no figures, and says a set-up fee may apply (0). The sandbox is free and self-service with test data and no card mentioned. There is no free live tier (10 of 20). A person requests a Data Recipient Hub account and sets up MFA, and production needs a security review and a signed agreement (0). Total 10."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 33,
            "points": 2.89,
            "reason": "The data API specification is marked \"Updated 08/05/2026\", read as 5 August 2026, and the newest changelog entry is about 31 July 2026, so the last dated change is within 90 days (20). Two dated changes in the last 90 days, short of three (0). A public changelog and a support centre with ticketing inside the Hub. No public community channel was found (8 of 15). No official SDK. A Postman workspace is the only client tooling (3 of 15). Six current OpenAPI specifications, with no packages to assess (2 of 10). Total 33."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 58,
            "points": 5.08,
            "note": "editorial 44, provenance 72",
            "reason": "Closed service. The Terms of Use are public and dated 20 December 2024, while the data access agreement that governs production is not published (12 of 30). The privacy policy of 9 June 2025 gives no retention periods. The security page says Akoya passes data through without storing consumer financial data, while the docs say tokenised account number mappings are kept in a vault. No DPA was found (12 of 30). A version timeline gives release, deprecation and sunset dates with a six-month sunset rule. The Terms of Use still allow changes without prior notice (17 of 20). The privacy policy names Google Analytics. No subprocessor list or data location was found (3 of 20). Regulatory standing counts here as an addition to the checklist (+5 for a named regulator with a register number, +3 for a named regulator alone). Akoya names no regulator on the pages read (+0). Total 44."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "Responses can be sized with `limit` (default 50), `offset`, `startTime`, `endTime` and an `accountIds` filter. No field selection was found (17 of 25). Link-based pagination through `links.next.href`, though a small number of providers return no `prev` link (17 of 20). Errors carry a stable `code`, a `message` and an optional `debugMessage`, with causes documented. Code 602 covers both an expired token and missing consent (15 of 20). Every data endpoint is a GET, so calls are safe to repeat, and retry advice is documented. App creation has no idempotency key (14 of 20). v3 needs two or three custom headers and a provider ID on every call, the ID token stands in for an access token, and there is no SDK, only a Postman workspace (4 of 15). Total 67.",
            "maintenance": "The data API specification is marked \"Updated 08/05/2026\", read as 5 August 2026, and the newest changelog entry is about 31 July 2026, so the last dated change is within 90 days (20). Two dated changes in the last 90 days, short of three (0). A public changelog and a support centre with ticketing inside the Hub. No public community channel was found (8 of 15). No official SDK. A Postman workspace is the only client tooling (3 of 15). Six current OpenAPI specifications, with no packages to assess (2 of 10). Total 33.",
            "payments": "No x402, MPP or L402 (0). The pricing page names Standard and Enterprise plans by monthly connections with no figures, and says a set-up fee may apply (0). The sandbox is free and self-service with test data and no card mentioned. There is no free live tier (10 of 20). A person requests a Data Recipient Hub account and sets up MFA, and production needs a security review and a signed agreement (0). Total 10.",
            "reliability": "Graded as a hosted service. No public status page was found. status.akoya.com did not connect, and the docs place network availability and provider outages inside the Data Recipient Hub, behind a login (0). No readable incident history (5). The only number is a recommended maximum of 5 calls a second on the Apps Management API, with none for the data APIs (5 of 15). The docs name 429 with code 1207 and say to slow bulk requests, and advise three retries with exponential backoff on 5xx. No Retry-After header and no idempotency key for app creation were found (8 of 15). No SLA is published. The home page's 99.9%+ network availability is a vendor claim, not a commitment (0). The v3 data APIs have been in production since 23 February 2026, with only the Tax product marked beta (10). Total 28.",
            "schema": "OpenAPI 3.1 specifications are published for all six APIs, as YAML code blocks to copy from docs pages with no raw file address (20 of 25). No `llms.txt` or Markdown docs. docs.akoya.com/llms.txt returns the HTML docs page (0). Each endpoint states its purpose, and guides say which product fits a use case, such as preferring customer information over `/contacts` (14 of 20). Parameters are typed and the data spec carries 73 enums, but `limit` is typed as a string and the docs warn that providers may return unknown enum values (10 of 15). The spec carries response examples, and an error reference lists codes with causes (13 of 15). The major version is in the path, with a version timeline and a changelog of eight entries since early 2025 (13 of 15). Total 70.",
            "security": "OAuth 2.0 authorisation code grant with OpenID Connect. Tokens are issued per consumer and per app, ID tokens last 15 minutes to 24 hours, refresh tokens rotate, and `/revoke` ends a grant. Scopes are fixed, and access is narrowed by product subscriptions and the consumer's account selection (26 of 30). The data APIs are read-only, and the Hub has admin and viewer roles with mandatory MFA (17 of 20). The APIs return bank-written transaction descriptions, and no guidance on treating them as untrusted was found (7 of 15). Each response carries `x-akoya-interaction-id` for tracing. No per-call log for the operator was found (4 of 15). The security page states SOC 2 Type 2 and a security review of every participant. No security.txt, disclosure policy or bug bounty was found (10 of 20). Total 64.",
            "transparency": "Closed service. The Terms of Use are public and dated 20 December 2024, while the data access agreement that governs production is not published (12 of 30). The privacy policy of 9 June 2025 gives no retention periods. The security page says Akoya passes data through without storing consumer financial data, while the docs say tokenised account number mappings are kept in a vault. No DPA was found (12 of 30). A version timeline gives release, deprecation and sunset dates with a six-month sunset rule. The Terms of Use still allow changes without prior notice (17 of 20). The privacy policy names Google Analytics. No subprocessor list or data location was found (3 of 20). Regulatory standing counts here as an addition to the checklist (+5 for a named regulator with a register number, +3 for a named regulator alone). Akoya names no regulator on the pages read (+0). Total 44."
