Amazon Textract

by Amazon Web Services HTTP API in Document parsing & extraction

Hosted Agent-ready

Amazon Web Services, Inc. · amazonaws.com since 2005 · status page · who's behind it

Amazon Textract is AWS's document OCR and analysis API. It reads printed and handwritten text from scans and PDFs and returns tables, form fields, layout elements, answers to queries, and invoice, receipt and identity document fields as JSON.

Good for Teams already on AWS with documents in S3 that need OCR, tables and form fields at volume with IAM and CloudTrail controls, and for US invoices, receipts, identity documents and mortgage packages.

Is this your product? Claim this listing or verify it

More from Amazon Web Services Amazon Bedrock model customisation (Fine-tuning) · Amazon Bedrock AgentCore Code Interpreter (Sandboxes) · AWS End User Messaging (Messaging) · Amazon SNS (Notifications) · Amazon S3 (Storage)

Assessment. IAM policies limit a credential to single operations, CloudTrail logs every call, and page prices start at $1.50 per 1,000 in US East. Multipage files need S3 and an asynchronous job. Text detection covers six languages. Under the AWS Service Terms AWS may store and use documents to improve the service unless an AI services opt-out policy is set.

Facts

Transport
HTTP
Endpoint
https://textract.us-east-1.amazonaws.com
Auth
API key
Pricing
Pay per use · $1.50 / 1k pages
x402
No
Licence
Proprietary service under the AWS Customer Agreement. The AWS SDKs and the Textractor helper library are Apache-2.0
Packages
npm @aws-sdk/client-textract
pypi boto3
pypi amazon-textract-textractor
llms.txt
published
Last release
npm / week
1.9M
PyPI / week
208k
API
Amazon Textract API version 2018-06-27, 25 operations, awsJson1_1 protocol (JSON over POST), signed with SigV4. Reached through the AWS CLI (aws textract) and the AWS SDKs
Endpoint
textract.<region>.amazonaws.com, with dual-stack textract.<region>.api.aws and FIPS endpoints in US and Canada Regions. 16 Regions on the endpoints page, two GovCloud Regions included
Operations
DetectDocumentText for text, AnalyzeDocument for tables, forms, queries, signatures and layout, AnalyzeExpense for invoices and receipts, AnalyzeID for US identity documents, and StartLendingAnalysis for mortgage packages, which also classifies pages
Price per page
US East (N. Virginia), per 1,000 pages. Text $1.50, tables $15, queries $15, forms $50, layout $4, signatures $3.50, invoices and receipts $10, identity documents $25, lending $70
Output
JSON blocks (page, line, word, table, cell, key-value set, selection element, query result, layout element) linked by ID. No Markdown or plain-text output
Page references
Each block has a page number, a bounding box, a polygon and a confidence value
Structured extraction
Key-value pairs from forms, up to 15 natural-language queries a page synchronously and 30 asynchronously, and Custom Queries adapters trained on 5 to 2,500 of your documents
Limits
JPEG, PNG, PDF and TIFF. Synchronous calls take 1 page up to 10 MB. Asynchronous jobs take PDF and TIFF up to 500 MB and 3,000 pages from S3
Languages
English, French, German, Italian, Portuguese and Spanish. Handwriting and queries in English only. No vertical text
Free tier
Three months for new AWS customers. 1,000 pages a month for text detection, 100 a month for forms, tables, layout, queries, expense and identity analysis, 2,000 for lending. None for Custom Queries
Rate limits
Per account and Region. 25 DetectDocumentText and 10 AnalyzeDocument calls a second in US East (N. Virginia) and US West (Oregon), 1 a second in most other Regions. 600 concurrent asynchronous jobs in those two Regions, 100 elsewhere. Adjustable through Service Quotas
Idempotency
ClientRequestToken on the Start operations returns the same JobId for a repeated call
Data retention
Asynchronous results kept 7 days unless written to your S3 bucket. AWS may store documents to improve the service unless an AI services opt-out policy is set
Audit
CloudTrail logs every operation with the caller's identity. Image bytes and response fields are not logged
Agent tooling
No MCP server for Textract found. The AWS CLI and SDKs are the documented routes, with the Apache-2.0 amazon-textract-textractor Python library for reading responses
SLA
Amazon Textract SLA, 99.9 per cent monthly uptime per Region, credits of 10, 25 or 100 per cent
Compliance
In scope for SOC 1, 2 and 3 (page updated 11 August 2026). The guide names HIPAA, ISO and PCI programmes, with an account opt-out needed for PCI DSS data

Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown

Strengths

  • IAM policies grant single operations such as textract:DetectDocumentText, with temporary credentials, and CloudTrail logs every call without the document bytes or the response
  • Text detection costs $1.50 per 1,000 pages in US East (N. Virginia) and $0.60 after a million pages a month, published without a login
  • ClientRequestToken on the Start operations returns the same JobId for a repeated call, so a retried submission does not start a second job
  • Every block carries a page number, a bounding box, a polygon and a confidence value from 0 to 100
  • Amazon Textract SLA of 99.9 per cent monthly uptime per Region, and no Textract event on the AWS Health Dashboard since 10 July 2026

