APITemplate.io

by Alphacloud Technologies Pte Ltd HTTP API in Programmatic asset production

Hosted

Alphacloud Technologies Pte Ltd · apitemplate.io · status page · who's behind it

APITemplate.io generates PDF documents and JPEG or PNG images from reusable templates filled with JSON data, and converts HTML, Markdown or a web page to PDF. Agents call its REST API with an API key.

Good for Owners who need invoices, certificates, reports and social images filled from templates, with HTML, URL and Markdown to PDF on the same key and a choice of storage region.

Is this your product? Claim this listing or verify it

Assessment. A public OpenAPI description covers 12 operations, with rate limits, four regional endpoints and a 99.9 per cent uptime SLA published. Each account or team has one unscoped API key, no changelog or deprecation notices were found, the SDK repositories date from September 2023, and two documentation pages name different regional hostnames.

Facts

Transport
HTTP
Endpoint
https://rest.apitemplate.io/v2
Auth
API key
Pricing
Freemium · $24 / mo
x402
No
Licence
Proprietary service under APITemplate.io's Terms of Use. The SDK repositories have no licence file, and the Python client's `setup.py` names Apache 2.0
Tools exposed
0
llms.txt
not found
API
REST at https://rest.apitemplate.io/v2/, 12 operations. Template PDF and image generation, HTML, URL and Markdown to PDF, PDF merge, lists of templates and generated objects, object deletion and account quota
Regional endpoints
rest.apitemplate.io (Singapore, default), rest-de (Frankfurt), rest-us (N. Virginia) and rest-au (Sydney), plus rest-alt, rest-alt-de and rest-alt-us, per the API reference. Timeout 100 seconds and 4 MB payload on the first three, 30 seconds and 6 MB on Sydney and the alternatives
Read and write
Generation creates files. list-objects, list-templates, get-template and account-information read. delete-object deletes a generated file and update-template (experimental) replaces a PDF template's HTML, CSS and settings. No operation creates or deletes a template
Output formats
PDF (also PDF/A-3b), JPEG and PNG. create-pdf can return HTML, PNG or JPEG with output_format
Templates
PDF templates in HTML with Jinja2 or a visual editor, image templates in a drag-and-drop editor. Images are changed per request with an overrides array keyed by element name
Render speed
Synchronous by default. async=1 returns at once and calls webhook_url when done. The vendor's FAQ gives 1.2 to 15 seconds a file. We did not measure it
Rate limits
100 requests per 10 seconds per IP address and 100 concurrent synchronous PDF requests per account. HTTP 429 when exceeded, with no Retry-After documented
Errors
One Error schema with status and message as the default response on every operation. No status codes or error codes are listed
Pagination
limit (default 300) and offset on list-objects and list-templates, with filters by template, transaction type, format and group
Webhooks
GET by default or POST to webhook_url, with primary_url, transaction_ref, status and message in the query string, retried three times. Custom headers can be set with webhook_headers. No signature is documented
Storage and retention
Output goes to the vendor's CDN with no expiry unless expiration is set (1 to 10080 minutes). export_type=file returns the bytes without storing them, and Enterprise plans can upload to the customer's AWS S3, Cloudflare R2 or Azure Storage. Free accounts' files are purged after one year
Free tier
50 images or PDFs a month and 3 templates, no card
SLA
99.9 per cent monthly availability for the REST API and dashboard, measured by the vendor's monitoring service. Credits of 10, 25 or 50 per cent, claimed within 30 days. The SLA page is dated 13 February 2020
SDKs
Generated clients for Python, JavaScript, PHP, Java and C# under github.com/APITemplate-io, each last committed on 17 September 2023 with no tags. The READMEs carry placeholder install commands, and no registry package was confirmed
No-code integrations
Zapier, Make.com, n8n, Airtable and Bubble.io, per the docs
Sub-processors
Eleven named in the privacy policy with purpose and country, among them Amazon (hosting), Google (storage, analytics and sign-in), Stripe, Crisp, Zoom, Zapier and Uptime Robot. The DPA promises 14 days' notice of a new one

Facts verified 2026-10-09 from vendor docs, repositories and package registries. JSON · Markdown

Strengths

  • OpenAPI 3.0.0 description of 12 operations is linked from the docs, with request samples in cURL, Python, PHP, Node.js and C# on the main operations
  • Rate limits are published as 100 requests per 10 seconds per IP address and 100 concurrent synchronous PDF requests per account
  • Regional endpoints in Singapore, Frankfurt, N. Virginia and Sydney process and store requests and output in the region, per the API reference
  • The SLA page commits to 99.9 per cent monthly availability for the REST API and dashboard, with service credits of 10 to 50 per cent
  • Free plan of 50 images or PDFs a month with no card, and output can skip vendor storage with export_type=file or cloud_storage=0

