Aurinko Calendar API
by Yoxel, Inc. HTTP API in Calendars & scheduling
Hosted
Yoxel, Inc. · aurinko.io since 2019 · who's behind it
Unified calendar REST API from Yoxel, Inc. It reads and writes calendars and events on Google, Office 365, Outlook.com, Exchange and iCloud through one interface, with free/busy queries, booking profiles and webhooks.
Good for A product that connects many users' Google and Microsoft calendars and wants availability and booking at a low price per account.
Is this your product? Claim this listing or verify it
Assessment. A public OpenAPI 3.0 spec covers 154 operations, with free/busy, meeting-time suggestion and booking profiles alongside calendar reads and writes, and prices start at $1 an active account a month. No status page, SLA, changelog or official SDK was found, and the application's client secret reaches every connected account.
Facts
- Transport
- HTTP
- Endpoint
https://api.aurinko.io- Auth
- OAuth
- Pricing
- Paid · Paid
- x402
- No
- Licence
- Proprietary service under Yoxel's Terms of Services Agreement
- Docs
- docs.aurinko.io/
- llms.txt
- published
- API
- REST at https://api.aurinko.io/v1, OpenAPI 3.0.0 spec with 112 paths and 154 operations across email, calendar, contacts, tasks, booking and webhooks
- Calendar endpoints
/v1/calendars,/v1/calendars/{calendarId}/events,/events/range,/events/find, series and occurrences,/syncwith delta tokens,/freeBusy,/availableTimesand/v1/calendars/suggestMeetingTimes- Booking
- Booking profiles for one account under
/v1/book/account/profilesand for groups under/v1/book/group/profiles, with available meeting times, meeting creation, reservations that can be confirmed or cancelled, and a hosted booking page - Providers
- Google, Office 365, Outlook.com, MS Exchange and iCloud for calendars per the vendor's site. The spec's service types also list Zoho and IMAP
- Credentials
- Account access token (Bearer) from the OAuth flow, client ID and secret (Basic) for application-level calls, or a user session in
X-Aurinko-Sessionor a cookie - Scopes
Calendar.Read,Calendar.ReadWrite,Mail.Read,Mail.ReadWrite,Mail.Send,Mail.Drafts,Mail.All,Contacts.Read,Contacts.ReadWrite,Tasks.Read,Tasks.ReadWrite- Rate limits
- 250 requests a second for API calls, per the spec. Provider limits behind the API can also return 429
- Errors
- JSON body with
code,message,requestIdand the provider'soriginalError. The spec advises exponential backoff on 429 and 5xx, a retry on 408, and no retry on 404 - Webhooks
POST /v1/subscriptionsfor/calendars/primary/events,/calendars/{calId}/eventsand/booking/{bookingId}, signed with HMAC SHA256 inX-Aurinko-Signature- Trial
- 14 days with full API access and no card. Access is blocked at expiry until a card is added
- SDKs
- No official SDK found.
aurinko-sdkon npm describes itself as unofficial - Security statement
- TLS in transit and AES-256 at rest, MFA and role-based access, third-party penetration tests, SOC 2 Type I targeted for Q3 2026 (statement of 18 June 2026)
Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- Public OpenAPI 3.0 spec at
apirefs.aurinko.io/assets/swagger.jsonwith 154 operations, 110 of them carrying a cURL sample - Availability in three forms,
/v1/calendars/freeBusy,/v1/calendars/suggestMeetingTimesand booking profiles for one calendar or a group - Prices published per active account a month ($1, $1.50 and $2), with a 14-day trial that needs no card
- Eleven OAuth scopes, with
Calendar.Readseparate fromCalendar.ReadWrite, andDELETE /v1/account/tokento revoke a token - Docs state that event, email and contact contents are passed through and never stored, with only IDs cached for sync
Weaknesses
- No status page, incident history or SLA found, and the terms supply the service as is
- No changelog, deprecation policy or official SDK. The only npm package,
aurinko-sdk, is unofficial - The application's client ID and secret, sent as Basic auth with
X-Aurinko-Account-Id, reach every connected account - SOC 2 is not yet held. The security statement of 18 June 2026 targets a Type I examination for Q3 2026
- Terms and privacy policy date from 11 August 2022, with no retention period, DPA or sub-processor list found
Before you call it notes for agents
- Use
https://api.aurinko.io/v1. Several cURL examples in the docs printhttps:/api.aurinko.iowith one slash - Send
If-Matchwith the event'setagonPATCH /v1/calendars/{calendarId}/events/{eventId}. A stale value returns 412 - Use
primaryas the calendar ID for an account's main calendar, and page withpageTokenuntil none is returned - Hold a slot with
