{
  "data": {
    "similar": [
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/nylas-calendar.json",
        "name": "Nylas Calendar and Scheduler API",
        "score": 71,
        "shared": [
          "calendar.read",
          "calendar.write",
          "calendar.availability",
          "calendar.booking",
          "calendar.webhooks"
        ],
        "slug": "nylas-calendar"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/cronofy.json",
        "name": "Cronofy API",
        "score": 64.2,
        "shared": [
          "calendar.read",
          "calendar.write",
          "calendar.availability",
          "calendar.booking",
          "calendar.webhooks"
        ],
        "slug": "cronofy"
      },
      {
        "grade": "A",
        "json": "https://www.anchorterminal.com/tools/google-calendar-api.json",
        "name": "Google Calendar API",
        "score": 80.6,
        "shared": [
          "calendar.read",
          "calendar.write",
          "calendar.availability",
          "calendar.webhooks"
        ],
        "slug": "google-calendar-api"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/calendly.json",
        "name": "Calendly API + MCP",
        "score": 68.3,
        "shared": [
          "calendar.read",
          "calendar.availability",
          "calendar.booking",
          "calendar.webhooks"
        ],
        "slug": "calendly"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/microsoft-graph-calendar.json",
        "name": "Microsoft Graph Calendar API",
        "score": 65.1,
        "shared": [
          "calendar.read",
          "calendar.write",
          "calendar.availability",
          "calendar.webhooks"
        ],
        "slug": "microsoft-graph-calendar"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/cal-com.json",
        "name": "Cal.com API v2 + MCP",
        "score": 57.2,
        "shared": [
          "calendar.read",
          "calendar.availability",
          "calendar.booking",
          "calendar.webhooks"
        ],
        "slug": "cal-com"
      }
    ],
    "tool": {
      "slug": "aurinko-calendar",
      "name": "Aurinko Calendar API",
      "vendor": "Yoxel, Inc.",
      "vendorUrl": "https://www.aurinko.io",
      "kind": "http-api",
      "category": "scheduling",
      "summary": "Unified calendar REST API from Yoxel, Inc. It reads and writes calendars and events on Google, Office 365, Outlook.com, Exchange and iCloud through one interface, with free/busy queries, booking profiles and webhooks.",
      "url": "https://www.anchorterminal.com/tools/aurinko-calendar",
      "markdownUrl": "https://www.anchorterminal.com/tools/aurinko-calendar.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/aurinko-calendar.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/aurinko-calendar.json",
      "license": "Proprietary service under Yoxel's Terms of Services Agreement",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.aurinko.io",
      "packages": [],
      "auth": "oauth",
      "authNotes": "Self-serve. A developer signs up at app.aurinko.io and gets a client ID and secret for each application. Each end user connects a calendar through Aurinko's OAuth flow at `/v1/auth/authorize`, which returns an account access token sent as a Bearer token. Eleven scopes include `Calendar.Read` and `Calendar.ReadWrite`. Group booking and other application-level calls take the client ID and secret as Basic auth. Production use with Google or Office 365 needs the developer's own OAuth app registration with those providers.",
      "pricing": "paid",
      "pricingNotes": "$1 an active account a month for one of Calendar, Contacts or Tasks with up to 1 GB of traffic, $1.50 for Email or CRM, and $2 for any number of APIs with unlimited traffic, per the billing FAQ. A 14-day trial needs no card, and API requests are blocked when it ends without a subscription (https://docs.aurinko.io/faq/how-does-aurinko-billing-work).",
      "priceSummary": "Paid",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the OpenAPI spec or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.aurinko.io/",
      "llmsTxt": "https://docs.aurinko.io/llms.txt",
      "openapi": "https://apirefs.aurinko.io/assets/swagger.json",
      "capabilities": [
        "calendar.read",
        "calendar.write",
        "calendar.availability",
        "calendar.booking",
        "calendar.webhooks"
      ],
      "tags": [
        "hosted",
        "oauth",
        "openapi",
        "llms-txt",
        "webhooks",
        "closed-source",
        "free-trial"
      ],
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 45.6,
        "grade": "E",
        "agentReady": false,
        "rank": 654,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 7,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 56,
          "maintenance": 20,
          "payments": 40,
          "reliability": 40,
          "schema": 66,
          "security": 41,
          "transparency": 44
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 40,
            "points": 8,
            "reason": "Graded as a hosted API. No status page is linked from the site, the docs or the spec, and status.aurinko.io did not resolve (0). With no readable incident history the record scores 5. The spec gives a limit of 250 requests a second (15). It advises exponential backoff on 429 and 5xx and a retry on 408, with no Retry-After header documented and no idempotency keys for event or booking writes (10). No SLA found, and the terms supply the service as is (0). The API is at `/v1` with no beta label (10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 66,
            "points": 10.73,
            "reason": "Public OpenAPI 3.0.0 spec with 112 paths and 154 operations (25). `llms.txt` and a Markdown copy of every docs page (10). Every operation has a summary but only 17 have a description, and 193 of 893 schema properties are described (8). Enums appear in 44 of 190 schemas, but only two schemas mark required fields (8). 110 operations carry a cURL sample and the Errors section shows the JSON body, though operations declare only 401 and a default response (10). `/v1` in the path and spec version 1.0.0, with no changelog found (5)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 56,
            "points": 9.1,
            "reason": "Graded on the REST API. `returnRecord=false` trims write responses to an ID and reads take `timeMin` and `timeMax`, but no field selection was found (12). `pageToken` on lists, `limit` and `offset` on booking profiles, and delta tokens for incremental sync (16). Errors carry `code`, `message`, `requestId` and the provider's `originalError`, with retry advice per status (14). No idempotency keys. `If-Match` with an ETag is required on event updates, and `reserveForMinutes` holds a slot before a booking is confirmed (8). `primary` works as a calendar ID and few parameters are required, but no official SDK was found (6)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 41,
            "points": 7.18,
            "reason": "Per-user OAuth with 11 scopes, `Calendar.Read` separate from `Calendar.ReadWrite`, and `DELETE /v1/account/token` to revoke. The application's client ID and secret, sent as Basic auth with `X-Aurinko-Account-Id`, reach every connected account, and the implicit grant is still supported though not recommended (22). A read-only scope exists, with no confirmation step for deletes (12). Event content from third parties is returned with no injection guidance (0). No operator audit log found in the docs (0). A security statement with a reporting address, security@yoxel.com, and penetration tests claimed. SOC 2 is not yet held, with no bug bounty and no security.txt (7). `rescheduleToken` travels in the query string on booking calls. No deduction, because it is not the API credential."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 40,
            "points": 5,
            "reason": "No x402, MPP or L402 (0). Prices per active account a month published without login, $1, $1.50 and $2 (20). A 14-day trial with no card (20). Signup is in a browser at app.aurinko.io, and each calendar needs its owner's OAuth consent (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 20,
            "points": 1.75,
