# Basiq (slim) > Basiq is an Australian open banking platform owned by Cuscal Limited. Its REST API reads accounts, transactions and identity details from Australian and New Zealand institutions with the holder's consent, and builds income, expense and affordability reports. - Full: https://www.anchorterminal.com/tools/basiq.md (~8,500 tokens) · this version ~1,930 tokens · JSON https://www.anchorterminal.com/tools/basiq.json · canonical https://www.anchorterminal.com/tools/basiq - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-10 **C · 60.4/100 · rank #515 of 950 · #6 in Bank data & open banking · not agent-ready · confidence medium** Assessment: Ten public OpenAPI files, an llms.txt index with Markdown twins and a free self-serve sandbox let an agent start on test data. Live access needs a 12-month plan with an unpublished platform access fee, no SLA or security.txt was found, and the privacy policy says collected content may be kept indefinitely. ## Facts - Kind: HTTP API · vendor: Basiq Pty Ltd (Cuscal Limited) · category: Bank data & open banking · legal entity: Basiq Pty Ltd · provenance 83/100 - Endpoint: `https://au-api.basiq.io` (HTTP, Streamable HTTP) - Auth: API key · pricing: Paid · x402: no · licence: Proprietary service under the Basiq Terms of Service. The public docs repository carries no licence file, and the OpenAPI files state the licence as Commercial - Probe metrics: not measured yet (probes haven't run) - API: REST over HTTPS at https://au-api.basiq.io, version 3.0 selected with the `basiq-version` header. Ten OpenAPI files list 73 operations - Authentication: API key exchanged at `POST /token` for a bearer token that lasts 60 minutes. Scope `SERVER_ACCESS` for servers, `CLIENT_ACCESS` bound to a `userId` for the Consent UI - Data endpoints: `/users/{userId}/accounts`, `/users/{userId}/transactions`, `/users/{userId}/identities`, `/users/{userId}/connections`, `/connectors`, `/jobs/{jobId}` - Consent: Hosted Consent UI at consent.basiq.io, required on version 3.0. `GET /users/{userId}/consents` lists consents and `DELETE /users/{userId}/consents/{consentId}` removes one. The CDR Policy says data is destroyed or de-identified within seconds of withdrawal - Transactions: `limit` up to 500 a page, `links.next` for the next page, `filter` on connection, account, post date, status, institution, direction and class - Async: Connections, refreshes, reports and statement uploads return a job. `GET /users/{userId}/jobs` returns jobs less than 7 days old - Rate limits: 1,500 token requests per 5 minutes. Reports and affordability summaries capped at the lesser of users created that day or 1,000 a day. Open Banking connections refresh at most 20 times a day. General limits are not published - Insights and reports: Enrich for merchant and category, CDR Insights for income, balance, account, identity and expense ratio checks, and consumer and business affordability reports kept for 24 hours - Sandbox: Free from the dashboard, 500 connections, test bank Hooli (AU00000) with published test logins. Enrich is limited to 100 requests a month in sandbox - Webhooks: Signed with HMAC-SHA256 in `webhook-signature`, with `webhook-id` and `webhook-timestamp`. Eight delivery attempts over about 27 hours - Coverage: Australia and New Zealand. Basiq says 135+ institutions on the home page and over 170 on the Data page - MCP server: https://api.basiq.io/mcp, streamable HTTP. Tools seen without a credential are `list-endpoints`, `get-endpoint`, `search-endpoints`, `list-specs` and `execute-request`. Route groups are switched on or off in the dashboard - AI resources: llms.txt with an index per section, a Markdown twin of each docs and reference page, and the OpenAPI files on GitHub - Data location: AWS data centres in Sydney and Melbourne, per the CDR Policy. Support staff of Basiq.io D.O.O. in Serbia and AuthSignal Ltd in New Zealand are named as outsourced service providers - SDKs: None published. The docs point to generating a JavaScript or TypeScript client from the OpenAPI files - Support: support@basiq.io, in-app chat and a Jira service desk - Scores: Reliability 70, Performance pending, Schema & documentation 84, Agent ergonomics 62, Security & auth 55, Payments & pricing 20, Task success pending, Maintenance & community 48, Transparency & trust 72 · total over the 7 assessed categories - Why: Reliability, Graded on the REST API with the hosted lines. · Schema & documentation, Ten OpenAPI 3.0 files are public in the `basiqio-oss/Basiq-docs` repository and embedded in each reference page, 73 operations in all (25). · Agent ergonomics, Transactions take `limit` up to 500 and a `filter` on seven fields. · Security & auth, API keys are named, many to an application, revocable in the dashboard and limited to chosen endpoints by permission sets, with a 90-day rot… · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, The newest changelog entry, Sep '26 Basiq Product Updates, read 9 days old on 9 October 2026, which puts it at about 30 September (30). · Transparency & trust, A closed service with public Terms of Service that name Basiq Pty Ltd (15). - Sources: 24, open questions: 13, both in the full twin - Capabilities: bank.accounts, bank.transactions, bank.identity, bank.consent - JSON: https://www.anchorterminal.com/api/v1/tools/basiq.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/basiq.svg` or a link to https://www.anchorterminal.com/tools/basiq from a page on basiq.io or one of its subdomains, or the README of github.com/basiqio-oss/Basiq-docs, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Send the API key verbatim after `Basic` in the `Authorization` header of `POST /token`. Base64-encoding it returns a 400. 2. Send `basiq-version: 3.0` on the token request, cache the bearer token for its 60 minutes, and stay under 1,500 token requests per 5 minutes. 3. Send the account holder through the hosted Consent UI in a browser with a `CLIENT_ACCESS` token bound to their `userId`. The API alone cannot create a first connection on version 3.0. 4. Poll `GET /jobs/{jobId}` until `verify-credentials`, `retrieve-accounts` and `retrieve-transactions` all read `success` before reading accounts or transactions. 5. Follow `links.next` on `GET /users/{userId}/transactions`. A page holds at most 500 items, and pending transactions get new ids on each refresh. ## Connect ```bash curl --location --request POST 'https://au-api.basiq.io/token' \ --header 'Authorization: Basic $YOUR_API_KEY' \ --header 'Content-Type: application/x-www-form-urlencoded' \ --header 'basiq-version: 3.0' \ --data-urlencode 'scope=SERVER_ACCESS' ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/basiq ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Plaid | B | 69.8 | bank.accounts, bank.transactions, bank.identity, bank.consent | https://www.anchorterminal.com/tools/plaid.min.md | | Belvo | B | 63.5 | bank.accounts, bank.transactions, bank.identity, bank.consent | https://www.anchorterminal.com/tools/belvo.min.md | | MX Platform API | B | 62.5 | bank.accounts, bank.transactions, bank.identity, bank.consent | https://www.anchorterminal.com/tools/mx.min.md | | Tink | B | 62.5 | bank.accounts, bank.transactions, bank.consent, bank.identity | https://www.anchorterminal.com/tools/tink.min.md | | TrueLayer | B | 62.1 | bank.accounts, bank.transactions, bank.identity, bank.consent | https://www.anchorterminal.com/tools/truelayer.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)