{
  "data": {
    "similar": [
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/plaid.json",
        "name": "Plaid",
        "score": 69.8,
        "shared": [
          "bank.accounts",
          "bank.transactions",
          "bank.identity",
          "bank.consent"
        ],
        "slug": "plaid"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/belvo.json",
        "name": "Belvo",
        "score": 63.5,
        "shared": [
          "bank.accounts",
          "bank.transactions",
          "bank.identity",
          "bank.consent"
        ],
        "slug": "belvo"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/mx.json",
        "name": "MX Platform API",
        "score": 62.5,
        "shared": [
          "bank.accounts",
          "bank.transactions",
          "bank.identity",
          "bank.consent"
        ],
        "slug": "mx"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/tink.json",
        "name": "Tink",
        "score": 62.5,
        "shared": [
          "bank.accounts",
          "bank.transactions",
          "bank.consent",
          "bank.identity"
        ],
        "slug": "tink"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/truelayer.json",
        "name": "TrueLayer",
        "score": 62.1,
        "shared": [
          "bank.accounts",
          "bank.transactions",
          "bank.identity",
          "bank.consent"
        ],
        "slug": "truelayer"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/yapily.json",
        "name": "Yapily",
        "score": 57.6,
        "shared": [
          "bank.accounts",
          "bank.transactions",
          "bank.identity",
          "bank.consent"
        ],
        "slug": "yapily"
      }
    ],
    "tool": {
      "slug": "basiq",
      "name": "Basiq",
      "vendor": "Basiq Pty Ltd (Cuscal Limited)",
      "vendorUrl": "https://www.basiq.io",
      "kind": "http-api",
      "category": "banking-data",
      "summary": "Basiq is an Australian open banking platform owned by Cuscal Limited. Its REST API reads accounts, transactions and identity details from Australian and New Zealand institutions with the holder's consent, and builds income, expense and affordability reports.",
      "url": "https://www.anchorterminal.com/tools/basiq",
      "markdownUrl": "https://www.anchorterminal.com/tools/basiq.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/basiq.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/basiq.json",
      "repo": "https://github.com/basiqio-oss/Basiq-docs",
      "license": "Proprietary service under the Basiq Terms of Service. The public docs repository carries no licence file, and the OpenAPI files state the licence as Commercial",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://au-api.basiq.io",
      "packages": [],
      "auth": "api-key",
      "authNotes": "A self-serve API key from the dashboard at dashboard.basiq.io, sent verbatim (not Base64-encoded) as `Authorization: Basic \u003ckey\u003e` to `POST /token` with a `basiq-version: 3.0` header. The call returns a bearer token that lasts 60 minutes. Scope `SERVER_ACCESS` covers server calls and `CLIENT_ACCESS`, bound to one `userId`, is for the hosted Consent UI. An application can hold many named keys, each revocable, and permission sets limit a key to chosen endpoints. The docs advise rotating keys every 90 days. Dashboard logins support 2FA by text message and SAML single sign-on on request. Live Open Banking data is switched on by Basiq's customer success team after a contract. The MCP server at api.basiq.io/mcp listed its tools with no credential, and its `execute-request` tool takes API credentials as headers set in the MCP client.",
      "pricing": "paid",
      "pricingNotes": "$0.50 per user per month for customer data plus a platform access fee with no published amount, $0.25 per user per month for enrichment and from $3.00 per affordability report (https://www.basiq.io/pricing.html, checked 2026-10-09). The home page does not link that page, so the figures may be out of date. The page does not state the currency, and the Terms of Service say all amounts are in Australian dollars. A user is billable for the full month once created. Plans run for at least 12 months and volume discounts go through sales. The sandbox is free and self-serve from the dashboard, with no card mentioned, so an agent's owner can start on test data without a contract. The pricing page is not linked from the site pages we read.",
      "priceSummary": "Paid",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs index, the ten OpenAPI files or the pricing page (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://api.basiq.io/docs",
      "llmsTxt": "https://api.basiq.io/llms.txt",
      "openapi": "https://raw.githubusercontent.com/basiqio-oss/Basiq-docs/refs/heads/v3.0/reference/connect.json",
      "capabilities": [
        "bank.accounts",
        "bank.transactions",
        "bank.identity",
        "bank.consent"
      ],
      "tags": [
        "hosted",
        "api-key",
        "openapi",
        "llms-txt",
        "mcp",
        "webhooks",
        "sandbox",
        "australia",
        "new-zealand",
        "status-page",
        "closed-source"
      ],
      "lastRelease": "2026-09-30",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 60.4,
        "grade": "C",
        "agentReady": false,
        "rank": 515,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 6,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 62,
          "maintenance": 48,
          "payments": 20,
          "reliability": 70,
          "schema": 84,
          "security": 55,
          "transparency": 72
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 70,
            "points": 14,
            "reason": "Graded on the REST API with the hosted lines. Statuspage at status.basiq.io with components for the APIs, dashboard, documentation, website and connectors, and a history feed whose 25 entries reach back to October 2024 (20). No incident was posted in the 90 days to 9 October 2026. The newest entries are from April 2026, when NAB began blocking the web connector, and that connector still shows a partial outage, which is the bank's doing (25 of 30). Numbers are published for some parts, 1,500 token requests per 5 minutes, 1,000 reports a day and 20 refreshes a day on an Open Banking connection, while the general limits are described without figures (10 of 15). A 429 with code `too-many-requests` is documented with the advice to retry after the limit resets. No `Retry-After` header, backoff timings or idempotency keys were found (5 of 15). No SLA was found, and the Terms of Service say Basiq does not warrant uninterrupted service (0). Version 3.0 is generally available (10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 84,
            "points": 13.65,
            "reason": "Ten OpenAPI 3.0 files are public in the `basiqio-oss/Basiq-docs` repository and embedded in each reference page, 73 operations in all (25). llms.txt indexes the docs, reference and changelog, and each page has a Markdown twin (10). Every operation has a description except the nine webhook operations. Descriptions state the purpose and some say when a call applies, such as purge working only on active connections (14 of 20). Schemas use enums and required fields, with 167 enums in the Connect file, but `filter` is a free-form expression string and the token `scope` is an untyped string (10 of 15). Request and response examples are dense, and an error codes page lists codes by HTTP status (13 of 15). The version is pinned with the `basiq-version` header, the docs repository is tagged (v3.0.8 on 16 July 2026) and the changelog has ten entries for 2026, dated by month (12 of 15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 62,
            "points": 10.07,
            "reason": "Transactions take `limit` up to 500 and a `filter` on seven fields. No field selection or summary mode was found (15 of 25). List calls page with `links.next` and Insights lists hold at most 20 a page (17 of 20). Errors return a `correlationId`, a string `code`, `title`, `detail` and a `source` pointer, and failed job steps carry the bank's own message (17 of 20). No idempotency keys were found, so a repeated `POST /users` creates a second billable user. Reads are safe to repeat, and the five MCP tools set `readOnlyHint` and `destructiveHint` (8 of 20). Every call needs the `basiq-version` header and a token exchange with a non-standard Basic header, and no official SDK is published (5 of 15)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 55,
            "points": 9.63,
            "reason": "API keys are named, many to an application, revocable in the dashboard and limited to chosen endpoints by permission sets, with a 90-day rotation guide and 60-minute bearer tokens (27 of 30). The `CLIENT_ACCESS` token travels in the query string of the Consent UI address, and the MCP page says headers can be passed as query parameters, so the checklist's 10 comes off (17 of 30). The service reads bank data and cannot move money, consent scopes are set per data type and MCP route groups can be switched off. Deleting a user or connection has no confirmation step, and web connectors mean Basiq stores bank logins, encrypted with AES-256 per connection (16 of 20). Responses carry bank-written transaction descriptions and no guidance on treating them as untrusted was found (7 of 15). `GET /events` and the webhook message log record activity. No per-request audit log was found in the docs (8 of 15). No security.txt, disclosure policy or bug bounty was found. A 2020 information security policy aims at ISO/IEC 27001:2013, the certifications named in the docs belong to the AWS data centres, and the accreditation logos on the data security page carry no text (7 of 20)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 20,
            "points": 2.5,
            "reason": "No x402, MPP or L402 (0). Unit prices are public, $0.50 per user per month for data, $0.25 for enrichment and from $3.00 a report, but a platform access fee has no published amount and plans run for at least 12 months. The pricing page is not linked from the home page and may be out of date, so half marks (10 of 20). The sandbox is free and self-serve with no card mentioned. There is no free live tier (10 of 20). A person registers in the dashboard and live access goes through sales (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 48,
            "points": 4.2,
            "reason": "The newest changelog entry, Sep '26 Basiq Product Updates, read 9 days old on 9 October 2026, which puts it at about 30 September (30). Two changelog entries fall in the last 90 days, September and July, so the line for three is not met (0). A public changelog, support by email, chat and a service desk, and an issues link on the docs repository. Reply times were not sampled (9 of 15). No official SDK. The OpenAPI files are kept in a tagged repository (3 of 15). The docs repository runs lint, link-check and release workflows and merged dependency updates on 1 October 2026 (6 of 10)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 72,
            "points": 6.3,
            "note": "editorial 61, provenance 83",
            "reason": "A closed service with public Terms of Service that name Basiq Pty Ltd (15). The privacy policy, the CDR Policy and a complaints policy are public, and the CDR Policy says data is destroyed or de-identified within seconds of a consent ending. The privacy policy says collected content may be retained indefinitely after an account ends, which does not agree with the docs security page, and no DPA was found (17 of 30). The OpenAPI page says breaking changes come with major versions, a migration checklist covers version 3.0 and legacy endpoints are labelled. The ANZ New Zealand end-of-support notice carries no date and no notice period is stated (8 of 20). Storage in AWS Sydney and Melbourne, outsourced service providers in New Zealand and Serbia by name, and representatives allowed to store data in New Zealand and the United Kingdom are disclosed (16 of 20). Regulatory standing counts as an addition, as on other bank-data listings. The footer gives ACCC accreditation ADRBNK000208 (+5)."