          },
          "sources": [
            {
              "what": "home page with network claims",
              "url": "https://akoya.com/",
              "seen": "2026-10-08"
            },
            {
              "what": "pricing page and FAQ",
              "url": "https://akoya.com/pricing",
              "seen": "2026-10-08"
            },
            {
              "what": "security page",
              "url": "https://akoya.com/security",
              "seen": "2026-10-08"
            },
            {
              "what": "Terms of Use",
              "url": "https://akoya.com/terms-of-use",
              "seen": "2026-10-08"
            },
            {
              "what": "privacy policy",
              "url": "https://akoya.com/privacy-policy",
              "seen": "2026-10-08"
            },
            {
              "what": "API overview",
              "url": "https://docs.akoya.com/guides/api-overview",
              "seen": "2026-10-08"
            },
            {
              "what": "getting started, with the first sandbox calls",
              "url": "https://docs.akoya.com/guides/getting-started",
              "seen": "2026-10-08"
            },
            {
              "what": "requirements and best practices",
              "url": "https://docs.akoya.com/guides/requirements",
              "seen": "2026-10-08"
            },
            {
              "what": "guide for production access",
              "url": "https://docs.akoya.com/guides/guide-for-production-access",
              "seen": "2026-10-08"
            },
            {
              "what": "API versioning and version timeline",
              "url": "https://docs.akoya.com/guides/api-versioning",
              "seen": "2026-10-08"
            },
            {
              "what": "API servers",
              "url": "https://docs.akoya.com/guides/api-servers",
              "seen": "2026-10-08"
            },
            {
              "what": "API error reference",
              "url": "https://docs.akoya.com/guides/api-error-reference",
              "seen": "2026-10-08"
            },
            {
              "what": "pagination guide",
              "url": "https://docs.akoya.com/guides/pagination",
              "seen": "2026-10-08"
            },
            {
              "what": "headers reference",
              "url": "https://docs.akoya.com/guides/headers",
              "seen": "2026-10-08"
            },
            {
              "what": "token overview",
              "url": "https://docs.akoya.com/guides/token-overview",
              "seen": "2026-10-08"
            },
            {
              "what": "OpenAPI 3.1 specification for the data APIs v3.0.0",
              "url": "https://docs.akoya.com/guides/akoya-apis-3-0-0-spec",
              "seen": "2026-10-08"
            },
            {
              "what": "Apps Management API guide",
              "url": "https://docs.akoya.com/reference/management-api",
              "seen": "2026-10-08"
            },
            {
              "what": "Notifications API guide",
              "url": "https://docs.akoya.com/reference/notifications-api",
              "seen": "2026-10-08"
            },
            {
              "what": "webhooks technical guide",
              "url": "https://docs.akoya.com/reference/webhooks",
              "seen": "2026-10-08"
            },
            {
              "what": "Data Recipient Hub manual, My Company",
              "url": "https://docs.akoya.com/guides/hub-manual-my-company",
              "seen": "2026-10-08"
            },
            {
              "what": "changelog",
              "url": "https://docs.akoya.com/akoya/changelog",
              "seen": "2026-10-08"
            },
            {
              "what": "v3 release note",
              "url": "https://docs.akoya.com/changelog/akoya-apis-v3-released-february-23-2026",
              "seen": "2026-10-08"
            },
            {
              "what": "sandbox data endpoint, unauthenticated request",
              "url": "https://sandbox-products.ddp.akoya.com/accounts-info/v3/mikomo",
              "seen": "2026-10-08"
            },
            {
              "what": "RDAP record for akoya.com",
              "url": "https://rdap.verisign.com/com/v1/domain/akoya.com",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "unchecked: whether a status page exists at an address we did not try. status.akoya.com, trust.akoya.com and security.akoya.com did not connect from our network",
            "unchecked: the data access agreement that governs production use, which is sent through Docusign and not published",
            "unchecked: https://recipient.ddp.akoya.com/terms-of-use, named as the licence in the OpenAPI files, which returned a script shell",
            "The specification date \"Updated 08/05/2026\" is read in US order as 5 August 2026. Read as 8 May 2026, the newest dated change would be the changelog entry of about 31 July 2026",
            "The changelog shows relative dates only (\"69 days ago\"), so its entry dates are computed from 8 October 2026",
            "Whether the Standard plan has a list price. None is shown on the pricing page",
            "Whether section 7(b) of the Terms of Use, on automated systems, is meant to cover an AI agent calling the API under a data recipient's credentials",
            "The lead described Akoya as bank-owned. The pages read today do not state its ownership",
            "No sunset date is shown for v2 in the version timeline. The six-month rule would place it near 23 August 2026"
          ]
        },
        "negative": 0,
        "verdict": "Six OpenAPI 3.1 specifications, a free self-service sandbox and read-only data endpoints behind per-consumer OAuth tokens make the API straightforward to test. Production needs a security review and a signed agreement, no price is published, and no public status page, SLA, SDK or `llms.txt` was found.",
        "bestFor": "A US fintech that wants consumer-permissioned data over direct institution APIs in FDX format and can pass a security review.",
        "strengths": [
          "Data APIs are read-only GET endpoints, and each token covers one consumer, one app and the accounts that consumer selected",
          "OpenAPI 3.1 specifications are published for the Token, Service Token, data, Apps Management, Notifications and Consent APIs",
          "Free self-service sandbox with a test institution (`mikomo`), scripted test users and a public Postman workspace",
          "Written version policy. Breaking changes only in major versions, with a six-month sunset after deprecation",
          "Webhooks report consent revocation, consent updates and planned or unplanned outages, with three delivery attempts"
        ],
        "weaknesses": [
          "No price is published. Standard (under 10,000 monthly connections) and Enterprise are named without figures, and a set-up fee may apply",
          "Production access needs an onboarding questionnaire, a security review (SOC 2 report or questionnaire) and an agreement signed by Docusign",
          "No public status page, SLA or numeric rate limit for the data APIs was found. Availability figures sit inside the Data Recipient Hub",
          "The Terms of Use forbid using any automated system to access the network and allow changes and termination without prior notice",