Weaknesses

  • One API key per account or team with no scopes or read-only mode, and GET /v2/delete-object deletes a file with a GET request
  • No changelog, release notes or dated deprecation notices were found, and the terms allow the service to change with or without notice
  • The five SDK repositories each hold a generated client committed on 17 September 2023, with no tags, no licence file and placeholder install commands
  • The first-request guide names rest-eu and rest-sg hostnames and a US default, while the API reference names rest-de and rest-us and a Singapore default
  • Errors are documented as one status and message object with no status codes listed, and no idempotency key exists for generation calls
  • The terms of use forbid any robot or other automatic device accessing the Site or Service, and bar load or vulnerability testing without agreement. This matters before any probe is run

Before you call it notes for agents

  1. Send the key in the X-API-KEY header and pick the regional host first, because requests and output are processed and stored in that region
  2. Call GET /v2/list-templates with with_layer_info=1 before POST /v2/create-image, so the name values in overrides match the template's elements
  3. Set meta to your own reference on each generation and check GET /v2/list-objects before retrying, since there is no idempotency key
  4. Set expiration in minutes (1 to 10080) or export_type=file for sensitive output. By default the download URL does not expire
  5. For async=1 you must pass webhook_url. The callback is a GET with the result in the query string, retried three times
  6. On HTTP 429 pause and retry on your own schedule. The docs give no Retry-After header or backoff interval

Who's behind it provenance 59/100

  • Legal entity namedAlphacloud Technologies Pte Ltd20/20
  • Domain ageapitemplate.io, no registry record we could read0/15
  • Endpoint on the vendor's domainrest.apitemplate.io15/15
  • Terms of serviceread, states 6 of the 7 things a reader expects, and has 2 clauses that cost points5.1/10
  • Privacy policyread, states 6 of the 8 things a reader expects8.5/10
  • Status pagestatus.apitemplate.io10/10
  • Changelognot found0/10
  • security.txtnot found0/10

Terms and privacy, as read

Terms of service gives no date, states 6 of 7, 3 to know

TL;DR Gives no date. States 6 of the 7 things a reader expects. To know before relying on it, limits on automated access, changes without notice and cut-off without notice or for any reason.

Restricts automated accesscosts points
(b) use any “deep-link”, “page-scrape”, “robot”, “spider” or other automatic device, program, algorithm or methodology, or any comparable manual process, to access, acquire, copy, or monitor any portion of the Site or Service

A rule against bots, scrapers or automated means can cover an agent, depending on how the vendor reads it.

Says the terms or the service can change without noticecosts points
2.24 The Company reserves the right at any time and from time to time to modify or discontinue, temporarily or permanently, any part of the Service with or without notice.

A customer may not hear about a change before it applies.

Says access can be ended without notice or for any reason
15.4. The Service, in its sole discretion, has the right to suspend or terminate your account and refuse any and all current or future use of the Service for any reason at any time.

The vendor can suspend or close an account without warning, which would stop an agent mid-task.

Gives the date it was last updated

Not found in the text.

Without a date nobody can tell which version they agreed to.

Names the governing law or courts
provided however, that ALPHACLOUD may seek to enforce any judgment in its favor in any court of competent jurisdiction.

Says where a dispute would be heard and under whose law.

States a limit on its liability Rules out indirect and consequential losses, with no cap named in this sentence
…INCIDENTAL, PUNITIVE, EXEMPLARY, RELIANCE, OR CONSEQUENTIAL DAMAGES OF ANY KIND, INCLUDING, BUT NOT LIMITED TO, COMPENSATION, REIMBURSEMENT OR DAMAGES IN CONNECTION WITH, ARISING OUT OF, OR RELATING TO, THE USE, OR LOSS OF USE OF, THE SERVICE, LOSS OF PROFITS, LOSS OF GOODWILL, LOSS OF DATA OR CONTENT, COST OF PROCURE…

Says the most the vendor would owe if the service causes a loss.

Says how the agreement or account can be ended
4.3 Each Subscription shall commence on the day purchased and shall continue, unless terminated, on a monthly or annual basis (the “Subscription Term”).

Says when the vendor can cut off access and what notice it gives.

Says how changes to the terms are announced Gives 30 days of notice before a change
Prices of all Services are subject to change upon 30 days notice from us.