          }
        ],
        "assessment": {
          "date": "2026-10-09",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "Transactions take `limit` up to 500 and a `filter` on seven fields. No field selection or summary mode was found (15 of 25). List calls page with `links.next` and Insights lists hold at most 20 a page (17 of 20). Errors return a `correlationId`, a string `code`, `title`, `detail` and a `source` pointer, and failed job steps carry the bank's own message (17 of 20). No idempotency keys were found, so a repeated `POST /users` creates a second billable user. Reads are safe to repeat, and the five MCP tools set `readOnlyHint` and `destructiveHint` (8 of 20). Every call needs the `basiq-version` header and a token exchange with a non-standard Basic header, and no official SDK is published (5 of 15).",
            "maintenance": "The newest changelog entry, Sep '26 Basiq Product Updates, read 9 days old on 9 October 2026, which puts it at about 30 September (30). Two changelog entries fall in the last 90 days, September and July, so the line for three is not met (0). A public changelog, support by email, chat and a service desk, and an issues link on the docs repository. Reply times were not sampled (9 of 15). No official SDK. The OpenAPI files are kept in a tagged repository (3 of 15). The docs repository runs lint, link-check and release workflows and merged dependency updates on 1 October 2026 (6 of 10).",
            "payments": "No x402, MPP or L402 (0). Unit prices are public, $0.50 per user per month for data, $0.25 for enrichment and from $3.00 a report, but a platform access fee has no published amount and plans run for at least 12 months. The pricing page is not linked from the home page and may be out of date, so half marks (10 of 20). The sandbox is free and self-serve with no card mentioned. There is no free live tier (10 of 20). A person registers in the dashboard and live access goes through sales (0).",
            "reliability": "Graded on the REST API with the hosted lines. Statuspage at status.basiq.io with components for the APIs, dashboard, documentation, website and connectors, and a history feed whose 25 entries reach back to October 2024 (20). No incident was posted in the 90 days to 9 October 2026. The newest entries are from April 2026, when NAB began blocking the web connector, and that connector still shows a partial outage, which is the bank's doing (25 of 30). Numbers are published for some parts, 1,500 token requests per 5 minutes, 1,000 reports a day and 20 refreshes a day on an Open Banking connection, while the general limits are described without figures (10 of 15). A 429 with code `too-many-requests` is documented with the advice to retry after the limit resets. No `Retry-After` header, backoff timings or idempotency keys were found (5 of 15). No SLA was found, and the Terms of Service say Basiq does not warrant uninterrupted service (0). Version 3.0 is generally available (10).",
            "schema": "Ten OpenAPI 3.0 files are public in the `basiqio-oss/Basiq-docs` repository and embedded in each reference page, 73 operations in all (25). llms.txt indexes the docs, reference and changelog, and each page has a Markdown twin (10). Every operation has a description except the nine webhook operations. Descriptions state the purpose and some say when a call applies, such as purge working only on active connections (14 of 20). Schemas use enums and required fields, with 167 enums in the Connect file, but `filter` is a free-form expression string and the token `scope` is an untyped string (10 of 15). Request and response examples are dense, and an error codes page lists codes by HTTP status (13 of 15). The version is pinned with the `basiq-version` header, the docs repository is tagged (v3.0.8 on 16 July 2026) and the changelog has ten entries for 2026, dated by month (12 of 15).",
            "security": "API keys are named, many to an application, revocable in the dashboard and limited to chosen endpoints by permission sets, with a 90-day rotation guide and 60-minute bearer tokens (27 of 30). The `CLIENT_ACCESS` token travels in the query string of the Consent UI address, and the MCP page says headers can be passed as query parameters, so the checklist's 10 comes off (17 of 30). The service reads bank data and cannot move money, consent scopes are set per data type and MCP route groups can be switched off. Deleting a user or connection has no confirmation step, and web connectors mean Basiq stores bank logins, encrypted with AES-256 per connection (16 of 20). Responses carry bank-written transaction descriptions and no guidance on treating them as untrusted was found (7 of 15). `GET /events` and the webhook message log record activity. No per-request audit log was found in the docs (8 of 15). No security.txt, disclosure policy or bug bounty was found. A 2020 information security policy aims at ISO/IEC 27001:2013, the certifications named in the docs belong to the AWS data centres, and the accreditation logos on the data security page carry no text (7 of 20).",
            "transparency": "A closed service with public Terms of Service that name Basiq Pty Ltd (15). The privacy policy, the CDR Policy and a complaints policy are public, and the CDR Policy says data is destroyed or de-identified within seconds of a consent ending. The privacy policy says collected content may be retained indefinitely after an account ends, which does not agree with the docs security page, and no DPA was found (17 of 30). The OpenAPI page says breaking changes come with major versions, a migration checklist covers version 3.0 and legacy endpoints are labelled. The ANZ New Zealand end-of-support notice carries no date and no notice period is stated (8 of 20). Storage in AWS Sydney and Melbourne, outsourced service providers in New Zealand and Serbia by name, and representatives allowed to store data in New Zealand and the United Kingdom are disclosed (16 of 20). Regulatory standing counts as an addition, as on other bank-data listings. The footer gives ACCC accreditation ADRBNK000208 (+5)."