            "reason": "No changelog or release notes found, so no API change can be dated. Docs pages were edited on 22 and 23 September 2026 per the docs sitemap, counted as partial evidence of activity (15). No dated changelog entries (0). Support is by email at support@aurinko.io, with no public forum or issue tracker found (3). No official SDK. `aurinko-sdk` on npm is unofficial (0). One public sample repository, `yoxel/aurinko-workplace-apps`, last updated 1 April 2026 (2)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 44,
            "points": 3.85,
            "note": "editorial 27, provenance 60",
            "reason": "Closed service under a Terms of Services Agreement naming Yoxel, Inc. of California, last updated 11 August 2022 (15). The docs say content is passed through and never stored, with only IDs cached, and the privacy policy commits to Google's Limited Use requirements. The policy gives no retention period, and no DPA was found (12). No deprecation policy or dated notices found (0). No sub-processor list or data location. The security statement names no cloud provider (0)."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "Graded on the REST API. `returnRecord=false` trims write responses to an ID and reads take `timeMin` and `timeMax`, but no field selection was found (12). `pageToken` on lists, `limit` and `offset` on booking profiles, and delta tokens for incremental sync (16). Errors carry `code`, `message`, `requestId` and the provider's `originalError`, with retry advice per status (14). No idempotency keys. `If-Match` with an ETag is required on event updates, and `reserveForMinutes` holds a slot before a booking is confirmed (8). `primary` works as a calendar ID and few parameters are required, but no official SDK was found (6).",
            "maintenance": "No changelog or release notes found, so no API change can be dated. Docs pages were edited on 22 and 23 September 2026 per the docs sitemap, counted as partial evidence of activity (15). No dated changelog entries (0). Support is by email at support@aurinko.io, with no public forum or issue tracker found (3). No official SDK. `aurinko-sdk` on npm is unofficial (0). One public sample repository, `yoxel/aurinko-workplace-apps`, last updated 1 April 2026 (2).",
            "payments": "No x402, MPP or L402 (0). Prices per active account a month published without login, $1, $1.50 and $2 (20). A 14-day trial with no card (20). Signup is in a browser at app.aurinko.io, and each calendar needs its owner's OAuth consent (0).",
            "reliability": "Graded as a hosted API. No status page is linked from the site, the docs or the spec, and status.aurinko.io did not resolve (0). With no readable incident history the record scores 5. The spec gives a limit of 250 requests a second (15). It advises exponential backoff on 429 and 5xx and a retry on 408, with no Retry-After header documented and no idempotency keys for event or booking writes (10). No SLA found, and the terms supply the service as is (0). The API is at `/v1` with no beta label (10).",
            "schema": "Public OpenAPI 3.0.0 spec with 112 paths and 154 operations (25). `llms.txt` and a Markdown copy of every docs page (10). Every operation has a summary but only 17 have a description, and 193 of 893 schema properties are described (8). Enums appear in 44 of 190 schemas, but only two schemas mark required fields (8). 110 operations carry a cURL sample and the Errors section shows the JSON body, though operations declare only 401 and a default response (10). `/v1` in the path and spec version 1.0.0, with no changelog found (5).",
            "security": "Per-user OAuth with 11 scopes, `Calendar.Read` separate from `Calendar.ReadWrite`, and `DELETE /v1/account/token` to revoke. The application's client ID and secret, sent as Basic auth with `X-Aurinko-Account-Id`, reach every connected account, and the implicit grant is still supported though not recommended (22). A read-only scope exists, with no confirmation step for deletes (12). Event content from third parties is returned with no injection guidance (0). No operator audit log found in the docs (0). A security statement with a reporting address, security@yoxel.com, and penetration tests claimed. SOC 2 is not yet held, with no bug bounty and no security.txt (7). `rescheduleToken` travels in the query string on booking calls. No deduction, because it is not the API credential.",
            "transparency": "Closed service under a Terms of Services Agreement naming Yoxel, Inc. of California, last updated 11 August 2022 (15). The docs say content is passed through and never stored, with only IDs cached, and the privacy policy commits to Google's Limited Use requirements. The policy gives no retention period, and no DPA was found (12). No deprecation policy or dated notices found (0). No sub-processor list or data location. The security statement names no cloud provider (0)."
          },
          "sources": [
            {
              "what": "OpenAPI spec, errors and rate limits",
              "url": "https://apirefs.aurinko.io/assets/swagger.json",
              "seen": "2026-10-08"
            },
            {
              "what": "docs index for agents",
              "url": "https://docs.aurinko.io/llms.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "Calendar API guide",
              "url": "https://docs.aurinko.io/unified-apis/calendar-api.md",
              "seen": "2026-10-08"
            },
            {
              "what": "Booking API guide",
              "url": "https://docs.aurinko.io/scheduling/booking-api.md",
              "seen": "2026-10-08"
            },
            {
              "what": "Group Booking API guide",
              "url": "https://docs.aurinko.io/scheduling/group-booking-api.md",
              "seen": "2026-10-08"
            },
            {
              "what": "authentication scopes",
              "url": "https://docs.aurinko.io/authentication/authentication-scopes.md",
              "seen": "2026-10-08"
            },
            {
              "what": "account OAuth flow",
              "url": "https://docs.aurinko.io/authentication/oauth-flow/account-oauth-flow.md",
              "seen": "2026-10-08"
            },
            {
              "what": "webhooks and signature validation",
              "url": "https://docs.aurinko.io/unified-apis/webhooks-api.md",
              "seen": "2026-10-08"
            },
            {
              "what": "billing FAQ and price tiers",
              "url": "https://docs.aurinko.io/faq/how-does-aurinko-billing-work.md",
              "seen": "2026-10-08"
            },
            {
              "what": "trial and subscription",
              "url": "https://docs.aurinko.io/getting-started/subscribe-to-aurinko.md",
              "seen": "2026-10-08"
            },
            {
              "what": "data handling statement",
              "url": "https://docs.aurinko.io/getting-started/readme.md",
              "seen": "2026-10-08"
            },
            {
              "what": "pricing page",
              "url": "https://www.aurinko.io/pricing/",
              "seen": "2026-10-08"
            },
            {
              "what": "terms of services agreement",
              "url": "https://www.aurinko.io/terms/",
              "seen": "2026-10-08"
            },
            {
              "what": "privacy policy",
              "url": "https://www.aurinko.io/privacy/",
              "seen": "2026-10-08"
            },
            {
              "what": "security statement",
              "url": "https://www.aurinko.io/certifications/",
              "seen": "2026-10-08"
            },
            {
              "what": "security.txt, 404",
              "url": "https://www.aurinko.io/.well-known/security.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "docs sitemap with page dates",
              "url": "https://docs.aurinko.io/sitemap-pages.xml",
              "seen": "2026-10-08"
            },
            {
              "what": "unauthenticated request, 401 body",
              "url": "https://api.aurinko.io/v1/account",
              "seen": "2026-10-08"
            },
            {
              "what": "unofficial npm SDK",
              "url": "https://registry.npmjs.org/aurinko-sdk/latest",
              "seen": "2026-10-08"
            },
            {
              "what": "vendor's GitHub organisation",
              "url": "https://github.com/yoxel",
              "seen": "2026-10-08"
            },
            {
              "what": "domain registration",
