Basiq
by Basiq Pty Ltd (Cuscal Limited) HTTP API in Bank data & open banking
Hosted
Basiq Pty Ltd · basiq.io since 2015 · status page · who's behind it
Basiq is an Australian open banking platform owned by Cuscal Limited. Its REST API reads accounts, transactions and identity details from Australian and New Zealand institutions with the holder's consent, and builds income, expense and affordability reports.
Good for Consented bank data for Australia and New Zealand, with income and affordability reports for lenders.
Is this your product? Claim this listing or verify it
Assessment. Ten public OpenAPI files, an llms.txt index with Markdown twins and a free self-serve sandbox let an agent start on test data. Live access needs a 12-month plan with an unpublished platform access fee, no SLA or security.txt was found, and the privacy policy says collected content may be kept indefinitely.
Facts
- Transport
- HTTP, Streamable HTTP
- Endpoint
https://au-api.basiq.io- Auth
- API key
- Pricing
- Paid · Paid
- x402
- No
- Licence
- Proprietary service under the Basiq Terms of Service. The public docs repository carries no licence file, and the OpenAPI files state the licence as Commercial
- llms.txt
- published
- Last release
- API
- REST over HTTPS at https://au-api.basiq.io, version 3.0 selected with the
basiq-versionheader. Ten OpenAPI files list 73 operations - Authentication
- API key exchanged at
POST /tokenfor a bearer token that lasts 60 minutes. ScopeSERVER_ACCESSfor servers,CLIENT_ACCESSbound to auserIdfor the Consent UI - Data endpoints
/users/{userId}/accounts,/users/{userId}/transactions,/users/{userId}/identities,/users/{userId}/connections,/connectors,/jobs/{jobId}- Consent
- Hosted Consent UI at consent.basiq.io, required on version 3.0.
GET /users/{userId}/consentslists consents andDELETE /users/{userId}/consents/{consentId}removes one. The CDR Policy says data is destroyed or de-identified within seconds of withdrawal - Transactions
limitup to 500 a page,links.nextfor the next page,filteron connection, account, post date, status, institution, direction and class- Async
- Connections, refreshes, reports and statement uploads return a job.
GET /users/{userId}/jobsreturns jobs less than 7 days old - Rate limits
- 1,500 token requests per 5 minutes. Reports and affordability summaries capped at the lesser of users created that day or 1,000 a day. Open Banking connections refresh at most 20 times a day. General limits are not published
- Insights and reports
- Enrich for merchant and category, CDR Insights for income, balance, account, identity and expense ratio checks, and consumer and business affordability reports kept for 24 hours
- Sandbox
- Free from the dashboard, 500 connections, test bank Hooli (AU00000) with published test logins. Enrich is limited to 100 requests a month in sandbox
- Webhooks
- Signed with HMAC-SHA256 in
webhook-signature, withwebhook-idandwebhook-timestamp. Eight delivery attempts over about 27 hours - Coverage
- Australia and New Zealand. Basiq says 135+ institutions on the home page and over 170 on the Data page
- MCP server
- https://api.basiq.io/mcp, streamable HTTP. Tools seen without a credential are
list-endpoints,get-endpoint,search-endpoints,list-specsandexecute-request. Route groups are switched on or off in the dashboard - AI resources
- llms.txt with an index per section, a Markdown twin of each docs and reference page, and the OpenAPI files on GitHub
- Data location
- AWS data centres in Sydney and Melbourne, per the CDR Policy. Support staff of Basiq.io D.O.O. in Serbia and AuthSignal Ltd in New Zealand are named as outsourced service providers
- SDKs
- None published. The docs point to generating a JavaScript or TypeScript client from the OpenAPI files
- Support
- support@basiq.io, in-app chat and a Jira service desk
- Capabilities
- bank.accounts bank.transactions bank.identity bank.consent
Facts verified 2026-10-09 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- Ten OpenAPI 3.0 files are public in the
basiqio-oss/Basiq-docsrepository, 73 operations in all, and every reference page has a Markdown twin listed in llms.txt - The sandbox is free and self-serve from the dashboard, with a test bank named Hooli and an Open Banking flow that covers authorise, extend, refresh and revoke
- API keys are created, named and revoked in the dashboard, permission sets limit a key to chosen endpoints, and access tokens expire after 60 minutes
- The CDR Policy names the outsourced service providers and says data is stored in AWS data centres in Sydney and Melbourne
- Error bodies carry a
correlationId, a stringcode, atitle, adetailand asourcepointer, with the codes listed by HTTP status in the docs
Weaknesses
- Live data needs a plan with a 12-month minimum and a platform access fee whose amount is not published
- No SLA was found, and the Terms of Service say Basiq does not warrant uninterrupted service
- The privacy policy says collected content may be retained indefinitely after an account ends, while the docs security page says data is deleted at once
- No security.txt, disclosure policy or bug bounty was found, and the accreditation logos on the data security page carry no text
- No idempotency keys or
Retry-Afterheader are documented, and no official SDK is published. The docs say to generate one from the OpenAPI files
Before you call it notes for agents
- Send the API key verbatim after
Basicin theAuthorizationheader ofPOST /token. Base64-encoding it returns a 400. - Send
basiq-version: 3.0on the token request, cache the bearer token for its 60 minutes, and stay under 1,500 token requests per 5 minutes. - Send the account holder through the hosted Consent UI in a browser with a
CLIENT_ACCESStoken bound to theiruserId. The API alone cannot create a first connection on version 3.0. - Poll
GET /jobs/{jobId}untilverify-credentials,retrieve-accountsandretrieve-transactionsall readsuccessbefore reading accounts or transactions. - Follow
links.nextonGET /users/{userId}/transactions. A page holds at most 500 items, and pending transactions get new ids on each refresh.