          },
          "sources": [
            {
              "what": "docs index for agents",
              "url": "https://api.basiq.io/llms.txt",
              "seen": "2026-10-09"
            },
            {
              "what": "quickstart and authentication",
              "url": "https://api.basiq.io/docs/quickstart-api.md",
              "seen": "2026-10-09"
            },
            {
              "what": "rate limits",
              "url": "https://api.basiq.io/docs/api-rate-limiting.md",
              "seen": "2026-10-09"
            },
            {
              "what": "error codes",
              "url": "https://api.basiq.io/docs/codes.md",
              "seen": "2026-10-09"
            },
            {
              "what": "API key management",
              "url": "https://api.basiq.io/docs/api-key-management.md",
              "seen": "2026-10-09"
            },
            {
              "what": "permission sets",
              "url": "https://api.basiq.io/docs/permission-sets.md",
              "seen": "2026-10-09"
            },
            {
              "what": "security page in the docs",
              "url": "https://api.basiq.io/docs/security.md",
              "seen": "2026-10-09"
            },
            {
              "what": "MCP server reference",
              "url": "https://api.basiq.io/reference/mcp-server.md",
              "seen": "2026-10-09"
            },
            {
              "what": "MCP server, initialize and tools/list without a credential",
              "url": "https://api.basiq.io/mcp",
              "seen": "2026-10-09"
            },
            {
              "what": "OpenAPI page",
              "url": "https://api.basiq.io/reference/openapi.md",
              "seen": "2026-10-09"
            },
            {
              "what": "OpenAPI files, read from a shallow clone of the v3.0 branch and not from the rendered pages",
              "url": "https://github.com/basiqio-oss/Basiq-docs",
              "seen": "2026-10-09"
            },
            {
              "what": "sandbox and test data",
              "url": "https://api.basiq.io/reference/testing.md",
              "seen": "2026-10-09"
            },
            {
              "what": "changelog",
              "url": "https://api.basiq.io/changelog",
              "seen": "2026-10-09"
            },
            {
              "what": "status page",
              "url": "https://status.basiq.io",
              "seen": "2026-10-09"
            },
            {
              "what": "status history feed",
              "url": "https://status.basiq.io/history.atom",
              "seen": "2026-10-09"
            },
            {
              "what": "pricing",
              "url": "https://www.basiq.io/pricing.html",
              "seen": "2026-10-09"
            },
            {
              "what": "Terms of Service",
              "url": "https://docs.basiq.io/en/articles/415750-basiq-terms-of-service",
              "seen": "2026-10-09"
            },
            {
              "what": "Privacy Policy",
              "url": "https://docs.basiq.io/en/articles/382581-basiq-privacy-policy",
              "seen": "2026-10-09"
            },
            {
              "what": "Consumer Data Right (CDR) Policy",
              "url": "https://docs.basiq.io/en/articles/5088017-consumer-data-right-cdr-policy",
              "seen": "2026-10-09"
            },
            {
              "what": "Information Security Policy",
              "url": "https://docs.basiq.io/en/articles/4668914-basiq-information-security-policy",
              "seen": "2026-10-09"
            },
            {
              "what": "data security page",
              "url": "https://www.basiq.io/data-security.html",
              "seen": "2026-10-09"
            },
            {
              "what": "home page and footer",
              "url": "https://www.basiq.io/home.html",
              "seen": "2026-10-09"
            },
            {
              "what": "security.txt (404)",
              "url": "https://www.basiq.io/.well-known/security.txt",
              "seen": "2026-10-09"
            },
            {
              "what": "domain registration",
              "url": "https://rdap.identitydigital.services/rdap/domain/basiq.io",
              "seen": "2026-10-09"
            }
          ],
          "openQuestions": [
            "The pricing page was reached by its address and is not linked from the home, product or about pages we read, so its figures may be out of date. It carries a 2026 footer.",
            "unchecked: the amount of the platform access fee and the currency of the listed prices. The Terms of Service say amounts are in Australian dollars",
            "unchecked: whether Basiq itself holds ISO 27001 or SOC 2. The accreditation logos on the data security page are images with no text, and Cuscal's site was not read",
            "unchecked: the changelog entries for May 2026 (CDR Insights API Updates) and March 2026, whose Markdown pages answered HTTP 500",
            "unchecked: exact dates of changelog entries. The page shows relative ages, so the last release date is derived from 9 days ago on 9 October 2026",
            "unchecked: the dashboard, which needs a login, so the request log, key permissions screen and MCP route switches are known from the docs alone",
            "unchecked: uptime percentages on the status page, which are drawn by script, and the status API, which robots.txt disallows",
            "unchecked: GitHub stars and issue reply times on the docs repository",
            "The MCP docs list seven tools and the server returned five to an unauthenticated client. Whether `fetch` and `search` appear with a credential or a paid docs plan was not established",
            "Which Consumer Data Right access model a new customer needs for live Open Banking data (representative, affiliate or own accreditation) was not read in detail",
            "One request to au-api.basiq.io for robots.txt returned the API's 403 JSON error, so the host has no robots file. No other request was sent to it",
            "Two addresses were tried without a link, www.basiq.io/pricing.html (200) and www.basiq.io/sitemap.xml (404)",
            "No clause on automated access, scraping or benchmarking was found in the Terms of Service"
          ]
        },
        "negative": 0,
        "verdict": "Ten public OpenAPI files, an llms.txt index with Markdown twins and a free self-serve sandbox let an agent start on test data. Live access needs a 12-month plan with an unpublished platform access fee, no SLA or security.txt was found, and the privacy policy says collected content may be kept indefinitely.",
        "bestFor": "Consented bank data for Australia and New Zealand, with income and affordability reports for lenders.",
        "strengths": [
          "Ten OpenAPI 3.0 files are public in the `basiqio-oss/Basiq-docs` repository, 73 operations in all, and every reference page has a Markdown twin listed in llms.txt",
          "The sandbox is free and self-serve from the dashboard, with a test bank named Hooli and an Open Banking flow that covers authorise, extend, refresh and revoke",
          "API keys are created, named and revoked in the dashboard, permission sets limit a key to chosen endpoints, and access tokens expire after 60 minutes",
          "The CDR Policy names the outsourced service providers and says data is stored in AWS data centres in Sydney and Melbourne",
          "Error bodies carry a `correlationId`, a string `code`, a `title`, a `detail` and a `source` pointer, with the codes listed by HTTP status in the docs"
        ],
        "weaknesses": [
          "Live data needs a plan with a 12-month minimum and a platform access fee whose amount is not published",
          "No SLA was found, and the Terms of Service say Basiq does not warrant uninterrupted service",
          "The privacy policy says collected content may be retained indefinitely after an account ends, while the docs security page says data is deleted at once",
          "No security.txt, disclosure policy or bug bounty was found, and the accreditation logos on the data security page carry no text",
          "No idempotency keys or `Retry-After` header are documented, and no official SDK is published. The docs say to generate one from the OpenAPI files"
        ],
        "agentNotes": [
          "Send the API key verbatim after `Basic` in the `Authorization` header of `POST /token`. Base64-encoding it returns a 400.",
          "Send `basiq-version: 3.0` on the token request, cache the bearer token for its 60 minutes, and stay under 1,500 token requests per 5 minutes.",
          "Send the account holder through the hosted Consent UI in a browser with a `CLIENT_ACCESS` token bound to their `userId`. The API alone cannot create a first connection on version 3.0.",
          "Poll `GET /jobs/{jobId}` until `verify-credentials`, `retrieve-accounts` and `retrieve-transactions` all read `success` before reading accounts or transactions.",
          "Follow `links.next` on `GET /users/{userId}/transactions`. A page holds at most 500 items, and pending transactions get new ids on each refresh."