              "url": "https://rdap.identitydigital.services/rdap/domain/aurinko.io",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "unchecked: whether a status page exists under an address the site does not link. status.aurinko.io did not resolve from our network",
            "unchecked: the portal at app.aurinko.io behind login, so key rotation, team roles in practice and any request log were not seen",
            "Whether the SOC 2 Type I examination targeted for Q3 2026 has been completed. The security statement was last updated 18 June 2026",
            "Which of the two published descriptions of the $1.50 tier applies",
            "Whether a DPA or sub-processor list is available on request. None is published",
            "Whether 429 responses carry a Retry-After header. The spec does not say"
          ]
        },
        "negative": 0,
        "verdict": "A public OpenAPI 3.0 spec covers 154 operations, with free/busy, meeting-time suggestion and booking profiles alongside calendar reads and writes, and prices start at $1 an active account a month. No status page, SLA, changelog or official SDK was found, and the application's client secret reaches every connected account.",
        "bestFor": "A product that connects many users' Google and Microsoft calendars and wants availability and booking at a low price per account.",
        "strengths": [
          "Public OpenAPI 3.0 spec at `apirefs.aurinko.io/assets/swagger.json` with 154 operations, 110 of them carrying a cURL sample",
          "Availability in three forms, `/v1/calendars/freeBusy`, `/v1/calendars/suggestMeetingTimes` and booking profiles for one calendar or a group",
          "Prices published per active account a month ($1, $1.50 and $2), with a 14-day trial that needs no card",
          "Eleven OAuth scopes, with `Calendar.Read` separate from `Calendar.ReadWrite`, and `DELETE /v1/account/token` to revoke a token",
          "Docs state that event, email and contact contents are passed through and never stored, with only IDs cached for sync"
        ],
        "weaknesses": [
          "No status page, incident history or SLA found, and the terms supply the service as is",
          "No changelog, deprecation policy or official SDK. The only npm package, `aurinko-sdk`, is unofficial",
          "The application's client ID and secret, sent as Basic auth with `X-Aurinko-Account-Id`, reach every connected account",
          "SOC 2 is not yet held. The security statement of 18 June 2026 targets a Type I examination for Q3 2026",
          "Terms and privacy policy date from 11 August 2022, with no retention period, DPA or sub-processor list found"
        ],
        "agentNotes": [
          "Use `https://api.aurinko.io/v1`. Several cURL examples in the docs print `https:/api.aurinko.io` with one slash",
          "Send `If-Match` with the event's `etag` on `PATCH /v1/calendars/{calendarId}/events/{eventId}`. A stale value returns 412",
          "Use `primary` as the calendar ID for an account's main calendar, and page with `pageToken` until none is returned",
          "Hold a slot with `reserveForMinutes` on the booking `meeting` call, then confirm or cancel the reservation, since no idempotency key exists",
          "Retry 429, 408 and 5xx with exponential backoff. Do not retry 404. A 429 can come from Google or Microsoft limits behind the API"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "E",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 45.6
          }
        ],
        "editorialScores": {
          "ergonomics": 56,
          "maintenance": 20,
          "payments": 40,
          "reliability": 40,
          "schema": 66,
          "security": 41,
          "transparency": 27
        },
        "provenanceScore": 60
      },
      "connect": {
        "http": "curl -H 'Authorization: Bearer \u003caccess_token\u003e' \\\n  -X GET https://api.aurinko.io/v1/calendars/primary"
      },
      "letme": {
        "capability": "https://letme.dev/calendar.read",
        "tool": "https://letme.dev/aurinko-calendar"
      },
      "notable": [
        "The spec at apirefs.aurinko.io is OpenAPI 3.0.0, titled Aurinko.io API 1.0.0, with 112 paths and 154 operations, 21 of them under Calendars, Events, CalSync and FreeBusySchedule and 33 under Booking, GroupBooking and Availability (https://apirefs.aurinko.io/assets/swagger.json)",
        "Billing counts active accounts, meaning more than 10 API calls or more than 1 MB transferred in a billing month, and the same mailbox connected twice is billed once (https://docs.aurinko.io/faq/how-does-aurinko-billing-work)",
        "The docs describe the API as mainly a pass-through that proxies requests to the provider, caching IDs and master-instance relations but never the contents of events, emails, contacts or tasks (https://docs.aurinko.io/getting-started/readme)",
        "Group booking profiles attach accounts or groups of accounts with `required` set to `one` or `all`, and the availability response names which accounts and groups are free for each slot (https://docs.aurinko.io/scheduling/group-booking-api)",
        "Webhook requests are signed with HMAC SHA256 over `v0:{timestamp}:{raw_body}` in `X-Aurinko-Signature`, and subscriptions cover `/calendars/{calId}/events` and `/booking/{bookingId}` (https://docs.aurinko.io/unified-apis/webhooks-api/authentication)",
        "The security statement, last updated 18 June 2026, says Yoxel is preparing for a SOC 2 Type I examination targeted for Q3 2026 with Secureframe, and takes vulnerability reports at security@yoxel.com (https://www.aurinko.io/certifications/)",
        "The pricing page and the billing FAQ describe the $1.50 tier differently, as under 5 GB of data transfer on one and as Email or CRM up to 1 GB on the other (https://www.aurinko.io/pricing/)"
      ],
      "area": "everyday",
      "details": [
        {
          "label": "API",
          "value": "REST at https://api.aurinko.io/v1, OpenAPI 3.0.0 spec with 112 paths and 154 operations across email, calendar, contacts, tasks, booking and webhooks"
        },
        {
          "label": "Calendar endpoints",
          "value": "`/v1/calendars`, `/v1/calendars/{calendarId}/events`, `/events/range`, `/events/find`, series and occurrences, `/sync` with delta tokens, `/freeBusy`, `/availableTimes` and `/v1/calendars/suggestMeetingTimes`"
        },
        {
          "label": "Booking",
          "value": "Booking profiles for one account under `/v1/book/account/profiles` and for groups under `/v1/book/group/profiles`, with available meeting times, meeting creation, reservations that can be confirmed or cancelled, and a hosted booking page"
        },
        {
          "label": "Providers",
          "value": "Google, Office 365, Outlook.com, MS Exchange and iCloud for calendars per the vendor's site. The spec's service types also list Zoho and IMAP"
        },
        {
          "label": "Credentials",
          "value": "Account access token (Bearer) from the OAuth flow, client ID and secret (Basic) for application-level calls, or a user session in `X-Aurinko-Session` or a cookie"
        },
        {
          "label": "Scopes",
          "value": "`Calendar.Read`, `Calendar.ReadWrite`, `Mail.Read`, `Mail.ReadWrite`, `Mail.Send`, `Mail.Drafts`, `Mail.All`, `Contacts.Read`, `Contacts.ReadWrite`, `Tasks.Read`, `Tasks.ReadWrite`"
        },
        {
          "label": "Rate limits",
          "value": "250 requests a second for API calls, per the spec. Provider limits behind the API can also return 429"
        },
        {
          "label": "Errors",
          "value": "JSON body with `code`, `message`, `requestId` and the provider's `originalError`. The spec advises exponential backoff on 429 and 5xx, a retry on 408, and no retry on 404"
        },
        {
          "label": "Webhooks",
          "value": "`POST /v1/subscriptions` for `/calendars/primary/events`, `/calendars/{calId}/events` and `/booking/{bookingId}`, signed with HMAC SHA256 in `X-Aurinko-Signature`"
        },
        {
          "label": "Trial",
          "value": "14 days with full API access and no card. Access is blocked at expiry until a card is added"
        },
        {
          "label": "SDKs",
          "value": "No official SDK found. `aurinko-sdk` on npm describes itself as unofficial"
        },
        {
          "label": "Security statement",