Who's behind it provenance 83/100
- Legal entity namedBasiq Pty Ltd20/20
- Domain agebasiq.io, registered 2015-10-08 (11 years)15/15
- Endpoint on the vendor's domainau-api.basiq.io15/15
- Terms of serviceread, states 5 of the 7 things a reader expects, and has 1 clause that costs points6.3/10
- Privacy policyread, states 4 of the 8 things a reader expects7/10
- Status pagestatus.basiq.io10/10
- Changelogpublished10/10
- security.txtnot found0/10
Terms and privacy, as read
Terms of service gives no date, states 5 of 7, 2 to know
TL;DR Gives no date. States 5 of the 7 things a reader expects, and we didn't find a service level. To know before relying on it, limits on benchmarking and cut-off without notice or for any reason.
Restricts benchmarking or competitive usecosts points
create a Developer Product that substantially replicates the Services or any component therein including but not limited to the Platform;
A clause against publishing test results or using the service to build something that competes.
Says access can be ended without notice or for any reason
If Basiq is not made within 14 days of the date of the Invoice, Basiq may at its discretion suspend or terminate your access to the Services without notice to you, in which case you will not be able to access or use the Services User Data or Aggregated Data and Basiq is not responsible for any interruption this may ca…
The vendor can suspend or close an account without warning, which would stop an agent mid-task.
Gives the date it was last updated
Not found in the text.
Without a date nobody can tell which version they agreed to.
Names the governing law or courts The law of New South Wales
24.1 These Terms are governed by the laws of New South Wales and the Commonwealth of Australia.
Says where a dispute would be heard and under whose law.
States a limit on its liability Rules out indirect and consequential losses, with no cap named in this sentence
11.11 In no event will Basiq or its licensors be liable for any consequential, incidental, indirect, special, punitive, or other damages whatsoever arising out of these Terms or the interruption to, use of or inability to use the Services, even if Basiq has been advised of the possibility of such damages.
Says the most the vendor would owe if the service causes a loss.
Says how the agreement or account can be ended
If you do not agree to these changes, you may terminate these Terms and you must cease to access and use the Services.
Says when the vendor can cut off access and what notice it gives.
Says how changes to the terms are announced Changes are posted, with no other notice named
Any changes to the Terms will be effective upon the posting of the modified Terms on the Website.
Says whether a customer hears about a change before it binds them.
Lists what users may not do
you will not make any representations or warranties regarding Basiq or the Services as supplied by Basiq without Basiq’s prior written consent;
The acceptable-use rules an agent acting for a user has to stay inside.
Refers to a service level or uptime commitment
Not found in the text.
Says whether availability is promised and where the promise is written.
Basiq may use customer data stripped of personal identifiers to improve and develop its services and products, and says it will not sell or license that data.
3.3 You agree that Basiq may use Aggregated Data to provide customer support and to improve and develop services and products. Basiq will not sell or license Aggregated Data.
Noted by a second reader on 2026-10-08.
Access to the customer's own User Data and continued use of the service depend on payment of the fees.
However, your access to the User Data and/or Aggregated Data and your continued use of the Services is contingent on payment of the applicable Fees for the Services.
Noted by a second reader on 2026-10-08.
The customer is responsible for retrieving its data before termination.
5.3 It is your responsibility to retrieve your data or replace the functionality supplied by the Services on your Developer Product prior to termination.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-09 · 8,626 words
Privacy policy gives no date, states 4 of 8
TL;DR Gives no date. States 4 of the 8 things a reader expects, and we didn't find how long data is kept, people's rights or where data goes. The rules found no clause to flag.