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 60.4
          }
        ],
        "editorialScores": {
          "ergonomics": 62,
          "maintenance": 48,
          "payments": 20,
          "reliability": 70,
          "schema": 84,
          "security": 55,
          "transparency": 61
        },
        "provenanceScore": 83
      },
      "connect": {
        "http": "curl --location --request POST 'https://au-api.basiq.io/token' \\\n  --header 'Authorization: Basic $YOUR_API_KEY' \\\n  --header 'Content-Type: application/x-www-form-urlencoded' \\\n  --header 'basiq-version: 3.0' \\\n  --data-urlencode 'scope=SERVER_ACCESS'",
        "config": {
          "mcpServers": {
            "basiq": {
              "url": "https://api.basiq.io/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/bank.accounts",
        "tool": "https://letme.dev/basiq"
      },
      "notable": [
        "Basiq Pty Ltd is a wholly owned subsidiary of Cuscal Limited and an accredited data recipient under the Consumer Data Right, accreditation ADRBNK000208, per the site footer (https://www.basiq.io/home.html)",
        "A hosted MCP server at https://api.basiq.io/mcp was added in May 2026. It answered an unauthenticated `tools/list` on 9 October 2026 with five tools, among them `execute-request`, which sends a HAR request to the API (https://api.basiq.io/reference/mcp-server)",
        "The MCP docs page lists seven built-in tools, including `fetch` and `search`. The server returned five to an unauthenticated client (https://api.basiq.io/reference/mcp-server)",
        "Version 3.0 requires the hosted Consent UI for every connection. The `CLIENT_ACCESS` token travels in the query string of `https://consent.basiq.io/home?token=` (https://api.basiq.io/docs/quickstart-api)",
        "Three access methods sit behind one API. Open Banking under the Consumer Data Right, web connectors that log in with the holder's bank credentials, and statement upload as PDF or CSV (https://api.basiq.io/docs/access-method)",
        "The status page shows the NAB web connector in partial outage. NAB began blocking web scraping in April 2026 and Basiq advises moving to Open Banking (https://status.basiq.io/history)",
        "Basiq ended support for its ANZ New Zealand connector in 2026. The connector stays selectable and failures are not investigated (https://api.basiq.io/changelog/anz-new-zealand-nz00101-end-of-support)",
        "The home and pricing pages say 135+ institutions, and the Data product page says over 170 (https://www.basiq.io/products/data.html)",
        "The Terms of Service, dated 27 August 2025, give at least 7 days' notice of changes and say user data is stored in Australia. No clause on automated access or benchmarking was found (https://docs.basiq.io/en/articles/415750-basiq-terms-of-service)"
      ],
      "area": "domain-data",
      "details": [
        {
          "label": "API",
          "value": "REST over HTTPS at https://au-api.basiq.io, version 3.0 selected with the `basiq-version` header. Ten OpenAPI files list 73 operations"
        },
        {
          "label": "Authentication",
          "value": "API key exchanged at `POST /token` for a bearer token that lasts 60 minutes. Scope `SERVER_ACCESS` for servers, `CLIENT_ACCESS` bound to a `userId` for the Consent UI"
        },
        {
          "label": "Data endpoints",
          "value": "`/users/{userId}/accounts`, `/users/{userId}/transactions`, `/users/{userId}/identities`, `/users/{userId}/connections`, `/connectors`, `/jobs/{jobId}`"
        },
        {
          "label": "Consent",
          "value": "Hosted Consent UI at consent.basiq.io, required on version 3.0. `GET /users/{userId}/consents` lists consents and `DELETE /users/{userId}/consents/{consentId}` removes one. The CDR Policy says data is destroyed or de-identified within seconds of withdrawal"
        },
        {
          "label": "Transactions",
          "value": "`limit` up to 500 a page, `links.next` for the next page, `filter` on connection, account, post date, status, institution, direction and class"
        },
        {
          "label": "Async",
          "value": "Connections, refreshes, reports and statement uploads return a job. `GET /users/{userId}/jobs` returns jobs less than 7 days old"
        },
        {
          "label": "Rate limits",
          "value": "1,500 token requests per 5 minutes. Reports and affordability summaries capped at the lesser of users created that day or 1,000 a day. Open Banking connections refresh at most 20 times a day. General limits are not published"
        },
        {
          "label": "Insights and reports",
          "value": "Enrich for merchant and category, CDR Insights for income, balance, account, identity and expense ratio checks, and consumer and business affordability reports kept for 24 hours"
        },
        {
          "label": "Sandbox",
          "value": "Free from the dashboard, 500 connections, test bank Hooli (AU00000) with published test logins. Enrich is limited to 100 requests a month in sandbox"
        },
        {
          "label": "Webhooks",
          "value": "Signed with HMAC-SHA256 in `webhook-signature`, with `webhook-id` and `webhook-timestamp`. Eight delivery attempts over about 27 hours"
        },
        {
          "label": "Coverage",
          "value": "Australia and New Zealand. Basiq says 135+ institutions on the home page and over 170 on the Data page"
        },
        {
          "label": "MCP server",
          "value": "https://api.basiq.io/mcp, streamable HTTP. Tools seen without a credential are `list-endpoints`, `get-endpoint`, `search-endpoints`, `list-specs` and `execute-request`. Route groups are switched on or off in the dashboard"
        },
        {
          "label": "AI resources",
          "value": "llms.txt with an index per section, a Markdown twin of each docs and reference page, and the OpenAPI files on GitHub"
        },
        {
          "label": "Data location",
          "value": "AWS data centres in Sydney and Melbourne, per the CDR Policy. Support staff of Basiq.io D.O.O. in Serbia and AuthSignal Ltd in New Zealand are named as outsourced service providers"
        },
        {
          "label": "SDKs",
          "value": "None published. The docs point to generating a JavaScript or TypeScript client from the OpenAPI files"
        },
        {
          "label": "Support",
          "value": "support@basiq.io, in-app chat and a Jira service desk"
        }
      ],
      "provenance": {
        "legalEntity": "Basiq Pty Ltd",
        "domain": "basiq.io",
        "domainRegistered": "2015-10-08",
        "endpointOnVendorDomain": true,
        "terms": "https://docs.basiq.io/en/articles/415750-basiq-terms-of-service",
        "privacy": "https://docs.basiq.io/en/articles/382581-basiq-privacy-policy",
        "statusPage": "https://status.basiq.io",
        "changelog": "https://api.basiq.io/changelog",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The site footer names Basiq Pty Ltd, ABN 95 616 592 011, a wholly owned but non-guaranteed subsidiary of Cuscal Limited, ABN 95 087 822 455, and gives the Consumer Data Right accreditation number ADRBNK000208.",
          "The terms link is the Basiq Terms of Service, dated 27 August 2025 on the help centre, which govern the platform, SDK and APIs and carry the SDK licence as Schedule 1.",
          "The privacy link is the Basiq Privacy Policy, dated 4 November 2025. A separate Consumer Data Right (CDR) Policy, dated 8 September 2026, covers data received under that regime.",
          "The API answers at au-api.basiq.io, the docs and MCP server at api.basiq.io, the Consent UI at consent.basiq.io and the dashboard at dashboard.basiq.io, all under basiq.io.",
          "www.basiq.io/.well-known/security.txt returns 404, and www.basiq.io has no robots.txt.",
          "status.basiq.io runs on Atlassian Statuspage. Its robots.txt disallows `/api/`, so the record was read from the page and the Atom feed it links.",
          "The registry's RDAP record gives 2015-10-08 as the registration date of basiq.io and Name.com, Inc. as registrar. The privacy policy gives PO Box Q279, Queen Victoria Building NSW 1230."
        ],
        "score": 83,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Basiq Pty Ltd",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "basiq.io, registered 2015-10-08 (11 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "au-api.basiq.io",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 5 of the 7 things a reader expects, and has 1 clause that costs points",
            "points": 6.3,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 4 of the 8 things a reader expects",
            "points": 7,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Status page",
            "value": "status.basiq.io",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://docs.basiq.io/en/articles/415750-basiq-terms-of-service",
            "state": "read",
            "readAt": "2026-10-09",
            "words": 8626,
            "points": 6.3,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": false
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "24.1 These Terms are governed by the laws of New South Wales and the Commonwealth of Australia.",
                "says": "The law of New South Wales"
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "11.11 In no event will Basiq or its licensors be liable for any consequential, incidental, indirect, special, punitive, or other damages whatsoever arising out of these Terms or the interruption to, use of or inability to use the Services, even if Basiq has been advised of the possibility of such damages.",
                "says": "Rules out indirect and consequential losses, with no cap named in this sentence"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "If you do not agree to these changes, you may terminate these Terms and you must cease to access and use the Services."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": true,
                "quote": "Any changes to the Terms will be effective upon the posting of the modified Terms on the Website.",
                "says": "Changes are posted, with no other notice named"
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "you will not make any representations or warranties regarding Basiq or the Services as supplied by Basiq without Basiq’s prior written consent;"
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": false
              }
            ],
            "toKnow": [
              {
                "key": "terms.benchmark",
                "label": "Restricts benchmarking or competitive use",
                "found": true,
                "quote": "create a Developer Product that substantially replicates the Services or any component therein including but not limited to the Platform;",
                "costsPoints": true
              },
              {
                "key": "terms.cutoff",
                "label": "Says access can be ended without notice or for any reason",
                "found": true,
                "quote": "If Basiq is not made within 14 days of the date of the Invoice, Basiq may at its discretion suspend or terminate your access to the Services without notice to you, in which case you will not be able to access or use the Services User Data or Aggregated Data and Basiq is not responsible for any interruption this may ca…"
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Basiq may use customer data stripped of personal identifiers to improve and develop its services and products, and says it will not sell or license that data.",
                "quote": "3.3 You agree that Basiq may use Aggregated Data to provide customer support and to improve and develop services and products. Basiq will not sell or license Aggregated Data."
              },
              {
                "date": "2026-10-08",
                "text": "Access to the customer's own User Data and continued use of the service depend on payment of the fees.",
                "quote": "However, your access to the User Data and/or Aggregated Data and your continued use of the Services is contingent on payment of the applicable Fees for the Services."
              },
              {
                "date": "2026-10-08",
                "text": "The customer is responsible for retrieving its data before termination.",
                "quote": "5.3 It is your responsibility to retrieve your data or replace the functionality supplied by the Services on your Developer Product prior to termination."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://docs.basiq.io/en/articles/382581-basiq-privacy-policy",
            "state": "read",
            "readAt": "2026-10-09",
            "words": 2416,
            "points": 7,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": false
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "This Privacy Policy will help you understand what Personal Information we collect and how this is managed."