          "No SDK, `llms.txt` or Markdown docs. The OpenAPI files are code blocks to copy from docs pages, not downloadable files"
        ],
        "agentNotes": [
          "Send `x-akoya-interaction-type` (USER or BATCH) and `x-akoya-last-access` on every v3 data call, plus `x-akoya-intent-type` if the app subscribes to Payments",
          "Use the `id_token` as the bearer token. The `/token` response has no `access_token` field, so generic OAuth libraries need adjusting",
          "Treat ID tokens as valid for 15 minutes, refresh on error 602, and store the new refresh token returned by every refresh",
          "Page transactions by following `links.next.href` unchanged. Set `limit`, `startTime` and `endTime` on the first call only",
          "On 429 with code 1207 slow the request rate. On 5xx retry up to three times with exponential backoff"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 48.3
          }
        ],
        "editorialScores": {
          "ergonomics": 67,
          "maintenance": 33,
          "payments": 10,
          "reliability": 28,
          "schema": 70,
          "security": 64,
          "transparency": 44
        },
        "provenanceScore": 72
      },
      "connect": {
        "http": "curl --request GET --url 'https://sandbox-products.ddp.akoya.com/accounts-info/v3/mikomo' --header 'x-akoya-interaction-type: USER' --header 'x-akoya-last-access: 2025-11-24T00:00:00Z' --header 'accept: application/json' --header 'authorization: Bearer {{id_token}}'"
      },
      "letme": {
        "capability": "https://letme.dev/bank.accounts",
        "tool": "https://letme.dev/akoya"
      },
      "notable": [
        "The data APIs moved to v3 in production on 23 February 2026, a breaking change announced on 15 January 2026 that made three request headers mandatory (https://docs.akoya.com/reference/akoya-apis-v3-guide)",
        "An unauthenticated GET to `https://sandbox-products.ddp.akoya.com/accounts-info/v3/mikomo` answered 401 with `{\"code\":602, \"message\":\"Customer not authorized\"}` on 8 October 2026",
        "Section 7(b) of the Terms of Use, last updated 20 December 2024, forbids using or launching any automated system to access the network, and acting as an intermediary or aggregator (https://akoya.com/terms-of-use)",
        "Production access follows an onboarding questionnaire, a security and risk review and a data access agreement signed through Docusign (https://docs.akoya.com/guides/guide-for-production-access)",
        "The pricing page names two plans by monthly connections and gives no figures. Its FAQ says a set-up or implementation fee may apply (https://akoya.com/pricing)",
        "The Payments product returns account and routing identifiers, or tokenised account numbers, for ACH and RTP. It does not move money (https://docs.akoya.com/guides/api-overview)",
        "Akoya says it passes data through and does not store consumer financial data or login credentials, and that it holds SOC 2 Type 2 (https://akoya.com/security)",
        "The home page counts 4,500+ financial institutions and 7,500+ apps, while the fintechs page says 4,300+ and 7,000+. Both are vendor claims (https://akoya.com/)"
      ],
      "area": "domain-data",
      "details": [
        {
          "label": "APIs",
          "value": "Token API v2.2.0, Service Token API v1.0.1, data APIs v3.0.0 (12 paths), Apps Management API v2.0.0, Notifications API v1.1.0, Consent API v1.1.0"
        },
        {
          "label": "Data endpoints",
          "value": "`/accounts-info`, `/balances`, `/accounts` (investments), `/taxlots`, `/customers/.../current`, `/contacts`, `/payments/.../payment-networks`, `/statements`, `/tax-forms` (beta), `/transactions`, each as `/{product}/v3/{providerId}`"
        },
        {
          "label": "Servers",
          "value": "Sandbox `sandbox-idp.ddp.akoya.com`, `sandbox-sts.ddp.akoya.com`, `sandbox-products.ddp.akoya.com`, `sandbox-api.akoya.com`. Production `idp.ddp.akoya.com`, `sts.ddp.akoya.com`, `products.ddp.akoya.com`, `api.akoya.com`"
        },
        {
          "label": "Credentials",
          "value": "Per-app client ID and secret, authorisation code valid 5 minutes, ID token (JWT) valid up to 24 hours and often 15 minutes, rotating refresh token, 24-hour service token for the service APIs"
        },
        {
          "label": "Required v3 headers",
          "value": "`x-akoya-interaction-type` (USER or BATCH), `x-akoya-last-access` (ISO 8601, UTC), `x-akoya-intent-type` (payments or nonpayments) for apps subscribed to Payments"
        },
        {
          "label": "Pagination",
          "value": "`limit` (default 50), `offset`, `startTime`, `endTime` on the first call, then `links.next.href`. A small number of providers return no `prev` link"
        },
        {
          "label": "Errors",
          "value": "JSON body with `code`, `message` and optional `debugMessage`. 602 customer not authorised, 701 account not found, 703 invalid date range, 1207 too many requests (429), 503 scheduled maintenance"
        },
        {
          "label": "Rate limits",
          "value": "A recommended maximum of 5 calls a second on the Apps Management API. No number found for the data APIs"
        },
        {
          "label": "Sandbox",
          "value": "Free and self-service through the Data Recipient Hub, test institution `mikomo`, up to 10 sandbox apps through the Apps Management API"
        },
        {
          "label": "Webhooks",
          "value": "CONSENT_REVOKED, CONSENT_UPDATED, PLANNED_OUTAGE and SERVICE events to an HTTPS callback, three delivery attempts, a sandbox test event endpoint"
        },
        {
          "label": "Versions",
          "value": "v1 sunset 2 May 2023, v2 deprecated 23 February 2026, v3 current. A deprecated version sunsets six months after deprecation"
        },
        {
          "label": "Coverage",
          "value": "United States only. The Terms of Use limit use to people located in the US"
        }
      ],
      "provenance": {
        "legalEntity": "Akoya LLC",
        "domain": "akoya.com",
        "domainRegistered": "1998-06-24",
        "endpointOnVendorDomain": true,
        "terms": "https://akoya.com/terms-of-use",
        "privacy": "https://akoya.com/privacy-policy",
        "statusPage": "",
        "changelog": "https://docs.akoya.com/akoya/changelog",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The Terms of Use (last updated 20 December 2024) name Akoya LLC and govern use of the Akoya Data Access Network and akoya.com. Production use also runs under a data access agreement signed through Docusign, which is not published.",
          "The privacy policy (last updated 9 June 2025) covers the website and Akoya's products and services, and gives the address 6 Liberty Square #2381, Boston, MA 02109.",
          "The OpenAPI files name https://recipient.ddp.akoya.com/terms-of-use as their licence. That address returned a 755-byte script shell to our reader.",
          "akoya.com/.well-known/security.txt and docs.akoya.com/.well-known/security.txt both returned 404.",
          "No public status page was found. status.akoya.com did not connect, and the docs place network availability and outages inside the Data Recipient Hub, behind a login.",
          "RDAP (Verisign) gives a registration date of 1998-06-24 for akoya.com."