Gives the date it was last updated
Not found in the text.
Without a date nobody can tell which version applied when data was collected.
Says what personal data is collected
This Privacy Policy will help you understand what Personal Information we collect and how this is managed.
The basic statement a privacy policy exists to make.
Says how long data is kept
Not found in the text.
Says when data sent to the service is deleted.
Says who else receives the data
We may continue to disclose such content to third parties in a manner that does not reveal Personal Information, as described in this Privacy Policy.
Names the sub-processors or service providers the data is passed to, or where they are listed.
Says whether personal data is sold or shared for advertising Says it does not sell personal data
Basiq does not sell or rent any personal information to marketers or third parties that have not been explicitly authorised (e.g., in the case of a client).
A plain statement either way.
Says what rights people have over their data
Not found in the text.
Access, correction, deletion and objection, and how to use them.
Gives a privacy contact
If you need more information, want to access or update your personal information or if you have a privacy concern, please contact us using the contact details below.
An address or officer to send a request to.
Says where data is transferred or stored
Not found in the text.
The countries data goes to and the safeguard used.
Content submitted to the service or collected from a client application or a financial institution may be kept indefinitely, including after the account is terminated.
All content submitted by you to the Service or collected on your behalf from a third-party (e.g., client) application or a financial institution (e.g., a bank) may be retained by us indefinitely, even after you terminate your account.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-09 · 2,416 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The site footer names Basiq Pty Ltd, ABN 95 616 592 011, a wholly owned but non-guaranteed subsidiary of Cuscal Limited, ABN 95 087 822 455, and gives the Consumer Data Right accreditation number ADRBNK000208.
The terms link is the Basiq Terms of Service, dated 27 August 2025 on the help centre, which govern the platform, SDK and APIs and carry the SDK licence as Schedule 1.
The privacy link is the Basiq Privacy Policy, dated 4 November 2025. A separate Consumer Data Right (CDR) Policy, dated 8 September 2026, covers data received under that regime.
The API answers at au-api.basiq.io, the docs and MCP server at api.basiq.io, the Consent UI at consent.basiq.io and the dashboard at dashboard.basiq.io, all under basiq.io.
www.basiq.io/.well-known/security.txt returns 404, and www.basiq.io has no robots.txt.
status.basiq.io runs on Atlassian Statuspage. Its robots.txt disallows /api/, so the record was read from the page and the Atom feed it links.
The registry's RDAP record gives 2015-10-08 as the registration date of basiq.io and Name.com, Inc. as registrar. The privacy policy gives PO Box Q279, Queen Victoria Building NSW 1230.
Checked 2026-10-09 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-10 00:51 UTC
Probed every five minutes at https://au-api.basiq.io. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.
- Vendor status page minor, Minor Service Outage · 3 minutes ago
- github
basiqio-oss/Basiq-docsv3.0.8, released 2026-07-16 - GitHub stars 5
Pages we watch
| Page | Kind | Last checked | Last changed |
|---|---|---|---|
| api.basiq.io/changelog | changelog | 6 hours ago · 200 | no change seen |
| www.basiq.io/pricing.html | pricing | 6 hours ago · 200 | no change seen |
| docs.basiq.io/en/articles/382581-basiq-privacy-policy | privacy | 6 hours ago · 200 | no change seen |
| docs.basiq.io/en/articles/415750-basiq-terms-of-service | terms | 6 hours ago · 200 | no change seen |
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/basiq.json
Notable
- Basiq Pty Ltd is a wholly owned subsidiary of Cuscal Limited and an accredited data recipient under the Consumer Data Right, accreditation ADRBNK000208, per the site footer source
- A hosted MCP server at https://api.basiq.io/mcp was added in May 2026. It answered an unauthenticated
tools/liston 9 October 2026 with five tools, among themexecute-request, which sends a HAR request to the API source - The MCP docs page lists seven built-in tools, including
fetchandsearch. The server returned five to an unauthenticated client source - Version 3.0 requires the hosted Consent UI for every connection. The
CLIENT_ACCESStoken travels in the query string ofhttps://consent.basiq.io/home?token=source - Three access methods sit behind one API. Open Banking under the Consumer Data Right, web connectors that log in with the holder's bank credentials, and statement upload as PDF or CSV source
- The status page shows the NAB web connector in partial outage. NAB began blocking web scraping in April 2026 and Basiq advises moving to Open Banking source
- Basiq ended support for its ANZ New Zealand connector in 2026. The connector stays selectable and failures are not investigated source
- The home and pricing pages say 135+ institutions, and the Data product page says over 170 source
- The Terms of Service, dated 27 August 2025, give at least 7 days' notice of changes and say user data is stored in Australia. No clause on automated access or benchmarking was found source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 9 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 14.0 | |
