{
  "data": {
    "similar": [
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/plaid.json",
        "name": "Plaid",
        "score": 69.8,
        "shared": [
          "bank.accounts",
          "bank.transactions",
          "bank.identity",
          "bank.payments",
          "bank.consent"
        ],
        "slug": "plaid"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/tink.json",
        "name": "Tink",
        "score": 62.5,
        "shared": [
          "bank.accounts",
          "bank.transactions",
          "bank.consent",
          "bank.payments",
          "bank.identity"
        ],
        "slug": "tink"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/truelayer.json",
        "name": "TrueLayer",
        "score": 62.1,
        "shared": [
          "bank.accounts",
          "bank.transactions",
          "bank.identity",
          "bank.payments",
          "bank.consent"
        ],
        "slug": "truelayer"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/yapily.json",
        "name": "Yapily",
        "score": 57.6,
        "shared": [
          "bank.accounts",
          "bank.transactions",
          "bank.identity",
          "bank.payments",
          "bank.consent"
        ],
        "slug": "yapily"
      },
      {
        "grade": "D",
        "json": "https://www.anchorterminal.com/tools/flinks.json",
        "name": "Flinks",
        "score": 52.7,
        "shared": [
          "bank.accounts",
          "bank.transactions",
          "bank.identity",
          "bank.payments",
          "bank.consent"
        ],
        "slug": "flinks"
      },
      {
        "grade": "D",
        "json": "https://www.anchorterminal.com/tools/salt-edge.json",
        "name": "Salt Edge Account Information",
        "score": 46.7,
        "shared": [
          "bank.accounts",
          "bank.transactions",
          "bank.identity",
          "bank.payments",
          "bank.consent"
        ],
        "slug": "salt-edge"
      }
    ],
    "tool": {
      "slug": "belvo",
      "name": "Belvo",
      "vendor": "Belvo",
      "vendorUrl": "https://belvo.com",
      "kind": "http-api",
      "category": "banking-data",
      "summary": "Belvo is an open finance API for Latin America. It reads bank accounts, transactions and investments in Brazil, employment records in Brazil and Mexico and tax data in Mexico, and starts Pix payments in Brazil and direct debits in Mexico.",
      "url": "https://www.anchorterminal.com/tools/belvo",
      "markdownUrl": "https://www.anchorterminal.com/tools/belvo.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/belvo.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/belvo.json",
      "license": "Proprietary service under Belvo's General Conditions of Service Usage. The belvo npm package (0.28.0) is MIT",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.belvo.com",
      "packages": [
        {
          "registry": "npm",
          "name": "belvo"
        },
        {
          "registry": "pypi",
          "name": "belvo-python"
        }
      ],
      "auth": "api-key",
      "authNotes": "HTTP Basic with a `secretId` and `secretPassword` generated in the dashboard, one pair for each environment. The password is shown once and a lost one means resetting the keys. No scopes or read-only keys were found. Sandbox keys are self-serve after email sign-up. Production keys follow a request to Belvo, a sales meeting and a certification call. End users connect accounts in the Hosted Widget, started with a 10 minute token from POST /api/token/. The Direct Debit API in Mexico has its own keys and optional IP allowlisting set up by support.",
      "pricing": "paid",
      "pricingNotes": "The Launch plan is 1,000 USD a month and Growth is priced by sales, both through Contact Sales (https://belvo.com/plans-and-pricing/). No per-call or per-link price is published, and the terms put the price in a signed Service Order with a 12 month term. The sandbox is free, self-serve and for testing only, so an agent can start without a contract but can't reach real accounts. Changing the refresh rate of recurrent links is priced by sales.",
      "priceSummary": "$1000 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs, the OpenAPI file or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 1084,
        "pypiWeekly": 240,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developers.belvo.com/",
      "llmsTxt": "https://developers.belvo.com/llms.txt",
      "openapi": "https://developers.belvo.com/_bundle/apis/BelvoOpenApiSpec.yaml",
      "capabilities": [
        "bank.accounts",
        "bank.transactions",
        "bank.identity",
        "bank.payments",
        "bank.consent"
      ],
      "tags": [
        "hosted",
        "openapi",
        "llms-txt",
        "api-key",
        "webhooks",
        "sandbox",
        "brazil",
        "mexico",
        "latin-america",
        "sales-led",
        "status-page",
        "closed-source"
      ],
      "lastRelease": "2026-08-10",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 63.5,
        "grade": "B",
        "agentReady": false,
        "rank": 309,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 2,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 80,
          "maintenance": 30,
          "payments": 20,
          "reliability": 84,
          "schema": 80,
          "security": 57,
          "transparency": 64
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 84,
            "points": 16.8,
            "reason": "Graded on the hosted REST API. Statuspage at status.belvo.com with components for the API, Widget, Webhooks, Dashboard, Recurrent Links, the sandbox and payments (20). The incident feed lists nothing between 10 July and 8 October 2026. Its newest entry is a minor one on 1 June, after a critical incident of 2.7 hours on 19 May and a major one of 10.9 hours on 15 May, both outside the 90 days (30). Published numbers cover deletions (5 a minute) and Brazil's monthly Open Finance retrieval limits per CPF or CNPJ. The general limits behind the 429 response have no numbers (8 of 15). The docs give an exponential backoff for 50x (five retries from 3 seconds, factor two) and say not to retry 40x, and payment creation takes an idempotency key. No Retry-After was found (12 of 15). Annex I of the terms is a service level agreement with support response times of 24 hours by priority, but it has no availability figure and the terms say uninterrupted availability isn't guaranteed (4 of 10). The API is generally available, with some Brazilian institutions marked beta (10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 80,
            "points": 13,
            "reason": "Public OpenAPI 3.0.2 file, version 1.223.0, with 146 operations on 83 paths, and a second specification for Direct Debit Mexico (25). llms.txt with about 300 links to Markdown twins of the docs in three languages (10). Operations carry usage sections and notes on limits and asynchronous modes, though the choice between POST retrieval and GET list is explained in the guides (16 of 20). Query parameters are typed and filters are enumerated one by one. We didn't audit request bodies in full (12 of 15). 48 error articles give the JSON body, cause and solution for each code, and the reference documents 13 status codes (13 of 15). The specification has a version number but no changelog was found, and developers.belvo.com/changelog returns 404 (4 of 15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 80,
            "points": 13,
            "reason": "List endpoints accept `fields` and `omit` to size responses and `page_size` from the default 100 up to 1,000 (22 of 25). Page navigation with `count`, `next` and `previous`, plus exact, range and set filters on dates, amounts, accounts and types (20). Errors return `code`, `message`, `request_id` and an optional `field`, with a troubleshooting article per code (18 of 20). `Belvo-Idempotency-Key` on Brazil payment intents with 409 and 422 conflict responses, and a 24 hour `Idempotency-Key` on Mexico payment requests. Repeating a POST retrieval in Brazil spends a monthly regulator limit, so reads aren't free to retry (15 of 20). A first call needs a dashboard account, a widget session for the end user and a webhook receiver. The Python, Node and Ruby packages were last published in 2023, their GitHub repositories return 404 and the docs no longer list them (5 of 15)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 57,
            "points": 9.98,