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": false
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "We may continue to disclose such content to third parties in a manner that does not reveal Personal Information, as described in this Privacy Policy."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "Basiq does not sell or rent any personal information to marketers or third parties that have not been explicitly authorised (e.g., in the case of a client).",
                "says": "Says it does not sell personal data"
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": false
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "If you need more information, want to access or update your personal information or if you have a privacy concern, please contact us using the contact details below."
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": false
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Content submitted to the service or collected from a client application or a financial institution may be kept indefinitely, including after the account is terminated.",
                "quote": "All content submitted by you to the Service or collected on your behalf from a third-party (e.g., client) application or a financial institution (e.g., a bank) may be retained by us indefinitely, even after you terminate your account."
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/basiq.json",
      "live": {
        "slug": "basiq",
        "probe": {
          "target": "https://au-api.basiq.io",
          "method": "get",
          "lastAt": "2026-10-10T01:37:44.772316254Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 842,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 849,
          "p95ms24h": 941,
          "samples24h": 102,
          "samples30d": 102,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 85,
              "ok": 85
            },
            {
              "date": "2026-10-10",
              "probes": 17,
              "ok": 17
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.basiq.io",
          "indicator": "minor",
          "summary": "Minor Service Outage",
          "checkedAt": "2026-10-10T01:33:22.347990381Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "basiqio-oss/Basiq-docs",
            "version": "v3.0.8",
            "released": "2026-07-16",
            "seenAt": "2026-10-09T16:42:41.939603853Z"
          }
        ],
        "githubStars": 5,
        "pages": [
          {
            "url": "https://api.basiq.io/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:32:31.512737613Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "7ea5161f947f"
          },
          {
            "url": "https://www.basiq.io/pricing.html",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-09T18:48:29.43933836Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "1c9866bc1634"
          },
          {
            "url": "https://docs.basiq.io/en/articles/382581-basiq-privacy-policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-09T18:36:36.227093441Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "af5c5eabea79"
          },
          {
            "url": "https://docs.basiq.io/en/articles/415750-basiq-terms-of-service",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-09T18:36:38.602578211Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "2bce9aa59c11"
          }
        ],
        "updatedAt": "2026-10-10T01:37:44.772316254Z"
      }
    },
    "verify": {
      "accepts": "a page on basiq.io or one of its subdomains, or the README of github.com/basiqio-oss/Basiq-docs",
      "badgeUrl": "https://www.anchorterminal.com/badges/basiq.svg",
      "body": {
        "slug": "basiq",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/basiq",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/basiq\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/basiq.svg\" alt=\"Basiq on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Basiq on Anchor Terminal](https://www.anchorterminal.com/badges/basiq.svg)](https://www.anchorterminal.com/tools/basiq)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/basiq\"\u003eBasiq on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/basiq",
    "json": "https://www.anchorterminal.com/tools/basiq.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/basiq.md",
    "slim": "https://www.anchorterminal.com/tools/basiq.min.md"
  },
  "markdown": "## Overview\n\n**Grade C · 60.4/100 · rank #515 of 950 · #6 in Bank data \u0026 open banking · not agent-ready · confidence medium**\n\n\n## Assessment\n\nTen public OpenAPI files, an llms.txt index with Markdown twins and a free self-serve sandbox let an agent start on test data. Live access needs a 12-month plan with an unpublished platform access fee, no SLA or security.txt was found, and the privacy policy says collected content may be kept indefinitely.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Basiq Pty Ltd (Cuscal Limited) (https://www.basiq.io) |\n| Kind | HTTP API |\n| Category | Bank data \u0026 open banking (https://www.anchorterminal.com/categories/banking-data) |\n| Transport | HTTP, Streamable HTTP |\n| Endpoint | `https://au-api.basiq.io` |\n| Auth | API key · A self-serve API key from the dashboard at dashboard.basiq.io, sent verbatim (not Base64-encoded) as `Authorization: Basic \u003ckey\u003e` to `POST /token` with a `basiq-version: 3.0` header. The call returns a bearer token that lasts 60 minutes. Scope `SERVER_ACCESS` covers server calls and `CLIENT_ACCESS`, bound to one `userId`, is for the hosted Consent UI. An application can hold many named keys, each revocable, and permission sets limit a key to chosen endpoints. The docs advise rotating keys every 90 days. Dashboard logins support 2FA by text message and SAML single sign-on on request. Live Open Banking data is switched on by Basiq's customer success team after a contract. The MCP server at api.basiq.io/mcp listed its tools with no credential, and its `execute-request` tool takes API credentials as headers set in the MCP client. |\n| Pricing | Paid (Paid) · $0.50 per user per month for customer data plus a platform access fee with no published amount, $0.25 per user per month for enrichment and from $3.00 per affordability report (https://www.basiq.io/pricing.html, checked 2026-10-09). The home page does not link that page, so the figures may be out of date. The page does not state the currency, and the Terms of Service say all amounts are in Australian dollars. A user is billable for the full month once created. Plans run for at least 12 months and volume discounts go through sales. The sandbox is free and self-serve from the dashboard, with no card mentioned, so an agent's owner can start on test data without a contract. The pricing page is not linked from the site pages we read. |\n| x402 | No · No x402, MPP or L402 in the docs index, the ten OpenAPI files or the pricing page (checked 2026-10-09). |\n| Licence | Proprietary service under the Basiq Terms of Service. The public docs repository carries no licence file, and the OpenAPI files state the licence as Commercial |\n| Source | https://github.com/basiqio-oss/Basiq-docs |\n| Docs | https://api.basiq.io/docs |\n| llms.txt | https://api.basiq.io/llms.txt |\n| Last release | 2026-09-30 |\n| API | REST over HTTPS at https://au-api.basiq.io, version 3.0 selected with the `basiq-version` header. Ten OpenAPI files list 73 operations |\n| Authentication | API key exchanged at `POST /token` for a bearer token that lasts 60 minutes. Scope `SERVER_ACCESS` for servers, `CLIENT_ACCESS` bound to a `userId` for the Consent UI |\n| Data endpoints | `/users/{userId}/accounts`, `/users/{userId}/transactions`, `/users/{userId}/identities`, `/users/{userId}/connections`, `/connectors`, `/jobs/{jobId}` |\n| Consent | Hosted Consent UI at consent.basiq.io, required on version 3.0. `GET /users/{userId}/consents` lists consents and `DELETE /users/{userId}/consents/{consentId}` removes one. The CDR Policy says data is destroyed or de-identified within seconds of withdrawal |\n| Transactions | `limit` up to 500 a page, `links.next` for the next page, `filter` on connection, account, post date, status, institution, direction and class |\n| Async | Connections, refreshes, reports and statement uploads return a job. `GET /users/{userId}/jobs` returns jobs less than 7 days old |\n| Rate limits | 1,500 token requests per 5 minutes. Reports and affordability summaries capped at the lesser of users created that day or 1,000 a day. Open Banking connections refresh at most 20 times a day. General limits are not published |\n| Insights and reports | Enrich for merchant and category, CDR Insights for income, balance, account, identity and expense ratio checks, and consumer and business affordability reports kept for 24 hours |\n| Sandbox | Free from the dashboard, 500 connections, test bank Hooli (AU00000) with published test logins. Enrich is limited to 100 requests a month in sandbox |\n| Webhooks | Signed with HMAC-SHA256 in `webhook-signature`, with `webhook-id` and `webhook-timestamp`. Eight delivery attempts over about 27 hours |\n| Coverage | Australia and New Zealand. Basiq says 135+ institutions on the home page and over 170 on the Data page |\n| MCP server | https://api.basiq.io/mcp, streamable HTTP. Tools seen without a credential are `list-endpoints`, `get-endpoint`, `search-endpoints`, `list-specs` and `execute-request`. Route groups are switched on or off in the dashboard |\n| AI resources | llms.txt with an index per section, a Markdown twin of each docs and reference page, and the OpenAPI files on GitHub |\n| Data location | AWS data centres in Sydney and Melbourne, per the CDR Policy. Support staff of Basiq.io D.O.O. in Serbia and AuthSignal Ltd in New Zealand are named as outsourced service providers |\n| SDKs | None published. The docs point to generating a JavaScript or TypeScript client from the OpenAPI files |\n| Support | support@basiq.io, in-app chat and a Jira service desk |\n| Capabilities | bank.accounts, bank.transactions, bank.identity, bank.consent |\n| Tags | hosted, api-key, openapi, llms-txt, mcp, webhooks, sandbox, australia, new-zealand, status-page, closed-source |\n| JSON | https://www.anchorterminal.com/api/v1/tools/basiq.