Graded on the REST API with the hosted lines. Statuspage at status.basiq.io with components for the APIs, dashboard, documentation, website and connectors, and a history feed whose 25 entries reach back to October 2024 (20). No incident was posted in the 90 days to 9 October 2026. The newest entries are from April 2026, when NAB began blocking the web connector, and that connector still shows a partial outage, which is the bank's doing (25 of 30). Numbers are published for some parts, 1,500 token requests per 5 minutes, 1,000 reports a day and 20 refreshes a day on an Open Banking connection, while the general limits are described without figures (10 of 15). A 429 with code too-many-requests is documented with the advice to retry after the limit resets. No Retry-After header, backoff timings or idempotency keys were found (5 of 15). No SLA was found, and the Terms of Service say Basiq does not warrant uninterrupted service (0). Version 3.0 is generally available (10). | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 13.7 | |
Ten OpenAPI 3.0 files are public in the basiqio-oss/Basiq-docs repository and embedded in each reference page, 73 operations in all (25). llms.txt indexes the docs, reference and changelog, and each page has a Markdown twin (10). Every operation has a description except the nine webhook operations. Descriptions state the purpose and some say when a call applies, such as purge working only on active connections (14 of 20). Schemas use enums and required fields, with 167 enums in the Connect file, but filter is a free-form expression string and the token scope is an untyped string (10 of 15). Request and response examples are dense, and an error codes page lists codes by HTTP status (13 of 15). The version is pinned with the basiq-version header, the docs repository is tagged (v3.0.8 on 16 July 2026) and the changelog has ten entries for 2026, dated by month (12 of 15). | |||
| Agent ergonomics | 13%16.2 | 10.1 | |
Transactions take limit up to 500 and a filter on seven fields. No field selection or summary mode was found (15 of 25). List calls page with links.next and Insights lists hold at most 20 a page (17 of 20). Errors return a correlationId, a string code, title, detail and a source pointer, and failed job steps carry the bank's own message (17 of 20). No idempotency keys were found, so a repeated POST /users creates a second billable user. Reads are safe to repeat, and the five MCP tools set readOnlyHint and destructiveHint (8 of 20). Every call needs the basiq-version header and a token exchange with a non-standard Basic header, and no official SDK is published (5 of 15). | |||
| Security & auth | 14%17.5 | 9.6 | |
API keys are named, many to an application, revocable in the dashboard and limited to chosen endpoints by permission sets, with a 90-day rotation guide and 60-minute bearer tokens (27 of 30). The CLIENT_ACCESS token travels in the query string of the Consent UI address, and the MCP page says headers can be passed as query parameters, so the checklist's 10 comes off (17 of 30). The service reads bank data and cannot move money, consent scopes are set per data type and MCP route groups can be switched off. Deleting a user or connection has no confirmation step, and web connectors mean Basiq stores bank logins, encrypted with AES-256 per connection (16 of 20). Responses carry bank-written transaction descriptions and no guidance on treating them as untrusted was found (7 of 15). GET /events and the webhook message log record activity. No per-request audit log was found in the docs (8 of 15). No security.txt, disclosure policy or bug bounty was found. A 2020 information security policy aims at ISO/IEC 27001:2013, the certifications named in the docs belong to the AWS data centres, and the accreditation logos on the data security page carry no text (7 of 20). | |||
| Payments & pricing | 10%12.5 | 2.5 | |
| No x402, MPP or L402 (0). Unit prices are public, $0.50 per user per month for data, $0.25 for enrichment and from $3.00 a report, but a platform access fee has no published amount and plans run for at least 12 months. The pricing page is not linked from the home page and may be out of date, so half marks (10 of 20). The sandbox is free and self-serve with no card mentioned. There is no free live tier (10 of 20). A person registers in the dashboard and live access goes through sales (0). | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 4.2 | |
| The newest changelog entry, Sep '26 Basiq Product Updates, read 9 days old on 9 October 2026, which puts it at about 30 September (30). Two changelog entries fall in the last 90 days, September and July, so the line for three is not met (0). A public changelog, support by email, chat and a service desk, and an issues link on the docs repository. Reply times were not sampled (9 of 15). No official SDK. The OpenAPI files are kept in a tagged repository (3 of 15). The docs repository runs lint, link-check and release workflows and merged dependency updates on 1 October 2026 (6 of 10). | |||
| Transparency & trusteditorial 61, provenance 83 | 7%8.8 | 6.3 | |
| A closed service with public Terms of Service that name Basiq Pty Ltd (15). The privacy policy, the CDR Policy and a complaints policy are public, and the CDR Policy says data is destroyed or de-identified within seconds of a consent ending. The privacy policy says collected content may be retained indefinitely after an account ends, which does not agree with the docs security page, and no DPA was found (17 of 30). The OpenAPI page says breaking changes come with major versions, a migration checklist covers version 3.0 and legacy endpoints are labelled. The ANZ New Zealand end-of-support notice carries no date and no notice period is stated (8 of 20). Storage in AWS Sydney and Melbourne, outsourced service providers in New Zealand and Serbia by name, and representatives allowed to store data in New Zealand and the United Kingdom are disclosed (16 of 20). Regulatory standing counts as an addition, as on other bank-data listings. The footer gives ACCC accreditation ADRBNK000208 (+5). | |||
| Negative events | ≤15 | None recorded | 0 |
| Total | 60.4 · C | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 23 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Basiq, or have the agent fetch /fixes/basiq.md. A fix counts at the next check, once it's public.