          "value": "TLS in transit and AES-256 at rest, MFA and role-based access, third-party penetration tests, SOC 2 Type I targeted for Q3 2026 (statement of 18 June 2026)"
        }
      ],
      "unitPrices": [
        {
          "item": "Unified API, one of Calendar, Contacts or Tasks",
          "unit": "account-month",
          "usd": 1,
          "note": "Per active account, up to 1 GB of traffic a month"
        },
        {
          "item": "Email or CRM",
          "unit": "account-month",
          "usd": 1.5,
          "note": "Per active account, up to 1 GB of traffic a month"
        },
        {
          "item": "Full platform, any number of APIs",
          "unit": "account-month",
          "usd": 2,
          "note": "Per active account, unlimited traffic"
        }
      ],
      "provenance": {
        "legalEntity": "Yoxel, Inc.",
        "domain": "aurinko.io",
        "domainRegistered": "2019-05-08",
        "endpointOnVendorDomain": true,
        "terms": "https://www.aurinko.io/terms/",
        "privacy": "https://www.aurinko.io/privacy/",
        "statusPage": "",
        "changelog": "",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The Terms of Services Agreement, last updated 11 August 2022, names Yoxel, Inc., organised under the laws of California, and covers the API and the workspace integrations platform. Disputes go to binding arbitration.",
          "The privacy policy, last updated 11 August 2022, covers the site and the services, API included, and commits to Google's API Services User Data Policy and its Limited Use requirements.",
          "The API answers at api.aurinko.io, the portal at app.aurinko.io and the reference at apirefs.aurinko.io, all on the vendor's domain.",
          "www.aurinko.io/.well-known/security.txt returns 404. The security statement gives security@yoxel.com for reports.",
          "No status page or changelog is linked from the site, the docs or the spec. status.aurinko.io did not resolve from our network.",
          "RDAP for aurinko.io gives a registration date of 2019-05-08."
        ],
        "score": 60,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Yoxel, Inc.",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "aurinko.io, registered 2019-05-08 (7 years)",
            "points": 11,
            "max": 15,
            "state": "part"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "api.aurinko.io",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points",
            "points": 5.1,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 7 of the 8 things a reader expects",
            "points": 9.3,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Status page",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          },
          {
            "check": "Changelog",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://www.aurinko.io/terms/",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2022-08-11",
            "words": 6042,
            "points": 5.1,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last Updated: Aug 11, 2022",
                "says": "Last updated 2022-08-11"
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "The Yoxel Site and Services are provided by, and you’re contracting with: Yoxel that is organized under the laws of the State of California, USA.",
                "says": "The law of the State of California"
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "Under no circumstances will Yoxel be responsible or liable to you for any indirect, punitive, incidental, special, consequential, or exemplary damages resulting from your use or inability to use the Services or for the unavailability of the Services, for lost profits, personal injury, or property damage, or for any ot…",
                "says": "Rules out indirect and consequential losses, with no cap named in this sentence"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "Until you have submitted, and we have reviewed and approved, all Required Information, your Yoxel Account will be available to you on a preliminary basis only, and we may terminate it at any time and for any reason."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": true,
                "quote": "If you are an existing user of our Services, the material changes to this Agreement will come into effect 10 days after we provide you with the Notice.",
                "says": "Gives 10 days of notice before a change"
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "You may not access or use our Services or Site unless you agree to abide by all the terms and conditions set in this Agreement."
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": false
              }
            ],
            "toKnow": [
              {
                "key": "terms.automated",
                "label": "Restricts automated access",
                "found": true,
                "quote": "…re-publish, license, reverse engineer, or create derivative works from Service Materials, nor use any robots, data mining, or similar data extraction or gathering methods in connection with our Services.",
                "costsPoints": true
              },
              {
                "key": "terms.benchmark",
                "label": "Restricts benchmarking or competitive use",
                "found": true,
                "quote": "use the Services and the Site in any manner to compete with Yoxel.",
                "costsPoints": true
              },
              {
                "key": "terms.cutoff",
                "label": "Says access can be ended without notice or for any reason",
                "found": true,
                "quote": "We may terminate this Agreement or close your Yoxel Account at any time for any reason (including, without limitation, for any activity that may create harm or loss to the goodwill of a Payment Method) by providing you Notice."
              },
              {
                "key": "terms.arbitration",
                "label": "Requires arbitration or waives class actions",
                "found": true,
                "quote": "IMPORTANT NOTICE REGARDING ARBITRATION: WHEN YOU AGREE TO THIS AGREEMENT YOU ARE AGREEING (WITH LIMITED EXCEPTION) TO RESOLVE ANY DISPUTE BETWEEN YOU AND YOXEL THROUGH BINDING ARBITRATION RATHER THAN IN COURT."
              },
              {
                "key": "old",
                "label": "Has not been updated for three years or more",
                "found": true,
                "quote": "Last Updated: Aug 11, 2022"
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Liability not otherwise disclaimed is capped at the fees paid in the three months before the event behind the claim.",
                "quote": "you further agree that under no circumstances will any such liability exceed in the aggregate the amount of Fees paid by you to Yoxel during the three-month period immediately preceding the event that gave rise to your claim for damages."
              },
              {
                "date": "2026-10-08",
                "text": "On monthly plans Yoxel may change the fees at any time, and a customer who does not accept the new fees is told to cancel.",
                "quote": "We reserve the right to change the Fees at any time. If you do not accept the new Fees, you should cancel your subscription."
              },
              {
                "date": "2026-10-08",
                "text": "On termination Yoxel may delete all of the customer’s stored information but is not obliged to.",
                "quote": "we reserve the right (but have no obligation) to delete all of your information stored on our servers;"
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://www.aurinko.io/privacy/",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2022-08-11",
            "words": 3325,
            "points": 9.3,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last Updated: Aug 11, 2022",
                "says": "Last updated 2022-08-11"
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "We are committed to respecting the privacy and security of the personal information we collect."
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "To determine how long we keep personal information we consider the amount, nature and sensitivity of personal information, the reasons for which we collect and process the information and applicable legal requirements."