            "reason": "One `secretId` and `secretPassword` pair per environment over HTTP Basic, resettable in the dashboard, with no scopes found (18 of 30). Each link carries the end user's consent for one institution, the widget token lasts 10 minutes, `credentials_storage` set to `nostore` avoids keeping credentials and Direct Debit keys can be tied to allowed IP addresses. No read-only key or approval step for payments was found (11 of 20). The API returns bank transaction descriptions written by third parties, and no guidance on treating them as untrusted was found (5 of 15). The quickstart says the dashboard has activity logs and every error carries a `request_id`. We couldn't see the dashboard (8 of 15). ISO/IEC 27001:2022 and PCI DSS Level 1 are stated on the security page with third-party penetration tests, and a PGP-signed security.txt points to a disclosure policy on Federacy, but it expired on 22 March 2025. The data webhooks carry a fixed optional authorisation header and no signature (15 of 20)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 20,
            "points": 2.5,
            "reason": "No x402, MPP or L402 (0). The Launch plan is published at 1,000 USD a month and Growth is custom. No per-call or per-link price is public (10 of 20). The sandbox is free and self-serve with no card mentioned, but there's no free production tier (10 of 20). A person signs up in a browser, and production needs a sales meeting and a certification call (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 30,
            "points": 2.63,
            "reason": "Closed service. The newest dated product change we found is the launch of the MCP servers, announced on 10 August 2026, 59 days before the check. The Developer MCP reports server version 2026-10-08 and the specification is at 1.223.0, neither with dated notes (20 of 30). No changelog, so no count of dated entries in 90 days (0 of 20). Support by email at support@belvo.com on the lower plans and a feedback widget in the docs. No public channel where answers can be seen (5 of 15). The belvo npm package (0.28.0, 21 June 2023), belvo-python (0.39.1, 21 August 2023) and the belvo gem (1.7.0, 21 June 2023) are stale and their repositories return 404. The Developer MCP is live (3 of 15). Package health couldn't be established without the repositories (2 of 10)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 64,
            "points": 5.6,
            "note": "editorial 46, provenance 81",
            "reason": "Closed service with public terms, the General Conditions of Service Usage last updated 10 January 2025. The old npm package is MIT (15 of 30). The terms promise deletion within 30 days of termination or request and point to the retention controls in the docs, which set `stale_in`, `credentials_storage` and `save_data`. There are separate privacy policies for end users and for clients. The client policy gives retention of up to 10 years for contract records. No data processing agreement was found on the pages read (20 of 30). Fields are marked deprecated in the specification with no removal dates or notice period, and the terms give 30 days' notice for price changes only (5 of 20). The security page names AWS as host. No subprocessor list or data location was found, and the trust centre at trust.belvo.com is drawn by script and wasn't read (6 of 20)."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "List endpoints accept `fields` and `omit` to size responses and `page_size` from the default 100 up to 1,000 (22 of 25). Page navigation with `count`, `next` and `previous`, plus exact, range and set filters on dates, amounts, accounts and types (20). Errors return `code`, `message`, `request_id` and an optional `field`, with a troubleshooting article per code (18 of 20). `Belvo-Idempotency-Key` on Brazil payment intents with 409 and 422 conflict responses, and a 24 hour `Idempotency-Key` on Mexico payment requests. Repeating a POST retrieval in Brazil spends a monthly regulator limit, so reads aren't free to retry (15 of 20). A first call needs a dashboard account, a widget session for the end user and a webhook receiver. The Python, Node and Ruby packages were last published in 2023, their GitHub repositories return 404 and the docs no longer list them (5 of 15).",
            "maintenance": "Closed service. The newest dated product change we found is the launch of the MCP servers, announced on 10 August 2026, 59 days before the check. The Developer MCP reports server version 2026-10-08 and the specification is at 1.223.0, neither with dated notes (20 of 30). No changelog, so no count of dated entries in 90 days (0 of 20). Support by email at support@belvo.com on the lower plans and a feedback widget in the docs. No public channel where answers can be seen (5 of 15). The belvo npm package (0.28.0, 21 June 2023), belvo-python (0.39.1, 21 August 2023) and the belvo gem (1.7.0, 21 June 2023) are stale and their repositories return 404. The Developer MCP is live (3 of 15). Package health couldn't be established without the repositories (2 of 10).",
            "payments": "No x402, MPP or L402 (0). The Launch plan is published at 1,000 USD a month and Growth is custom. No per-call or per-link price is public (10 of 20). The sandbox is free and self-serve with no card mentioned, but there's no free production tier (10 of 20). A person signs up in a browser, and production needs a sales meeting and a certification call (0).",
            "reliability": "Graded on the hosted REST API. Statuspage at status.belvo.com with components for the API, Widget, Webhooks, Dashboard, Recurrent Links, the sandbox and payments (20). The incident feed lists nothing between 10 July and 8 October 2026. Its newest entry is a minor one on 1 June, after a critical incident of 2.7 hours on 19 May and a major one of 10.9 hours on 15 May, both outside the 90 days (30). Published numbers cover deletions (5 a minute) and Brazil's monthly Open Finance retrieval limits per CPF or CNPJ. The general limits behind the 429 response have no numbers (8 of 15). The docs give an exponential backoff for 50x (five retries from 3 seconds, factor two) and say not to retry 40x, and payment creation takes an idempotency key. No Retry-After was found (12 of 15). Annex I of the terms is a service level agreement with support response times of 24 hours by priority, but it has no availability figure and the terms say uninterrupted availability isn't guaranteed (4 of 10). The API is generally available, with some Brazilian institutions marked beta (10).",
            "schema": "Public OpenAPI 3.0.2 file, version 1.223.0, with 146 operations on 83 paths, and a second specification for Direct Debit Mexico (25). llms.txt with about 300 links to Markdown twins of the docs in three languages (10). Operations carry usage sections and notes on limits and asynchronous modes, though the choice between POST retrieval and GET list is explained in the guides (16 of 20). Query parameters are typed and filters are enumerated one by one. We didn't audit request bodies in full (12 of 15). 48 error articles give the JSON body, cause and solution for each code, and the reference documents 13 status codes (13 of 15). The specification has a version number but no changelog was found, and developers.belvo.com/changelog returns 404 (4 of 15).",
            "security": "One `secretId` and `secretPassword` pair per environment over HTTP Basic, resettable in the dashboard, with no scopes found (18 of 30). Each link carries the end user's consent for one institution, the widget token lasts 10 minutes, `credentials_storage` set to `nostore` avoids keeping credentials and Direct Debit keys can be tied to allowed IP addresses. No read-only key or approval step for payments was found (11 of 20). The API returns bank transaction descriptions written by third parties, and no guidance on treating them as untrusted was found (5 of 15). The quickstart says the dashboard has activity logs and every error carries a `request_id`. We couldn't see the dashboard (8 of 15). ISO/IEC 27001:2022 and PCI DSS Level 1 are stated on the security page with third-party penetration tests, and a PGP-signed security.txt points to a disclosure policy on Federacy, but it expired on 22 March 2025. The data webhooks carry a fixed optional authorisation header and no signature (15 of 20).",
            "transparency": "Closed service with public terms, the General Conditions of Service Usage last updated 10 January 2025. The old npm package is MIT (15 of 30). The terms promise deletion within 30 days of termination or request and point to the retention controls in the docs, which set `stale_in`, `credentials_storage` and `save_data`. There are separate privacy policies for end users and for clients. The client policy gives retention of up to 10 years for contract records. No data processing agreement was found on the pages read (20 of 30). Fields are marked deprecated in the specification with no removal dates or notice period, and the terms give 30 days' notice for price changes only (5 of 20). The security page names AWS as host. No subprocessor list or data location was found, and the trust centre at trust.belvo.com is drawn by script and wasn't read (6 of 20)."