Show it
# Fix list: Basiq
From Anchor Terminal's listing at https://www.anchorterminal.com/tools/basiq, the October 2026 research run, assessed 9 October 2026. Grade C, 60.4 out of 100.
This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.
For a coding agent working on Basiq: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.
## 1. Payments & pricing, 20 out of 100, up to 10 more on the total
Why it scored 20: No x402, MPP or L402 (0). Unit prices are public, $0.50 per user per month for data, $0.25 for enrichment and from $3.00 a report, but a platform access fee has no published amount and plans run for at least 12 months. The pricing page is not linked from the home page and may be out of date, so half marks (10 of 20). The sandbox is free and self-serve with no card mentioned. There is no free live tier (10 of 20). A person registers in the dashboard and live access goes through sales (0).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):
The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).
- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.
- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login.
- 20, a free tier or trial that doesn't need a card.
- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).
Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.
Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.
## 2. Security & auth, 55 out of 100, up to 7.9 more on the total
Why it scored 55: API keys are named, many to an application, revocable in the dashboard and limited to chosen endpoints by permission sets, with a 90-day rotation guide and 60-minute bearer tokens (27 of 30). The `CLIENT_ACCESS` token travels in the query string of the Consent UI address, and the MCP page says headers can be passed as query parameters, so the checklist's 10 comes off (17 of 30). The service reads bank data and cannot move money, consent scopes are set per data type and MCP route groups can be switched off. Deleting a user or connection has no confirmation step, and web connectors mean Basiq stores bank logins, encrypted with AES-256 per connection (16 of 20). Responses carry bank-written transaction descriptions and no guidance on treating them as untrusted was found (7 of 15). `GET /events` and the webhook message log record activity. No per-request audit log was found in the docs (8 of 15). No security.txt, disclosure policy or bug bounty was found. A 2020 information security policy aims at ISO/IEC 27001:2013, the certifications named in the docs belong to the AWS data centres, and the accreditation logos on the data security page carry no text (7 of 20).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-security):
- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.
- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.
- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.
- 0 to 15, audit logs or per-call visibility for the operator.
- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.
Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.
## 3. Agent ergonomics, 62 out of 100, up to 6.2 more on the total
Why it scored 62: Transactions take `limit` up to 500 and a `filter` on seven fields. No field selection or summary mode was found (15 of 25). List calls page with `links.next` and Insights lists hold at most 20 a page (17 of 20). Errors return a `correlationId`, a string `code`, `title`, `detail` and a `source` pointer, and failed job steps carry the bank's own message (17 of 20). No idempotency keys were found, so a repeated `POST /users` creates a second billable user. Reads are safe to repeat, and the five MCP tools set `readOnlyHint` and `destructiveHint` (8 of 20). Every call needs the `basiq-version` header and a token exchange with a non-standard Basic header, and no official SDK is published (5 of 15).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):
- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).
- 20, pagination, filtering and output-size controls.
- 20, actionable, documented error responses, codes and messages an agent can recover from.
- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.
- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.
Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.