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "Collected Indirectly: We and our authorized third-party service providers collect certain information by automated means using cookies and other tracking technologies."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "Business Transfers: We may also share personal information with third parties whom we choose to acquire, or to whom we choose to sell, transfer, or merge parts of our business or our assets."
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "This Privacy Policy («Privacy Policy») provides important information about our use of personal information and informs you of your rights."
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "If you have any questions about this Privacy Policy or our privacy practices, please contact us by email at: compliance@yoxel.com.",
                "says": "compliance@yoxel.com"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": false
              }
            ],
            "toKnow": [
              {
                "key": "old",
                "label": "Has not been updated for three years or more",
                "found": true,
                "quote": "Last Updated: Aug 11, 2022"
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Personal information is shared with the third parties whose APIs are integrated, and the policy says they may use it for their own purposes.",
                "quote": "These third parties may use your personal information to operate their services and for their own purposes."
              },
              {
                "date": "2026-10-08",
                "text": "Use and transfer of personal information received from Google Accounts is stated to follow the Google API Services User Data Policy, including its Limited Use requirements.",
                "quote": "Our use and transfer to any other app of personal information received from Google Accounts will adhere to Google API Services User Data Policy"
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/aurinko-calendar.json",
      "live": {
        "slug": "aurinko-calendar",
        "probe": {
          "target": "https://api.aurinko.io",
          "method": "get",
          "lastAt": "2026-10-08T21:53:16.118387345Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 233,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 255,
          "p95ms24h": 311,
          "samples24h": 28,
          "samples30d": 28,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 28,
              "ok": 28
            }
          ]
        },
        "updatedAt": "2026-10-08T21:53:16.118387345Z"
      }
    },
    "verify": {
      "accepts": "a page on aurinko.io or one of its subdomains",
      "badgeUrl": "https://www.anchorterminal.com/badges/aurinko-calendar.svg",
      "body": {
        "slug": "aurinko-calendar",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/aurinko-calendar",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/aurinko-calendar\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/aurinko-calendar.svg\" alt=\"Aurinko Calendar API on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Aurinko Calendar API on Anchor Terminal](https://www.anchorterminal.com/badges/aurinko-calendar.svg)](https://www.anchorterminal.com/tools/aurinko-calendar)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/aurinko-calendar\"\u003eAurinko Calendar API on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/aurinko-calendar",
    "json": "https://www.anchorterminal.com/tools/aurinko-calendar.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/aurinko-calendar.md",
    "slim": "https://www.anchorterminal.com/tools/aurinko-calendar.min.md"
  },
  "markdown": "## Overview\n\n**Grade E · 45.6/100 · rank #654 of 722 · #7 in Calendars \u0026 scheduling · not agent-ready · confidence medium**\n\n\n## Assessment\n\nA public OpenAPI 3.0 spec covers 154 operations, with free/busy, meeting-time suggestion and booking profiles alongside calendar reads and writes, and prices start at $1 an active account a month. No status page, SLA, changelog or official SDK was found, and the application's client secret reaches every connected account.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Yoxel, Inc. (https://www.aurinko.io) |\n| Kind | HTTP API |\n| Category | Calendars \u0026 scheduling (https://www.anchorterminal.com/categories/scheduling) |\n| Transport | HTTP |\n| Endpoint | `https://api.aurinko.io` |\n| Auth | OAuth · Self-serve. A developer signs up at app.aurinko.io and gets a client ID and secret for each application. Each end user connects a calendar through Aurinko's OAuth flow at `/v1/auth/authorize`, which returns an account access token sent as a Bearer token. Eleven scopes include `Calendar.Read` and `Calendar.ReadWrite`. Group booking and other application-level calls take the client ID and secret as Basic auth. Production use with Google or Office 365 needs the developer's own OAuth app registration with those providers. |\n| Pricing | Paid (Paid) · $1 an active account a month for one of Calendar, Contacts or Tasks with up to 1 GB of traffic, $1.50 for Email or CRM, and $2 for any number of APIs with unlimited traffic, per the billing FAQ. A 14-day trial needs no card, and API requests are blocked when it ends without a subscription (https://docs.aurinko.io/faq/how-does-aurinko-billing-work). |\n| x402 | No · No x402, MPP or L402 in the docs, the OpenAPI spec or the pricing page (checked 2026-10-08). |\n| Licence | Proprietary service under Yoxel's Terms of Services Agreement |\n| Docs | https://docs.aurinko.io/ |\n| llms.txt | https://docs.aurinko.io/llms.txt |\n| API | REST at https://api.aurinko.io/v1, OpenAPI 3.0.0 spec with 112 paths and 154 operations across email, calendar, contacts, tasks, booking and webhooks |\n| Calendar endpoints | `/v1/calendars`, `/v1/calendars/{calendarId}/events`, `/events/range`, `/events/find`, series and occurrences, `/sync` with delta tokens, `/freeBusy`, `/availableTimes` and `/v1/calendars/suggestMeetingTimes` |\n| Booking | Booking profiles for one account under `/v1/book/account/profiles` and for groups under `/v1/book/group/profiles`, with available meeting times, meeting creation, reservations that can be confirmed or cancelled, and a hosted booking page |\n| Providers | Google, Office 365, Outlook.com, MS Exchange and iCloud for calendars per the vendor's site. The spec's service types also list Zoho and IMAP |\n| Credentials | Account access token (Bearer) from the OAuth flow, client ID and secret (Basic) for application-level calls, or a user session in `X-Aurinko-Session` or a cookie |\n| Scopes | `Calendar.Read`, `Calendar.ReadWrite`, `Mail.Read`, `Mail.ReadWrite`, `Mail.Send`, `Mail.Drafts`, `Mail.All`, `Contacts.Read`, `Contacts.ReadWrite`, `Tasks.Read`, `Tasks.ReadWrite` |\n| Rate limits | 250 requests a second for API calls, per the spec. Provider limits behind the API can also return 429 |\n| Errors | JSON body with `code`, `message`, `requestId` and the provider's `originalError`. The spec advises exponential backoff on 429 and 5xx, a retry on 408, and no retry on 404 |\n| Webhooks | `POST /v1/subscriptions` for `/calendars/primary/events`, `/calendars/{calId}/events` and `/booking/{bookingId}`, signed with HMAC SHA256 in `X-Aurinko-Signature` |\n| Trial | 14 days with full API access and no card. Access is blocked at expiry until a card is added |\n| SDKs | No official SDK found. `aurinko-sdk` on npm describes itself as unofficial |\n| Security statement | TLS in transit and AES-256 at rest, MFA and role-based access, third-party penetration tests, SOC 2 Type I targeted for Q3 2026 (statement of 18 June 2026) |\n| Capabilities | calendar.read, calendar.write, calendar.availability, calendar.booking, calendar.webhooks |\n| Tags | hosted, oauth, openapi, llms-txt, webhooks, closed-source, free-trial |\n| JSON | https://www.anchorterminal.com/api/v1/tools/aurinko-calendar.