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-09 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 70 | 14.0 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 84 | 13.7 |\n| Agent ergonomics | 13% | 16.2 | 62 | 10.1 |\n| Security \u0026 auth | 14% | 17.5 | 55 | 9.6 |\n| Payments \u0026 pricing | 10% | 12.5 | 20 | 2.5 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 48 | 4.2 |\n| Transparency \u0026 trust (editorial 61, provenance 83) | 7% | 8.8 | 72 | 6.3 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **60.4 → C** |\n\n### Why each score\n\n- Reliability 70: Graded on the REST API with the hosted lines. Statuspage at status.basiq.io with components for the APIs, dashboard, documentation, website and connectors, and a history feed whose 25 entries reach back to October 2024 (20). No incident was posted in the 90 days to 9 October 2026. The newest entries are from April 2026, when NAB began blocking the web connector, and that connector still shows a partial outage, which is the bank's doing (25 of 30). Numbers are published for some parts, 1,500 token requests per 5 minutes, 1,000 reports a day and 20 refreshes a day on an Open Banking connection, while the general limits are described without figures (10 of 15). A 429 with code `too-many-requests` is documented with the advice to retry after the limit resets. No `Retry-After` header, backoff timings or idempotency keys were found (5 of 15). No SLA was found, and the Terms of Service say Basiq does not warrant uninterrupted service (0). Version 3.0 is generally available (10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 84: Ten OpenAPI 3.0 files are public in the `basiqio-oss/Basiq-docs` repository and embedded in each reference page, 73 operations in all (25). llms.txt indexes the docs, reference and changelog, and each page has a Markdown twin (10). Every operation has a description except the nine webhook operations. Descriptions state the purpose and some say when a call applies, such as purge working only on active connections (14 of 20). Schemas use enums and required fields, with 167 enums in the Connect file, but `filter` is a free-form expression string and the token `scope` is an untyped string (10 of 15). Request and response examples are dense, and an error codes page lists codes by HTTP status (13 of 15). The version is pinned with the `basiq-version` header, the docs repository is tagged (v3.0.8 on 16 July 2026) and the changelog has ten entries for 2026, dated by month (12 of 15).\n- Agent ergonomics 62: Transactions take `limit` up to 500 and a `filter` on seven fields. No field selection or summary mode was found (15 of 25). List calls page with `links.next` and Insights lists hold at most 20 a page (17 of 20). Errors return a `correlationId`, a string `code`, `title`, `detail` and a `source` pointer, and failed job steps carry the bank's own message (17 of 20). No idempotency keys were found, so a repeated `POST /users` creates a second billable user. Reads are safe to repeat, and the five MCP tools set `readOnlyHint` and `destructiveHint` (8 of 20). Every call needs the `basiq-version` header and a token exchange with a non-standard Basic header, and no official SDK is published (5 of 15).\n- Security \u0026 auth 55: API keys are named, many to an application, revocable in the dashboard and limited to chosen endpoints by permission sets, with a 90-day rotation guide and 60-minute bearer tokens (27 of 30). The `CLIENT_ACCESS` token travels in the query string of the Consent UI address, and the MCP page says headers can be passed as query parameters, so the checklist's 10 comes off (17 of 30). The service reads bank data and cannot move money, consent scopes are set per data type and MCP route groups can be switched off. Deleting a user or connection has no confirmation step, and web connectors mean Basiq stores bank logins, encrypted with AES-256 per connection (16 of 20). Responses carry bank-written transaction descriptions and no guidance on treating them as untrusted was found (7 of 15). `GET /events` and the webhook message log record activity. No per-request audit log was found in the docs (8 of 15). No security.txt, disclosure policy or bug bounty was found. A 2020 information security policy aims at ISO/IEC 27001:2013, the certifications named in the docs belong to the AWS data centres, and the accreditation logos on the data security page carry no text (7 of 20).\n- Payments \u0026 pricing 20: No x402, MPP or L402 (0). Unit prices are public, $0.50 per user per month for data, $0.25 for enrichment and from $3.00 a report, but a platform access fee has no published amount and plans run for at least 12 months. The pricing page is not linked from the home page and may be out of date, so half marks (10 of 20). The sandbox is free and self-serve with no card mentioned. There is no free live tier (10 of 20). A person registers in the dashboard and live access goes through sales (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 48: The newest changelog entry, Sep '26 Basiq Product Updates, read 9 days old on 9 October 2026, which puts it at about 30 September (30). Two changelog entries fall in the last 90 days, September and July, so the line for three is not met (0). A public changelog, support by email, chat and a service desk, and an issues link on the docs repository. Reply times were not sampled (9 of 15). No official SDK. The OpenAPI files are kept in a tagged repository (3 of 15). The docs repository runs lint, link-check and release workflows and merged dependency updates on 1 October 2026 (6 of 10).\n- Transparency \u0026 trust 72: A closed service with public Terms of Service that name Basiq Pty Ltd (15). The privacy policy, the CDR Policy and a complaints policy are public, and the CDR Policy says data is destroyed or de-identified within seconds of a consent ending. The privacy policy says collected content may be retained indefinitely after an account ends, which does not agree with the docs security page, and no DPA was found (17 of 30). The OpenAPI page says breaking changes come with major versions, a migration checklist covers version 3.0 and legacy endpoints are labelled. The ANZ New Zealand end-of-support notice carries no date and no notice period is stated (8 of 20). Storage in AWS Sydney and Melbourne, outsourced service providers in New Zealand and Serbia by name, and representatives allowed to store data in New Zealand and the United Kingdom are disclosed (16 of 20). Regulatory standing counts as an addition, as on other bank-data listings. The footer gives ACCC accreditation ADRBNK000208 (+5).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (23 items): https://www.anchorterminal.com/fixes/basiq.md (JSON https://www.anchorterminal.com/fixes/basiq.json)\n\n### What we couldn't check\n\n- The pricing page was reached by its address and is not linked from the home, product or about pages we read, so its figures may be out of date. It carries a 2026 footer.