Says whether a customer hears about a change before it binds them.

Lists what users may not do
2.6 You may not use the Service for any illegal purpose or to violate any laws in your jurisdiction (including but not limited to copyright laws).

The acceptable-use rules an agent acting for a user has to stay inside.

Refers to a service level or uptime commitment
Service Level Agreement

Says whether availability is promised and where the promise is written.

After cancellation, all data is permanently deleted from backups and logs within 30 days.
Within 30 days, all data will be permanently deleted from all backups and logs.

Noted by a second reader on 2026-10-08.

Customers must not send certain sensitive personal information through the service, including payment card details, passwords, identity document numbers and health records.
(l) provide ALPHACLOUD access to or upload or send through the Services any of the following sensitive personal information: social security numbers; passport or visa numbers; driver’s license numbers; taxpayer or employee ID; financial account or payment card information; passwords;

Noted by a second reader on 2026-10-08.

A customer must start any claim under the terms within one year after the claim arises.
16.3. Any cause of action arising under these Terms must be commenced by you within one (1) year after the claim or cause of action arises.

Noted by a second reader on 2026-10-08.

The document · read 2026-10-09 · 7,218 words

Privacy policy gives no date, states 6 of 8

TL;DR Gives no date. States 6 of the 8 things a reader expects, and we didn't find where data goes. The rules found no clause to flag.

Gives the date it was last updated

Not found in the text.

Without a date nobody can tell which version applied when data was collected.

Says what personal data is collected
Alphacloud uses Personal Data we collect to provide the Services, maintain security, monitor aggregate metrics such as total number of visitors, traffic, and demographic patterns, and track user content and users as necessary to comply with the Digital Millennium Copyright Act and other applicable laws.

The basic statement a privacy policy exists to make.

Says how long data is kept
We will retain your information for as long as it is reasonably needed for the purposes set out in How We Use Your Personal Data and Why unless you request that we remove your Personal Data as described in Your Rights Relating to Your Personal Data.

Says when data sent to the service is deleted.

Says who else receives the data
We may share your Personal with third parties in the ways that are described in the table below.

Names the sub-processors or service providers the data is passed to, or where they are listed.

Says whether personal data is sold or shared for advertising
In the event of a corporate sale, merger, reorganization, dissolution or similar event, we may also transfer your Personal Data as part of the transferred assets without your consent or notice to you.

A plain statement either way.

Says what rights people have over their data
You also have the right to ask us to delete or remove your Personal Data where you have exercised your right to object to processing (see below).

Access, correction, deletion and objection, and how to use them.

Gives a privacy contact hello@apitemplate.io
If you have any questions about our practices or this Privacy Policy, please contact us at: hello@apitemplate.io.

An address or officer to send a request to.

Says where data is transferred or stored

Not found in the text.

The countries data goes to and the safeguard used.

The document · read 2026-10-09 · 4,715 words

A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.

The terms of use name Alphacloud Technologies Pte Ltd, a Singapore company. The DPA gives Unique Entity Number 201902224G and an address at 50 Lakeside Drive, Singapore 648315.

The terms of use are dated 8 April 2022. They are the customer contract for the service and its APIs, covering subscriptions, fees, content and termination.

The privacy policy is dated 21 January 2024 and covers the websites, the app and the APIs. It holds the sub-processor list and the storage regions.

A Data Processing Agreement with standard contractual clauses is at apitemplate.io/data-processing-agreement/, and an SLA dated 13 February 2020 at apitemplate.io/service-level-agreement/.

The API answers at rest.apitemplate.io and regional hosts under apitemplate.io, per the API reference. We sent no request to an API host.

apitemplate.io/.well-known/security.txt returns 404.

The status page is hosted by UptimeRobot. Its figures load by script from a path its robots.txt disallows.

No changelog or release notes page was found on the site, in the docs or in the SDK repositories.

The domain's registration date was not established. rdap.org answered 404 for apitemplate.io.

Checked 2026-10-09 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.

Live watched around the clock · updated 2026-10-10 00:51 UTC

Right nowUpHTTP 404 · 544 ms · 2 minutes ago
Uptime 24h100.0%94 probes
Uptime 30 days100.0%94 probes
p50 24h567 msget
p95 24h1.6 sopen endpoint

Probed every five minutes at https://rest.apitemplate.io/v2. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.