## 4. Reliability, 70 out of 100, up to 6 more on the total
Why it scored 70: Graded on the REST API with the hosted lines. Statuspage at status.basiq.io with components for the APIs, dashboard, documentation, website and connectors, and a history feed whose 25 entries reach back to October 2024 (20). No incident was posted in the 90 days to 9 October 2026. The newest entries are from April 2026, when NAB began blocking the web connector, and that connector still shows a partial outage, which is the bank's doing (25 of 30). Numbers are published for some parts, 1,500 token requests per 5 minutes, 1,000 reports a day and 20 refreshes a day on an Open Banking connection, while the general limits are described without figures (10 of 15). A 429 with code `too-many-requests` is documented with the advice to retry after the limit resets. No `Retry-After` header, backoff timings or idempotency keys were found (5 of 15). No SLA was found, and the Terms of Service say Basiq does not warrant uninterrupted service (0). Version 3.0 is generally available (10).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):
Hosted APIs, MCP servers, models and platforms.
- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).
- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.
- 15, rate limits documented with numbers.
- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.
- 10, an SLA published for any paid tier.
- 10, the surface agents use is generally available, not beta or preview.
Local packages, SDKs, frameworks and stdio MCP servers.
- 20, installs from an official package with supported runtimes stated.
- 25, a public CI and test suite, passing on the default branch.
- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).
- 15, semver discipline and breaking changes called out in a changelog.
- 15, version 1.0 or later, or declared stable.
Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.
## 5. Maintenance & community, 48 out of 100, up to 4.6 more on the total
Why it scored 48: The newest changelog entry, Sep '26 Basiq Product Updates, read 9 days old on 9 October 2026, which puts it at about 30 September (30). Two changelog entries fall in the last 90 days, September and July, so the line for three is not met (0). A public changelog, support by email, chat and a service desk, and an issues link on the docs repository. Reply times were not sampled (9 of 15). No official SDK. The OpenAPI files are kept in a tagged repository (3 of 15). The docs repository runs lint, link-check and release workflows and merged dependency updates on 1 October 2026 (6 of 10).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):
- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.
- 20, at least three releases or dated changelog entries in the last 90 days.
- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.
- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).
- 10, package health, current dependencies and CI.
Models are read for deprecation notice periods and model churn rather than release counts.
## 6. Schema & documentation, 84 out of 100, up to 2.6 more on the total
Why it scored 84: Ten OpenAPI 3.0 files are public in the `basiqio-oss/Basiq-docs` repository and embedded in each reference page, 73 operations in all (25). llms.txt indexes the docs, reference and changelog, and each page has a Markdown twin (10). Every operation has a description except the nine webhook operations. Descriptions state the purpose and some say when a call applies, such as purge working only on active connections (14 of 20). Schemas use enums and required fields, with 167 enums in the Connect file, but `filter` is a free-form expression string and the token `scope` is an untyped string (10 of 15). Request and response examples are dense, and an error codes page lists codes by HTTP status (13 of 15). The version is pinned with the `basiq-version` header, the docs repository is tagged (v3.0.8 on 16 July 2026) and the changelog has ten entries for 2026, dated by month (12 of 15).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):
APIs and MCP servers.
- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).
- 10, llms.txt or Markdown docs served for agents.
- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.
- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.
- 0 to 15, examples and documented error responses.
- 15, versioning and a public changelog.
Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.
## 7. Transparency & trust, 72 out of 100, up to 2.5 more on the total
Made of editorial 61, provenance 83.
Why it scored 72: A closed service with public Terms of Service that name Basiq Pty Ltd (15). The privacy policy, the CDR Policy and a complaints policy are public, and the CDR Policy says data is destroyed or de-identified within seconds of a consent ending. The privacy policy says collected content may be retained indefinitely after an account ends, which does not agree with the docs security page, and no DPA was found (17 of 30). The OpenAPI page says breaking changes come with major versions, a migration checklist covers version 3.0 and legacy endpoints are labelled. The ANZ New Zealand end-of-support notice carries no date and no notice period is stated (8 of 20). Storage in AWS Sydney and Melbourne, outsourced service providers in New Zealand and Serbia by name, and representatives allowed to store data in New Zealand and the United Kingdom are disclosed (16 of 20). Regulatory standing counts as an addition, as on other bank-data listings. The footer gives ACCC accreditation ADRBNK000208 (+5).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):
- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.
- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).
- 0 to 20, a deprecation policy or notices with dates.
- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).
The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.
Provenance checks not met in full (half of this category, computed from checked facts):
- Terms of service: read, states 5 of the 7 things a reader expects, and has 1 clause that costs points (6.3 of 10)
- Privacy policy: read, states 4 of the 8 things a reader expects (7 of 10)
- security.txt: not found (0 of 10)
## What we couldn't check
What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.
- The pricing page was reached by its address and is not linked from the home, product or about pages we read, so its figures may be out of date. It carries a 2026 footer.