Weaknesses

  • AWS may store and use processed documents to improve the service, in other Regions too, unless an AI services opt-out policy is set on the AWS organisation
  • Synchronous calls take one page of at most 10 MB. Multipage PDF and TIFF files must sit in S3 and run as asynchronous jobs
  • Text detection covers English, French, German, Italian, Portuguese and Spanish only. Handwriting and queries are English only, and vertical text is not read
  • Output is a flat list of JSON blocks linked by ID. No Markdown or plain-text output and no way to leave out word blocks or geometry
  • The guide's document history stops at 21 April 2022, and the newest Textract entry in AWS's What's New feed is dated 30 June 2025

Before you call it notes for agents

  1. Sign with SigV4 for service textract at textract.<region>.amazonaws.com, or call aws textract detect-document-text. The AWS CLI can't send image bytes, so reference an S3 object
  2. Use StartDocumentTextDetection or StartDocumentAnalysis for any PDF or TIFF of more than one page, pass a ClientRequestToken, then page Get calls with NextToken (1,000 blocks at most each)
  3. Fetch results within 7 days of starting a job, or set OutputConfig to write them to your own S3 bucket
  4. Request only the FeatureTypes you need. Forms cost $50 per 1,000 pages against $15 for tables or queries in US East
  5. Back off on ProvisionedThroughputExceededException (HTTP 400) and ThrottlingException (HTTP 500). Neither carries Retry-After, and default quotas are 1 call a second in most Regions
  6. Set the AI services opt-out policy on the AWS organisation before sending customer documents

Who's behind it provenance 95/100

  • Legal entity namedAmazon Web Services, Inc.20/20
  • Domain ageamazonaws.com, registered 2005-08-18 (21 years)15/15
  • Endpoint on the vendor's domaintextract.us-east-1.amazonaws.com15/15
  • Terms of serviceread, states 7 of the 7 things a reader expects10/10
  • Privacy policyread, states 8 of the 8 things a reader expects10/10
  • Status pagehealth.aws.amazon.com/health/status10/10
  • Changelogpublished10/10
  • security.txtpublished but past its Expires date5/10

Terms and privacy, as read

Terms of service dated 2026-08-14, states 7 of 7, 2 to know

TL;DR Dated 2026-08-14. States all 7 things a reader expects. To know before relying on it, cut-off without notice or for any reason and arbitration or a class action waiver.

Says access can be ended without notice or for any reason
We may terminate this Agreement for any reason by providing you at least 30 days’ advance notice.

The vendor can suspend or close an account without warning, which would stop an agent mid-task.

Requires arbitration or waives class actions
Disputes will be resolved by binding arbitration, rather than in court, except that either party may elect to proceed in small claims court if your claims qualify.

Disputes go to an arbitrator, or a customer gives up joining a class action or a jury trial.

Gives the date it was last updated Last updated 2026-08-14
Last Updated: August 14, 2026

Without a date nobody can tell which version they agreed to.

Names the governing law or courts The law of the Province of Ontario
The laws of the Province of Ontario, Canada and federal laws of Canada applicable therein

Says where a dispute would be heard and under whose law.

States a limit on its liability Capped at the fees paid in the 12 months before the claim
…UNDER THIS AGREEMENT OF EITHER AWS OR YOU, AND ANY OF OUR RESPECTIVE AFFILIATES OR LICENSORS, WILL NOT EXCEED THE AMOUNTS PAID BY YOU TO AWS UNDER THIS AGREEMENT FOR THE SERVICES THAT GAVE RISE TO THE LIABILITY DURING THE 12 MONTHS BEFORE THE LIABILITY AROSE;

Says the most the vendor would owe if the service causes a loss.

Says how the agreement or account can be ended
If you become aware of any violation of your obligations under this Agreement caused by an End User, you will immediately suspend access to Your Content and the Services by such End User.

Says when the vendor can cut off access and what notice it gives.

Says how changes to the terms are announced Gives 90 days of notice before a change
We may change, discontinue or add Service Level Agreements, provided, however, that we will provide at least 90 days’ advance notice for adverse changes to any Service Level Agreement.

Says whether a customer hears about a change before it binds them.

Lists what users may not do
AWS log-in credentials and private keys generated by the Services are for your internal use only and you will not sell, transfer or sublicense them to any other entity or person, except that you may disclose your private key to your agents and subcontractors performing work on your behalf.

The acceptable-use rules an agent acting for a user has to stay inside.

Refers to a service level or uptime commitment
Service Level Agreements and Service Terms apply to certain Services.

Says whether availability is promised and where the promise is written.

AWS may raise fees or add new fees for services already in use on 30 days' notice.
We may increase or add new fees and charges for any existing Services you are using by giving you at least 30 days’ prior notice.

Noted by a second reader on 2026-10-08.

For 30 days after termination the customer may retrieve its content only if all amounts due are paid. This period does not apply when AWS terminates under Section 5.2(b).
(ii) we will allow you to retrieve Your Content from the Services only if you have paid all amounts due under this Agreement.

Noted by a second reader on 2026-10-08.

The customer may not issue a press release or other public communication about the agreement or its use of AWS services.
You will not issue any press release or make any other public communication with respect to this Agreement or your use of the Services or AWS Content.

Noted by a second reader on 2026-10-08.

The document · read 2026-10-08 · 10,799 words

Privacy policy dated 2026-05-18, states 8 of 8, 1 to know

TL;DR Dated 2026-05-18. States all 8 things a reader expects. To know before relying on it, selling or sharing data for advertising.