reserveForMinuteson the bookingmeetingcall, then confirm or cancel the reservation, since no idempotency key exists - Retry 429, 408 and 5xx with exponential backoff. Do not retry 404. A 429 can come from Google or Microsoft limits behind the API
Who's behind it provenance 60/100
- Legal entity namedYoxel, Inc.20/20
- Domain ageaurinko.io, registered 2019-05-08 (7 years)11/15
- Endpoint on the vendor's domainapi.aurinko.io15/15
- Terms of serviceread, states 6 of the 7 things a reader expects, and has 2 clauses that cost points5.1/10
- Privacy policyread, states 7 of the 8 things a reader expects9.3/10
- Status pagenot found0/10
- Changelognot found0/10
- security.txtnot found0/10
Terms and privacy, as read
Terms of service dated 2022-08-11, states 6 of 7, 5 to know
TL;DR Dated 2022-08-11. States 6 of the 7 things a reader expects, and we didn't find a service level. To know before relying on it, limits on automated access, limits on benchmarking, cut-off without notice or for any reason, arbitration or a class action waiver and no update in three years.
Restricts automated accesscosts points
…re-publish, license, reverse engineer, or create derivative works from Service Materials, nor use any robots, data mining, or similar data extraction or gathering methods in connection with our Services.
A rule against bots, scrapers or automated means can cover an agent, depending on how the vendor reads it.
Restricts benchmarking or competitive usecosts points
use the Services and the Site in any manner to compete with Yoxel.
A clause against publishing test results or using the service to build something that competes.
Says access can be ended without notice or for any reason
We may terminate this Agreement or close your Yoxel Account at any time for any reason (including, without limitation, for any activity that may create harm or loss to the goodwill of a Payment Method) by providing you Notice.
The vendor can suspend or close an account without warning, which would stop an agent mid-task.
Requires arbitration or waives class actions
IMPORTANT NOTICE REGARDING ARBITRATION: WHEN YOU AGREE TO THIS AGREEMENT YOU ARE AGREEING (WITH LIMITED EXCEPTION) TO RESOLVE ANY DISPUTE BETWEEN YOU AND YOXEL THROUGH BINDING ARBITRATION RATHER THAN IN COURT.
Disputes go to an arbitrator, or a customer gives up joining a class action or a jury trial.
Has not been updated for three years or more
Last Updated: Aug 11, 2022
The date the document gives for itself is more than three years ago.
Gives the date it was last updated Last updated 2022-08-11
Last Updated: Aug 11, 2022
Without a date nobody can tell which version they agreed to.
Names the governing law or courts The law of the State of California
The Yoxel Site and Services are provided by, and you’re contracting with: Yoxel that is organized under the laws of the State of California, USA.
Says where a dispute would be heard and under whose law.
States a limit on its liability Rules out indirect and consequential losses, with no cap named in this sentence
Under no circumstances will Yoxel be responsible or liable to you for any indirect, punitive, incidental, special, consequential, or exemplary damages resulting from your use or inability to use the Services or for the unavailability of the Services, for lost profits, personal injury, or property damage, or for any ot…
Says the most the vendor would owe if the service causes a loss.
Says how the agreement or account can be ended
Until you have submitted, and we have reviewed and approved, all Required Information, your Yoxel Account will be available to you on a preliminary basis only, and we may terminate it at any time and for any reason.
Says when the vendor can cut off access and what notice it gives.
Says how changes to the terms are announced Gives 10 days of notice before a change
If you are an existing user of our Services, the material changes to this Agreement will come into effect 10 days after we provide you with the Notice.
Says whether a customer hears about a change before it binds them.
Lists what users may not do
You may not access or use our Services or Site unless you agree to abide by all the terms and conditions set in this Agreement.
The acceptable-use rules an agent acting for a user has to stay inside.
Refers to a service level or uptime commitment
Not found in the text.
Says whether availability is promised and where the promise is written.
Liability not otherwise disclaimed is capped at the fees paid in the three months before the event behind the claim.
you further agree that under no circumstances will any such liability exceed in the aggregate the amount of Fees paid by you to Yoxel during the three-month period immediately preceding the event that gave rise to your claim for damages.