        ],
        "score": 72,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Akoya LLC",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "akoya.com, registered 1998-06-24 (28 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "products.ddp.akoya.com",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 7 of the 7 things a reader expects, and has 2 clauses that cost points",
            "points": 6,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 2 of the 8 things a reader expects",
            "points": 5.5,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Status page",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://akoya.com/terms-of-use",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2024-12-20",
            "words": 3509,
            "points": 6,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last Updated: December 20, 2024",
                "says": "Last updated 2024-12-20"
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "These Terms and their enforcement will be governed by the laws of the New York, without regard to conflicts of law provisions.",
                "says": "The law of New York"
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "…TO THOSE BASED ON CONTRACT, TORT OR OTHERWISE, ARISING OUT OF YOUR USE OF THE DAN OR THE SITE WILL NOT EXCEED ONE HUNDRED DOLLARS ($100).",
                "says": "Capped at $100"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "(b) Akoya may, in its sole discretion, accept or reject your request to register for an Account and may disable or otherwise suspend your access to your Account or the DAN at any time for any reason or no reason whatsoever, including if Akoya suspects fraud or illegal, unauthorized, or improper conduct or for security…"
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": true,
                "quote": "Akoya may modify these Terms at any time and without prior notice.",
                "says": "Says it gives notice of a change"
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "IF YOU DO NOT AGREE TO THESE TERMS, YOU MAY NOT USE THE DAN OR THE SITE."
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": true,
                "quote": "The DAN and the Site may be subject to sporadic interruptions and failures for a variety of reasons beyond Akoya’s control, including third party network failures and coverage limitations, service provider uptime, and acts of God."
              }
            ],
            "toKnow": [
              {
                "key": "terms.automated",
                "label": "Restricts automated access",
                "found": true,
                "quote": "(iv) use or launch any automated system, including “robots,” “spiders,” or “offline readers,” to access the DAN or the Site;",
                "costsPoints": true
              },
              {
                "key": "terms.nonotice",
                "label": "Says the terms or the service can change without notice",
                "found": true,
                "quote": "Akoya may modify these Terms at any time and without prior notice.",
                "costsPoints": true
              },
              {
                "key": "terms.cutoff",
                "label": "Says access can be ended without notice or for any reason",
                "found": true,
                "quote": "Akoya may discontinue the DAN or the Site or terminate your access to all or any part thereof for any reason, without prior notice, with or without cause."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Total liability for use of the network or the site is capped at 100 US dollars.",
                "quote": "ARISING OUT OF YOUR USE OF THE DAN OR THE SITE WILL NOT EXCEED ONE HUNDRED DOLLARS ($100)."
              },
              {
                "date": "2026-10-08",
                "text": "The user grants Akoya a perpetual, irrevocable licence over data submitted through the network or site, for running them and for any other lawful purpose, and the licence survives termination.",
                "quote": "to use any such data or information as is necessary or useful in connection with the provision of the DAN or the Site and for any other lawful purpose."
              },
              {
                "date": "2026-10-08",
                "text": "Users may not act as an intermediary, aggregator or service bureau, for themselves or for a third party.",
                "quote": "(v) act as an intermediary, aggregator, or service bureau yourself or on behalf of any third party."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://akoya.com/privacy-policy",
            "state": "read",
            "readAt": "2026-10-08",
            "words": 1174,
            "points": 5.5,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": false
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "When you use the Services, we may collect your contact information (such as your name, the company you work for or represent, telephone number(s), email address), unique device and online identifiers (such as IP address, device IDs), and internet or other electronic activity information (such as browser type, web page…"
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": false
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "We may share your personal information with third party vendors that help us create and deliver the Services and improve our Services."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": false
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": false
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": false
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": false
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/akoya.json",
      "live": {
        "slug": "akoya",
        "probe": {
          "target": "https://products.ddp.akoya.com",
          "method": "get",
          "lastAt": "2026-10-08T22:39:40.088616835Z",
          "lastOk": true,
          "lastStatus": 403,
          "lastMs": 342,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 333,
          "p95ms24h": 384,
          "samples24h": 36,
          "samples30d": 36,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 36,
              "ok": 36
            }
          ]
        },
        "updatedAt": "2026-10-08T22:39:40.088616835Z"
      }
    },
    "verify": {
      "accepts": "a page on akoya.com or one of its subdomains",
      "badgeUrl": "https://www.anchorterminal.com/badges/akoya.svg",
      "body": {