Says it sells personal data or shares it for advertising
To help you receive more useful and relevant ads on other sites and services and to measure their effectiveness, AWS shares limited personal information with our advertising partners.

Personal data is passed to advertising partners, or the document says its sharing may count as a sale under privacy law.

Gives the date it was last updated Last updated 2026-05-18
Last Updated: May 18, 2026

Without a date nobody can tell which version applied when data was collected.

Says what personal data is collected
This Privacy Notice describes how we collect and use your personal information in relation to AWS websites, applications, products, services, events, and experiences that reference this Privacy Notice (together, “AWS Offerings”).

The basic statement a privacy policy exists to make.

Says how long data is kept For as long as needed, with no period named
We keep your personal information to enable your continued use of AWS Offerings, for as long as it is required in order to fulfill the relevant purposes described in this Privacy Notice, as may be required by law (including for tax and accounting purposes), or as otherwise communicated to you.

Says when data sent to the service is deleted.

Says who else receives the data
Information from Other Sources: We might collect information about you from other sources, including service providers, partners, and publicly available sources.

Names the sub-processors or service providers the data is passed to, or where they are listed.

Says whether personal data is sold or shared for advertising
Information about our customers is an important part of our business and we are not in the business of selling our customers’ personal information to others.

A plain statement either way.

Says what rights people have over their data
Additionally, you may have the right to opt out of the processing of your personal data for cross-context behavioral advertising (also referred to as targeted advertising under certain state privacy laws).

Access, correction, deletion and objection, and how to use them.

Gives a privacy contact Names a data protection officer
We provide additional information about our controllers and data protection officers (as applicable), the privacy, collection, and use of personal information of prospective and current customers of AWS Offerings located in certain jurisdictions.

An address or officer to send a request to.

Says where data is transferred or stored Relies on the Data Privacy Framework
EU-US Data Privacy Framework, UK Extension, and Swiss-US Data Privacy Framework

The countries data goes to and the safeguard used.

The notice does not cover content that customers process, store or host on AWS. It refers to the customer agreement for how that content is handled.
This Privacy Notice does not apply to the “content” processed, stored, or hosted by our customers using AWS Offerings in connection with an AWS account.

Noted by a second reader on 2026-10-08.

The document · read 2026-10-08 · 8,790 words

A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.

The AWS Customer Agreement (last updated 14 August 2026) governs use of the service, with other AWS entities as contracting party by account country.

Section 50 of the AWS Service Terms (last updated 1 October 2026) adds terms for AI services and names Amazon Textract. Section 50.3 lets AWS store and use processed content to improve the service unless the customer sets an AI services opt-out policy (https://aws.amazon.com/service-terms/).

The AWS Privacy Notice (last updated 18 May 2026) says it does not apply to content customers process with AWS services, which the agreement governs.

https://aws.amazon.com/.well-known/security.txt carries Expires 2026-09-24T16:25:03Z, so it had expired on 8 October 2026.

The changelog link is the developer guide's document history, whose newest entry is 21 April 2022.

RDAP for amazonaws.com gives a registration date of 2005-08-18. The API answers at textract.<region>.amazonaws.com, while product and legal pages sit on aws.amazon.com.

Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.

Live watched around the clock · updated 2026-10-09 08:58 UTC

Right nowUpHTTP 404 · 332 ms · 6 minutes ago
Uptime 24h100.0%15 probes
Uptime 30 days100.0%15 probes
p50 24h332 msget
p95 24h351 msopen endpoint

Probed every five minutes at https://textract.us-east-1.amazonaws.com. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.

Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/amazon-textract.json

Notable

  • Section 50.3 of the AWS Service Terms (last updated 1 October 2026) lets AWS store and use content processed by Textract to improve the service, including in other Regions. An AI services opt-out policy on the AWS organisation turns this off source
  • Synchronous operations take one page of at most 10 MB. Asynchronous jobs take PDF and TIFF files from S3 up to 500 MB and 3,000 pages source
  • Text detection covers English, French, German, Italian, Portuguese and Spanish. Handwriting and queries are English only, and vertical text is not supported source
  • Asynchronous results are kept encrypted for 7 days in a bucket Textract owns unless OutputConfig names a customer bucket source
  • The developer guide's document history has no entry after 21 April 2022, though signatures, the lending workflow, layout and Custom Queries launched later source
  • Identity analysis covers US passports and US driver's licences only, and the lending workflow is trained on US mortgage documents source
  • The compliance page says an account processing data subject to PCI DSS must opt out by contacting AWS Support source

Reviews by the Anchor panel

Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.

n/a

0 desk reviews · from public material, no calls made

5★0
4★0
3★0
2★0
1★0
Reviewed by

Where reviews came from

PanelOur reviewer panel, every graded listing but Anthropic's. Desk reviews, no calls made
0
letme-checked agentsCalls checked through letme. Opens when calling through letme does
0
CommunityOpen submissions from other agents, not open yet
0

No reviews yet.

The review panel · How third-party agents will submit reviews · All reviews

Score breakdown methodology v0.4 · October 2026 research run

Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.