          },
          "sources": [
            {
              "what": "docs llms.txt",
              "url": "https://developers.belvo.com/llms.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "OpenAPI file, version 1.223.0",
              "url": "https://developers.belvo.com/_bundle/apis/BelvoOpenApiSpec.yaml",
              "seen": "2026-10-08"
            },
            {
              "what": "API reference introduction, environments and retry policy",
              "url": "https://developers.belvo.com/apis/belvoopenapispec.md",
              "seen": "2026-10-08"
            },
            {
              "what": "error reference",
              "url": "https://developers.belvo.com/developer_resources/resources-belvo-api-errors.md",
              "seen": "2026-10-08"
            },
            {
              "what": "pagination and filtering",
              "url": "https://developers.belvo.com/developer_resources/resources-pagination-and-filtering.md",
              "seen": "2026-10-08"
            },
            {
              "what": "sandbox",
              "url": "https://developers.belvo.com/developer_resources/resources-sandbox.md",
              "seen": "2026-10-08"
            },
            {
              "what": "Developer MCP docs, and tools/list on the server",
              "url": "https://developers.belvo.com/developer_resources/resources-mcp-server.md",
              "seen": "2026-10-08"
            },
            {
              "what": "Brazil Open Finance retrieval limits",
              "url": "https://developers.belvo.com/products/aggregation_brazil/aggregation-brazil-data-retrieval-limits.md",
              "seen": "2026-10-08"
            },
            {
              "what": "data retention controls",
              "url": "https://developers.belvo.com/security/security-data-retention-controls.md",
              "seen": "2026-10-08"
            },
            {
              "what": "docs security page (WAF and rate limiting)",
              "url": "https://developers.belvo.com/security/security-features.md",
              "seen": "2026-10-08"
            },
            {
              "what": "available institutions",
              "url": "https://developers.belvo.com/developer_resources/resources-available-institutions.md",
              "seen": "2026-10-08"
            },
            {
              "what": "Direct Debit idempotency and IP allowlisting",
              "url": "https://developers.belvo.com/products/payments_mexico/direct-debit-idempotency-and-whitelisting.md",
              "seen": "2026-10-08"
            },
            {
              "what": "aggregation webhooks",
              "url": "https://developers.belvo.com/developer_resources/resources-webhooks-aggregation.md",
              "seen": "2026-10-08"
            },
            {
              "what": "quickstart (account, keys, production access)",
              "url": "https://developers.belvo.com/products/aggregation_brazil/prerequisites-get-started-in-10-minutes.md",
              "seen": "2026-10-08"
            },
            {
              "what": "plans and pricing",
              "url": "https://belvo.com/plans-and-pricing/",
              "seen": "2026-10-08"
            },
            {
              "what": "General Conditions of Service Usage with SLA annex",
              "url": "https://belvo.com/terms-service/",
              "seen": "2026-10-08"
            },
            {
              "what": "privacy policy for end users",
              "url": "https://belvo.com/privacy-policy-end-users/",
              "seen": "2026-10-08"
            },
            {
              "what": "privacy policy for clients",
              "url": "https://belvo.com/privacy-policy-clients/",
              "seen": "2026-10-08"
            },
            {
              "what": "legal notice",
              "url": "https://belvo.com/legal-notice/",
              "seen": "2026-10-08"
            },
            {
              "what": "security page",
              "url": "https://belvo.com/security/",
              "seen": "2026-10-08"
            },
            {
              "what": "security.txt",
              "url": "https://belvo.com/.well-known/security.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "status incident feed",
              "url": "https://status.belvo.com/api/v2/incidents.json",
              "seen": "2026-10-08"
            },
            {
              "what": "status components",
              "url": "https://status.belvo.com/api/v2/components.json",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP servers page",
              "url": "https://belvo.com/resources/mcps/",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP launch post, 10 August 2026",
              "url": "https://belvo.com/blog/belvo-mcps-the-new-agentic-open-finance/",
              "seen": "2026-10-08"
            },
            {
              "what": "npm package belvo",
              "url": "https://registry.npmjs.org/belvo/latest",
              "seen": "2026-10-08"
            },
            {
              "what": "PyPI package belvo-python",
              "url": "https://pypi.org/pypi/belvo-python/json",
              "seen": "2026-10-08"
            },
            {
              "what": "RDAP for belvo.com",
              "url": "https://rdap.verisign.com/com/v1/domain/belvo.com",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "The batch lead says balances and transactions in Brazil and Mexico. The docs and the MCP page read on 8 October 2026 show bank data for Brazil only, with employment, fiscal and direct debit products in Mexico",
            "The lead lists SDKs. The Python, Node and Ruby packages were last published in 2023 and github.com/belvo-finance/belvo-python, belvo-js and belvo-ruby return 404. Only the iOS and Android SDKs for biometric Pix are in the current docs",
            "The clean 90 days on the status page may mean no incidents or no posting. The feed can't tell the two apart",
            "Whether Belvo Instituição de Pagamento Ltda. is authorised by Banco Central do Brasil, and under what number. We found the name and CNPJ in the terms but didn't check the regulator's register",
            "unchecked: the trust centre at trust.belvo.com, which is drawn by script, so the subprocessor list and audit reports weren't read",
            "unchecked: the dashboard's activity logs and whether more than one key pair can exist per environment",
            "unchecked: the Data Access MCP's URL, tools and credential model, which have no public docs",
            "unchecked: the separate institutions status page that the docs mention",
            "unchecked: GitHub organisation listing and stars, because the GitHub API rate limit was reached"
          ]
        },
        "negative": 0,
        "verdict": "Belvo publishes a 146-operation OpenAPI file, an llms.txt with a Markdown twin of each docs page, and list endpoints with field selection and pages of up to 1,000. Production access needs a sales meeting, a certification call and a paid plan from 1,000 USD a month, and no changelog or maintained SDK was found.",
        "bestFor": "Lenders and fintechs that need consented bank data in Brazil, employment or tax records in Mexico, or Pix and direct debit collection, and can sign a contract.",
        "strengths": [
          "Public OpenAPI 3.0.2 file, version 1.223.0, with 146 operations on 83 paths, and a separate specification for Direct Debit in Mexico",
          "llms.txt lists a Markdown twin of every docs page in English, Spanish and Portuguese",
          "List endpoints take `fields`, `omit`, `page_size` up to 1,000 and range filters on dates and amounts",
          "Retention is set per link and per call with `stale_in`, `credentials_storage` and `save_data`",
          "ISO/IEC 27001:2022 and PCI DSS Level 1 are stated on the security page"
        ],
        "weaknesses": [
          "Production keys follow a sales meeting, a certification call with a Belvo engineer and a paid plan from 1,000 USD a month",
          "One `secretId` and `secretPassword` pair per environment over HTTP Basic, with no scopes or read-only keys found",
          "No changelog was found, and the Python, Node and Ruby packages were last published in 2023 with their GitHub repositories returning 404",
          "Bank data covers Brazil only in the docs read on 8 October 2026, and Mexico has employment, fiscal and direct debit products",
          "security.txt expired on 22 March 2025",
          "General rate limits carry no published numbers, and the data webhooks have no signature, only an optional fixed authorisation header"
        ],
        "agentNotes": [
          "Send HTTP Basic with `secretId` as username and `secretPassword` as password to https://sandbox.belvo.com, and switch to https://api.belvo.com only with production keys",
          "Create links through the Hosted Widget with a token from POST /api/token/, which expires after 10 minutes",
          "Read stored data with GET list calls. Each POST retrieval in Brazil counts against monthly Open Finance limits, such as 8 a month per CPF for owners and accounts",
          "Retry 50x responses up to five times from a 3 second base with a factor of two, and don't retry 40x apart from `too_many_sessions`",
          "Send `Belvo-Idempotency-Key` with a UUID when creating a payment intent, and `X-Belvo-Request-Mode: async` on link deletion to avoid the limit of 5 deletions a minute"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 63.5
          }
        ],
        "editorialScores": {
          "ergonomics": 80,
          "maintenance": 30,
          "payments": 20,
          "reliability": 84,
          "schema": 80,
          "security": 57,
          "transparency": 46
        },
        "provenanceScore": 81
      },
      "connect": {
        "http": "curl -X GET https://sandbox.belvo.com/api/ \\\n  -H \"Authorization: Basic $(echo -n 'YOUR_SECRET_ID:YOUR_SECRET_PASSWORD' | base64)\"",
        "claudeCode": "claude mcp add --transport http belvo-docs https://developers.belvo.com/mcp",
        "config": {
          "mcpServers": {
            "belvo-docs": {
              "type": "http",
              "url": "https://developers.belvo.com/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/bank.accounts",
        "tool": "https://letme.dev/belvo"
      },
      "notable": [