Noted by a second reader on 2026-10-08.
On monthly plans Yoxel may change the fees at any time, and a customer who does not accept the new fees is told to cancel.
We reserve the right to change the Fees at any time. If you do not accept the new Fees, you should cancel your subscription.
Noted by a second reader on 2026-10-08.
On termination Yoxel may delete all of the customer’s stored information but is not obliged to.
we reserve the right (but have no obligation) to delete all of your information stored on our servers;
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 6,042 words
Privacy policy dated 2022-08-11, states 7 of 8, 1 to know
TL;DR Dated 2022-08-11. States 7 of the 8 things a reader expects, and we didn't find where data goes. To know before relying on it, no update in three years.
Has not been updated for three years or more
Last Updated: Aug 11, 2022
The date the document gives for itself is more than three years ago.
Gives the date it was last updated Last updated 2022-08-11
Last Updated: Aug 11, 2022
Without a date nobody can tell which version applied when data was collected.
Says what personal data is collected
We are committed to respecting the privacy and security of the personal information we collect.
The basic statement a privacy policy exists to make.
Says how long data is kept
To determine how long we keep personal information we consider the amount, nature and sensitivity of personal information, the reasons for which we collect and process the information and applicable legal requirements.
Says when data sent to the service is deleted.
Says who else receives the data
Collected Indirectly: We and our authorized third-party service providers collect certain information by automated means using cookies and other tracking technologies.
Names the sub-processors or service providers the data is passed to, or where they are listed.
Says whether personal data is sold or shared for advertising
Business Transfers: We may also share personal information with third parties whom we choose to acquire, or to whom we choose to sell, transfer, or merge parts of our business or our assets.
A plain statement either way.
Says what rights people have over their data
This Privacy Policy («Privacy Policy») provides important information about our use of personal information and informs you of your rights.
Access, correction, deletion and objection, and how to use them.
Gives a privacy contact compliance@yoxel.com
If you have any questions about this Privacy Policy or our privacy practices, please contact us by email at: compliance@yoxel.com.
An address or officer to send a request to.
Says where data is transferred or stored
Not found in the text.
The countries data goes to and the safeguard used.
Personal information is shared with the third parties whose APIs are integrated, and the policy says they may use it for their own purposes.
These third parties may use your personal information to operate their services and for their own purposes.
Noted by a second reader on 2026-10-08.
Use and transfer of personal information received from Google Accounts is stated to follow the Google API Services User Data Policy, including its Limited Use requirements.
Our use and transfer to any other app of personal information received from Google Accounts will adhere to Google API Services User Data Policy
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 3,325 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The Terms of Services Agreement, last updated 11 August 2022, names Yoxel, Inc., organised under the laws of California, and covers the API and the workspace integrations platform. Disputes go to binding arbitration.
The privacy policy, last updated 11 August 2022, covers the site and the services, API included, and commits to Google's API Services User Data Policy and its Limited Use requirements.
The API answers at api.aurinko.io, the portal at app.aurinko.io and the reference at apirefs.aurinko.io, all on the vendor's domain.
www.aurinko.io/.well-known/security.txt returns 404. The security statement gives security@yoxel.com for reports.
No status page or changelog is linked from the site, the docs or the spec. status.aurinko.io did not resolve from our network.
RDAP for aurinko.io gives a registration date of 2019-05-08.
Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-08 21:12 UTC
Probed every five minutes at https://api.aurinko.io. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/aurinko-calendar.json
Notable
- The spec at apirefs.aurinko.io is OpenAPI 3.0.0, titled Aurinko.io API 1.0.0, with 112 paths and 154 operations, 21 of them under Calendars, Events, CalSync and FreeBusySchedule and 33 under Booking, GroupBooking and Availability source
- Billing counts active accounts, meaning more than 10 API calls or more than 1 MB transferred in a billing month, and the same mailbox connected twice is billed once source
- The docs describe the API as mainly a pass-through that proxies requests to the provider, caching IDs and master-instance relations but never the contents of events, emails, contacts or tasks source
- Group booking profiles attach accounts or groups of accounts with
requiredset tooneorall, and the availability response names which accounts and groups are free for each slot source - Webhook requests are signed with HMAC SHA256 over
v0:{timestamp}:{raw_body}inX-Aurinko-Signature, and subscriptions cover/calendars/{calId}/eventsand/booking/{bookingId}source - The security statement, last updated 18 June 2026, says Yoxel is preparing for a SOC 2 Type I examination targeted for Q3 2026 with Secureframe, and takes vulnerability reports at security@yoxel.com source
- The pricing page and the billing FAQ describe the $1.50 tier differently, as under 5 GB of data transfer on one and as Email or CRM up to 1 GB on the other source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 8.0 | |
Graded as a hosted API. No status page is linked from the site, the docs or the spec, and status.aurinko.io did not resolve (0). With no readable incident history the record scores 5. The spec gives a limit of 250 requests a second (15). It advises exponential backoff on 429 and 5xx and a retry on 408, with no Retry-After header documented and no idempotency keys for event or booking writes (10). No SLA found, and the terms supply the service as is (0). The API is at /v1 with no beta label (10). | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 10.7 | |
Public OpenAPI 3.0.0 spec with 112 paths and 154 operations (25). llms.txt and a Markdown copy of every docs page (10). Every operation has a summary but only 17 have a description, and 193 of 893 schema properties are described (8). Enums appear in 44 of 190 schemas, but only two schemas mark required fields (8). 110 operations carry a cURL sample and the Errors section shows the JSON body, though operations declare only 401 and a default response (10). /v1 in the path and spec version 1.0.0, with no changelog found (5). | |||
| Agent ergonomics | 13%16.2 | 9.1 | |
Graded on the REST API. returnRecord=false trims write responses to an ID and reads take timeMin and timeMax, but no field selection was found (12). pageToken on lists, limit and offset on booking profiles, and delta tokens for incremental sync (16). Errors carry code, message, requestId and the provider's originalError, with retry advice per status (14). No idempotency keys. If-Match with an ETag is required on event updates, and reserveForMinutes holds a slot before a booking is confirmed (8). primary works as a calendar ID and few parameters are required, but no official SDK was found (6). | |||
| Security & auth | 14%17.5 | 7.2 | |
Per-user OAuth with 11 scopes, Calendar.Read separate from Calendar.ReadWrite, and DELETE /v1/account/token to revoke. The application's client ID and secret, sent as Basic auth with X-Aurinko-Account-Id, reach every connected account, and the implicit grant is still supported though not recommended (22). A read-only scope exists, with no confirmation step for deletes (12). Event content from third parties is returned with no injection guidance (0). No operator audit log found in the docs (0). A security statement with a reporting address, security@yoxel.com, and penetration tests claimed. SOC 2 is not yet held, with no bug bounty and no security.txt (7). rescheduleToken travels in the query string on booking calls. No deduction, because it is not the API credential. | |||
| Payments & pricing | 10%12.5 | 5.0 | |
| No x402, MPP or L402 (0). Prices per active account a month published without login, $1, $1.50 and $2 (20). A 14-day trial with no card (20). Signup is in a browser at app.aurinko.io, and each calendar needs its owner's OAuth consent (0). | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 1.8 | |
No changelog or release notes found, so no API change can be dated. Docs pages were edited on 22 and 23 September 2026 per the docs sitemap, counted as partial evidence of activity (15). No dated changelog entries (0). Support is by email at support@aurinko.io, with no public forum or issue tracker found (3). No official SDK. aurinko-sdk on npm is unofficial (0). One public sample repository, yoxel/aurinko-workplace-apps, last updated 1 April 2026 (2). | |||
| Transparency & trusteditorial 27, provenance 60 | 7%8.8 | 3.9 | |
| Closed service under a Terms of Services Agreement naming Yoxel, Inc. of California, last updated 11 August 2022 (15). The docs say content is passed through and never stored, with only IDs cached, and the privacy policy commits to Google's Limited Use requirements. The policy gives no retention period, and no DPA was found (12). No deprecation policy or dated notices found (0). No sub-processor list or data location. The security statement names no cloud provider (0). | |||
| Negative events | ≤15 | None recorded | 0 |
| Total | 45.6 · E | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 19 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Aurinko Calendar API, or have the agent fetch /fixes/aurinko-calendar.md. A fix counts at the next check, once it's public.
Show it
# Fix list: Aurinko Calendar API
From Anchor Terminal's listing at https://www.anchorterminal.com/tools/aurinko-calendar, the October 2026 research run, assessed 8 October 2026. Grade E, 45.6 out of 100.
This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.
For a coding agent working on Aurinko Calendar API: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.