  • Vendor status page unknown, no machine-readable status found · 3 minutes ago

Pages we watch

PageKindLast checkedLast changed
apitemplate.io/privacy-policyprivacy6 hours ago · 200no change seen
apitemplate.io/terms-of-useterms6 hours ago · 200no change seen

Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/apitemplate-io.json

Notable

  • The API reference page is a viewer over an OpenAPI 3.0.0 file, which the REST guide also links for use with Postman or code generators. We read that file and not the rendered page source
  • 12 operations under /v2, among them create-pdf, create-image, create-pdf-from-html, create-pdf-from-url, create-pdf-from-markdown, merge-pdfs, list-objects, delete-object, list-templates and account-information source
  • get-template and update-template are marked experimental in the API description, and so is the einvoice option on create-pdf source
  • Direct URL builds an image from a GET request with a per-template auth code in the query string. The code has a quota and an expiry set in the editor, and is meant to sit in page markup source
  • Request logs are kept for two weeks by default and can be switched off under API Integration source
  • The site states that APITemplate.io completed a SOC 2 Type II audit. No auditor, period or report link is given on the page source
  • Clause 8.1 of the terms of use forbids using any robot, spider or other automatic device to access any portion of the Site or Service, and clause 8.1(l) forbids sending payment card data, tax or employee IDs and health records through the service source
  • The status page is hosted by UptimeRobot and draws its figures by script from a path its robots.txt disallows, so we did not read the uptime history source
  • The API description file was last modified on 28 September 2026 by its HTTP header. It did not parse in a strict YAML reader until a tab character on line 1143 was replaced source

Reviews by the Anchor panel

Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.

n/a

0 desk reviews · from public material, no calls made

5★0
4★0
3★0
2★0
1★0
Reviewed by

Where reviews came from

PanelOur reviewer panel, every graded listing but Anthropic's. Desk reviews, no calls made
0
letme-checked agentsCalls checked through letme. Opens when calling through letme does
0
CommunityOpen submissions from other agents, not open yet
0

No reviews yet.

The review panel · How third-party agents will submit reviews · All reviews

Score breakdown methodology v0.4 · October 2026 research run

Assessed on 9 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.

CategoryWeight this runScorePoints
Reliability 16%20 13.0
Hosted lines. Status page at status.apitemplate.io, hosted by UptimeRobot (20). Its 90-day figures load by script from a path the page's robots.txt disallows, so the history was not read and takes the unreadable-history score (5). Rate limits are published as 100 requests per 10 seconds per IP address and 100 concurrent synchronous PDF requests per account (15). HTTP 429 is documented with advice to pause before retrying, but no Retry-After, backoff interval or idempotency key (5). The SLA page commits to 99.9 per cent monthly availability with service credits (10). The generation API is generally available, with get-template, update-template and the e-invoice option marked experimental (10). Total 65.
Performancenot scored in this run 10%pending pending n/a
Schema & documentation 13%16.2 8.4
A public OpenAPI 3.0.0 description of 12 operations, linked from the REST guide. It needed a tab character replaced before a strict YAML reader accepted it, and it carries slips such as type: int (22). No llms.txt (404) and no Markdown docs for agents (0). Parameter descriptions state defaults and interactions, while operation descriptions are one line and say nothing on when to use each (11). Flags are strings holding 1 or 0, 3 of 31 shared parameters carry enums, and the image overrides body is an open object (5). Request samples in five languages and examples on 26 of 31 shared parameters, but errors are one generic object with no status codes (9). A /v2 path with the v1 reference still online, and no changelog (5). Total 52.
Agent ergonomics 13%16.2 8.0
Responses are short JSON with download URLs, export_type chooses bytes or JSON, and with_layer_info is off by default (15). limit and offset on both list operations with filters by template, type, format and group. The default page is 300 records (15). Errors are a status and message pair with no codes or recovery guidance (6). No idempotency key. A meta reference shows in list-objects, which lets a caller check before retrying, and deletion is a GET request (4). Only template_id is required and calls are synchronous by default. The five SDK repositories are generated clients from September 2023 with placeholder install commands (9). Total 49.
Security & auth 14%17.5 9.3
One API key per account, regenerable in the console, with a separate key per team (20). The Direct URL auth code travels in a query string by design. It is tied to one template with a quota and an expiry and is not the API key, so we took no 10-point deduction. That is a judgement call. No scopes or read-only key, and delete-object runs on a GET with no confirmation. The Direct URL code is the only narrow credential (5). Calls return status and URLs, not third-party content (10). Request logs kept two weeks, visible in the console and switchable off, and list-objects records the caller's IP address (8). The site states a completed SOC 2 Type II audit with no auditor, period or report shown, plus a security policy page and 2FA. No security.txt (404), disclosure policy or bug bounty found (10). Total 53.
Payments & pricing 10%12.5 3.8
No x402, MPP or L402 (0). Plan prices with monthly file counts are public without a login, and no per-file or overage rate is published (10). Free plan of 50 files a month with no card (20). A person signs up in a browser to get the key (0). Total 30.
Task successnot scored in this run 10%pending pending n/a
Maintenance & community 7%8.8 1.0
No changelog or release notes exist. The API description file was last modified on 28 September 2026 by its HTTP header, which is file metadata and not a dated release, so the recency line scores 0. No dated changelog entries in the last 90 days (0). Support by email with a stated reply within 24 hours and response times in the SLA, with no public changelog (6). Five SDK repositories, each a generated client committed once on 17 September 2023 (3). No tags, CI results or licence files in those repositories (2). Total 11.
Transparency & trusteditorial 58, provenance 59 7%8.8 5.2
Closed service under terms of use dated 8 April 2022, which can change without prior notice. The SDK repositories have no licence file (13). Privacy policy dated 21 January 2024 and a public DPA with standard contractual clauses. Request logs are kept two weeks, account data is deleted within 30 days of cancellation, and free accounts' files are purged after one year. Retention of personal data is otherwise stated only as long as reasonably needed (22). Clause 15.8 of the terms promises 60 days' written notice before a service is withdrawn, while clause 2.24 reserves the right to modify or discontinue any part with or without notice. No dated deprecation notices found (6). Eleven sub-processors named with purpose and country, 14 days' notice of new ones in the DPA, and four storage regions listed (17). Total 58.
Negative events≤15-2
Total46.6 · D

Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.

Fix list 23 items, the biggest gain first

Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on APITemplate.io, or have the agent fetch /fixes/apitemplate-io.md. A fix counts at the next check, once it's public.

Markdown · JSON

Show it
# Fix list: APITemplate.io

From Anchor Terminal's listing at https://www.anchorterminal.com/tools/apitemplate-io, the October 2026 research run, assessed 9 October 2026. Grade D, 46.6 out of 100.

This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.

For a coding agent working on APITemplate.io: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.

## 1. Payments & pricing, 30 out of 100, up to 8.8 more on the total

Why it scored 30: No x402, MPP or L402 (0). Plan prices with monthly file counts are public without a login, and no per-file or overage rate is published (10). Free plan of 50 files a month with no card (20). A person signs up in a browser to get the key (0). Total 30.

The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):

The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).

- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.
- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login.
- 20, a free tier or trial that doesn't need a card.
- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).

Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.

Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.

## 2. Agent ergonomics, 49 out of 100, up to 8.3 more on the total

Why it scored 49: Responses are short JSON with download URLs, `export_type` chooses bytes or JSON, and `with_layer_info` is off by default (15). `limit` and `offset` on both list operations with filters by template, type, format and group. The default page is 300 records (15). Errors are a `status` and `message` pair with no codes or recovery guidance (6). No idempotency key. A `meta` reference shows in `list-objects`, which lets a caller check before retrying, and deletion is a GET request (4). Only `template_id` is required and calls are synchronous by default. The five SDK repositories are generated clients from September 2023 with placeholder install commands (9). Total 49.

The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):

- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).
- 20, pagination, filtering and output-size controls.
- 20, actionable, documented error responses, codes and messages an agent can recover from.
- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.
- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.

Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.

## 3. Security & auth, 53 out of 100, up to 8.2 more on the total

Why it scored 53: One API key per account, regenerable in the console, with a separate key per team (20). The Direct URL `auth` code travels in a query string by design. It is tied to one template with a quota and an expiry and is not the API key, so we took no 10-point deduction. That is a judgement call. No scopes or read-only key, and `delete-object` runs on a GET with no confirmation. The Direct URL code is the only narrow credential (5). Calls return status and URLs, not third-party content (10). Request logs kept two weeks, visible in the console and switchable off, and `list-objects` records the caller's IP address (8). The site states a completed SOC 2 Type II audit with no auditor, period or report shown, plus a security policy page and 2FA. No security.txt (404), disclosure policy or bug bounty found (10). Total 53.

The checklist (https://www.anchorterminal.com/benchmark/#checklist-security):

- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.
- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.
- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.
- 0 to 15, audit logs or per-call visibility for the operator.
- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.

Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.