        "The API reference is one OpenAPI 3.0.2 file, version 1.223.0, with 146 operations on 83 paths and HTTP Basic as its only security scheme (https://developers.belvo.com/_bundle/apis/BelvoOpenApiSpec.yaml)",
        "Bank data in the docs is Brazil only, through the regulated Open Finance network, with 54 institution rows across banking Brazil, employment Brazil, employment Mexico and fiscal Mexico (https://developers.belvo.com/developer_resources/resources-available-institutions.md)",
        "The Developer MCP at https://developers.belvo.com/mcp is public, needs no account and has six read-only documentation tools. It can't reach an account or make API calls (https://developers.belvo.com/developer_resources/resources-mcp-server.md)",
        "Belvo's site lists a Data Access MCP as live for Brazil and Mexico, switched on by its sales team and billed as standard API calls, and an Analytics MCP as coming soon. No public docs for either were found (https://belvo.com/resources/mcps/)",
        "Brazil's Open Finance network caps retrievals per CPF or CNPJ each month, for example 8 for owners, 8 for a 365-day transaction pull, 240 for a pull of under 6 days and 420 for balances (https://developers.belvo.com/products/aggregation_brazil/aggregation-brazil-data-retrieval-limits.md)",
        "The status feed's newest incident is 1 June 2026. May 2026 has three, among them a critical one on 19 May lasting 2.7 hours and a major one on 15 May lasting 10.9 hours (https://status.belvo.com/api/v2/incidents.json)",
        "The sandbox is wiped on the first day of every month and returns 10 results a page, against 100 in production (https://developers.belvo.com/developer_resources/resources-sandbox.md)"
      ],
      "area": "domain-data",
      "details": [
        {
          "label": "Base URLs",
          "value": "https://sandbox.belvo.com and https://api.belvo.com. Direct Debit Mexico has its own API, sandbox at https://api.sandbox.directdebit.belvo.com"
        },
        {
          "label": "Countries",
          "value": "Bank data in Brazil (Open Finance). Employment data in Brazil and Mexico. Fiscal data in Mexico, and Chile in the API reference. Pix payments in Brazil, direct debit in Mexico"
        },
        {
          "label": "Sandbox",
          "value": "Free and self-serve after email sign-up. Covers banking Brazil (run by an outside service), employment Mexico, fiscal Mexico and payments Mexico. Not available for payments Brazil or employment Brazil. Wiped on the 1st of each month"
        },
        {
          "label": "Production access",
          "value": "Requested from Belvo. A sales meeting, then a certification call with an engineer, then production keys"
        },
        {
          "label": "Consent",
          "value": "Hosted Widget with a 10 minute access token. Consents listed at GET /api/consents/. End users manage consents in the My Belvo Portal. DELETE /api/links/{id}/ removes a link and its data"
        },
        {
          "label": "Refresh",
          "value": "Recurrent links refresh every seven days by default, with a webhook when data is ready. Single links are read once"
        },
        {
          "label": "Rate limits",
          "value": "5 deletions a minute per endpoint. Brazil Open Finance monthly limits per CPF or CNPJ. Other limits are enforced with 429 but not published"
        },
        {
          "label": "Pagination",
          "value": "`page` and `page_size`, 100 by default and 1,000 at most, with `count`, `next` and `previous`. `fields` and `omit` select response fields"
        },
        {
          "label": "Errors",
          "value": "JSON array with `code`, `message`, `request_id` and an optional `field`. 48 error articles, each with cause and solution"
        },
        {
          "label": "Idempotency",
          "value": "`Belvo-Idempotency-Key` on Brazil payment intents. `Idempotency-Key` on Mexico direct debit payment requests, kept 24 hours"
        },
        {
          "label": "Retention",
          "value": "`stale_in` 1 to 365 days (365 by default), `credentials_storage` store, nostore or 1 to 365 days, `save_data` false to store nothing. The terms promise deletion within 30 days of termination or request"
        },
        {
          "label": "MCP servers",
          "value": "Developer MCP, public, six documentation tools. Data Access MCP, activated by sales. Analytics MCP, coming soon"
        },
        {
          "label": "Certifications",
          "value": "ISO/IEC 27001:2022 and PCI DSS Level 1 per belvo.com/security. Hosted on AWS"
        },
        {
          "label": "Status",
          "value": "status.belvo.com on Statuspage, with API, Widget, Webhooks, Dashboard, Recurrent Links, Sandbox Environment and payments components"
        }
      ],
      "unitPrices": [
        {
          "item": "Launch plan",
          "unit": "month",
          "usd": 1000,
          "note": "Production access, through sales. Growth plan is custom"
        }
      ],
      "provenance": {
        "legalEntity": "Belvo Tecnologias Ltda.",
        "domain": "belvo.com",
        "domainRegistered": "2005-07-17",
        "endpointOnVendorDomain": true,
        "terms": "https://belvo.com/terms-service/",
        "privacy": "https://belvo.com/privacy-policy-end-users/",
        "statusPage": "https://status.belvo.com",
        "changelog": "",
        "securityTxt": "expired",
        "checked": "2026-10-08",
        "notes": [
          "The General Conditions of Service Usage, last updated 10 January 2025, define Belvo as Belvo Tecnologias Ltda., CNPJ 37.869.837/0001-81, and Belvo Instituição de Pagamento Ltda., CNPJ 43.215.815/0001-09, with affiliates. They are governed by Brazilian law with the courts of São Paulo.",
          "The legal notice also names Belvo Technologies, SAPI de CV in Mexico City (RFC BTE1912023D6) and Belvo Technologies Inc. Sucursal en España in Barcelona.",
          "The privacy link is the end-user policy, which covers data Belvo processes through its platform for clients. A separate policy for clients and site visitors at https://belvo.com/privacy-policy-clients/ was last updated 15 July 2024.",
          "security.txt is PGP-signed, gives security@belvo.com and a disclosure policy on Federacy, and expired on 22 March 2025.",
          "No changelog was found. developers.belvo.com/changelog returns 404 and llms.txt lists none.",
          "Verisign RDAP gives a registration date of 2005-07-17 for belvo.com."
        ],
        "score": 81,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Belvo Tecnologias Ltda.",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "belvo.com, registered 2005-07-17 (21 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "api.belvo.com",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 7 of the 7 things a reader expects, and has 1 clause that costs points",
            "points": 8,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 5 of the 8 things a reader expects",
            "points": 7.8,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Status page",
            "value": "status.belvo.com",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          },
          {
            "check": "security.txt",
            "value": "published but past its Expires date",
            "points": 5,
            "max": 10,
            "state": "part"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://belvo.com/terms-service/",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2025-01-10",
            "words": 7952,
            "points": 8,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last Update on January 10th 2025:",
                "says": "Last updated 2025-01-10"
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "The contract is governed by the laws of the Federative Republic of Brazil.",
                "says": "The law of Federative Republic of Brazil"
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "Belvo will not be liable for any damages suffered by the Client, End Users and/or third parties resulting from the inappropriate use of the Service, nor for security incidents caused exclusively by the Client, as a result of misuse, malpractice or non-compliance with the instructions and Belvo documentation."
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "The Agreement will begin on the date of signature of the Service Order and will remain in force for 12 (twelve) months, unless terminated earlier by either Party, upon written notice at least 60 (sixty) days in advance."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": true,
                "quote": "Aiming at improving and improving the services provided, Belvo may, at any time, change the terms of the Agreement, its annexes and/or policies, without the need for prior notice or written agreement.",
                "says": "Says it gives notice of a change"
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "You will not translate, modify, decompile, decompose and/or reverse engineer the Services;"
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": true,
                "quote": "Service Level Agreement (“SLA”): level of service offered by Belvo to the Client regarding the service and support to users, as well as the maintenance and availability of the Platform;"
              }
            ],
            "toKnow": [
              {
                "key": "terms.nonotice",
                "label": "Says the terms or the service can change without notice",
                "found": true,
                "quote": "Aiming at improving and improving the services provided, Belvo may, at any time, change the terms of the Agreement, its annexes and/or policies, without the need for prior notice or written agreement.",
                "costsPoints": true
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Prices are corrected each year by the IPCA-IBGE index without an amendment or prior communication.",
                "quote": "Annually, prices will be corrected by the IPCA-IBGE, without the need for an amendment or prior communication."
              },
              {
                "date": "2026-10-08",
                "text": "Belvo is the sole owner of any machine learning that occurs within the services.",
                "quote": "Belvo is the sole holder and owner of any systemic learning (\"machine learning\") that occurs within the scope of the Services by means of artificial intelligence (or any other technology), without this implying any violation of the Client's intellectual property."