        "slug": "akoya",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/akoya",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/akoya\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/akoya.svg\" alt=\"Akoya on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Akoya on Anchor Terminal](https://www.anchorterminal.com/badges/akoya.svg)](https://www.anchorterminal.com/tools/akoya)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/akoya\"\u003eAkoya on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/akoya",
    "json": "https://www.anchorterminal.com/tools/akoya.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/akoya.md",
    "slim": "https://www.anchorterminal.com/tools/akoya.min.md"
  },
  "markdown": "## Overview\n\n**Grade D · 48.3/100 · rank #623 of 722 · #8 in Bank data \u0026 open banking · not agent-ready · confidence medium**\n\n\n## Assessment\n\nSix OpenAPI 3.1 specifications, a free self-service sandbox and read-only data endpoints behind per-consumer OAuth tokens make the API straightforward to test. Production needs a security review and a signed agreement, no price is published, and no public status page, SLA, SDK or `llms.txt` was found.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Akoya LLC (https://akoya.com) |\n| Kind | HTTP API |\n| Category | Bank data \u0026 open banking (https://www.anchorterminal.com/categories/banking-data) |\n| Transport | HTTP |\n| Endpoint | `https://products.ddp.akoya.com` |\n| Auth | OAuth · OAuth 2.0 authorisation code grant with OpenID Connect. A person requests a Data Recipient Hub account (MFA is mandatory), registers an app and receives a client ID and secret. The consumer signs in at their own institution, picks the accounts to share, and the app exchanges the code at `/token` for an ID token and a refresh token. The ID token is the bearer token for data calls. The only scopes are `openid profile offline_access`, and what an app can read is set by its product subscriptions and the consumer's account selection. The service APIs take a 24-hour service token from separate credentials. Sandbox access is self-service. Production needs a questionnaire, a security review and a signed agreement. |\n| Pricing | Paid (Paid) · No price is published. The pricing page names Standard (fewer than 10,000 monthly connections, self-service onboarding) and Enterprise (10,000 or more, custom pricing) without figures, and its FAQ says a set-up or implementation fee may apply. The sandbox is free and self-service with test data, so an agent's owner can start without a contract. Live data needs production approval (https://akoya.com/pricing, checked 2026-10-08). |\n| x402 | No · No x402, MPP or L402 in the docs, the OpenAPI specifications or the pricing page (checked 2026-10-08). |\n| Licence | Proprietary service under the Akoya Terms of Use and a signed data access agreement |\n| Docs | https://docs.akoya.com |\n| llms.txt | not found |\n| Last release | 2026-08-05 |\n| APIs | Token API v2.2.0, Service Token API v1.0.1, data APIs v3.0.0 (12 paths), Apps Management API v2.0.0, Notifications API v1.1.0, Consent API v1.1.0 |\n| Data endpoints | `/accounts-info`, `/balances`, `/accounts` (investments), `/taxlots`, `/customers/.../current`, `/contacts`, `/payments/.../payment-networks`, `/statements`, `/tax-forms` (beta), `/transactions`, each as `/{product}/v3/{providerId}` |\n| Servers | Sandbox `sandbox-idp.ddp.akoya.com`, `sandbox-sts.ddp.akoya.com`, `sandbox-products.ddp.akoya.com`, `sandbox-api.akoya.com`. Production `idp.ddp.akoya.com`, `sts.ddp.akoya.com`, `products.ddp.akoya.com`, `api.akoya.com` |\n| Credentials | Per-app client ID and secret, authorisation code valid 5 minutes, ID token (JWT) valid up to 24 hours and often 15 minutes, rotating refresh token, 24-hour service token for the service APIs |\n| Required v3 headers | `x-akoya-interaction-type` (USER or BATCH), `x-akoya-last-access` (ISO 8601, UTC), `x-akoya-intent-type` (payments or nonpayments) for apps subscribed to Payments |\n| Pagination | `limit` (default 50), `offset`, `startTime`, `endTime` on the first call, then `links.next.href`. A small number of providers return no `prev` link |\n| Errors | JSON body with `code`, `message` and optional `debugMessage`. 602 customer not authorised, 701 account not found, 703 invalid date range, 1207 too many requests (429), 503 scheduled maintenance |\n| Rate limits | A recommended maximum of 5 calls a second on the Apps Management API. No number found for the data APIs |\n| Sandbox | Free and self-service through the Data Recipient Hub, test institution `mikomo`, up to 10 sandbox apps through the Apps Management API |\n| Webhooks | CONSENT_REVOKED, CONSENT_UPDATED, PLANNED_OUTAGE and SERVICE events to an HTTPS callback, three delivery attempts, a sandbox test event endpoint |\n| Versions | v1 sunset 2 May 2023, v2 deprecated 23 February 2026, v3 current. A deprecated version sunsets six months after deprecation |\n| Coverage | United States only. The Terms of Use limit use to people located in the US |\n| Capabilities | bank.accounts, bank.transactions, bank.identity, bank.consent |\n| Tags | hosted, oauth, openapi, fdx, us-only, sandbox, webhooks, sales-led, closed-source, soc2 |\n| JSON | https://www.anchorterminal.com/api/v1/tools/akoya.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 28 | 5.6 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 70 | 11.4 |\n| Agent ergonomics | 13% | 16.2 | 67 | 10.9 |\n| Security \u0026 auth | 14% | 17.5 | 64 | 11.2 |\n| Payments \u0026 pricing | 10% | 12.5 | 10 | 1.2 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 33 | 2.9 |\n| Transparency \u0026 trust (editorial 44, provenance 72) | 7% | 8.8 | 58 | 5.1 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **48.3 → D** |\n\n### Why each score\n\n- Reliability 28: Graded as a hosted service. No public status page was found. status.akoya.com did not connect, and the docs place network availability and provider outages inside the Data Recipient Hub, behind a login (0). No readable incident history (5). The only number is a recommended maximum of 5 calls a second on the Apps Management API, with none for the data APIs (5 of 15). The docs name 429 with code 1207 and say to slow bulk requests, and advise three retries with exponential backoff on 5xx. No Retry-After header and no idempotency key for app creation were found (8 of 15). No SLA is published. The home page's 99.9%+ network availability is a vendor claim, not a commitment (0). The v3 data APIs have been in production since 23 February 2026, with only the Tax product marked beta (10). Total 28.