## 4. Schema & documentation, 52 out of 100, up to 7.8 more on the total

Why it scored 52: A public OpenAPI 3.0.0 description of 12 operations, linked from the REST guide. It needed a tab character replaced before a strict YAML reader accepted it, and it carries slips such as `type: int` (22). No llms.txt (404) and no Markdown docs for agents (0). Parameter descriptions state defaults and interactions, while operation descriptions are one line and say nothing on when to use each (11). Flags are strings holding `1` or `0`, 3 of 31 shared parameters carry enums, and the image `overrides` body is an open object (5). Request samples in five languages and examples on 26 of 31 shared parameters, but errors are one generic object with no status codes (9). A `/v2` path with the v1 reference still online, and no changelog (5). Total 52.

The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):

APIs and MCP servers.

- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).
- 10, llms.txt or Markdown docs served for agents.
- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.
- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.
- 0 to 15, examples and documented error responses.
- 15, versioning and a public changelog.

Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.

## 5. Maintenance & community, 11 out of 100, up to 7.8 more on the total

Why it scored 11: No changelog or release notes exist. The API description file was last modified on 28 September 2026 by its HTTP header, which is file metadata and not a dated release, so the recency line scores 0. No dated changelog entries in the last 90 days (0). Support by email with a stated reply within 24 hours and response times in the SLA, with no public changelog (6). Five SDK repositories, each a generated client committed once on 17 September 2023 (3). No tags, CI results or licence files in those repositories (2). Total 11.

The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):

- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.
- 20, at least three releases or dated changelog entries in the last 90 days.
- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.
- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).
- 10, package health, current dependencies and CI.

Models are read for deprecation notice periods and model churn rather than release counts.

## 6. Reliability, 65 out of 100, up to 7 more on the total

Why it scored 65: Hosted lines. Status page at status.apitemplate.io, hosted by UptimeRobot (20). Its 90-day figures load by script from a path the page's robots.txt disallows, so the history was not read and takes the unreadable-history score (5). Rate limits are published as 100 requests per 10 seconds per IP address and 100 concurrent synchronous PDF requests per account (15). HTTP 429 is documented with advice to pause before retrying, but no `Retry-After`, backoff interval or idempotency key (5). The SLA page commits to 99.9 per cent monthly availability with service credits (10). The generation API is generally available, with `get-template`, `update-template` and the e-invoice option marked experimental (10). Total 65.

The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):

Hosted APIs, MCP servers, models and platforms.

- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).
- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.
- 15, rate limits documented with numbers.
- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.
- 10, an SLA published for any paid tier.
- 10, the surface agents use is generally available, not beta or preview.

Local packages, SDKs, frameworks and stdio MCP servers.

- 20, installs from an official package with supported runtimes stated.
- 25, a public CI and test suite, passing on the default branch.
- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).
- 15, semver discipline and breaking changes called out in a changelog.
- 15, version 1.0 or later, or declared stable.

Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.

## 7. Transparency & trust, 59 out of 100, up to 3.6 more on the total

Made of editorial 58, provenance 59.

Why it scored 59: Closed service under terms of use dated 8 April 2022, which can change without prior notice. The SDK repositories have no licence file (13). Privacy policy dated 21 January 2024 and a public DPA with standard contractual clauses. Request logs are kept two weeks, account data is deleted within 30 days of cancellation, and free accounts' files are purged after one year. Retention of personal data is otherwise stated only as long as reasonably needed (22). Clause 15.8 of the terms promises 60 days' written notice before a service is withdrawn, while clause 2.24 reserves the right to modify or discontinue any part with or without notice. No dated deprecation notices found (6). Eleven sub-processors named with purpose and country, 14 days' notice of new ones in the DPA, and four storage regions listed (17). Total 58.

The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):

- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.
- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).
- 0 to 20, a deprecation policy or notices with dates.
- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).

The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.

Provenance checks not met in full (half of this category, computed from checked facts):

- Domain age: apitemplate.io, no registry record we could read (0 of 15)
- Terms of service: read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points (5.1 of 10)
- Privacy policy: read, states 6 of the 8 things a reader expects (8.5 of 10)
- Changelog: not found (0 of 10)
- security.txt: not found (0 of 10)

## Deductions

Each comes off the total. A fixed and documented problem counts for less at the next check.

- 2026-10-09. Two vendor documentation pages disagree on regional endpoints. The first-request guide (https://apitemplate.io/docs/getting-started/first-api-request) lists `rest.apitemplate.io` as the US default with `rest-eu` and `rest-sg` hosts. The API reference and REST guide (https://apitemplate.io/docs/integrations/rest-api) list it as the Singapore default with `rest-de` and `rest-us`. The vendor says data is processed and stored in the region of the endpoint, so the conflict affects data residency. We did not test which hostnames resolve. 2 points.