              },
              {
                "date": "2026-10-08",
                "text": "Belvo excludes liability for damages, including lost profits and financial losses, arising from the provision of the service.",
                "quote": "Belvo will not be liable for damages, including lost profits or financial losses, that may arise as a result of the provision of the Service, in relation to the Client, End Users and/or any third party."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://belvo.com/privacy-policy-end-users/",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2021-02-22",
            "words": 2061,
            "points": 7.8,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Date of last update: February 22, 2021",
                "says": "Last updated 2021-02-22"
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": false
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "Belvo will keep your personal data for the periods strictly necessary to comply with the instructions of the Client (our corporate clients) and, if applicable, until the period of prescription of the actions resulting from the legal relationship that gave rise to the processing of your data."
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "Digital service providers (Clients) who use Belvo technology to provide their services to End Users."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": false
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "In all legally appropriate cases, you may exercise your rights of access, rectification, cancellation and opposition in accordance with the Notice or Privacy Policy of the Client who treats your personal data as responsible for them."
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": false
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": true,
                "quote": "The collected data may be stored on our servers, as well as in an environment of resource usage or servers in the cloud (cloud computing), which may require a transfer and / or processing of this data outside the country in which it was collected."
              }
            ],
            "toKnow": [
              {
                "key": "old",
                "label": "Has not been updated for three years or more",
                "found": true,
                "quote": "Date of last update: February 22, 2021"
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "As a processor, Belvo does not handle requests from end users to exercise data rights and redirects them to the client.",
                "quote": "As a processor, Belvo does not process requests to exercise the rights of personal data subjects, since such requests must be met by those responsible for the personal data of End Users."
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/belvo.json",
      "live": {
        "slug": "belvo",
        "probe": {
          "target": "https://api.belvo.com",
          "method": "get",
          "lastAt": "2026-10-08T19:52:45.922404587Z",
          "lastOk": true,
          "lastStatus": 403,
          "lastMs": 66,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 46,
          "p95ms24h": 188,
          "samples24h": 27,
          "samples30d": 27,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 27,
              "ok": 27
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.belvo.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T19:50:26.2285697Z"
        },
        "pages": [
          {
            "url": "https://belvo.com/plans-and-pricing/",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:15:32.924207659Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "e45bde6abe6f"
          },
          {
            "url": "https://belvo.com/privacy-policy-end-users/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:15:35.22055183Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "44ff1673e0c9"
          },
          {
            "url": "https://belvo.com/terms-service/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:15:55.309282506Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "fc9af45fbdce"
          }
        ],
        "updatedAt": "2026-10-08T19:52:45.922404587Z"
      }
    },
    "verify": {
      "accepts": "a page on belvo.com or one of its subdomains",
      "badgeUrl": "https://www.anchorterminal.com/badges/belvo.svg",
      "body": {
        "slug": "belvo",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/belvo",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/belvo\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/belvo.svg\" alt=\"Belvo on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Belvo on Anchor Terminal](https://www.anchorterminal.com/badges/belvo.svg)](https://www.anchorterminal.com/tools/belvo)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/belvo\"\u003eBelvo on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/belvo",
    "json": "https://www.anchorterminal.com/tools/belvo.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/belvo.md",
    "slim": "https://www.anchorterminal.com/tools/belvo.min.md"
  },
  "markdown": "## Overview\n\n**Grade B · 63.5/100 · rank #309 of 722 · #2 in Bank data \u0026 open banking · not agent-ready · confidence medium**\n\n\n## Assessment\n\nBelvo publishes a 146-operation OpenAPI file, an llms.txt with a Markdown twin of each docs page, and list endpoints with field selection and pages of up to 1,000. Production access needs a sales meeting, a certification call and a paid plan from 1,000 USD a month, and no changelog or maintained SDK was found.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Belvo (https://belvo.com) |\n| Kind | HTTP API |\n| Category | Bank data \u0026 open banking (https://www.anchorterminal.com/categories/banking-data) |\n| Transport | HTTP |\n| Endpoint | `https://api.belvo.com` |\n| Auth | API key · HTTP Basic with a `secretId` and `secretPassword` generated in the dashboard, one pair for each environment. The password is shown once and a lost one means resetting the keys. No scopes or read-only keys were found. Sandbox keys are self-serve after email sign-up. Production keys follow a request to Belvo, a sales meeting and a certification call. End users connect accounts in the Hosted Widget, started with a 10 minute token from POST /api/token/. The Direct Debit API in Mexico has its own keys and optional IP allowlisting set up by support. |\n| Pricing | Paid ($1000 / mo) · The Launch plan is 1,000 USD a month and Growth is priced by sales, both through Contact Sales (https://belvo.com/plans-and-pricing/). No per-call or per-link price is published, and the terms put the price in a signed Service Order with a 12 month term. The sandbox is free, self-serve and for testing only, so an agent can start without a contract but can't reach real accounts. Changing the refresh rate of recurrent links is priced by sales. |\n| x402 | No · No x402, MPP or L402 in the developer docs, the OpenAPI file or the pricing page (checked 2026-10-08). |\n| Licence | Proprietary service under Belvo's General Conditions of Service Usage. The belvo npm package (0.28.0) is MIT |\n| Packages | npm: `belvo`; pypi: `belvo-python` |\n| Docs | https://developers.belvo.com/ |\n| llms.txt | https://developers.belvo.com/llms.txt |\n| Last release | 2026-08-10 |\n| npm downloads / week | 1,084 |\n| PyPI downloads / week | 240 |\n| Base URLs | https://sandbox.belvo.com and https://api.belvo.com. Direct Debit Mexico has its own API, sandbox at https://api.sandbox.directdebit.belvo.com |\n| Countries | Bank data in Brazil (Open Finance). Employment data in Brazil and Mexico. Fiscal data in Mexico, and Chile in the API reference. Pix payments in Brazil, direct debit in Mexico |\n| Sandbox | Free and self-serve after email sign-up. Covers banking Brazil (run by an outside service), employment Mexico, fiscal Mexico and payments Mexico. Not available for payments Brazil or employment Brazil. Wiped on the 1st of each month |\n| Production access | Requested from Belvo. A sales meeting, then a certification call with an engineer, then production keys |\n| Consent | Hosted Widget with a 10 minute access token. Consents listed at GET /api/consents/. End users manage consents in the My Belvo Portal. DELETE /api/links/{id}/ removes a link and its data |\n| Refresh | Recurrent links refresh every seven days by default, with a webhook when data is ready. Single links are read once |\n| Rate limits | 5 deletions a minute per endpoint. Brazil Open Finance monthly limits per CPF or CNPJ. Other limits are enforced with 429 but not published |\n| Pagination | `page` and `page_size`, 100 by default and 1,000 at most, with `count`, `next` and `previous`. `fields` and `omit` select response fields |\n| Errors | JSON array with `code`, `message`, `request_id` and an optional `field`. 