\n- unchecked: the amount of the platform access fee and the currency of the listed prices. The Terms of Service say amounts are in Australian dollars\n- unchecked: whether Basiq itself holds ISO 27001 or SOC 2. The accreditation logos on the data security page are images with no text, and Cuscal's site was not read\n- unchecked: the changelog entries for May 2026 (CDR Insights API Updates) and March 2026, whose Markdown pages answered HTTP 500\n- unchecked: exact dates of changelog entries. The page shows relative ages, so the last release date is derived from 9 days ago on 9 October 2026\n- unchecked: the dashboard, which needs a login, so the request log, key permissions screen and MCP route switches are known from the docs alone\n- unchecked: uptime percentages on the status page, which are drawn by script, and the status API, which robots.txt disallows\n- unchecked: GitHub stars and issue reply times on the docs repository\n- The MCP docs list seven tools and the server returned five to an unauthenticated client. Whether `fetch` and `search` appear with a credential or a paid docs plan was not established\n- Which Consumer Data Right access model a new customer needs for live Open Banking data (representative, affiliate or own accreditation) was not read in detail\n- One request to au-api.basiq.io for robots.txt returned the API's 403 JSON error, so the host has no robots file. No other request was sent to it\n- Two addresses were tried without a link, www.basiq.io/pricing.html (200) and www.basiq.io/sitemap.xml (404)\n- No clause on automated access, scraping or benchmarking was found in the Terms of Service\n\n### Sources\n\n- docs index for agents: \u003chttps://api.basiq.io/llms.txt\u003e (seen 2026-10-09)\n- quickstart and authentication: \u003chttps://api.basiq.io/docs/quickstart-api.md\u003e (seen 2026-10-09)\n- rate limits: \u003chttps://api.basiq.io/docs/api-rate-limiting.md\u003e (seen 2026-10-09)\n- error codes: \u003chttps://api.basiq.io/docs/codes.md\u003e (seen 2026-10-09)\n- API key management: \u003chttps://api.basiq.io/docs/api-key-management.md\u003e (seen 2026-10-09)\n- permission sets: \u003chttps://api.basiq.io/docs/permission-sets.md\u003e (seen 2026-10-09)\n- security page in the docs: \u003chttps://api.basiq.io/docs/security.md\u003e (seen 2026-10-09)\n- MCP server reference: \u003chttps://api.basiq.io/reference/mcp-server.md\u003e (seen 2026-10-09)\n- MCP server, initialize and tools/list without a credential: \u003chttps://api.basiq.io/mcp\u003e (seen 2026-10-09)\n- OpenAPI page: \u003chttps://api.basiq.io/reference/openapi.md\u003e (seen 2026-10-09)\n- OpenAPI files, read from a shallow clone of the v3.0 branch and not from the rendered pages: \u003chttps://github.com/basiqio-oss/Basiq-docs\u003e (seen 2026-10-09)\n- sandbox and test data: \u003chttps://api.basiq.io/reference/testing.md\u003e (seen 2026-10-09)\n- changelog: \u003chttps://api.basiq.io/changelog\u003e (seen 2026-10-09)\n- status page: \u003chttps://status.basiq.io\u003e (seen 2026-10-09)\n- status history feed: \u003chttps://status.basiq.io/history.atom\u003e (seen 2026-10-09)\n- pricing: \u003chttps://www.basiq.io/pricing.html\u003e (seen 2026-10-09)\n- Terms of Service: \u003chttps://docs.basiq.io/en/articles/415750-basiq-terms-of-service\u003e (seen 2026-10-09)\n- Privacy Policy: \u003chttps://docs.basiq.io/en/articles/382581-basiq-privacy-policy\u003e (seen 2026-10-09)\n- Consumer Data Right (CDR) Policy: \u003chttps://docs.basiq.io/en/articles/5088017-consumer-data-right-cdr-policy\u003e (seen 2026-10-09)\n- Information Security Policy: \u003chttps://docs.basiq.io/en/articles/4668914-basiq-information-security-policy\u003e (seen 2026-10-09)\n- data security page: \u003chttps://www.basiq.io/data-security.html\u003e (seen 2026-10-09)\n- home page and footer: \u003chttps://www.basiq.io/home.html\u003e (seen 2026-10-09)\n- security.txt (404): \u003chttps://www.basiq.io/.well-known/security.txt\u003e (seen 2026-10-09)\n- domain registration: \u003chttps://rdap.identitydigital.services/rdap/domain/basiq.io\u003e (seen 2026-10-09)\n\n## Who's behind it (provenance 83/100, checked 2026-10-09)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Basiq Pty Ltd | 20/20 |\n| Domain age | basiq.io, registered 2015-10-08 (11 years) | 15/15 |\n| Endpoint on the vendor's domain | au-api.basiq.io | 15/15 |\n| Terms of service | read, states 5 of the 7 things a reader expects, and has 1 clause that costs points | 6.3/10 |\n| Privacy policy | read, states 4 of the 8 things a reader expects | 7/10 |\n| Status page | status.basiq.io | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | not found | 0/10 |\n\nThe site footer names Basiq Pty Ltd, ABN 95 616 592 011, a wholly owned but non-guaranteed subsidiary of Cuscal Limited, ABN 95 087 822 455, and gives the Consumer Data Right accreditation number ADRBNK000208.\n\nThe terms link is the Basiq Terms of Service, dated 27 August 2025 on the help centre, which govern the platform, SDK and APIs and carry the SDK licence as Schedule 1.\n\nThe privacy link is the Basiq Privacy Policy, dated 4 November 2025. A separate Consumer Data Right (CDR) Policy, dated 8 September 2026, covers data received under that regime.\n\nThe API answers at au-api.basiq.io, the docs and MCP server at api.basiq.io, the Consent UI at consent.basiq.io and the dashboard at dashboard.basiq.io, all under basiq.io.\n\nwww.basiq.io/.well-known/security.txt returns 404, and www.basiq.io has no robots.txt.\n\nstatus.basiq.io runs on Atlassian Statuspage. Its robots.txt disallows `/api/`, so the record was read from the page and the Atom feed it links.\n\nThe registry's RDAP record gives 2015-10-08 as the registration date of basiq.io and Name.com, Inc. as registrar. The privacy policy gives PO Box Q279, Queen Victoria Building NSW 1230.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://docs.basiq.io/en/articles/415750-basiq-terms-of-service), read 2026-10-09, gives no date, states 5 of the 7 things a reader expects.\n\n- To know. Restricts benchmarking or competitive use (costs points). \"create a Developer Product that substantially replicates the Services or any component therein including but not limited to the Platform;\"\n- To know. Says access can be ended without notice or for any reason. \"If Basiq is not made within 14 days of the date of the Invoice, Basiq may at its discretion suspend or terminate your access to the Services without notice to you, in which case you will not be able to access or use the Services User Data or Aggregated Data and Basiq is not responsible for any interruption this may ca…\"\n- Not found in the text. Gives the date it was last updated.\n- Names the governing law or courts. The law of New South Wales.\n- States a limit on its liability. Rules out indirect and consequential losses, with no cap named in this sentence.\n- Says how changes to the terms are announced. Changes are posted, with no other notice named.\n- Not found in the text. Refers to a service level or uptime commitment.\n- Also in the text (2026-10-08). Basiq may use customer data stripped of personal identifiers to improve and develop its services and products, and says it will not sell or license that data. \"3.3 You agree that Basiq may use Aggregated Data to provide customer support and to improve and develop services and products. Basiq will not sell or license Aggregated Data.\"\n- Also in the text (2026-10-08). Access to the customer's own User Data and continued use of the service depend on payment of the fees. \"However, your access to the User Data and/or Aggregated Data and your continued use of the Services is contingent on payment of the applicable Fees for the Services.\"\n- Also in the text (2026-10-08). The customer is responsible for retrieving its data before termination. \"5.3 It is your responsibility to retrieve your data or replace the functionality supplied by the Services on your Developer Product prior to termination.\"\n\n**Privacy policy** (https://docs.basiq.io/en/articles/382581-basiq-privacy-policy), read 2026-10-09, gives no date, states 4 of the 8 things a reader expects.\n\n- Not found in the text. Gives the date it was last updated.\n- Not found in the text. Says how long data is kept.\n- Says whether personal data is sold or shared for advertising. Says it does not sell personal data.\n- Not found in the text. Says what rights people have over their data.\n- Not found in the text. Says where data is transferred or stored.\n- Also in the text (2026-10-08). Content submitted to the service or collected from a client application or a financial institution may be kept indefinitely, including after the account is terminated. \"All content submitted by you to the Service or collected on your behalf from a third-party (e.g., client) application or a financial institution (e.g., a bank) may be retained by us indefinitely, even after you terminate your account.\"\n\n## Live (updated 2026-10-10 01:37 UTC)\n\n- Right now: up, HTTP 200, 842 ms, checked 2026-10-10 01:37 UTC (get on `https://au-api.basiq.io`)\n- Uptime 24h 100.0% (102 probes) · 30 days 100.0% (102 probes) · p50 849 ms · p95 941 ms\n- Vendor status page: minor, Minor Service Outage\n- github `basiqio-oss/Basiq-docs` v3.0.8, released 2026-07-16\n- Watching changelog \u003chttps://api.basiq.io/changelog\u003e\n- Watching pricing \u003chttps://www.basiq.io/pricing.html\u003e\n- Watching privacy \u003chttps://docs.basiq.io/en/articles/382581-basiq-privacy-policy\u003e\n- Watching terms \u003chttps://docs.basiq.io/en/articles/415750-basiq-terms-of-service\u003e\n- Always current: https://www.anchorterminal.com/api/v1/live/basiq.