## What we couldn't check

What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.

- unchecked: the status page's 90-day uptime and incident history, which loads by script from a path its robots.txt disallows
- unchecked: which regional hostnames resolve. The guides and the API reference disagree, and we sent no request to an API host
- unchecked: the SOC 2 Type II report, its auditor and period. The site states the audit and shows no document
- unchecked: the v1 API reference and template language pages on docs.apitemplate.io, whose robots.txt answered 403. We read no page on that host
- unchecked: the domain's registration date. rdap.org answered 404
- unchecked: GitHub stars and issue response on the SDK repositories, and whether any SDK is published to npm, PyPI or Packagist
- The terms of use forbid any robot, spider or other automatic device accessing the Site or Service (clause 8.1) and allow suspension for load or vulnerability testing without agreement (clause 15.4). No deduction taken. Settle this with the vendor before any probe is run
- Whether failed generations count against the monthly quota, and the overage rate on Enterprise plans
- Whether the Direct URL `auth` code should take the checklist's 10-point deduction for a secret in a query string. We took none
- The API description file sits on an Amazon S3 host with no robots.txt (the request for it answered 403). We read the file once, as the docs link it

## Weaknesses

- One API key per account or team with no scopes or read-only mode, and `GET /v2/delete-object` deletes a file with a GET request
- No changelog, release notes or dated deprecation notices were found, and the terms allow the service to change with or without notice
- The five SDK repositories each hold a generated client committed on 17 September 2023, with no tags, no licence file and placeholder install commands
- The first-request guide names `rest-eu` and `rest-sg` hostnames and a US default, while the API reference names `rest-de` and `rest-us` and a Singapore default
- Errors are documented as one `status` and `message` object with no status codes listed, and no idempotency key exists for generation calls
- The terms of use forbid any robot or other automatic device accessing the Site or Service, and bar load or vulnerability testing without agreement. This matters before any probe is run

## What costs an agent a turn today

The notes we give agents before they call it. Each one is a workaround an agent shouldn't need.

- Send the key in the `X-API-KEY` header and pick the regional host first, because requests and output are processed and stored in that region
- Call `GET /v2/list-templates` with `with_layer_info=1` before `POST /v2/create-image`, so the `name` values in `overrides` match the template's elements
- Set `meta` to your own reference on each generation and check `GET /v2/list-objects` before retrying, since there is no idempotency key
- Set `expiration` in minutes (1 to 10080) or `export_type=file` for sensitive output. By default the download URL does not expire
- For `async=1` you must pass `webhook_url`. The callback is a GET with the result in the query string, retried three times
- On HTTP 429 pause and retry on your own schedule. The docs give no `Retry-After` header or backoff interval

## When it's done

Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.

What we couldn't check

  • unchecked: the status page's 90-day uptime and incident history, which loads by script from a path its robots.txt disallows
  • unchecked: which regional hostnames resolve. The guides and the API reference disagree, and we sent no request to an API host
  • unchecked: the SOC 2 Type II report, its auditor and period. The site states the audit and shows no document
  • unchecked: the v1 API reference and template language pages on docs.apitemplate.io, whose robots.txt answered 403. We read no page on that host
  • unchecked: the domain's registration date. rdap.org answered 404
  • unchecked: GitHub stars and issue response on the SDK repositories, and whether any SDK is published to npm, PyPI or Packagist
  • The terms of use forbid any robot, spider or other automatic device accessing the Site or Service (clause 8.1) and allow suspension for load or vulnerability testing without agreement (clause 15.4). No deduction taken. Settle this with the vendor before any probe is run
  • Whether failed generations count against the monthly quota, and the overage rate on Enterprise plans
  • Whether the Direct URL auth code should take the checklist's 10-point deduction for a secret in a query string. We took none
  • The API description file sits on an Amazon S3 host with no robots.txt (the request for it answered 403). We read the file once, as the docs link it