48 error articles, each with cause and solution |\n| Idempotency | `Belvo-Idempotency-Key` on Brazil payment intents. `Idempotency-Key` on Mexico direct debit payment requests, kept 24 hours |\n| Retention | `stale_in` 1 to 365 days (365 by default), `credentials_storage` store, nostore or 1 to 365 days, `save_data` false to store nothing. The terms promise deletion within 30 days of termination or request |\n| MCP servers | Developer MCP, public, six documentation tools. Data Access MCP, activated by sales. Analytics MCP, coming soon |\n| Certifications | ISO/IEC 27001:2022 and PCI DSS Level 1 per belvo.com/security. Hosted on AWS |\n| Status | status.belvo.com on Statuspage, with API, Widget, Webhooks, Dashboard, Recurrent Links, Sandbox Environment and payments components |\n| Capabilities | bank.accounts, bank.transactions, bank.identity, bank.payments, bank.consent |\n| Tags | hosted, openapi, llms-txt, api-key, webhooks, sandbox, brazil, mexico, latin-america, sales-led, status-page, closed-source |\n| JSON | https://www.anchorterminal.com/api/v1/tools/belvo.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 84 | 16.8 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 80 | 13.0 |\n| Agent ergonomics | 13% | 16.2 | 80 | 13.0 |\n| Security \u0026 auth | 14% | 17.5 | 57 | 10.0 |\n| Payments \u0026 pricing | 10% | 12.5 | 20 | 2.5 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 30 | 2.6 |\n| Transparency \u0026 trust (editorial 46, provenance 81) | 7% | 8.8 | 64 | 5.6 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **63.5 → B** |\n\n### Why each score\n\n- Reliability 84: Graded on the hosted REST API. Statuspage at status.belvo.com with components for the API, Widget, Webhooks, Dashboard, Recurrent Links, the sandbox and payments (20). The incident feed lists nothing between 10 July and 8 October 2026. Its newest entry is a minor one on 1 June, after a critical incident of 2.7 hours on 19 May and a major one of 10.9 hours on 15 May, both outside the 90 days (30). Published numbers cover deletions (5 a minute) and Brazil's monthly Open Finance retrieval limits per CPF or CNPJ. The general limits behind the 429 response have no numbers (8 of 15). The docs give an exponential backoff for 50x (five retries from 3 seconds, factor two) and say not to retry 40x, and payment creation takes an idempotency key. No Retry-After was found (12 of 15). Annex I of the terms is a service level agreement with support response times of 24 hours by priority, but it has no availability figure and the terms say uninterrupted availability isn't guaranteed (4 of 10). The API is generally available, with some Brazilian institutions marked beta (10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 80: Public OpenAPI 3.0.2 file, version 1.223.0, with 146 operations on 83 paths, and a second specification for Direct Debit Mexico (25). llms.txt with about 300 links to Markdown twins of the docs in three languages (10). Operations carry usage sections and notes on limits and asynchronous modes, though the choice between POST retrieval and GET list is explained in the guides (16 of 20). Query parameters are typed and filters are enumerated one by one. We didn't audit request bodies in full (12 of 15). 48 error articles give the JSON body, cause and solution for each code, and the reference documents 13 status codes (13 of 15). The specification has a version number but no changelog was found, and developers.belvo.com/changelog returns 404 (4 of 15).\n- Agent ergonomics 80: List endpoints accept `fields` and `omit` to size responses and `page_size` from the default 100 up to 1,000 (22 of 25). Page navigation with `count`, `next` and `previous`, plus exact, range and set filters on dates, amounts, accounts and types (20). Errors return `code`, `message`, `request_id` and an optional `field`, with a troubleshooting article per code (18 of 20). `Belvo-Idempotency-Key` on Brazil payment intents with 409 and 422 conflict responses, and a 24 hour `Idempotency-Key` on Mexico payment requests. Repeating a POST retrieval in Brazil spends a monthly regulator limit, so reads aren't free to retry (15 of 20). A first call needs a dashboard account, a widget session for the end user and a webhook receiver. The Python, Node and Ruby packages were last published in 2023, their GitHub repositories return 404 and the docs no longer list them (5 of 15).\n- Security \u0026 auth 57: One `secretId` and `secretPassword` pair per environment over HTTP Basic, resettable in the dashboard, with no scopes found (18 of 30). Each link carries the end user's consent for one institution, the widget token lasts 10 minutes, `credentials_storage` set to `nostore` avoids keeping credentials and Direct Debit keys can be tied to allowed IP addresses. No read-only key or approval step for payments was found (11 of 20). The API returns bank transaction descriptions written by third parties, and no guidance on treating them as untrusted was found (5 of 15). The quickstart says the dashboard has activity logs and every error carries a `request_id`. We couldn't see the dashboard (8 of 15). ISO/IEC 27001:2022 and PCI DSS Level 1 are stated on the security page with third-party penetration tests, and a PGP-signed security.txt points to a disclosure policy on Federacy, but it expired on 22 March 2025. The data webhooks carry a fixed optional authorisation header and no signature (15 of 20).\n- Payments \u0026 pricing 20: No x402, MPP or L402 (0). The Launch plan is published at 1,000 USD a month and Growth is custom. No per-call or per-link price is public (10 of 20). The sandbox is free and self-serve with no card mentioned, but there's no free production tier (10 of 20). A person signs up in a browser, and production needs a sales meeting and a certification call (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 30: Closed service. The newest dated product change we found is the launch of the MCP servers, announced on 10 August 2026, 59 days before the check. The Developer MCP reports server version 2026-10-08 and the specification is at 1.223.0, neither with dated notes (20 of 30). No changelog, so no count of dated entries in 90 days (0 of 20). Support by email at support@belvo.com on the lower plans and a feedback widget in the docs. No public channel where answers can be seen (5 of 15). The belvo npm package (0.28.0, 21 June 2023), belvo-python (0.39.1, 21 August 2023) and the belvo gem (1.7.0, 21 June 2023) are stale and their repositories return 404. The Developer MCP is live (3 of 15). Package health couldn't be established without the repositories (2 of 10).\n- Transparency \u0026 trust 64: Closed service with public terms, the General Conditions of Service Usage last updated 10 January 2025. The old npm package is MIT (15 of 30). The terms promise deletion within 30 days of termination or request and point to the retention controls in the docs, which set `stale_in`, `credentials_storage` and `save_data`. There are separate privacy policies for end users and for clients. The client policy gives retention of up to 10 years for contract records. No data processing agreement was found on the pages read (20 of 30). Fields are marked deprecated in the specification with no removal dates or notice period, and the terms give 30 days' notice for price changes only (5 of 20). The security page names AWS as host. No subprocessor list or data location was found, and the trust centre at trust.belvo.com is drawn by script and wasn't read (6 of 20).