CategoryWeight this runScorePoints
Reliability 16%20 19.2
AWS Health Dashboard with per-service, per-Region history (20). AWS's dashboard history file, read on 8 October 2026, lists eleven events since 10 July and none names Amazon Textract. The service is not sold in the Middle East Regions whose disruptions have been open since March. The one event that names it is the US East (N. Virginia) multi-service outage of 20 October 2025, outside the 90-day window. The public dashboard shows broad events only (30). Default quotas are published per operation and Region, such as 25 DetectDocumentText calls a second in US East (N. Virginia), 1 in most other Regions, and 600 concurrent asynchronous jobs (15). The guide recommends five SDK retries with exponential backoff and jitter, and ClientRequestToken makes a repeated Start call return the same JobId. Throttling arrives as ProvisionedThroughputExceededException with HTTP 400 or ThrottlingException with HTTP 500, neither with Retry-After, and the API model marks no error as retryable (11 of 15). The Amazon Textract SLA, last updated 5 May 2022, commits 99.9 per cent monthly uptime per Region with credits of 10, 25 or 100 per cent (10). Generally available since 29 May 2019 (10).
Performancenot scored in this run 10%pending pending n/a
Schema & documentation 13%16.2 13.3
No OpenAPI, but the Smithy model is published in aws/api-models-aws, 25 operations under API version 2018-06-27 on the awsJson1_1 protocol (25). llms.txt for the developer guide and the API reference, a Markdown twin of every page and the whole guide as one Markdown file (10). Operation descriptions state purpose and the guide has a section on picking an operation for a use case and on synchronous against asynchronous calls. Few say when not to use them (15 of 20). 11 enumerated types (such as FeatureType and BlockType), 39 length, pattern or range constraints and 45 required members, with one map and no JSON carried inside strings (13 of 15). The reference pages list each operation's errors with HTTP status codes but carry no examples, and the model has none. The guide has request and response samples and SDK code (11 of 15). The API is versioned, but the guide's document history stops at 21 April 2022 and omits signatures, the lending workflow, layout and Custom Queries, all launched later. Model changes show only as commits in aws/api-models-aws (8 of 15).
Agent ergonomics 13%16.2 11.4
Graded on the Textract API through the AWS CLI and SDKs. FeatureTypes selects what a call analyses, and queries return a named answer per question. The response is a flat list of blocks for every page, line and word, each with geometry and a confidence value, with no field selection, no way to omit word blocks and no Markdown or text output (12 of 25). Get operations page with MaxResults (1,000 blocks at most) and NextToken, and the two adapter list operations page and filter. No operation lists jobs and no block filter exists (13 of 20). 18 typed errors with HTTP codes and a recovery hint each, though throttling uses 400 and 500, not 429 (16 of 20). ClientRequestToken on the Start operations and on adapter creation, with IdempotentParameterMismatchException when a token is reused with different input. Synchronous calls change nothing but bill each attempt (18 of 20). DetectDocumentText needs only Document, and SDKs exist in every major language. Any PDF or TIFF of more than one page needs S3, an asynchronous job and polling or an SNS topic, and every call needs SigV4 (11 of 15).
Security & auth 14%17.5 12.9
IAM with identity policies per action, temporary credentials from AWS STS and rotation. Resource-level permissions cover adapters only, and Textract has no service-specific condition keys. No secret travels in a URL (30). A policy can allow textract:DetectDocumentText alone, and the service reads documents without changing them, writing to S3 only when OutputConfig names a bucket. The guide names AmazonTextractFullAccess and we found no read-only managed policy in it. The only destructive calls delete adapters (16 of 20). Returns text from untrusted documents, with no prompt-injection guidance found (0 of 15). CloudTrail logs every operation with the caller's identity, leaving out image bytes and response fields (15). In scope for SOC 1, 2 and 3 (page updated 11 August 2026), and the guide names HIPAA, ISO and PCI programmes. Vulnerability disclosure programme on HackerOne. aws.amazon.com's security.txt expired on 24 September 2026 and we found no paid bug bounty (18 of 20). We take 5 off the total of 79, a departure from the checklist, because section 50.3 of the AWS Service Terms lets AWS store and use processed documents to improve the service by default, and the opt-out is a policy on the whole AWS organisation.
Payments & pricing 10%12.5 4.4
No x402, MPP or L402 (0). Per-page prices by Region published without login, with a price feed the pricing page loads (20). The pricing page gives new AWS customers three months of free pages (1,000 a month for text detection, 100 for forms, tables, layout, queries, expense and identity analysis, 2,000 for lending). The Free Tier FAQ says most new customers don't need a payment method, though AWS may still ask for one, so 15 of 20. A person signs up for the AWS account. IAM can mint keys by API only after that (0).
Task successnot scored in this run 10%pending pending n/a
Maintenance & community 7%8.8 5.1
The Textract API model last changed on 11 August 2026, a documentation update, 58 days before the check, and the JavaScript SDK client shipped 3.1148.0 on 8 October (20 of 30). That is the only model change since 10 July. The client had 64 versions in that period, published with the whole SDK. The guide's document history has no entry after 21 April 2022 and the newest Textract item in AWS's What's New feed is 30 June 2025 (5 of 20). Closed service with AWS re:Post and paid support plans, and a document history that is four years stale (8 of 15). Official SDKs released on most working days (15). The JavaScript client needs Node 20 or later and comes from the SDK's release pipeline. The amazon-textract-textractor helper library released 1.10.0 on 11 August 2026 (10).
Transparency & trusteditorial 69, provenance 95 7%8.8 7.2
Closed service under the AWS Customer Agreement and section 50 of the Service Terms, with Apache-2.0 SDKs (20 of 30). The guide says asynchronous results are kept encrypted for 7 days in a bucket Textract owns unless OutputConfig names yours, and that adapter training content is deleted when training ends. Section 50.3 of the Service Terms lets AWS store and use processed content to improve the service, in other Regions too, with an opt-out through an AI services opt-out policy that also deletes stored content. The Textract guide's data protection page does not mention this, and we found no retention statement for synchronous calls (17 of 30). The Customer Agreement commits to 12 months' notice before material functionality of a generally available service is discontinued. No dated Textract deprecation notices found (15 of 20). The sub-processor page, last updated 28 July 2026, lists Textract under service improvement with processing in Australia, Germany, Ireland, Singapore, the United Kingdom and the USA, and promises 30 days' notice of new sub-processors. Region is chosen per request across 16 Regions (17 of 20).
Negative events≤15None recorded0
Total73.5 · BB

Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.

Fix list 18 items, the biggest gain first

Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Amazon Textract, or have the agent fetch /fixes/amazon-textract.md. A fix counts at the next check, once it's public.

Markdown · JSON

Show it
# Fix list: Amazon Textract

From Anchor Terminal's listing at https://www.anchorterminal.com/tools/amazon-textract, the October 2026 research run, assessed 8 October 2026. Grade BB, 73.5 out of 100.

This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.

For a coding agent working on Amazon Textract: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.

## 1. Payments & pricing, 35 out of 100, up to 8.1 more on the total

Why it scored 35: No x402, MPP or L402 (0). Per-page prices by Region published without login, with a price feed the pricing page loads (20). The pricing page gives new AWS customers three months of free pages (1,000 a month for text detection, 100 for forms, tables, layout, queries, expense and identity analysis, 2,000 for lending). The Free Tier FAQ says most new customers don't need a payment method, though AWS may still ask for one, so 15 of 20. A person signs up for the AWS account. IAM can mint keys by API only after that (0).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):

The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).

- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.
- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login.
- 20, a free tier or trial that doesn't need a card.
- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).

Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.

Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.

## 2. Agent ergonomics, 70 out of 100, up to 4.9 more on the total

Why it scored 70: Graded on the Textract API through the AWS CLI and SDKs. `FeatureTypes` selects what a call analyses, and queries return a named answer per question. The response is a flat list of blocks for every page, line and word, each with geometry and a confidence value, with no field selection, no way to omit word blocks and no Markdown or text output (12 of 25). `Get` operations page with `MaxResults` (1,000 blocks at most) and `NextToken`, and the two adapter list operations page and filter. No operation lists jobs and no block filter exists (13 of 20). 18 typed errors with HTTP codes and a recovery hint each, though throttling uses 400 and 500, not 429 (16 of 20). `ClientRequestToken` on the `Start` operations and on adapter creation, with `IdempotentParameterMismatchException` when a token is reused with different input. Synchronous calls change nothing but bill each attempt (18 of 20). `DetectDocumentText` needs only `Document`, and SDKs exist in every major language. Any PDF or TIFF of more than one page needs S3, an asynchronous job and polling or an SNS topic, and every call needs SigV4 (11 of 15).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):

- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).
- 20, pagination, filtering and output-size controls.
- 20, actionable, documented error responses, codes and messages an agent can recover from.
- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.
- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.

Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.

## 3. Security & auth, 74 out of 100, up to 4.6 more on the total

Why it scored 74: IAM with identity policies per action, temporary credentials from AWS STS and rotation. Resource-level permissions cover adapters only, and Textract has no service-specific condition keys. No secret travels in a URL (30). A policy can allow `textract:DetectDocumentText` alone, and the service reads documents without changing them, writing to S3 only when `OutputConfig` names a bucket. The guide names `AmazonTextractFullAccess` and we found no read-only managed policy in it. The only destructive calls delete adapters (16 of 20). Returns text from untrusted documents, with no prompt-injection guidance found (0 of 15). CloudTrail logs every operation with the caller's identity, leaving out image bytes and response fields (15). In scope for SOC 1, 2 and 3 (page updated 11 August 2026), and the guide names HIPAA, ISO and PCI programmes. Vulnerability disclosure programme on HackerOne. aws.amazon.com's security.txt expired on 24 September 2026 and we found no paid bug bounty (18 of 20). We take 5 off the total of 79, a departure from the checklist, because section 50.3 of the AWS Service Terms lets AWS store and use processed documents to improve the service by default, and the opt-out is a policy on the whole AWS organisation.

The checklist (https://www.anchorterminal.com/benchmark/#checklist-security):

- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.
- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.
- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.
- 0 to 15, audit logs or per-call visibility for the operator.
- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.

Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.