- unchecked: the amount of the platform access fee and the currency of the listed prices. The Terms of Service say amounts are in Australian dollars
- unchecked: whether Basiq itself holds ISO 27001 or SOC 2. The accreditation logos on the data security page are images with no text, and Cuscal's site was not read
- unchecked: the changelog entries for May 2026 (CDR Insights API Updates) and March 2026, whose Markdown pages answered HTTP 500
- unchecked: exact dates of changelog entries. The page shows relative ages, so the last release date is derived from 9 days ago on 9 October 2026
- unchecked: the dashboard, which needs a login, so the request log, key permissions screen and MCP route switches are known from the docs alone
- unchecked: uptime percentages on the status page, which are drawn by script, and the status API, which robots.txt disallows
- unchecked: GitHub stars and issue reply times on the docs repository
- The MCP docs list seven tools and the server returned five to an unauthenticated client. Whether `fetch` and `search` appear with a credential or a paid docs plan was not established
- Which Consumer Data Right access model a new customer needs for live Open Banking data (representative, affiliate or own accreditation) was not read in detail
- One request to au-api.basiq.io for robots.txt returned the API's 403 JSON error, so the host has no robots file. No other request was sent to it
- Two addresses were tried without a link, www.basiq.io/pricing.html (200) and www.basiq.io/sitemap.xml (404)
- No clause on automated access, scraping or benchmarking was found in the Terms of Service
## Weaknesses
- Live data needs a plan with a 12-month minimum and a platform access fee whose amount is not published
- No SLA was found, and the Terms of Service say Basiq does not warrant uninterrupted service
- The privacy policy says collected content may be retained indefinitely after an account ends, while the docs security page says data is deleted at once
- No security.txt, disclosure policy or bug bounty was found, and the accreditation logos on the data security page carry no text
- No idempotency keys or `Retry-After` header are documented, and no official SDK is published. The docs say to generate one from the OpenAPI files
## What costs an agent a turn today
The notes we give agents before they call it. Each one is a workaround an agent shouldn't need.
- Send the API key verbatim after `Basic` in the `Authorization` header of `POST /token`. Base64-encoding it returns a 400.
- Send `basiq-version: 3.0` on the token request, cache the bearer token for its 60 minutes, and stay under 1,500 token requests per 5 minutes.
- Send the account holder through the hosted Consent UI in a browser with a `CLIENT_ACCESS` token bound to their `userId`. The API alone cannot create a first connection on version 3.0.
- Poll `GET /jobs/{jobId}` until `verify-credentials`, `retrieve-accounts` and `retrieve-transactions` all read `success` before reading accounts or transactions.
- Follow `links.next` on `GET /users/{userId}/transactions`. A page holds at most 500 items, and pending transactions get new ids on each refresh.
## When it's done
Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- The pricing page was reached by its address and is not linked from the home, product or about pages we read, so its figures may be out of date. It carries a 2026 footer.
- unchecked: the amount of the platform access fee and the currency of the listed prices. The Terms of Service say amounts are in Australian dollars
- unchecked: whether Basiq itself holds ISO 27001 or SOC 2. The accreditation logos on the data security page are images with no text, and Cuscal's site was not read
- unchecked: the changelog entries for May 2026 (CDR Insights API Updates) and March 2026, whose Markdown pages answered HTTP 500
- unchecked: exact dates of changelog entries. The page shows relative ages, so the last release date is derived from 9 days ago on 9 October 2026
- unchecked: the dashboard, which needs a login, so the request log, key permissions screen and MCP route switches are known from the docs alone
- unchecked: uptime percentages on the status page, which are drawn by script, and the status API, which robots.txt disallows
- unchecked: GitHub stars and issue reply times on the docs repository
- The MCP docs list seven tools and the server returned five to an unauthenticated client. Whether
fetchandsearchappear with a credential or a paid docs plan was not established - Which Consumer Data Right access model a new customer needs for live Open Banking data (representative, affiliate or own accreditation) was not read in detail
- One request to au-api.basiq.io for robots.txt returned the API's 403 JSON error, so the host has no robots file. No other request was sent to it
- Two addresses were tried without a link, www.basiq.io/pricing.html (200) and www.basiq.io/sitemap.xml (404)