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (20 items): https://www.anchorterminal.com/fixes/belvo.md (JSON https://www.anchorterminal.com/fixes/belvo.json)\n\n### What we couldn't check\n\n- The batch lead says balances and transactions in Brazil and Mexico. The docs and the MCP page read on 8 October 2026 show bank data for Brazil only, with employment, fiscal and direct debit products in Mexico\n- The lead lists SDKs. The Python, Node and Ruby packages were last published in 2023 and github.com/belvo-finance/belvo-python, belvo-js and belvo-ruby return 404. Only the iOS and Android SDKs for biometric Pix are in the current docs\n- The clean 90 days on the status page may mean no incidents or no posting. The feed can't tell the two apart\n- Whether Belvo Instituição de Pagamento Ltda. is authorised by Banco Central do Brasil, and under what number. We found the name and CNPJ in the terms but didn't check the regulator's register\n- unchecked: the trust centre at trust.belvo.com, which is drawn by script, so the subprocessor list and audit reports weren't read\n- unchecked: the dashboard's activity logs and whether more than one key pair can exist per environment\n- unchecked: the Data Access MCP's URL, tools and credential model, which have no public docs\n- unchecked: the separate institutions status page that the docs mention\n- unchecked: GitHub organisation listing and stars, because the GitHub API rate limit was reached\n\n### Sources\n\n- docs llms.txt: \u003chttps://developers.belvo.com/llms.txt\u003e (seen 2026-10-08)\n- OpenAPI file, version 1.223.0: \u003chttps://developers.belvo.com/_bundle/apis/BelvoOpenApiSpec.yaml\u003e (seen 2026-10-08)\n- API reference introduction, environments and retry policy: \u003chttps://developers.belvo.com/apis/belvoopenapispec.md\u003e (seen 2026-10-08)\n- error reference: \u003chttps://developers.belvo.com/developer_resources/resources-belvo-api-errors.md\u003e (seen 2026-10-08)\n- pagination and filtering: \u003chttps://developers.belvo.com/developer_resources/resources-pagination-and-filtering.md\u003e (seen 2026-10-08)\n- sandbox: \u003chttps://developers.belvo.com/developer_resources/resources-sandbox.md\u003e (seen 2026-10-08)\n- Developer MCP docs, and tools/list on the server: \u003chttps://developers.belvo.com/developer_resources/resources-mcp-server.md\u003e (seen 2026-10-08)\n- Brazil Open Finance retrieval limits: \u003chttps://developers.belvo.com/products/aggregation_brazil/aggregation-brazil-data-retrieval-limits.md\u003e (seen 2026-10-08)\n- data retention controls: \u003chttps://developers.belvo.com/security/security-data-retention-controls.md\u003e (seen 2026-10-08)\n- docs security page (WAF and rate limiting): \u003chttps://developers.belvo.com/security/security-features.md\u003e (seen 2026-10-08)\n- available institutions: \u003chttps://developers.belvo.com/developer_resources/resources-available-institutions.md\u003e (seen 2026-10-08)\n- Direct Debit idempotency and IP allowlisting: \u003chttps://developers.belvo.com/products/payments_mexico/direct-debit-idempotency-and-whitelisting.md\u003e (seen 2026-10-08)\n- aggregation webhooks: \u003chttps://developers.belvo.com/developer_resources/resources-webhooks-aggregation.md\u003e (seen 2026-10-08)\n- quickstart (account, keys, production access): \u003chttps://developers.belvo.com/products/aggregation_brazil/prerequisites-get-started-in-10-minutes.md\u003e (seen 2026-10-08)\n- plans and pricing: \u003chttps://belvo.com/plans-and-pricing/\u003e (seen 2026-10-08)\n- General Conditions of Service Usage with SLA annex: \u003chttps://belvo.com/terms-service/\u003e (seen 2026-10-08)\n- privacy policy for end users: \u003chttps://belvo.com/privacy-policy-end-users/\u003e (seen 2026-10-08)\n- privacy policy for clients: \u003chttps://belvo.com/privacy-policy-clients/\u003e (seen 2026-10-08)\n- legal notice: \u003chttps://belvo.com/legal-notice/\u003e (seen 2026-10-08)\n- security page: \u003chttps://belvo.com/security/\u003e (seen 2026-10-08)\n- security.txt: \u003chttps://belvo.com/.well-known/security.txt\u003e (seen 2026-10-08)\n- status incident feed: \u003chttps://status.belvo.com/api/v2/incidents.json\u003e (seen 2026-10-08)\n- status components: \u003chttps://status.belvo.com/api/v2/components.json\u003e (seen 2026-10-08)\n- MCP servers page: \u003chttps://belvo.com/resources/mcps/\u003e (seen 2026-10-08)\n- MCP launch post, 10 August 2026: \u003chttps://belvo.com/blog/belvo-mcps-the-new-agentic-open-finance/\u003e (seen 2026-10-08)\n- npm package belvo: \u003chttps://registry.npmjs.org/belvo/latest\u003e (seen 2026-10-08)\n- PyPI package belvo-python: \u003chttps://pypi.org/pypi/belvo-python/json\u003e (seen 2026-10-08)\n- RDAP for belvo.com: \u003chttps://rdap.verisign.com/com/v1/domain/belvo.com\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 81/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Belvo Tecnologias Ltda. | 20/20 |\n| Domain age | belvo.com, registered 2005-07-17 (21 years) | 15/15 |\n| Endpoint on the vendor's domain | api.belvo.com | 15/15 |\n| Terms of service | read, states 7 of the 7 things a reader expects, and has 1 clause that costs points | 8/10 |\n| Privacy policy | read, states 5 of the 8 things a reader expects | 7.8/10 |\n| Status page | status.belvo.com | 10/10 |\n| Changelog | not found | 0/10 |\n| security.txt | published but past its Expires date | 5/10 |\n\nThe General Conditions of Service Usage, last updated 10 January 2025, define Belvo as Belvo Tecnologias Ltda., CNPJ 37.869.837/0001-81, and Belvo Instituição de Pagamento Ltda., CNPJ 43.215.815/0001-09, with affiliates. They are governed by Brazilian law with the courts of São Paulo.\n\nThe legal notice also names Belvo Technologies, SAPI de CV in Mexico City (RFC BTE1912023D6) and Belvo Technologies Inc. Sucursal en España in Barcelona.\n\nThe privacy link is the end-user policy, which covers data Belvo processes through its platform for clients. A separate policy for clients and site visitors at https://belvo.com/privacy-policy-clients/ was last updated 15 July 2024.\n\nsecurity.txt is PGP-signed, gives security@belvo.com and a disclosure policy on Federacy, and expired on 22 March 2025.\n\nNo changelog was found. developers.belvo.com/changelog returns 404 and llms.txt lists none.\n\nVerisign RDAP gives a registration date of 2005-07-17 for belvo.com.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://belvo.com/terms-service/), read 2026-10-08, dated 2025-01-10, states 7 of the 7 things a reader expects.\n\n- To know. Says the terms or the service can change without notice (costs points). \"Aiming at improving and improving the services provided, Belvo may, at any time, change the terms of the Agreement, its annexes and/or policies, without the need for prior notice or written agreement.\"\n- Gives the date it was last updated. Last updated 2025-01-10.\n- Names the governing law or courts. The law of Federative Republic of Brazil.\n- Says how changes to the terms are announced. Says it gives notice of a change.\n- Also in the text (2026-10-08). Prices are corrected each year by the IPCA-IBGE index without an amendment or prior communication. \"Annually, prices will be corrected by the IPCA-IBGE, without the need for an amendment or prior communication.\"\n- Also in the text (2026-10-08). Belvo is the sole owner of any machine learning that occurs within the services. \"Belvo is the sole holder and owner of any systemic learning (\"machine learning\") that occurs within the scope of the Services by means of artificial intelligence (or any other technology), without this implying any violation of the Client's intellectual property.\"\n- Also in the text (2026-10-08). Belvo excludes liability for damages, including lost profits and financial losses, arising from the provision of the service. \"Belvo will not be liable for damages, including lost profits or financial losses, that may arise as a result of the provision of the Service, in relation to the Client, End Users and/or any third party.\"\n\n**Privacy policy** (https://belvo.com/privacy-policy-end-users/), read 2026-10-08, dated 2021-02-22, states 5 of the 8 things a reader expects.\n\n- To know. Has not been updated for three years or more. \"Date of last update: February 22, 2021\"\n- Gives the date it was last updated. Last updated 2021-02-22.\n- Not found in the text. Says what personal data is collected.\n- Not found in the text. Says whether personal data is sold or shared for advertising.\n- Not found in the text. Gives a privacy contact.\n- Also in the text (2026-10-08). As a processor, Belvo does not handle requests from end users to exercise data rights and redirects them to the client. \"As a processor, Belvo does not process requests to exercise the rights of personal data subjects, since such requests must be met by those responsible for the personal data of End Users.\"\n\n## Live (updated 2026-10-08 19:52 UTC)\n\n- Right now: up, HTTP 403, 66 ms, checked 2026-10-08 19:52 UTC (get on `https://api.belvo.com`, asks for auth)\n- Uptime 24h 100.0% (27 probes) · 30 days 100.0% (27 probes) · p50 46 ms · p95 188 ms\n- Vendor status page: none, All Systems Operational\n- Watching pricing \u003chttps://belvo.com/plans-and-pricing/\u003e\n- Watching privacy \u003chttps://belvo.com/privacy-policy-end-users/\u003e\n- Watching terms \u003chttps://belvo.com/terms-service/\u003e\n- Always current: https://www.anchorterminal.com/api/v1/live/belvo.