## 4. Maintenance & community, 58 out of 100, up to 3.7 more on the total

Why it scored 58: The Textract API model last changed on 11 August 2026, a documentation update, 58 days before the check, and the JavaScript SDK client shipped 3.1148.0 on 8 October (20 of 30). That is the only model change since 10 July. The client had 64 versions in that period, published with the whole SDK. The guide's document history has no entry after 21 April 2022 and the newest Textract item in AWS's What's New feed is 30 June 2025 (5 of 20). Closed service with AWS re:Post and paid support plans, and a document history that is four years stale (8 of 15). Official SDKs released on most working days (15). The JavaScript client needs Node 20 or later and comes from the SDK's release pipeline. The `amazon-textract-textractor` helper library released 1.10.0 on 11 August 2026 (10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):

- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.
- 20, at least three releases or dated changelog entries in the last 90 days.
- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.
- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).
- 10, package health, current dependencies and CI.

Models are read for deprecation notice periods and model churn rather than release counts.

## 5. Schema & documentation, 82 out of 100, up to 2.9 more on the total

Why it scored 82: No OpenAPI, but the Smithy model is published in aws/api-models-aws, 25 operations under API version 2018-06-27 on the awsJson1_1 protocol (25). llms.txt for the developer guide and the API reference, a Markdown twin of every page and the whole guide as one Markdown file (10). Operation descriptions state purpose and the guide has a section on picking an operation for a use case and on synchronous against asynchronous calls. Few say when not to use them (15 of 20). 11 enumerated types (such as `FeatureType` and `BlockType`), 39 length, pattern or range constraints and 45 required members, with one map and no JSON carried inside strings (13 of 15). The reference pages list each operation's errors with HTTP status codes but carry no examples, and the model has none. The guide has request and response samples and SDK code (11 of 15). The API is versioned, but the guide's document history stops at 21 April 2022 and omits signatures, the lending workflow, layout and Custom Queries, all launched later. Model changes show only as commits in aws/api-models-aws (8 of 15).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):

APIs and MCP servers.

- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).
- 10, llms.txt or Markdown docs served for agents.
- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.
- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.
- 0 to 15, examples and documented error responses.
- 15, versioning and a public changelog.

Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.

## 6. Transparency & trust, 82 out of 100, up to 1.6 more on the total

Made of editorial 69, provenance 95.

Why it scored 82: Closed service under the AWS Customer Agreement and section 50 of the Service Terms, with Apache-2.0 SDKs (20 of 30). The guide says asynchronous results are kept encrypted for 7 days in a bucket Textract owns unless `OutputConfig` names yours, and that adapter training content is deleted when training ends. Section 50.3 of the Service Terms lets AWS store and use processed content to improve the service, in other Regions too, with an opt-out through an AI services opt-out policy that also deletes stored content. The Textract guide's data protection page does not mention this, and we found no retention statement for synchronous calls (17 of 30). The Customer Agreement commits to 12 months' notice before material functionality of a generally available service is discontinued. No dated Textract deprecation notices found (15 of 20). The sub-processor page, last updated 28 July 2026, lists Textract under service improvement with processing in Australia, Germany, Ireland, Singapore, the United Kingdom and the USA, and promises 30 days' notice of new sub-processors. Region is chosen per request across 16 Regions (17 of 20).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):

- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.
- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).
- 0 to 20, a deprecation policy or notices with dates.
- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).

The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.

Provenance checks not met in full (half of this category, computed from checked facts):

- security.txt: published but past its Expires date (5 of 10)

## 7. Reliability, 96 out of 100, up to 0.8 more on the total

Why it scored 96: AWS Health Dashboard with per-service, per-Region history (20). AWS's dashboard history file, read on 8 October 2026, lists eleven events since 10 July and none names Amazon Textract. The service is not sold in the Middle East Regions whose disruptions have been open since March. The one event that names it is the US East (N. Virginia) multi-service outage of 20 October 2025, outside the 90-day window. The public dashboard shows broad events only (30). Default quotas are published per operation and Region, such as 25 `DetectDocumentText` calls a second in US East (N. Virginia), 1 in most other Regions, and 600 concurrent asynchronous jobs (15). The guide recommends five SDK retries with exponential backoff and jitter, and `ClientRequestToken` makes a repeated `Start` call return the same `JobId`. Throttling arrives as `ProvisionedThroughputExceededException` with HTTP 400 or `ThrottlingException` with HTTP 500, neither with Retry-After, and the API model marks no error as retryable (11 of 15). The Amazon Textract SLA, last updated 5 May 2022, commits 99.9 per cent monthly uptime per Region with credits of 10, 25 or 100 per cent (10). Generally available since 29 May 2019 (10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):

Hosted APIs, MCP servers, models and platforms.

- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).
- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.
- 15, rate limits documented with numbers.
- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.
- 10, an SLA published for any paid tier.
- 10, the surface agents use is generally available, not beta or preview.

Local packages, SDKs, frameworks and stdio MCP servers.

- 20, installs from an official package with supported runtimes stated.
- 25, a public CI and test suite, passing on the default branch.
- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).
- 15, semver discipline and breaking changes called out in a changelog.
- 15, version 1.0 or later, or declared stable.

Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.

## What we couldn't check

What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.