\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 70: OpenAPI 3.1 specifications are published for all six APIs, as YAML code blocks to copy from docs pages with no raw file address (20 of 25). No `llms.txt` or Markdown docs. docs.akoya.com/llms.txt returns the HTML docs page (0). Each endpoint states its purpose, and guides say which product fits a use case, such as preferring customer information over `/contacts` (14 of 20). Parameters are typed and the data spec carries 73 enums, but `limit` is typed as a string and the docs warn that providers may return unknown enum values (10 of 15). The spec carries response examples, and an error reference lists codes with causes (13 of 15). The major version is in the path, with a version timeline and a changelog of eight entries since early 2025 (13 of 15). Total 70.\n- Agent ergonomics 67: Responses can be sized with `limit` (default 50), `offset`, `startTime`, `endTime` and an `accountIds` filter. No field selection was found (17 of 25). Link-based pagination through `links.next.href`, though a small number of providers return no `prev` link (17 of 20). Errors carry a stable `code`, a `message` and an optional `debugMessage`, with causes documented. Code 602 covers both an expired token and missing consent (15 of 20). Every data endpoint is a GET, so calls are safe to repeat, and retry advice is documented. App creation has no idempotency key (14 of 20). v3 needs two or three custom headers and a provider ID on every call, the ID token stands in for an access token, and there is no SDK, only a Postman workspace (4 of 15). Total 67.\n- Security \u0026 auth 64: OAuth 2.0 authorisation code grant with OpenID Connect. Tokens are issued per consumer and per app, ID tokens last 15 minutes to 24 hours, refresh tokens rotate, and `/revoke` ends a grant. Scopes are fixed, and access is narrowed by product subscriptions and the consumer's account selection (26 of 30). The data APIs are read-only, and the Hub has admin and viewer roles with mandatory MFA (17 of 20). The APIs return bank-written transaction descriptions, and no guidance on treating them as untrusted was found (7 of 15). Each response carries `x-akoya-interaction-id` for tracing. No per-call log for the operator was found (4 of 15). The security page states SOC 2 Type 2 and a security review of every participant. No security.txt, disclosure policy or bug bounty was found (10 of 20). Total 64.\n- Payments \u0026 pricing 10: No x402, MPP or L402 (0). The pricing page names Standard and Enterprise plans by monthly connections with no figures, and says a set-up fee may apply (0). The sandbox is free and self-service with test data and no card mentioned. There is no free live tier (10 of 20). A person requests a Data Recipient Hub account and sets up MFA, and production needs a security review and a signed agreement (0). Total 10.\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 33: The data API specification is marked \"Updated 08/05/2026\", read as 5 August 2026, and the newest changelog entry is about 31 July 2026, so the last dated change is within 90 days (20). Two dated changes in the last 90 days, short of three (0). A public changelog and a support centre with ticketing inside the Hub. No public community channel was found (8 of 15). No official SDK. A Postman workspace is the only client tooling (3 of 15). Six current OpenAPI specifications, with no packages to assess (2 of 10). Total 33.\n- Transparency \u0026 trust 58: Closed service. The Terms of Use are public and dated 20 December 2024, while the data access agreement that governs production is not published (12 of 30). The privacy policy of 9 June 2025 gives no retention periods. The security page says Akoya passes data through without storing consumer financial data, while the docs say tokenised account number mappings are kept in a vault. No DPA was found (12 of 30). A version timeline gives release, deprecation and sunset dates with a six-month sunset rule. The Terms of Use still allow changes without prior notice (17 of 20). The privacy policy names Google Analytics. No subprocessor list or data location was found (3 of 20). Regulatory standing counts here as an addition to the checklist (+5 for a named regulator with a register number, +3 for a named regulator alone). Akoya names no regulator on the pages read (+0). Total 44.\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (20 items): https://www.anchorterminal.com/fixes/akoya.md (JSON https://www.anchorterminal.com/fixes/akoya.json)\n\n### What we couldn't check\n\n- unchecked: whether a status page exists at an address we did not try. status.akoya.com, trust.akoya.com and security.akoya.com did not connect from our network\n- unchecked: the data access agreement that governs production use, which is sent through Docusign and not published\n- unchecked: https://recipient.ddp.akoya.com/terms-of-use, named as the licence in the OpenAPI files, which returned a script shell\n- The specification date \"Updated 08/05/2026\" is read in US order as 5 August 2026. Read as 8 May 2026, the newest dated change would be the changelog entry of about 31 July 2026\n- The changelog shows relative dates only (\"69 days ago\"), so its entry dates are computed from 8 October 2026\n- Whether the Standard plan has a list price. None is shown on the pricing page\n- Whether section 7(b) of the Terms of Use, on automated systems, is meant to cover an AI agent calling the API under a data recipient's credentials\n- The lead described Akoya as bank-owned. The pages read today do not state its ownership\n- No sunset date is shown for v2 in the version timeline. The six-month rule would place it near 23 August 2026\n\n### Sources\n\n- home page with network claims: \u003chttps://akoya.com/\u003e (seen 2026-10-08)\n- pricing page and FAQ: \u003chttps://akoya.com/pricing\u003e (seen 2026-10-08)\n- security page: \u003chttps://akoya.com/security\u003e (seen 2026-10-08)\n- Terms of Use: \u003chttps://akoya.com/terms-of-use\u003e (seen 2026-10-08)\n- privacy policy: \u003chttps://akoya.com/privacy-policy\u003e (seen 2026-10-08)\n- API overview: \u003chttps://docs.akoya.com/guides/api-overview\u003e (seen 2026-10-08)\n- getting started, with the first sandbox calls: \u003chttps://docs.akoya.com/guides/getting-started\u003e (seen 2026-10-08)\n- requirements and best practices: \u003chttps://docs.akoya.com/guides/requirements\u003e (seen 2026-10-08)\n- guide for production access: \u003chttps://docs.akoya.com/guides/guide-for-production-access\u003e (seen 2026-10-08)\n- API versioning and version timeline: \u003chttps://docs.akoya.com/guides/api-versioning\u003e (seen 2026-10-08)\n- API servers: \u003chttps://docs.akoya.com/guides/api-servers\u003e (seen 2026-10-08)\n- API error reference: \u003chttps://docs.akoya.com/guides/api-error-reference\u003e (seen 2026-10-08)\n- pagination guide: \u003chttps://docs.akoya.com/guides/pagination\u003e (seen 2026-10-08)\n- headers reference: \u003chttps://docs.akoya.com/guides/headers\u003e (seen 2026-10-08)\n- token overview: \u003chttps://docs.akoya.com/guides/token-overview\u003e (seen 2026-10-08)\n- OpenAPI 3.1 specification for the data APIs v3.0.0: \u003chttps://docs.akoya.com/guides/akoya-apis-3-0-0-spec\u003e (seen 2026-10-08)\n- Apps Management API guide: \u003chttps://docs.akoya.com/reference/management-api\u003e (seen 2026-10-08)\n- Notifications API guide: \u003chttps://docs.akoya.com/reference/notifications-api\u003e (seen 2026-10-08)\n- webhooks technical guide: \u003chttps://docs.akoya.com/reference/webhooks\u003e (seen 2026-10-08)\n- Data Recipient Hub manual, My Company: \u003chttps://docs.akoya.com/guides/hub-manual-my-company\u003e (seen 2026-10-08)\n- changelog: \u003chttps://docs.akoya.com/akoya/changelog\u003e (seen 2026-10-08)\n- v3 release note: \u003chttps://docs.akoya.com/changelog/akoya-apis-v3-released-february-23-2026\u003e (seen 2026-10-08)\n- sandbox data endpoint, unauthenticated request: \u003chttps://sandbox-products.ddp.akoya.com/accounts-info/v3/mikomo\u003e (seen 2026-10-08)\n- RDAP record for akoya.com: \u003chttps://rdap.verisign.com/com/v1/domain/akoya.com\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 72/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Akoya LLC | 20/20 |\n| Domain age | akoya.com, registered 1998-06-24 (28 years) | 15/15 |\n| Endpoint on the vendor's domain | products.ddp.akoya.com | 15/15 |\n| Terms of service | read, states 7 of the 7 things a reader expects, and has 2 clauses that cost points | 6/10 |\n| Privacy policy | read, states 2 of the 8 things a reader expects | 5.5/10 |\n| Status page | not found | 0/10 |\n| Changelog | published | 10/10 |\n| security.txt | not found | 0/10 |\n\nThe Terms of Use (last updated 20 December 2024) name Akoya LLC and govern use of the Akoya Data Access Network and akoya.com. Production use also runs under a data access agreement signed through Docusign, which is not published.\n\nThe privacy policy (last updated 9 June 2025) covers the website and Akoya's products and services, and gives the address 6 Liberty Square #2381, Boston, MA 02109.\n\nThe OpenAPI files name https://recipient.ddp.akoya.com/terms-of-use as their licence. That address returned a 755-byte script shell to our reader.\n\nakoya.com/.well-known/security.txt and docs.akoya.com/.well-known/security.txt both returned 404.\n\nNo public status page was found. status.akoya.com did not connect, and the docs place network availability and outages inside the Data Recipient Hub, behind a login.\n\nRDAP (Verisign) gives a registration date of 1998-06-24 for akoya.com.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://akoya.com/terms-of-use), read 2026-10-08, dated 2024-12-20, states 7 of the 7 things a reader expects.\n\n- To know. Restricts automated access (costs points). \"(iv) use or launch any automated system, including “robots,” “spiders,” or “offline readers,” to access the DAN or the Site;\"\n- To know. Says the terms or the service can change without notice (costs points). \"Akoya may modify these Terms at any time and without prior notice.\"\n- To know. Says access can be ended without notice or for any reason. \"Akoya may discontinue the DAN or the Site or terminate your access to all or any part thereof for any reason, without prior notice, with or without cause.\"\n- Gives the date it was last updated. Last updated 2024-12-20.\n- Names the governing law or courts. The law of New York.\n- States a limit on its liability. Capped at $100.\n- Says how changes to the terms are announced. Says it gives notice of a change.\n- Also in the text (2026-10-08). Total liability for use of the network or the site is capped at 100 US dollars. \"ARISING OUT OF YOUR USE OF THE DAN OR THE SITE WILL NOT EXCEED ONE HUNDRED DOLLARS ($100).\"\n- Also in the text (2026-10-08). The user grants Akoya a perpetual, irrevocable licence over data submitted through the network or site, for running them and for any other lawful purpose, and the licence survives termination. \"to use any such data or information as is necessary or useful in connection with the provision of the DAN or the Site and for any other lawful purpose.\"\n- Also in the text (2026-10-08). Users may not act as an intermediary, aggregator or service bureau, for themselves or for a third party. \"(v) act as an intermediary, aggregator, or service bureau yourself or on behalf of any third party.\"\n\n**Privacy policy** (https://akoya.com/privacy-policy), read 2026-10-08, gives no date, states 2 of the 8 things a reader expects.\n\n- Not found in the text. Gives the date it was last updated.\n- Not found in the text. Says how long data is kept.\n- Not found in the text. Says whether personal data is sold or shared for advertising.\n- Not found in the text. Says what rights people have over their data.\n- Not found in the text. Gives a privacy contact.\n- Not found in the text. Says where data is transferred or stored.\n\n## Live (updated 2026-10-08 22:39 UTC)\n\n- Right now: up, HTTP 403, 342 ms, checked 2026-10-08 22:39 UTC (get on `https://products.ddp.akoya.com`, asks for auth)\n- Uptime 24h 100.0% (36 probes) · 30 days 100.0% (36 probes) · p50 333 ms · p95 384 ms\n- Always current: https://www.anchorterminal.com/api/v1/live/akoya.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Strengths\n\n- Data APIs are read-only GET endpoints, and each token covers one consumer, one app and the accounts that consumer selected\n- OpenAPI 3.1 specifications are published for the Token, Service Token, data, Apps Management, Notifications and Consent APIs\n- Free self-service sandbox with a test institution (`mikomo`), scripted test users and a public Postman workspace\n- Written version policy. Breaking changes only in major versions, with a six-month sunset after deprecation\n- Webhooks report consent revocation, consent updates and planned or unplanned outages, with three delivery attempts\n\n## Weaknesses\n\n- No price is published. Standard (under 10,000 monthly connections) and Enterprise are named without figures, and a set-up fee may apply\n- Production access needs an onboarding questionnaire, a security review (SOC 2 report or questionnaire) and an agreement signed by Docusign\n- No public status page, SLA or numeric rate limit for the data APIs was found. Availability figures sit inside the Data Recipient Hub\n- The Terms of Use forbid using any automated system to access the network and allow changes and termination without prior notice\n- No