- No clause on automated access, scraping or benchmarking was found in the Terms of Service
Sources 24
- docs index for agents api.basiq.io · seen 2026-10-09
- quickstart and authentication api.basiq.io · seen 2026-10-09
- rate limits api.basiq.io · seen 2026-10-09
- error codes api.basiq.io · seen 2026-10-09
- API key management api.basiq.io · seen 2026-10-09
- permission sets api.basiq.io · seen 2026-10-09
- security page in the docs api.basiq.io · seen 2026-10-09
- MCP server reference api.basiq.io · seen 2026-10-09
- MCP server, initialize and tools/list without a credential api.basiq.io · seen 2026-10-09
- OpenAPI page api.basiq.io · seen 2026-10-09
- OpenAPI files, read from a shallow clone of the v3.0 branch and not from the rendered pages github.com · seen 2026-10-09
- sandbox and test data api.basiq.io · seen 2026-10-09
- changelog api.basiq.io · seen 2026-10-09
- status page status.basiq.io · seen 2026-10-09
- status history feed status.basiq.io · seen 2026-10-09
- pricing basiq.io · seen 2026-10-09
- Terms of Service docs.basiq.io · seen 2026-10-09
- Privacy Policy docs.basiq.io · seen 2026-10-09
- Consumer Data Right (CDR) Policy docs.basiq.io · seen 2026-10-09
- Information Security Policy docs.basiq.io · seen 2026-10-09
- data security page basiq.io · seen 2026-10-09
- home page and footer basiq.io · seen 2026-10-09
- security.txt (404) basiq.io · seen 2026-10-09
- domain registration rdap.identitydigital.services · seen 2026-10-09
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Paid Paid $0.50 per user per month for customer data plus a platform access fee with no published amount, $0.25 per user per month for enrichment and from $3.00 per affordability report (https://www.basiq.io/pricing.html, checked 2026-10-09). The home page does not link that page, so the figures may be out of date. The page does not state the currency, and the Terms of Service say all amounts are in Australian dollars. A user is billable for the full month once created. Plans run for at least 12 months and volume discounts go through sales. The sandbox is free and self-serve from the dashboard, with no card mentioned, so an agent's owner can start on test data without a contract. The pricing page is not linked from the site pages we read.
Recent changes
- Latest release
Follow them as a feed at /feeds/tools/basiq.xml, or this listing's score history at history.json.
Connect
First request
curl --location --request POST 'https://au-api.basiq.io/token' \
--header 'Authorization: Basic $YOUR_API_KEY' \
--header 'Content-Type: application/x-www-form-urlencoded' \
--header 'basiq-version: 3.0' \
--data-urlencode 'scope=SERVER_ACCESS'
MCP client configuration
{
"mcpServers": {
"basiq": {
"url": "https://api.basiq.io/mcp"
}
}
}
Through letme picks today, calling later
GET https://letme.dev/basiq
letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.
Alternatives to Basiq
#6 of 15 in Best open banking and bank data APIs for AI agents · All 105 bank data comparisons
Plaid BBelvo BMX Platform API BTink BTrueLayer BYapily C
Head to head Akoya vs Basiq · Basiq vs Belvo · Basiq vs Enable Banking · Basiq vs Flinks · Basiq vs GoCardless Bank Account Data · Basiq vs MX Platform API · Basiq vs Plaid · Basiq vs Powens · Basiq vs Salt Edge Account Information · Basiq vs Teller · Basiq vs Tink · Basiq vs TrueLayer · Basiq vs Yapily · Basiq vs Yodlee Core API
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| Plaid Plaid | B | 69.8 | bank.accounts bank.transactions bank.identity bank.consent | no |
| Belvo Belvo | B | 63.5 | bank.accounts bank.transactions bank.identity bank.consent | no |
| MX Platform API MX Technologies, Inc. | B | 62.5 | bank.accounts bank.transactions bank.identity bank.consent | no |
| Tink Tink AB (Visa) | B | 62.5 | bank.accounts bank.transactions bank.consent bank.identity | no |
| TrueLayer TrueLayer | B | 62.1 | bank.accounts bank.transactions bank.identity bank.consent | no |
| Yapily Yapily | C | 57.6 | bank.accounts bank.transactions bank.identity bank.consent | no |
Machine-readable
- JSON
/api/v1/tools/basiq.json· historyhistory.json· badge/badges/basiq.svg· changes feed/feeds/tools/basiq.xml - Markdown
/tools/basiq.md· slim/tools/basiq.min.md(or sendAccept: text/markdown) - Fix list
/fixes/basiq.md·/fixes/basiq.json - From a terminal
anchor tool basiq --md(the CLI) · over MCPget_tool {"slug": "basiq"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/basiq"><img src="https://www.anchorterminal.com/badges/basiq.svg" alt="Basiq on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/basiq)<a href="https://www.anchorterminal.com/tools/basiq">Basiq on Anchor Terminal</a>It counts on a page on basiq.io or one of its subdomains, or the README of github.com/basiqio-oss/Basiq-docs.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "basiq", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.