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Strengths\n\n- Ten OpenAPI 3.0 files are public in the `basiqio-oss/Basiq-docs` repository, 73 operations in all, and every reference page has a Markdown twin listed in llms.txt\n- The sandbox is free and self-serve from the dashboard, with a test bank named Hooli and an Open Banking flow that covers authorise, extend, refresh and revoke\n- API keys are created, named and revoked in the dashboard, permission sets limit a key to chosen endpoints, and access tokens expire after 60 minutes\n- The CDR Policy names the outsourced service providers and says data is stored in AWS data centres in Sydney and Melbourne\n- Error bodies carry a `correlationId`, a string `code`, a `title`, a `detail` and a `source` pointer, with the codes listed by HTTP status in the docs\n\n## Weaknesses\n\n- Live data needs a plan with a 12-month minimum and a platform access fee whose amount is not published\n- No SLA was found, and the Terms of Service say Basiq does not warrant uninterrupted service\n- The privacy policy says collected content may be retained indefinitely after an account ends, while the docs security page says data is deleted at once\n- No security.txt, disclosure policy or bug bounty was found, and the accreditation logos on the data security page carry no text\n- No idempotency keys or `Retry-After` header are documented, and no official SDK is published. The docs say to generate one from the OpenAPI files\n\n## Before you call it (notes for agents)\n\n1. Send the API key verbatim after `Basic` in the `Authorization` header of `POST /token`. Base64-encoding it returns a 400.\n2. Send `basiq-version: 3.0` on the token request, cache the bearer token for its 60 minutes, and stay under 1,500 token requests per 5 minutes.\n3. Send the account holder through the hosted Consent UI in a browser with a `CLIENT_ACCESS` token bound to their `userId`. The API alone cannot create a first connection on version 3.0.\n4. Poll `GET /jobs/{jobId}` until `verify-credentials`, `retrieve-accounts` and `retrieve-transactions` all read `success` before reading accounts or transactions.\n5. Follow `links.next` on `GET /users/{userId}/transactions`. A page holds at most 500 items, and pending transactions get new ids on each refresh.\n\n## Connect\n\nFirst request:\n\n```bash\ncurl --location --request POST 'https://au-api.basiq.io/token' \\\n  --header 'Authorization: Basic $YOUR_API_KEY' \\\n  --header 'Content-Type: application/x-www-form-urlencoded' \\\n  --header 'basiq-version: 3.0' \\\n  --data-urlencode 'scope=SERVER_ACCESS'\n```\n\nMCP client configuration:\n\n```json\n{\n  \"mcpServers\": {\n    \"basiq\": {\n      \"url\": \"https://api.basiq.io/mcp\"\n    }\n  }\n}\n```\n\nThrough letme (picks today, calling later): https://letme.dev/basiq. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Plaid | B | 69.8 | 169 | bank.accounts, bank.transactions, bank.identity, bank.consent | no | https://www.anchorterminal.com/tools/plaid.md |\n| Belvo | B | 63.5 | 391 | bank.accounts, bank.transactions, bank.identity, bank.consent | no | https://www.anchorterminal.com/tools/belvo.md |\n| MX Platform API | B | 62.5 | 430 | bank.accounts, bank.transactions, bank.identity, bank.consent | no | https://www.anchorterminal.com/tools/mx.md |\n| Tink | B | 62.5 | 431 | bank.accounts, bank.transactions, bank.consent, bank.identity | no | https://www.anchorterminal.com/tools/tink.md |\n| TrueLayer | B | 62.1 | 443 | bank.accounts, bank.transactions, bank.identity, bank.consent | no | https://www.anchorterminal.com/tools/truelayer.md |\n| Yapily | C | 57.6 | 603 | bank.accounts, bank.transactions, bank.identity, bank.consent | no | https://www.anchorterminal.com/tools/yapily.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- Basiq Pty Ltd is a wholly owned subsidiary of Cuscal Limited and an accredited data recipient under the Consumer Data Right, accreditation ADRBNK000208, per the site footer (source: \u003chttps://www.basiq.io/home.html\u003e)\n- A hosted MCP server at https://api.basiq.io/mcp was added in May 2026. It answered an unauthenticated `tools/list` on 9 October 2026 with five tools, among them `execute-request`, which sends a HAR request to the API (source: \u003chttps://api.basiq.io/reference/mcp-server\u003e)\n- The MCP docs page lists seven built-in tools, including `fetch` and `search`. The server returned five to an unauthenticated client (source: \u003chttps://api.basiq.io/reference/mcp-server\u003e)\n- Version 3.0 requires the hosted Consent UI for every connection. The `CLIENT_ACCESS` token travels in the query string of `https://consent.basiq.io/home?token=` (source: \u003chttps://api.basiq.io/docs/quickstart-api\u003e)\n- Three access methods sit behind one API. Open Banking under the Consumer Data Right, web connectors that log in with the holder's bank credentials, and statement upload as PDF or CSV (source: \u003chttps://api.basiq.io/docs/access-method\u003e)\n- The status page shows the NAB web connector in partial outage. NAB began blocking web scraping in April 2026 and Basiq advises moving to Open Banking (source: \u003chttps://status.basiq.io/history\u003e)\n- Basiq ended support for its ANZ New Zealand connector in 2026. The connector stays selectable and failures are not investigated (source: \u003chttps://api.basiq.io/changelog/anz-new-zealand-nz00101-end-of-support\u003e)\n- The home and pricing pages say 135+ institutions, and the Data product page says over 170 (source: \u003chttps://www.basiq.io/products/data.html\u003e)\n- The Terms of Service, dated 27 August 2025, give at least 7 days' notice of changes and say user data is stored in Australia. No clause on automated access or benchmarking was found (source: \u003chttps://docs.basiq.io/en/articles/415750-basiq-terms-of-service\u003e)\n\n- #6 of 15 in Best open banking and bank data APIs for AI agents: https://www.anchorterminal.com/best/banking-data/index.md\n- All 105 bank data comparisons: https://www.anchorterminal.com/compare/banking-data/index.md\n\n## Compare\n\n- [Akoya vs Basiq](https://www.anchorterminal.com/compare/akoya-vs-basiq.md): D 48.3 vs C 60.4\n- [Basiq vs Belvo](https://www.anchorterminal.com/compare/basiq-vs-belvo.md): C 60.4 vs B 63.5\n- [Basiq vs Enable Banking](https://www.anchorterminal.com/compare/basiq-vs-enable-banking.md): C 60.4 vs D 47.1\n- [Basiq vs Flinks](https://www.anchorterminal.com/compare/basiq-vs-flinks.md): C 60.4 vs D 52.7\n- [Basiq vs GoCardless Bank Account Data](https://www.anchorterminal.com/compare/basiq-vs-gocardless-bank-account-data.md): C 60.4 vs E 41.7\n- [Basiq vs MX Platform API](https://www.anchorterminal.com/compare/basiq-vs-mx.md): C 60.4 vs B 62.5\n- [Basiq vs Plaid](https://www.anchorterminal.com/compare/basiq-vs-plaid.md): C 60.4 vs B 69.8\n- [Basiq vs Powens](https://www.anchorterminal.com/compare/basiq-vs-powens.md): C 60.4 vs E 42.6\n- [Basiq vs Salt Edge Account Information](https://www.anchorterminal.com/compare/basiq-vs-salt-edge.md): C 60.4 vs D 46.7\n- [Basiq vs Teller](https://www.anchorterminal.com/compare/basiq-vs-teller.md): C 60.4 vs E 42.7\n- [Basiq vs Tink](https://www.anchorterminal.com/compare/basiq-vs-tink.md): C 60.4 vs B 62.5\n- [Basiq vs TrueLayer](https://www.anchorterminal.com/compare/basiq-vs-truelayer.md): C 60.4 vs B 62.1\n- [Basiq vs Yapily](https://www.anchorterminal.com/compare/basiq-vs-yapily.md): C 60.4 vs C 57.6\n- [Basiq vs Yodlee Core API](https://www.anchorterminal.com/compare/basiq-vs-yodlee-financial-data.md): C 60.4 vs E 41.9\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on basiq.io or one of its subdomains, or the README of github.com/basiqio-oss/Basiq-docs. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"basiq\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/basiq\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/basiq.svg\" alt=\"Basiq on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Basiq on Anchor Terminal](https://www.anchorterminal.com/badges/basiq.svg)](https://www.anchorterminal.com/tools/basiq)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/basiq\"\u003eBasiq on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Basiq is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/basiq-dark.png\n- Light: https://www.anchorterminal.com/assets/share/basiq-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Bank data \u0026 open banking",
        "url": "https://www.anchorterminal.com/categories/banking-data"
      },
      {
        "name": "Basiq",
        "url": ""
      }
    ],
    "description": "Basiq is an Australian open banking platform owned by Cuscal Limited. Its REST API reads accounts, transactions and identity details from Australian and New Zealand institutions with the holder's consent, and builds income, expense and affordability reports.",
    "facts": [
      "rank #515 of 950",
      "API key auth",
      "0 desk reviews"
    ],
    "h1": "Basiq",
    "image": "https://www.anchorterminal.com/assets/og/tools-basiq.png",
    "path": "/tools/basiq",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Basiq review (2026): pricing, alternatives and grade C",
    "toc": null,
    "updated": "2026-10-10",
    "url": "https://www.anchorterminal.com/tools/basiq"
  },
  "tokens": {
    "markdown": 8500,
    "slim": 1930
  },
  "version": 1
}