SDK, `llms.txt` or Markdown docs. The OpenAPI files are code blocks to copy from docs pages, not downloadable files\n\n## Before you call it (notes for agents)\n\n1. Send `x-akoya-interaction-type` (USER or BATCH) and `x-akoya-last-access` on every v3 data call, plus `x-akoya-intent-type` if the app subscribes to Payments\n2. Use the `id_token` as the bearer token. The `/token` response has no `access_token` field, so generic OAuth libraries need adjusting\n3. Treat ID tokens as valid for 15 minutes, refresh on error 602, and store the new refresh token returned by every refresh\n4. Page transactions by following `links.next.href` unchanged. Set `limit`, `startTime` and `endTime` on the first call only\n5. On 429 with code 1207 slow the request rate. On 5xx retry up to three times with exponential backoff\n\n## Connect\n\nFirst request:\n\n```bash\ncurl --request GET --url 'https://sandbox-products.ddp.akoya.com/accounts-info/v3/mikomo' --header 'x-akoya-interaction-type: USER' --header 'x-akoya-last-access: 2025-11-24T00:00:00Z' --header 'accept: application/json' --header 'authorization: Bearer {{id_token}}'\n```\n\nThrough letme (picks today, calling later): https://letme.dev/akoya. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Plaid | B | 69.8 | 147 | bank.accounts, bank.transactions, bank.identity, bank.consent | no | https://www.anchorterminal.com/tools/plaid.md |\n| Belvo | B | 63.5 | 309 | bank.accounts, bank.transactions, bank.identity, bank.consent | no | https://www.anchorterminal.com/tools/belvo.md |\n| MX Platform API | B | 62.5 | 336 | bank.accounts, bank.transactions, bank.identity, bank.consent | no | https://www.anchorterminal.com/tools/mx.md |\n| Tink | B | 62.5 | 337 | bank.accounts, bank.transactions, bank.consent, bank.identity | no | https://www.anchorterminal.com/tools/tink.md |\n| TrueLayer | B | 62.1 | 347 | bank.accounts, bank.transactions, bank.identity, bank.consent | no | https://www.anchorterminal.com/tools/truelayer.md |\n| Yapily | C | 57.6 | 469 | bank.accounts, bank.transactions, bank.identity, bank.consent | no | https://www.anchorterminal.com/tools/yapily.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The data APIs moved to v3 in production on 23 February 2026, a breaking change announced on 15 January 2026 that made three request headers mandatory (source: \u003chttps://docs.akoya.com/reference/akoya-apis-v3-guide\u003e)\n- An unauthenticated GET to `https://sandbox-products.ddp.akoya.com/accounts-info/v3/mikomo` answered 401 with `{\"code\":602, \"message\":\"Customer not authorized\"}` on 8 October 2026\n- Section 7(b) of the Terms of Use, last updated 20 December 2024, forbids using or launching any automated system to access the network, and acting as an intermediary or aggregator (source: \u003chttps://akoya.com/terms-of-use\u003e)\n- Production access follows an onboarding questionnaire, a security and risk review and a data access agreement signed through Docusign (source: \u003chttps://docs.akoya.com/guides/guide-for-production-access\u003e)\n- The pricing page names two plans by monthly connections and gives no figures. Its FAQ says a set-up or implementation fee may apply (source: \u003chttps://akoya.com/pricing\u003e)\n- The Payments product returns account and routing identifiers, or tokenised account numbers, for ACH and RTP. It does not move money (source: \u003chttps://docs.akoya.com/guides/api-overview\u003e)\n- Akoya says it passes data through and does not store consumer financial data or login credentials, and that it holds SOC 2 Type 2 (source: \u003chttps://akoya.com/security\u003e)\n- The home page counts 4,500+ financial institutions and 7,500+ apps, while the fintechs page says 4,300+ and 7,000+. Both are vendor claims (source: \u003chttps://akoya.com/\u003e)\n\n## Compare\n\n- [Akoya vs Belvo](https://www.anchorterminal.com/compare/akoya-vs-belvo.md): D 48.3 vs B 63.5\n- [Akoya vs Enable Banking](https://www.anchorterminal.com/compare/akoya-vs-enable-banking.md): D 48.3 vs D 47.1\n- [Akoya vs Flinks](https://www.anchorterminal.com/compare/akoya-vs-flinks.md): D 48.3 vs D 52.7\n- [Akoya vs GoCardless Bank Account Data](https://www.anchorterminal.com/compare/akoya-vs-gocardless-bank-account-data.md): D 48.3 vs E 41.7\n- [Akoya vs MX Platform API](https://www.anchorterminal.com/compare/akoya-vs-mx.md): D 48.3 vs B 62.5\n- [Akoya vs Plaid](https://www.anchorterminal.com/compare/akoya-vs-plaid.md): D 48.3 vs B 69.8\n- [Akoya vs Salt Edge Account Information](https://www.anchorterminal.com/compare/akoya-vs-salt-edge.md): D 48.3 vs D 46.7\n- [Akoya vs Teller](https://www.anchorterminal.com/compare/akoya-vs-teller.md): D 48.3 vs E 42.7\n- [Akoya vs Tink](https://www.anchorterminal.com/compare/akoya-vs-tink.md): D 48.3 vs B 62.5\n- [Akoya vs TrueLayer](https://www.anchorterminal.com/compare/akoya-vs-truelayer.md): D 48.3 vs B 62.1\n- [Akoya vs Yapily](https://www.anchorterminal.com/compare/akoya-vs-yapily.md): D 48.3 vs C 57.6\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on akoya.com or one of its subdomains. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"akoya\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/akoya\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/akoya.svg\" alt=\"Akoya on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Akoya on Anchor Terminal](https://www.anchorterminal.com/badges/akoya.svg)](https://www.anchorterminal.com/tools/akoya)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/akoya\"\u003eAkoya on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Akoya is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/akoya-dark.png\n- Light: https://www.anchorterminal.com/assets/share/akoya-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Bank data \u0026 open banking",
        "url": "https://www.anchorterminal.com/categories/banking-data"
      },
      {
        "name": "Akoya",
        "url": ""
      }
    ],
    "description": "Akoya runs a US data access network through which consumers permit apps to read their bank and brokerage accounts. Data recipients call FDX-based REST APIs for accounts, balances, transactions, customer details, statements and consent, after an OAuth consent flow.",
    "facts": [
      "rank #623 of 722",
      "OAuth auth",
      "0 desk reviews"
    ],
    "h1": "Akoya",
    "image": "https://www.anchorterminal.com/assets/og/tools-akoya.png",
    "path": "/tools/akoya",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Akoya review for AI agents, grade D (48.3/100) | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/akoya"
  },
  "tokens": {
    "markdown": 7100,
    "slim": 1680
  },
  "version": 1
}