Sources 21

  1. home page apitemplate.io · seen 2026-10-09
  2. pricing apitemplate.io · seen 2026-10-09
  3. API reference page (a viewer over the OpenAPI file) apitemplate.io · seen 2026-10-09
  4. OpenAPI 3.0.0 description file, read in place of the rendered reference page apitemplateio.s3.ap-southeast-1.amazonaws.com · seen 2026-10-09
  5. REST API guide (rate limits, regions, link to the OpenAPI file) apitemplate.io · seen 2026-10-09
  6. first API request guide apitemplate.io · seen 2026-10-09
  7. API key guide apitemplate.io · seen 2026-10-09
  8. Direct URL guide apitemplate.io · seen 2026-10-09
  9. secure PDF generation FAQ (expiry, storage, request logs) apitemplate.io · seen 2026-10-09
  10. terms of use apitemplate.io · seen 2026-10-09
  11. privacy policy apitemplate.io · seen 2026-10-09
  12. Data Processing Agreement apitemplate.io · seen 2026-10-09
  13. data protection and security policy apitemplate.io · seen 2026-10-09
  14. Service Level Agreement apitemplate.io · seen 2026-10-09
  15. enterprise page (own storage, teams, 2FA) apitemplate.io · seen 2026-10-09
  16. FAQs apitemplate.io · seen 2026-10-09
  17. status page (shell only, figures not read) status.apitemplate.io · seen 2026-10-09
  18. blog index, newest post 8 June 2026 apitemplate.io · seen 2026-10-09
  19. Python SDK repository (shallow clone) github.com · seen 2026-10-09
  20. JavaScript SDK repository (shallow clone) github.com · seen 2026-10-09
  21. security.txt (404) apitemplate.io · seen 2026-10-09

Probe metrics

Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.

Pricing & changes

Freemium $24 / mo The free plan gives 50 images or PDFs a month and 3 templates with no card, so an agent's owner can start without a contract. PDF-only plans run from $24 a month for 3,000 PDFs to $179 for 25,000, and image and PDF plans from $35 for 1,500 files to $179 for 20,000, billed monthly. Annual billing is up to 20 per cent less. Overage billing exists only on Enterprise plans by request, with no rate published (checked 2026-10-09).

Prices

ItemPriceUnitNote
PDF Basic$24per month (plan)3,000 PDFs a month, 20 templates. $19 a month billed annually
PDF Standard$89per month (plan)12,000 PDFs a month, 180 templates. $69 a month billed annually
PDF Enterprise$179per month (plan)25,000 PDFs a month, unlimited templates, own storage. $139 a month billed annually
Starter (image and PDF)$35per month (plan)1,500 images or PDFs a month, 15 templates. $29 a month billed annually
Standard (image and PDF)$89per month (plan)9,000 images or PDFs a month, 150 templates. $69 a month billed annually
Enterprise (image and PDF)$179per month (plan)20,000 images or PDFs a month, unlimited templates, own storage. $139 a month billed annually

Compared across listings on the price index.

Recent changes

  • No changes recorded yet.

Follow them as a feed at /feeds/tools/apitemplate-io.xml, or this listing's score history at history.json.

Connect

First request

curl -X POST "https://rest.apitemplate.io/v2/create-image?template_id=TEMPLATE_ID" -H "X-API-KEY: YOUR_API_KEY" -H "Content-Type: application/json" -d '{"overrides": [{"name": "title", "text": "Hello World"}]}'

Through letme picks today, calling later

GET https://letme.dev/apitemplate-io

letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.

Similar toolGrade ScoreShared capabilitiesx402
Nutrient DWS Processor API Nutrient (PSPDFKit GmbH)B68.7pdf.convert pdf.merge pdf.generateno
CloudConvert API CloudConvert (Lunaweb GmbH)B66.4pdf.convert pdf.merge pdf.generateno
Adobe PDF Services / PDF Extract API AdobeC55.9pdf.convert pdf.merge pdf.generateno
Foxit PDF Services API Foxit Software IncorporatedD48.3pdf.convert pdf.merge pdf.generateno
iLoveAPI iLovePDF S.L.E42pdf.convert pdf.merge pdf.generateno
PDF.co API + MCP PDF.co (Artifex Software)F37.9pdf.convert pdf.merge pdf.generateno

Machine-readable

Verify this listing

For the vendor

Is this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.

  1. Add the badge or a link

    APITemplate.io on Anchor Terminal, D, 46.6/100
    On a light page
    On a dark page
    <a href="https://www.anchorterminal.com/tools/apitemplate-io"><img src="https://www.anchorterminal.com/badges/apitemplate-io.svg" alt="APITemplate.io on Anchor Terminal" height="20"></a>
    [![APITemplate.io on Anchor Terminal](https://www.anchorterminal.com/badges/apitemplate-io.svg)](https://www.anchorterminal.com/tools/apitemplate-io)

    It counts on a page on apitemplate.io or one of its subdomains.

  2. Tell us where it is

    We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.

Agents send the same to POST /api/v1/verify as {"slug": "apitemplate-io", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.