## 1. Reliability, 40 out of 100, up to 12 more on the total
Why it scored 40: Graded as a hosted API. No status page is linked from the site, the docs or the spec, and status.aurinko.io did not resolve (0). With no readable incident history the record scores 5. The spec gives a limit of 250 requests a second (15). It advises exponential backoff on 429 and 5xx and a retry on 408, with no Retry-After header documented and no idempotency keys for event or booking writes (10). No SLA found, and the terms supply the service as is (0). The API is at `/v1` with no beta label (10).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):
Hosted APIs, MCP servers, models and platforms.
- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).
- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.
- 15, rate limits documented with numbers.
- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.
- 10, an SLA published for any paid tier.
- 10, the surface agents use is generally available, not beta or preview.
Local packages, SDKs, frameworks and stdio MCP servers.
- 20, installs from an official package with supported runtimes stated.
- 25, a public CI and test suite, passing on the default branch.
- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).
- 15, semver discipline and breaking changes called out in a changelog.
- 15, version 1.0 or later, or declared stable.
Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.
## 2. Security & auth, 41 out of 100, up to 10.3 more on the total
Why it scored 41: Per-user OAuth with 11 scopes, `Calendar.Read` separate from `Calendar.ReadWrite`, and `DELETE /v1/account/token` to revoke. The application's client ID and secret, sent as Basic auth with `X-Aurinko-Account-Id`, reach every connected account, and the implicit grant is still supported though not recommended (22). A read-only scope exists, with no confirmation step for deletes (12). Event content from third parties is returned with no injection guidance (0). No operator audit log found in the docs (0). A security statement with a reporting address, security@yoxel.com, and penetration tests claimed. SOC 2 is not yet held, with no bug bounty and no security.txt (7). `rescheduleToken` travels in the query string on booking calls. No deduction, because it is not the API credential.
The checklist (https://www.anchorterminal.com/benchmark/#checklist-security):
- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.
- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.
- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.
- 0 to 15, audit logs or per-call visibility for the operator.
- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.
Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.
## 3. Payments & pricing, 40 out of 100, up to 7.5 more on the total
Why it scored 40: No x402, MPP or L402 (0). Prices per active account a month published without login, $1, $1.50 and $2 (20). A 14-day trial with no card (20). Signup is in a browser at app.aurinko.io, and each calendar needs its owner's OAuth consent (0).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):
The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).
- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.
- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login.
- 20, a free tier or trial that doesn't need a card.
- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).
Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.
Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.
## 4. Agent ergonomics, 56 out of 100, up to 7.2 more on the total
Why it scored 56: Graded on the REST API. `returnRecord=false` trims write responses to an ID and reads take `timeMin` and `timeMax`, but no field selection was found (12). `pageToken` on lists, `limit` and `offset` on booking profiles, and delta tokens for incremental sync (16). Errors carry `code`, `message`, `requestId` and the provider's `originalError`, with retry advice per status (14). No idempotency keys. `If-Match` with an ETag is required on event updates, and `reserveForMinutes` holds a slot before a booking is confirmed (8). `primary` works as a calendar ID and few parameters are required, but no official SDK was found (6).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):
- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).
- 20, pagination, filtering and output-size controls.
- 20, actionable, documented error responses, codes and messages an agent can recover from.
- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.
- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.
Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.
## 5. Maintenance & community, 20 out of 100, up to 7 more on the total
Why it scored 20: No changelog or release notes found, so no API change can be dated. Docs pages were edited on 22 and 23 September 2026 per the docs sitemap, counted as partial evidence of activity (15). No dated changelog entries (0). Support is by email at support@aurinko.io, with no public forum or issue tracker found (3). No official SDK. `aurinko-sdk` on npm is unofficial (0). One public sample repository, `yoxel/aurinko-workplace-apps`, last updated 1 April 2026 (2).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):
- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.
- 20, at least three releases or dated changelog entries in the last 90 days.
- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.
- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).
- 10, package health, current dependencies and CI.
Models are read for deprecation notice periods and model churn rather than release counts.
## 6. Schema & documentation, 66 out of 100, up to 5.5 more on the total
Why it scored 66: Public OpenAPI 3.0.0 spec with 112 paths and 154 operations (25). `llms.txt` and a Markdown copy of every docs page (10). Every operation has a summary but only 17 have a description, and 193 of 893 schema properties are described (8). Enums appear in 44 of 190 schemas, but only two schemas mark required fields (8). 110 operations carry a cURL sample and the Errors section shows the JSON body, though operations declare only 401 and a default response (10). `/v1` in the path and spec version 1.0.0, with no changelog found (5).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):
APIs and MCP servers.
- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).
- 10, llms.txt or Markdown docs served for agents.
- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.
- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.
- 0 to 15, examples and documented error responses.
- 15, versioning and a public changelog.
Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.
## 7. Transparency & trust, 44 out of 100, up to 4.9 more on the total
Made of editorial 27, provenance 60.
Why it scored 44: Closed service under a Terms of Services Agreement naming Yoxel, Inc. of California, last updated 11 August 2022 (15). The docs say content is passed through and never stored, with only IDs cached, and the privacy policy commits to Google's Limited Use requirements. The policy gives no retention period, and no DPA was found (12). No deprecation policy or dated notices found (0). No sub-processor list or data location. The security statement names no cloud provider (0).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):
- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.
- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).
- 0 to 20, a deprecation policy or notices with dates.
- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).
The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.
Provenance checks not met in full (half of this category, computed from checked facts):
- Domain age: aurinko.io, registered 2019-05-08 (7 years) (11 of 15)
- Terms of service: read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points (5.1 of 10)
- Privacy policy: read, states 7 of the 8 things a reader expects (9.3 of 10)
- Status page: not found (0 of 10)
- Changelog: not found (0 of 10)
- security.txt: not found (0 of 10)
## What we couldn't check
What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.
- unchecked: whether a status page exists under an address the site does not link. status.aurinko.io did not resolve from our network
- unchecked: the portal at app.aurinko.io behind login, so key rotation, team roles in practice and any request log were not seen
- Whether the SOC 2 Type I examination targeted for Q3 2026 has been completed. The security statement was last updated 18 June 2026
- Which of the two published descriptions of the $1.50 tier applies
- Whether a DPA or sub-processor list is available on request. None is published
- Whether 429 responses carry a Retry-After header. The spec does not say
## Weaknesses
- No status page, incident history or SLA found, and the terms supply the service as is
- No changelog, deprecation policy or official SDK. The only npm package, `aurinko-sdk`, is unofficial
- The application's client ID and secret, sent as Basic auth with `X-Aurinko-Account-Id`, reach every connected account
- SOC 2 is not yet held. The security statement of 18 June 2026 targets a Type I examination for Q3 2026
- Terms and privacy policy date from 11 August 2022, with no retention period, DPA or sub-processor list found
## What costs an agent a turn today
The notes we give agents before they call it. Each one is a workaround an agent shouldn't need.
- Use `https://api.aurinko.io/v1`. Several cURL examples in the docs print `https:/api.aurinko.io` with one slash
- Send `If-Match` with the event's `etag` on `PATCH /v1/calendars/{calendarId}/events/{eventId}`. A stale value returns 412
- Use `primary` as the calendar ID for an account's main calendar, and page with `pageToken` until none is returned
- Hold a slot with `reserveForMinutes` on the booking `meeting` call, then confirm or cancel the reservation, since no idempotency key exists
- Retry 429, 408 and 5xx with exponential backoff. Do not retry 404. A 429 can come from Google or Microsoft limits behind the API
## When it's done
Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- unchecked: whether a status page exists under an address the site does not link. status.aurinko.io did not resolve from our network
- unchecked: the portal at app.aurinko.io behind login, so key rotation, team roles in practice and any request log were not seen
- Whether the SOC 2 Type I examination targeted for Q3 2026 has been completed. The security statement was last updated 18 June 2026
- Which of the two published descriptions of the $1.50 tier applies
- Whether a DPA or sub-processor list is available on request. None is published
- Whether 429 responses carry a Retry-After header. The spec does not say
Sources 21
- OpenAPI spec, errors and rate limits apirefs.aurinko.io · seen 2026-10-08
- docs index for agents docs.aurinko.io · seen 2026-10-08
- Calendar API guide docs.aurinko.io · seen 2026-10-08
- Booking API guide docs.aurinko.io · seen 2026-10-08
- Group Booking API guide docs.aurinko.io · seen 2026-10-08
- authentication scopes docs.aurinko.io · seen 2026-10-08
- account OAuth flow docs.aurinko.io · seen 2026-10-08
- webhooks and signature validation docs.aurinko.io · seen 2026-10-08
- billing FAQ and price tiers docs.aurinko.io · seen 2026-10-08
- trial and subscription docs.aurinko.io · seen 2026-10-08
- data handling statement docs.aurinko.io · seen 2026-10-08
- pricing page aurinko.io · seen 2026-10-08
- terms of services agreement aurinko.io · seen 2026-10-08
- privacy policy aurinko.io · seen 2026-10-08
- security statement aurinko.io · seen 2026-10-08
- security.txt, 404 aurinko.io · seen 2026-10-08
- docs sitemap with page dates docs.aurinko.io · seen 2026-10-08
- unauthenticated request, 401 body api.aurinko.io · seen 2026-10-08
- unofficial npm SDK registry.npmjs.org · seen 2026-10-08
- vendor's GitHub organisation github.com · seen 2026-10-08
- domain registration rdap.identitydigital.services · seen 2026-10-08
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Paid Paid $1 an active account a month for one of Calendar, Contacts or Tasks with up to 1 GB of traffic, $1.50 for Email or CRM, and $2 for any number of APIs with unlimited traffic, per the billing FAQ. A 14-day trial needs no card, and API requests are blocked when it ends without a subscription (https://docs.aurinko.io/faq/how-does-aurinko-billing-work).