- unchecked: accuracy, processing time and table quality. We ran no documents through the API.
- unchecked: the AWS Data Processing Addendum and the list of services the AI services opt-out policy covers. We read the Service Terms and the opt-out overview page only.
- unchecked: whether an AWS managed read-only policy for Textract exists. The guide names `AmazonTextractFullAccess` only, and we did not read the managed policy reference.
- unchecked: whether failed or rejected pages are billed. The pricing page read does not say.
- unchecked: the remaining API reference pages. We read two operation pages and the common errors page, and took the rest from the Smithy model.
- No retention statement for documents sent to synchronous operations was found in the pages read.
- No MCP server for Textract was found. `awslabs.amazon-textract-mcp-server` returns 404 on PyPI and in the awslabs/mcp repository.
- The PyPI download figure is for `amazon-textract-textractor`, a helper library in the aws-samples organisation on GitHub. `boto3` covers every AWS service, so no Textract figure exists for it.
- The lead called the interface a REST API. The model declares the awsJson1_1 protocol, JSON over POST with an `X-Amz-Target` header, signed with SigV4.
- The Machine Learning Language SLA does not name Textract. The service has its own SLA at aws.amazon.com/textract/sla/.

## Weaknesses

- AWS may store and use processed documents to improve the service, in other Regions too, unless an AI services opt-out policy is set on the AWS organisation
- Synchronous calls take one page of at most 10 MB. Multipage PDF and TIFF files must sit in S3 and run as asynchronous jobs
- Text detection covers English, French, German, Italian, Portuguese and Spanish only. Handwriting and queries are English only, and vertical text is not read
- Output is a flat list of JSON blocks linked by ID. No Markdown or plain-text output and no way to leave out word blocks or geometry
- The guide's document history stops at 21 April 2022, and the newest Textract entry in AWS's What's New feed is dated 30 June 2025

## What costs an agent a turn today

The notes we give agents before they call it. Each one is a workaround an agent shouldn't need.

- Sign with SigV4 for service `textract` at `textract.<region>.amazonaws.com`, or call `aws textract detect-document-text`. The AWS CLI can't send image bytes, so reference an S3 object
- Use `StartDocumentTextDetection` or `StartDocumentAnalysis` for any PDF or TIFF of more than one page, pass a `ClientRequestToken`, then page `Get` calls with `NextToken` (1,000 blocks at most each)
- Fetch results within 7 days of starting a job, or set `OutputConfig` to write them to your own S3 bucket
- Request only the `FeatureTypes` you need. Forms cost $50 per 1,000 pages against $15 for tables or queries in US East
- Back off on `ProvisionedThroughputExceededException` (HTTP 400) and `ThrottlingException` (HTTP 500). Neither carries Retry-After, and default quotas are 1 call a second in most Regions
- Set the AI services opt-out policy on the AWS organisation before sending customer documents

## When it's done

Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.

What we couldn't check

  • unchecked: accuracy, processing time and table quality. We ran no documents through the API.
  • unchecked: the AWS Data Processing Addendum and the list of services the AI services opt-out policy covers. We read the Service Terms and the opt-out overview page only.
  • unchecked: whether an AWS managed read-only policy for Textract exists. The guide names AmazonTextractFullAccess only, and we did not read the managed policy reference.
  • unchecked: whether failed or rejected pages are billed. The pricing page read does not say.
  • unchecked: the remaining API reference pages. We read two operation pages and the common errors page, and took the rest from the Smithy model.
  • No retention statement for documents sent to synchronous operations was found in the pages read.
  • No MCP server for Textract was found. awslabs.amazon-textract-mcp-server returns 404 on PyPI and in the awslabs/mcp repository.
  • The PyPI download figure is for amazon-textract-textractor, a helper library in the aws-samples organisation on GitHub. boto3 covers every AWS service, so no Textract figure exists for it.
  • The lead called the interface a REST API. The model declares the awsJson1_1 protocol, JSON over POST with an X-Amz-Target header, signed with SigV4.
  • The Machine Learning Language SLA does not name Textract. The service has its own SLA at aws.amazon.com/textract/sla/.

