# Akoya (slim) > Akoya runs a US data access network through which consumers permit apps to read their bank and brokerage accounts. Data recipients call FDX-based REST APIs for accounts, balances, transactions, customer details, statements and consent, after an OAuth consent flow. - Full: https://www.anchorterminal.com/tools/akoya.md (~7,100 tokens) · this version ~1,680 tokens · JSON https://www.anchorterminal.com/tools/akoya.json · canonical https://www.anchorterminal.com/tools/akoya - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **D · 48.3/100 · rank #623 of 722 · #8 in Bank data & open banking · not agent-ready · confidence medium** Assessment: Six OpenAPI 3.1 specifications, a free self-service sandbox and read-only data endpoints behind per-consumer OAuth tokens make the API straightforward to test. Production needs a security review and a signed agreement, no price is published, and no public status page, SLA, SDK or `llms.txt` was found. ## Facts - Kind: HTTP API · vendor: Akoya LLC · category: Bank data & open banking · legal entity: Akoya LLC · provenance 72/100 - Endpoint: `https://products.ddp.akoya.com` (HTTP) - Auth: OAuth · pricing: Paid · x402: no · licence: Proprietary service under the Akoya Terms of Use and a signed data access agreement - Probe metrics: not measured yet (probes haven't run) - APIs: Token API v2.2.0, Service Token API v1.0.1, data APIs v3.0.0 (12 paths), Apps Management API v2.0.0, Notifications API v1.1.0, Consent API v1.1.0 - Data endpoints: `/accounts-info`, `/balances`, `/accounts` (investments), `/taxlots`, `/customers/.../current`, `/contacts`, `/payments/.../payment-networks`, `/statements`, `/tax-forms` (beta), `/transactions`, each as `/{product}/v3/{providerId}` - Servers: Sandbox `sandbox-idp.ddp.akoya.com`, `sandbox-sts.ddp.akoya.com`, `sandbox-products.ddp.akoya.com`, `sandbox-api.akoya.com`. Production `idp.ddp.akoya.com`, `sts.ddp.akoya.com`, `products.ddp.akoya.com`, `api.akoya.com` - Credentials: Per-app client ID and secret, authorisation code valid 5 minutes, ID token (JWT) valid up to 24 hours and often 15 minutes, rotating refresh token, 24-hour service token for the service APIs - Required v3 headers: `x-akoya-interaction-type` (USER or BATCH), `x-akoya-last-access` (ISO 8601, UTC), `x-akoya-intent-type` (payments or nonpayments) for apps subscribed to Payments - Pagination: `limit` (default 50), `offset`, `startTime`, `endTime` on the first call, then `links.next.href`. A small number of providers return no `prev` link - Errors: JSON body with `code`, `message` and optional `debugMessage`. 602 customer not authorised, 701 account not found, 703 invalid date range, 1207 too many requests (429), 503 scheduled maintenance - Rate limits: A recommended maximum of 5 calls a second on the Apps Management API. No number found for the data APIs - Sandbox: Free and self-service through the Data Recipient Hub, test institution `mikomo`, up to 10 sandbox apps through the Apps Management API - Webhooks: CONSENT_REVOKED, CONSENT_UPDATED, PLANNED_OUTAGE and SERVICE events to an HTTPS callback, three delivery attempts, a sandbox test event endpoint - Versions: v1 sunset 2 May 2023, v2 deprecated 23 February 2026, v3 current. A deprecated version sunsets six months after deprecation - Coverage: United States only. The Terms of Use limit use to people located in the US - Scores: Reliability 28, Performance pending, Schema & documentation 70, Agent ergonomics 67, Security & auth 64, Payments & pricing 10, Task success pending, Maintenance & community 33, Transparency & trust 58 · total over the 7 assessed categories - Why: Reliability, Graded as a hosted service. · Schema & documentation, OpenAPI 3.1 specifications are published for all six APIs, as YAML code blocks to copy from docs pages with no raw file address (20 of 25). · Agent ergonomics, Responses can be sized with `limit` (default 50), `offset`, `startTime`, `endTime` and an `accountIds` filter. · Security & auth, OAuth 2.0 authorisation code grant with OpenID Connect. · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, The data API specification is marked "Updated 08/05/2026", read as 5 August 2026, and the newest changelog entry is about 31 July 2026, so t… · Transparency & trust, Closed service. - Sources: 24, open questions: 9, both in the full twin - Capabilities: bank.accounts, bank.transactions, bank.identity, bank.consent - JSON: https://www.anchorterminal.com/api/v1/tools/akoya.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/akoya.svg` or a link to https://www.anchorterminal.com/tools/akoya from a page on akoya.com or one of its subdomains, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Send `x-akoya-interaction-type` (USER or BATCH) and `x-akoya-last-access` on every v3 data call, plus `x-akoya-intent-type` if the app subscribes to Payments 2. Use the `id_token` as the bearer token. The `/token` response has no `access_token` field, so generic OAuth libraries need adjusting 3. Treat ID tokens as valid for 15 minutes, refresh on error 602, and store the new refresh token returned by every refresh 4. Page transactions by following `links.next.href` unchanged. Set `limit`, `startTime` and `endTime` on the first call only 5. On 429 with code 1207 slow the request rate. On 5xx retry up to three times with exponential backoff ## Connect ```bash curl --request GET --url 'https://sandbox-products.ddp.akoya.com/accounts-info/v3/mikomo' --header 'x-akoya-interaction-type: USER' --header 'x-akoya-last-access: 2025-11-24T00:00:00Z' --header 'accept: application/json' --header 'authorization: Bearer {{id_token}}' ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/akoya ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Plaid | B | 69.8 | bank.accounts, bank.transactions, bank.identity, bank.consent | https://www.anchorterminal.com/tools/plaid.min.md | | Belvo | B | 63.5 | bank.accounts, bank.transactions, bank.identity, bank.consent | https://www.anchorterminal.com/tools/belvo.min.md | | MX Platform API | B | 62.5 | bank.accounts, bank.transactions, bank.identity, bank.consent | https://www.anchorterminal.com/tools/mx.min.md | | Tink | B | 62.5 | bank.accounts, bank.transactions, bank.consent, bank.identity | https://www.anchorterminal.com/tools/tink.min.md | | TrueLayer | B | 62.1 | bank.accounts, bank.transactions, bank.identity, bank.consent | https://www.anchorterminal.com/tools/truelayer.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)