Prices
| Item | Price | Unit | Note |
|---|---|---|---|
| Unified API, one of Calendar, Contacts or Tasks | $1 | per connected account per month | Per active account, up to 1 GB of traffic a month |
| Email or CRM | $1.50 | per connected account per month | Per active account, up to 1 GB of traffic a month |
| Full platform, any number of APIs | $2 | per connected account per month | Per active account, unlimited traffic |
Compared across listings on the price index.
Recent changes
- No changes recorded yet.
Follow them as a feed at /feeds/tools/aurinko-calendar.xml, or this listing's score history at history.json.
Connect
First request
curl -H 'Authorization: Bearer <access_token>' \
-X GET https://api.aurinko.io/v1/calendars/primary
Through letme picks today, calling later
GET https://letme.dev/aurinko-calendar
letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.
Compare with
Nylas Calendar and Scheduler API BBCronofy API BGoogle Calendar API ACalendly API + MCP BMicrosoft Graph Calendar API BCal.com API v2 + MCP C
Head to head Acuity Scheduling API vs Aurinko Calendar API · Apiroc Unified Calendar API vs Aurinko Calendar API · Aurinko Calendar API vs Cal.com API v2 + MCP · Aurinko Calendar API vs Calendly API + MCP · Aurinko Calendar API vs Cronofy API · Aurinko Calendar API vs Google Calendar API · Aurinko Calendar API vs Microsoft Graph Calendar API · Aurinko Calendar API vs Nylas Calendar and Scheduler API
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| Nylas Calendar and Scheduler API Nylas | BB | 71 | calendar.read calendar.write calendar.availability calendar.booking calendar.webhooks | no |
| Cronofy API Cronofy | B | 64.2 | calendar.read calendar.write calendar.availability calendar.booking calendar.webhooks | no |
| Google Calendar API Google | A | 80.6 | calendar.read calendar.write calendar.availability calendar.webhooks | no |
| Calendly API + MCP Calendly | B | 68.3 | calendar.read calendar.availability calendar.booking calendar.webhooks | no |
| Microsoft Graph Calendar API Microsoft | B | 65.1 | calendar.read calendar.write calendar.availability calendar.webhooks | no |
| Cal.com API v2 + MCP Cal.com | C | 57.2 | calendar.read calendar.availability calendar.booking calendar.webhooks | no |
Machine-readable
- JSON
/api/v1/tools/aurinko-calendar.json· historyhistory.json· badge/badges/aurinko-calendar.svg· changes feed/feeds/tools/aurinko-calendar.xml - Markdown
/tools/aurinko-calendar.md· slim/tools/aurinko-calendar.min.md(or sendAccept: text/markdown) - Fix list
/fixes/aurinko-calendar.md·/fixes/aurinko-calendar.json - From a terminal
anchor tool aurinko-calendar --md(the CLI) · over MCPget_tool {"slug": "aurinko-calendar"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/aurinko-calendar"><img src="https://www.anchorterminal.com/badges/aurinko-calendar.svg" alt="Aurinko Calendar API on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/aurinko-calendar)<a href="https://www.anchorterminal.com/tools/aurinko-calendar">Aurinko Calendar API on Anchor Terminal</a>It counts on a page on aurinko.io or one of its subdomains.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "aurinko-calendar", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.