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 40 | 8.0 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 66 | 10.7 |\n| Agent ergonomics | 13% | 16.2 | 56 | 9.1 |\n| Security \u0026 auth | 14% | 17.5 | 41 | 7.2 |\n| Payments \u0026 pricing | 10% | 12.5 | 40 | 5.0 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 20 | 1.8 |\n| Transparency \u0026 trust (editorial 27, provenance 60) | 7% | 8.8 | 44 | 3.9 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **45.6 → E** |\n\n### Why each score\n\n- Reliability 40: Graded as a hosted API. No status page is linked from the site, the docs or the spec, and status.aurinko.io did not resolve (0). With no readable incident history the record scores 5. The spec gives a limit of 250 requests a second (15). It advises exponential backoff on 429 and 5xx and a retry on 408, with no Retry-After header documented and no idempotency keys for event or booking writes (10). No SLA found, and the terms supply the service as is (0). The API is at `/v1` with no beta label (10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 66: Public OpenAPI 3.0.0 spec with 112 paths and 154 operations (25). `llms.txt` and a Markdown copy of every docs page (10). Every operation has a summary but only 17 have a description, and 193 of 893 schema properties are described (8). Enums appear in 44 of 190 schemas, but only two schemas mark required fields (8). 110 operations carry a cURL sample and the Errors section shows the JSON body, though operations declare only 401 and a default response (10). `/v1` in the path and spec version 1.0.0, with no changelog found (5).\n- Agent ergonomics 56: Graded on the REST API. `returnRecord=false` trims write responses to an ID and reads take `timeMin` and `timeMax`, but no field selection was found (12). `pageToken` on lists, `limit` and `offset` on booking profiles, and delta tokens for incremental sync (16). Errors carry `code`, `message`, `requestId` and the provider's `originalError`, with retry advice per status (14). No idempotency keys. `If-Match` with an ETag is required on event updates, and `reserveForMinutes` holds a slot before a booking is confirmed (8). `primary` works as a calendar ID and few parameters are required, but no official SDK was found (6).\n- Security \u0026 auth 41: Per-user OAuth with 11 scopes, `Calendar.Read` separate from `Calendar.ReadWrite`, and `DELETE /v1/account/token` to revoke. The application's client ID and secret, sent as Basic auth with `X-Aurinko-Account-Id`, reach every connected account, and the implicit grant is still supported though not recommended (22). A read-only scope exists, with no confirmation step for deletes (12). Event content from third parties is returned with no injection guidance (0). No operator audit log found in the docs (0). A security statement with a reporting address, security@yoxel.com, and penetration tests claimed. SOC 2 is not yet held, with no bug bounty and no security.txt (7). `rescheduleToken` travels in the query string on booking calls. No deduction, because it is not the API credential.\n- Payments \u0026 pricing 40: No x402, MPP or L402 (0). Prices per active account a month published without login, $1, $1.50 and $2 (20). A 14-day trial with no card (20). Signup is in a browser at app.aurinko.io, and each calendar needs its owner's OAuth consent (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 20: No changelog or release notes found, so no API change can be dated. Docs pages were edited on 22 and 23 September 2026 per the docs sitemap, counted as partial evidence of activity (15). No dated changelog entries (0). Support is by email at support@aurinko.io, with no public forum or issue tracker found (3). No official SDK. `aurinko-sdk` on npm is unofficial (0). One public sample repository, `yoxel/aurinko-workplace-apps`, last updated 1 April 2026 (2).\n- Transparency \u0026 trust 44: Closed service under a Terms of Services Agreement naming Yoxel, Inc. of California, last updated 11 August 2022 (15). The docs say content is passed through and never stored, with only IDs cached, and the privacy policy commits to Google's Limited Use requirements. The policy gives no retention period, and no DPA was found (12). No deprecation policy or dated notices found (0). No sub-processor list or data location. The security statement names no cloud provider (0).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (19 items): https://www.anchorterminal.com/fixes/aurinko-calendar.md (JSON https://www.anchorterminal.com/fixes/aurinko-calendar.json)\n\n### What we couldn't check\n\n- unchecked: whether a status page exists under an address the site does not link. status.aurinko.io did not resolve from our network\n- unchecked: the portal at app.aurinko.io behind login, so key rotation, team roles in practice and any request log were not seen\n- Whether the SOC 2 Type I examination targeted for Q3 2026 has been completed. The security statement was last updated 18 June 2026\n- Which of the two published descriptions of the $1.50 tier applies\n- Whether a DPA or sub-processor list is available on request. None is published\n- Whether 429 responses carry a Retry-After header. The spec does not say\n\n### Sources\n\n- OpenAPI spec, errors and rate limits: \u003chttps://apirefs.aurinko.io/assets/swagger.json\u003e (seen 2026-10-08)\n- docs index for agents: \u003chttps://docs.aurinko.io/llms.txt\u003e (seen 2026-10-08)\n- Calendar API guide: \u003chttps://docs.aurinko.io/unified-apis/calendar-api.md\u003e (seen 2026-10-08)\n- Booking API guide: \u003chttps://docs.aurinko.io/scheduling/booking-api.md\u003e (seen 2026-10-08)\n- Group Booking API guide: \u003chttps://docs.aurinko.io/scheduling/group-booking-api.md\u003e (seen 2026-10-08)\n- authentication scopes: \u003chttps://docs.aurinko.io/authentication/authentication-scopes.md\u003e (seen 2026-10-08)\n- account OAuth flow: \u003chttps://docs.aurinko.io/authentication/oauth-flow/account-oauth-flow.md\u003e (seen 2026-10-08)\n- webhooks and signature validation: \u003chttps://docs.aurinko.io/unified-apis/webhooks-api.md\u003e (seen 2026-10-08)\n- billing FAQ and price tiers: \u003chttps://docs.aurinko.io/faq/how-does-aurinko-billing-work.md\u003e (seen 2026-10-08)\n- trial and subscription: \u003chttps://docs.aurinko.io/getting-started/subscribe-to-aurinko.md\u003e (seen 2026-10-08)\n- data handling statement: \u003chttps://docs.aurinko.io/getting-started/readme.md\u003e (seen 2026-10-08)\n- pricing page: \u003chttps://www.aurinko.io/pricing/\u003e (seen 2026-10-08)\n- terms of services agreement: \u003chttps://www.aurinko.io/terms/\u003e (seen 2026-10-08)\n- privacy policy: \u003chttps://www.aurinko.io/privacy/\u003e (seen 2026-10-08)\n- security statement: \u003chttps://www.aurinko.io/certifications/\u003e (seen 2026-10-08)\n- security.txt, 404: \u003chttps://www.aurinko.io/.well-known/security.txt\u003e (seen 2026-10-08)\n- docs sitemap with page dates: \u003chttps://docs.aurinko.io/sitemap-pages.xml\u003e (seen 2026-10-08)\n- unauthenticated request, 401 body: \u003chttps://api.aurinko.io/v1/account\u003e (seen 2026-10-08)\n- unofficial npm SDK: \u003chttps://registry.npmjs.org/aurinko-sdk/latest\u003e (seen 2026-10-08)\n- vendor's GitHub organisation: \u003chttps://github.com/yoxel\u003e (seen 2026-10-08)\n- domain registration: \u003chttps://rdap.identitydigital.services/rdap/domain/aurinko.io\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 60/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Yoxel, Inc. | 20/20 |\n| Domain age | aurinko.io, registered 2019-05-08 (7 years) | 11/15 |\n| Endpoint on the vendor's domain | api.aurinko.io | 15/15 |\n| Terms of service | read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points | 5.1/10 |\n| Privacy policy | read, states 7 of the 8 things a reader expects | 9.3/10 |\n| Status page | not found | 0/10 |\n| Changelog | not found | 0/10 |\n| security.txt | not found | 0/10 |\n\nThe Terms of Services Agreement, last updated 11 August 2022, names Yoxel, Inc., organised under the laws of California, and covers the API and the workspace integrations platform. Disputes go to binding arbitration.\n\nThe privacy policy, last updated 11 August 2022, covers the site and the services, API included, and commits to Google's API Services User Data Policy and its Limited Use requirements.\n\nThe API answers at api.aurinko.io, the portal at app.aurinko.io and the reference at apirefs.aurinko.io, all on the vendor's domain.\n\nwww.aurinko.io/.well-known/security.txt returns 404. The security statement gives security@yoxel.com for reports.\n\nNo status page or changelog is linked from the site, the docs or the spec. status.aurinko.io did not resolve from our network.\n\nRDAP for aurinko.io gives a registration date of 2019-05-08.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://www.aurinko.io/terms/), read 2026-10-08, dated 2022-08-11, states 6 of the 7 things a reader expects.\n\n- To know. Restricts automated access (costs points). \"…re-publish, license, reverse engineer, or create derivative works from Service Materials, nor use any robots, data mining, or similar data extraction or gathering methods in connection with our Services.\"\n- To know. Restricts benchmarking or competitive use (costs points). \"use the Services and the Site in any manner to compete with Yoxel.\"\n- To know. Says access can be ended without notice or for any reason. \"We may terminate this Agreement or close your Yoxel Account at any time for any reason (including, without limitation, for any activity that may create harm or loss to the goodwill of a Payment Method) by providing you Notice.\"\n- To know. Requires arbitration or waives class actions. \"IMPORTANT NOTICE REGARDING ARBITRATION: WHEN YOU AGREE TO THIS AGREEMENT YOU ARE AGREEING (WITH LIMITED EXCEPTION) TO RESOLVE ANY DISPUTE BETWEEN YOU AND YOXEL THROUGH BINDING ARBITRATION RATHER THAN IN COURT.\"\n- To know. Has not been updated for three years or more. \"Last Updated: Aug 11, 2022\"\n- Gives the date it was last updated. Last updated 2022-08-11.\n- Names the governing law or courts. The law of the State of California.\n- States a limit on its liability. Rules out indirect and consequential losses, with no cap named in this sentence.\n- Says how changes to the terms are announced. Gives 10 days of notice before a change.\n- Not found in the text. Refers to a service level or uptime commitment.\n- Also in the text (2026-10-08). Liability not otherwise disclaimed is capped at the fees paid in the three months before the event behind the claim. \"you further agree that under no circumstances will any such liability exceed in the aggregate the amount of Fees paid by you to Yoxel during the three-month period immediately preceding the event that gave rise to your claim for damages.\"\n- Also in the text (2026-10-08). On monthly plans Yoxel may change the fees at any time, and a customer who does not accept the new fees is told to cancel. \"We reserve the right to change the Fees at any time. If you do not accept the new Fees, you should cancel your subscription.\"\n- Also in the text (2026-10-08). On termination Yoxel may delete all of the customer’s stored information but is not obliged to. \"we reserve the right (but have no obligation) to delete all of your information stored on our servers;\"\n\n**Privacy policy** (https://www.aurinko.io/privacy/), read 2026-10-08, dated 2022-08-11, states 7 of the 8 things a reader expects.\n\n- To know. Has not been updated for three years or more. \"Last Updated: Aug 11, 2022\"\n- Gives the date it was last updated. Last updated 2022-08-11.\n- Gives a privacy contact. compliance@yoxel.com.\n- Not found in the text. Says where data is transferred or stored.\n- Also in the text (2026-10-08). Personal information is shared with the third parties whose APIs are integrated, and the policy says they may use it for their own purposes. \"These third parties may use your personal information to operate their services and for their own purposes.\"\n- Also in the text (2026-10-08). Use and transfer of personal information received from Google Accounts is stated to follow the Google API Services User Data Policy, including its Limited Use requirements. \"Our use and transfer to any other app of personal information received from Google Accounts will adhere to Google API Services User Data Policy\"\n\n## Live (updated 2026-10-08 21:53 UTC)\n\n- Right now: up, HTTP 404, 233 ms, checked 2026-10-08 21:53 UTC (get on `https://api.aurinko.io`)\n- Uptime 24h 100.0% (28 probes) · 30 days 100.0% (28 probes) · p50 255 ms · p95 311 ms\n- Always current: https://www.anchorterminal.com/api/v1/live/aurinko-calendar.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Prices\n\n| Item | Price | Unit | Note |\n| --- | --- | --- | --- |\n| Unified API, one of Calendar, Contacts or Tasks | $1 | per connected account per month | Per active account, up to 1 GB of traffic a month |\n| Email or CRM | $1.50 | per connected account per month | Per active account, up to 1 GB of traffic a month |\n| Full platform, any number of APIs | $2 | per connected account per month | Per active account, unlimited traffic |\n\nAcross all listings: https://www.anchorterminal.com/prices/index.md\n\n## Strengths\n\n- Public OpenAPI 3.0 spec at `apirefs.aurinko.io/assets/swagger.json` with 154 operations, 110 of them carrying a cURL sample\n- Availability in three forms, `/v1/calendars/freeBusy`, `/v1/calendars/suggestMeetingTimes` and booking profiles for one calendar or a group\n- Prices published per active account a month ($1, $1.50 and $2), with a 14-day trial that needs no card\n- Eleven OAuth scopes, with `Calendar.Read` separate from `Calendar.ReadWrite`, and `DELETE /v1/account/token` to revoke a token\n- Docs state that event, email and contact contents are passed through and never stored, with only IDs cached for sync\n\n## Weaknesses\n\n- No status page, incident history or SLA found, and the terms supply the service as is\n- No changelog, deprecation policy or official SDK. The only npm package, `aurinko-sdk`, is