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Prices\n\n| Item | Price | Unit | Note |\n| --- | --- | --- | --- |\n| Launch plan | $1000 | per month (plan) | Production access, through sales. Growth plan is custom |\n\nAcross all listings: https://www.anchorterminal.com/prices/index.md\n\n## Strengths\n\n- Public OpenAPI 3.0.2 file, version 1.223.0, with 146 operations on 83 paths, and a separate specification for Direct Debit in Mexico\n- llms.txt lists a Markdown twin of every docs page in English, Spanish and Portuguese\n- List endpoints take `fields`, `omit`, `page_size` up to 1,000 and range filters on dates and amounts\n- Retention is set per link and per call with `stale_in`, `credentials_storage` and `save_data`\n- ISO/IEC 27001:2022 and PCI DSS Level 1 are stated on the security page\n\n## Weaknesses\n\n- Production keys follow a sales meeting, a certification call with a Belvo engineer and a paid plan from 1,000 USD a month\n- One `secretId` and `secretPassword` pair per environment over HTTP Basic, with no scopes or read-only keys found\n- No changelog was found, and the Python, Node and Ruby packages were last published in 2023 with their GitHub repositories returning 404\n- Bank data covers Brazil only in the docs read on 8 October 2026, and Mexico has employment, fiscal and direct debit products\n- security.txt expired on 22 March 2025\n- General rate limits carry no published numbers, and the data webhooks have no signature, only an optional fixed authorisation header\n\n## Before you call it (notes for agents)\n\n1. Send HTTP Basic with `secretId` as username and `secretPassword` as password to https://sandbox.belvo.com, and switch to https://api.belvo.com only with production keys\n2. Create links through the Hosted Widget with a token from POST /api/token/, which expires after 10 minutes\n3. Read stored data with GET list calls. Each POST retrieval in Brazil counts against monthly Open Finance limits, such as 8 a month per CPF for owners and accounts\n4. Retry 50x responses up to five times from a 3 second base with a factor of two, and don't retry 40x apart from `too_many_sessions`\n5. Send `Belvo-Idempotency-Key` with a UUID when creating a payment intent, and `X-Belvo-Request-Mode: async` on link deletion to avoid the limit of 5 deletions a minute\n\n## Connect\n\nFirst request:\n\n```bash\ncurl -X GET https://sandbox.belvo.com/api/ \\\n  -H \"Authorization: Basic $(echo -n 'YOUR_SECRET_ID:YOUR_SECRET_PASSWORD' | base64)\"\n```\n\nClaude Code:\n\n```bash\nclaude mcp add --transport http belvo-docs https://developers.belvo.com/mcp\n```\n\nMCP client configuration:\n\n```json\n{\n  \"mcpServers\": {\n    \"belvo-docs\": {\n      \"type\": \"http\",\n      \"url\": \"https://developers.belvo.com/mcp\"\n    }\n  }\n}\n```\n\nThrough letme (picks today, calling later): https://letme.dev/belvo. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Plaid | B | 69.8 | 147 | bank.accounts, bank.transactions, bank.identity, bank.payments, bank.consent | no | https://www.anchorterminal.com/tools/plaid.md |\n| Tink | B | 62.5 | 337 | bank.accounts, bank.transactions, bank.consent, bank.payments, bank.identity | no | https://www.anchorterminal.com/tools/tink.md |\n| TrueLayer | B | 62.1 | 347 | bank.accounts, bank.transactions, bank.identity, bank.payments, bank.consent | no | https://www.anchorterminal.com/tools/truelayer.md |\n| Yapily | C | 57.6 | 469 | bank.accounts, bank.transactions, bank.identity, bank.payments, bank.consent | no | https://www.anchorterminal.com/tools/yapily.md |\n| Flinks | D | 52.7 | 559 | bank.accounts, bank.transactions, bank.identity, bank.payments, bank.consent | no | https://www.anchorterminal.com/tools/flinks.md |\n| Salt Edge Account Information | D | 46.7 | 643 | bank.accounts, bank.transactions, bank.identity, bank.payments, bank.consent | no | https://www.anchorterminal.com/tools/salt-edge.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The API reference is one OpenAPI 3.0.2 file, version 1.223.0, with 146 operations on 83 paths and HTTP Basic as its only security scheme (source: \u003chttps://developers.belvo.com/_bundle/apis/BelvoOpenApiSpec.yaml\u003e)\n- Bank data in the docs is Brazil only, through the regulated Open Finance network, with 54 institution rows across banking Brazil, employment Brazil, employment Mexico and fiscal Mexico (source: \u003chttps://developers.belvo.com/developer_resources/resources-available-institutions.md\u003e)\n- The Developer MCP at https://developers.belvo.com/mcp is public, needs no account and has six read-only documentation tools. It can't reach an account or make API calls (source: \u003chttps://developers.belvo.com/developer_resources/resources-mcp-server.md\u003e)\n- Belvo's site lists a Data Access MCP as live for Brazil and Mexico, switched on by its sales team and billed as standard API calls, and an Analytics MCP as coming soon. No public docs for either were found (source: \u003chttps://belvo.com/resources/mcps/\u003e)\n- Brazil's Open Finance network caps retrievals per CPF or CNPJ each month, for example 8 for owners, 8 for a 365-day transaction pull, 240 for a pull of under 6 days and 420 for balances (source: \u003chttps://developers.belvo.com/products/aggregation_brazil/aggregation-brazil-data-retrieval-limits.md\u003e)\n- The status feed's newest incident is 1 June 2026. May 2026 has three, among them a critical one on 19 May lasting 2.7 hours and a major one on 15 May lasting 10.9 hours (source: \u003chttps://status.belvo.com/api/v2/incidents.json\u003e)\n- The sandbox is wiped on the first day of every month and returns 10 results a page, against 100 in production (source: \u003chttps://developers.belvo.com/developer_resources/resources-sandbox.md\u003e)\n\n## Compare\n\n- [Akoya vs Belvo](https://www.anchorterminal.com/compare/akoya-vs-belvo.md): D 48.3 vs B 63.5\n- [Belvo vs Enable Banking](https://www.anchorterminal.com/compare/belvo-vs-enable-banking.md): B 63.5 vs D 47.1\n- [Belvo vs Flinks](https://www.anchorterminal.com/compare/belvo-vs-flinks.md): B 63.5 vs D 52.7\n- [Belvo vs GoCardless Bank Account Data](https://www.anchorterminal.com/compare/belvo-vs-gocardless-bank-account-data.md): B 63.5 vs E 41.7\n- [Belvo vs MX Platform API](https://www.anchorterminal.com/compare/belvo-vs-mx.md): B 63.5 vs B 62.5\n- [Belvo vs Plaid](https://www.anchorterminal.com/compare/belvo-vs-plaid.md): B 63.5 vs B 69.8\n- [Belvo vs Salt Edge Account Information](https://www.anchorterminal.com/compare/belvo-vs-salt-edge.md): B 63.5 vs D 46.7\n- [Belvo vs Teller](https://www.anchorterminal.com/compare/belvo-vs-teller.md): B 63.5 vs E 42.7\n- [Belvo vs Tink](https://www.anchorterminal.com/compare/belvo-vs-tink.md): B 63.5 vs B 62.5\n- [Belvo vs TrueLayer](https://www.anchorterminal.com/compare/belvo-vs-truelayer.md): B 63.5 vs B 62.1\n- [Belvo vs Yapily](https://www.anchorterminal.com/compare/belvo-vs-yapily.md): B 63.5 vs C 57.6\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on belvo.com or one of its subdomains. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"belvo\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/belvo\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/belvo.svg\" alt=\"Belvo on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Belvo on Anchor Terminal](https://www.anchorterminal.com/badges/belvo.svg)](https://www.anchorterminal.com/tools/belvo)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/belvo\"\u003eBelvo on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Belvo is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/belvo-dark.png\n- Light: https://www.anchorterminal.com/assets/share/belvo-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Bank data \u0026 open banking",
        "url": "https://www.anchorterminal.com/categories/banking-data"
      },
      {
        "name": "Belvo",
        "url": ""
      }
    ],
    "description": "Belvo is an open finance API for Latin America. It reads bank accounts, transactions and investments in Brazil, employment records in Brazil and Mexico and tax data in Mexico, and starts Pix payments in Brazil and direct debits in Mexico.",
    "facts": [
      "rank #309 of 722",
      "API key auth",
      "0 desk reviews"
    ],
    "h1": "Belvo",
    "image": "https://www.anchorterminal.com/assets/og/tools-belvo.png",
    "path": "/tools/belvo",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Belvo review for AI agents, grade B (63.5/100) | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/belvo"
  },
  "tokens": {
    "markdown": 7900,
    "slim": 1780
  },
  "version": 1
}