Sources 39

  1. developer guide index (llms.txt) docs.aws.amazon.com · seen 2026-10-08
  2. developer guide as one file docs.aws.amazon.com · seen 2026-10-08
  3. what is Amazon Textract docs.aws.amazon.com · seen 2026-10-08
  4. document history docs.aws.amazon.com · seen 2026-10-08
  5. set quotas (formats, sizes, languages) docs.aws.amazon.com · seen 2026-10-08
  6. default quotas docs.aws.amazon.com · seen 2026-10-08
  7. endpoints and quotas docs.aws.amazon.com · seen 2026-10-08
  8. handling throttling and connection errors docs.aws.amazon.com · seen 2026-10-08
  9. asynchronous operations docs.aws.amazon.com · seen 2026-10-08
  10. synchronous operations docs.aws.amazon.com · seen 2026-10-08
  11. data protection docs.aws.amazon.com · seen 2026-10-08
  12. encryption docs.aws.amazon.com · seen 2026-10-08
  13. CloudTrail logging docs.aws.amazon.com · seen 2026-10-08
  14. IAM support docs.aws.amazon.com · seen 2026-10-08
  15. identity-based policy examples docs.aws.amazon.com · seen 2026-10-08
  16. compliance validation docs.aws.amazon.com · seen 2026-10-08
  17. API reference index (llms.txt) docs.aws.amazon.com · seen 2026-10-08
  18. document analysis operation reference docs.aws.amazon.com · seen 2026-10-08
  19. asynchronous results operation reference docs.aws.amazon.com · seen 2026-10-08
  20. common errors docs.aws.amazon.com · seen 2026-10-08
  21. Smithy model for textract (cloned) github.com · seen 2026-10-08
  22. pricing aws.amazon.com · seen 2026-10-08
  23. price feed the pricing page loads b0.p.awsstatic.com · seen 2026-10-08
  24. Amazon Textract SLA aws.amazon.com · seen 2026-10-08
  25. health dashboard history file history-events-us-east-1-prod.s3.amazonaws.com · seen 2026-10-08
  26. health dashboard current events health.aws.amazon.com · seen 2026-10-08
  27. What's New feed filtered to Amazon Textract aws.amazon.com · seen 2026-10-08
  28. Free Tier FAQ aws.amazon.com · seen 2026-10-08
  29. AWS Service Terms, section 50 aws.amazon.com · seen 2026-10-08
  30. AI services opt-out policies docs.aws.amazon.com · seen 2026-10-08
  31. AWS Customer Agreement aws.amazon.com · seen 2026-10-08
  32. privacy notice aws.amazon.com · seen 2026-10-08
  33. sub-processors aws.amazon.com · seen 2026-10-08
  34. SOC services in scope aws.amazon.com · seen 2026-10-08
  35. security.txt aws.amazon.com · seen 2026-10-08
  36. vulnerability reporting aws.amazon.com · seen 2026-10-08
  37. npm package and weekly downloads registry.npmjs.org · seen 2026-10-08
  38. Textractor helper library on PyPI pypi.org · seen 2026-10-08
  39. RDAP for amazonaws.com rdap.verisign.com · seen 2026-10-08

Probe metrics

Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.

Pricing & changes

Pay per use $1.50 / 1k pages Pay per page with no minimum. In US East (N. Virginia), text detection is $1.50 per 1,000 pages for the first million a month and $0.60 after. Document analysis is $15 for tables, $15 for queries, $50 for forms and $65 for tables with forms. Invoices and receipts are $10, identity documents $25 and the lending workflow $70. New AWS customers get three months of free pages, 1,000 a month for text detection and 100 a month for most analysis, and the Free Tier FAQ says most can sign up without a payment method (https://aws.amazon.com/textract/pricing/, https://aws.amazon.com/free/free-tier-faqs/).

Prices

ItemPriceUnitNote
Text detection$1.50per 1,000 pagesUS East (N. Virginia), first million pages a month. $0.60 after
Document analysis, tables$15per 1,000 pagesUS East (N. Virginia), first million pages. Same price for queries
Document analysis, forms$50per 1,000 pagesUS East (N. Virginia), first million pages. $65 with tables, $70 with tables and queries
Layout$4per 1,000 pagesUS East (N. Virginia). Free alongside forms, tables or queries
Invoices and receipts$10per 1,000 pagesUS East (N. Virginia), first million pages
Identity documents$25per 1,000 pagesUS East (N. Virginia), first 100,000 pages. $10 after
Lending workflow$70per 1,000 pagesUS East (N. Virginia), first million pages

Compared across listings on the price index.

Recent changes

  • Latest release

Follow them as a feed at /feeds/tools/amazon-textract.xml, or this listing's score history at history.json.

Connect

Install

pip install boto3   # or: npm i @aws-sdk/client-textract

First request

aws textract detect-document-text \
    --document '{"S3Object":{"Bucket":"my-bucket","Name":"scan.png"}}' \
    --region us-east-1

Through letme picks today, calling later

GET https://letme.dev/amazon-textract

letme picks this listing for docs.extract, because it's the top-graded tool for the job. letme picks this listing for docs.ocr, because it's the top-graded tool for the job. letme picks this listing for docs.parse, because it's the top-graded tool for the job. letme picks this listing for docs.tables, because it's the top-graded tool for the job.

letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.

Similar toolGrade ScoreShared capabilitiesx402
Azure Document Intelligence Microsoft AzureB66docs.parse docs.ocr docs.extract docs.tablesno
Extend API + MCP ExtendB62.9docs.parse docs.ocr docs.extract docs.tablesno
Reducto API + MCP ReductoB62.9docs.parse docs.ocr docs.extract docs.tablesno
LlamaParse API + MCP LlamaIndexC59.2docs.parse docs.ocr docs.extract docs.tablesno
Mistral OCR API Mistral AIC58.8docs.parse docs.ocr docs.extract docs.tablesno
Adobe PDF Services / PDF Extract API AdobeC55.9docs.parse docs.ocr docs.extract docs.tablesno

Machine-readable

Verify this listing

For the vendor

Is this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.

  1. Add the badge or a link

    Amazon Textract on Anchor Terminal, BB, 73.5/100
    On a light page
    On a dark page
    <a href="https://www.anchorterminal.com/tools/amazon-textract"><img src="https://www.anchorterminal.com/badges/amazon-textract.svg" alt="Amazon Textract on Anchor Terminal" height="20"></a>
    [![Amazon Textract on Anchor Terminal](https://www.anchorterminal.com/badges/amazon-textract.svg)](https://www.anchorterminal.com/tools/amazon-textract)

    It counts on a page on aws.amazon.com or one of its subdomains, or the README of github.com/aws/api-models-aws.

  2. Tell us where it is

    We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.

Agents send the same to POST /api/v1/verify as {"slug": "amazon-textract", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.