unofficial\n- The application's client ID and secret, sent as Basic auth with `X-Aurinko-Account-Id`, reach every connected account\n- SOC 2 is not yet held. The security statement of 18 June 2026 targets a Type I examination for Q3 2026\n- Terms and privacy policy date from 11 August 2022, with no retention period, DPA or sub-processor list found\n\n## Before you call it (notes for agents)\n\n1. Use `https://api.aurinko.io/v1`. Several cURL examples in the docs print `https:/api.aurinko.io` with one slash\n2. Send `If-Match` with the event's `etag` on `PATCH /v1/calendars/{calendarId}/events/{eventId}`. A stale value returns 412\n3. Use `primary` as the calendar ID for an account's main calendar, and page with `pageToken` until none is returned\n4. Hold a slot with `reserveForMinutes` on the booking `meeting` call, then confirm or cancel the reservation, since no idempotency key exists\n5. Retry 429, 408 and 5xx with exponential backoff. Do not retry 404. A 429 can come from Google or Microsoft limits behind the API\n\n## Connect\n\nFirst request:\n\n```bash\ncurl -H 'Authorization: Bearer \u003caccess_token\u003e' \\\n  -X GET https://api.aurinko.io/v1/calendars/primary\n```\n\nThrough letme (picks today, calling later): https://letme.dev/aurinko-calendar. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Nylas Calendar and Scheduler API | BB | 71 | 121 | calendar.read, calendar.write, calendar.availability, calendar.booking, calendar.webhooks | no | https://www.anchorterminal.com/tools/nylas-calendar.md |\n| Cronofy API | B | 64.2 | 282 | calendar.read, calendar.write, calendar.availability, calendar.booking, calendar.webhooks | no | https://www.anchorterminal.com/tools/cronofy.md |\n| Google Calendar API | A | 80.6 | 7 | calendar.read, calendar.write, calendar.availability, calendar.webhooks | no | https://www.anchorterminal.com/tools/google-calendar-api.md |\n| Calendly API + MCP | B | 68.3 | 182 | calendar.read, calendar.availability, calendar.booking, calendar.webhooks | no | https://www.anchorterminal.com/tools/calendly.md |\n| Microsoft Graph Calendar API | B | 65.1 | 264 | calendar.read, calendar.write, calendar.availability, calendar.webhooks | no | https://www.anchorterminal.com/tools/microsoft-graph-calendar.md |\n| Cal.com API v2 + MCP | C | 57.2 | 480 | calendar.read, calendar.availability, calendar.booking, calendar.webhooks | no | https://www.anchorterminal.com/tools/cal-com.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The spec at apirefs.aurinko.io is OpenAPI 3.0.0, titled Aurinko.io API 1.0.0, with 112 paths and 154 operations, 21 of them under Calendars, Events, CalSync and FreeBusySchedule and 33 under Booking, GroupBooking and Availability (source: \u003chttps://apirefs.aurinko.io/assets/swagger.json\u003e)\n- Billing counts active accounts, meaning more than 10 API calls or more than 1 MB transferred in a billing month, and the same mailbox connected twice is billed once (source: \u003chttps://docs.aurinko.io/faq/how-does-aurinko-billing-work\u003e)\n- The docs describe the API as mainly a pass-through that proxies requests to the provider, caching IDs and master-instance relations but never the contents of events, emails, contacts or tasks (source: \u003chttps://docs.aurinko.io/getting-started/readme\u003e)\n- Group booking profiles attach accounts or groups of accounts with `required` set to `one` or `all`, and the availability response names which accounts and groups are free for each slot (source: \u003chttps://docs.aurinko.io/scheduling/group-booking-api\u003e)\n- Webhook requests are signed with HMAC SHA256 over `v0:{timestamp}:{raw_body}` in `X-Aurinko-Signature`, and subscriptions cover `/calendars/{calId}/events` and `/booking/{bookingId}` (source: \u003chttps://docs.aurinko.io/unified-apis/webhooks-api/authentication\u003e)\n- The security statement, last updated 18 June 2026, says Yoxel is preparing for a SOC 2 Type I examination targeted for Q3 2026 with Secureframe, and takes vulnerability reports at security@yoxel.com (source: \u003chttps://www.aurinko.io/certifications/\u003e)\n- The pricing page and the billing FAQ describe the $1.50 tier differently, as under 5 GB of data transfer on one and as Email or CRM up to 1 GB on the other (source: \u003chttps://www.aurinko.io/pricing/\u003e)\n\n## Compare\n\n- [Acuity Scheduling API vs Aurinko Calendar API](https://www.anchorterminal.com/compare/acuity-scheduling-vs-aurinko-calendar.md): E 42.4 vs E 45.6\n- [Apiroc Unified Calendar API vs Aurinko Calendar API](https://www.anchorterminal.com/compare/apiroc-vs-aurinko-calendar.md): E 41.1 vs E 45.6\n- [Aurinko Calendar API vs Cal.com API v2 + MCP](https://www.anchorterminal.com/compare/aurinko-calendar-vs-cal-com.md): E 45.6 vs C 57.2\n- [Aurinko Calendar API vs Calendly API + MCP](https://www.anchorterminal.com/compare/aurinko-calendar-vs-calendly.md): E 45.6 vs B 68.3\n- [Aurinko Calendar API vs Cronofy API](https://www.anchorterminal.com/compare/aurinko-calendar-vs-cronofy.md): E 45.6 vs B 64.2\n- [Aurinko Calendar API vs Google Calendar API](https://www.anchorterminal.com/compare/aurinko-calendar-vs-google-calendar-api.md): E 45.6 vs A 80.6\n- [Aurinko Calendar API vs Microsoft Graph Calendar API](https://www.anchorterminal.com/compare/aurinko-calendar-vs-microsoft-graph-calendar.md): E 45.6 vs B 65.1\n- [Aurinko Calendar API vs Nylas Calendar and Scheduler API](https://www.anchorterminal.com/compare/aurinko-calendar-vs-nylas-calendar.md): E 45.6 vs BB 71\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on aurinko.io or one of its subdomains. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"aurinko-calendar\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/aurinko-calendar\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/aurinko-calendar.svg\" alt=\"Aurinko Calendar API on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Aurinko Calendar API on Anchor Terminal](https://www.anchorterminal.com/badges/aurinko-calendar.svg)](https://www.anchorterminal.com/tools/aurinko-calendar)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/aurinko-calendar\"\u003eAurinko Calendar API on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Aurinko Calendar API is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/aurinko-calendar-dark.png\n- Light: https://www.anchorterminal.com/assets/share/aurinko-calendar-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Calendars \u0026 scheduling",
        "url": "https://www.anchorterminal.com/categories/scheduling"
      },
      {
        "name": "Aurinko Calendar API",
        "url": ""
      }
    ],
    "description": "Unified calendar REST API from Yoxel, Inc. It reads and writes calendars and events on Google, Office 365, Outlook.com, Exchange and iCloud through one interface, with free/busy queries, booking profiles and webhooks.",
    "facts": [
      "rank #654 of 722",
      "OAuth auth",
      "0 desk reviews"
    ],
    "h1": "Aurinko Calendar API",
    "image": "https://www.anchorterminal.com/assets/og/tools-aurinko-calendar.png",
    "path": "/tools/aurinko-calendar",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Aurinko Calendar API review for AI agents, grade E (45.6/100)",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/aurinko-calendar"
  },
  "tokens": {
    "markdown": 7000,
    "slim": 1730
  },
  "version": 1
}
