# Codat > Codat connects a business's accounting, banking and commerce software to financial products and banks through one REST API. Product APIs cover bill pay, expenses, bank feeds and lending data, with official SDKs for TypeScript, Python and C#. - Canonical: https://www.anchorterminal.com/tools/codat - Markdown: https://www.anchorterminal.com/tools/codat.md (~7,050 tokens) - Slim: https://www.anchorterminal.com/tools/codat.min.md (~1,780 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/codat.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-08 ## Overview **Grade B · 64.3/100 · rank #280 of 722 · #4 in Accounting & invoicing · not agent-ready · confidence medium** ## Assessment Public OpenAPI specs, an Idempotency-Key header on writes, Retry-After on 429 and a written three-month deprecation notice suit an agent that retries. Access is the limitation. No price or self-serve signup is published, the general Accounting API is closed to new clients, and API keys carry no scopes. ## Facts | Field | Value | | --- | --- | | Vendor | Codat Limited (https://codat.io) | | Kind | HTTP API | | Category | Accounting & invoicing (https://www.anchorterminal.com/categories/accounting) | | Transport | HTTP | | Endpoint | `https://api.codat.io` | | Auth | API key · An API key, Base64 encoded, in an `Authorization: Basic` header on every call to https://api.codat.io. An account comes through Codat's sales team. The docs say to get in touch to create one, and no self-serve signup was found. A client can hold up to 10 named keys, created and deleted in the Portal by Administrator or Developer users or through the /apiKeys endpoints. Keys have no scopes, so each one reaches every company the client has connected. End customers authorise their accounting package through Codat's Link flow. | | Pricing | Paid (Paid) · No public price. codat.io/pricing returns 404 and the site's buttons ask for a meeting. The standard MSA sets a platform fee invoiced in advance and a unit fee per active company per month, both in an order form. The docs describe a free trial limited to 50 companies, no hourly syncs and 365 days, and a Codat Sandbox integration that is excluded from billing, but an account starts with a request to Codat (checked 2026-10-08). | | x402 | No · No x402, MPP or L402 in the docs repository, the OpenAPI specs or the site (checked 2026-10-08). | | Licence | Proprietary service under Codat's Master Services Agreement. The documentation repository codatio/codat-docs is Apache-2.0 | | Packages | npm: `@codat/platform`; pypi: `codat-platform` | | Source | https://github.com/codatio/oas | | Docs | https://docs.codat.io/using-the-api/overview | | llms.txt | not found | | Last release | 2026-10-01 | | npm downloads / week | 2,690 | | PyPI downloads / week | 222 | | APIs for new clients | Platform (52 operations), Lending (156), Bill Pay synchronous (25), Expenses (48), Bank Feeds (33) and Spend Insights (7), all OpenAPI 3 in codatio/oas and served from https://api.codat.io | | Legacy APIs | Accounting (135 operations), Banking, Commerce, Assess and Files, each marked as relevant only to existing clients. Sync for Payables v1, Sync for Expenses v1 and Sync for Payroll are in maintenance until 1 May 2027 | | Accounting packages | 22 integration folders in the docs, among them Xero, QuickBooks Online and Desktop, NetSuite, Sage Intacct, Sage 50 and 200, Dynamics 365 Business Central, MYOB, FreshBooks, Zoho Books, Workday and a Codat Sandbox | | Credentials | API key, Base64 encoded in an `Authorization: Basic` header. Up to 10 named keys, created and deleted in the Portal or through /apiKeys. No scopes | | Rate limits | 1,000 requests a day times (1 + active connected companies), reset at 00:00 UTC. 10 concurrent requests per active connected company. 1,000 a minute per IP | | Writes | Create, update and delete across 18 accounting data types, asynchronous with a push operation key and write webhooks. The synchronous Bill Pay API answers in the request | | Idempotency | `Idempotency-Key` GUID on POST and PATCH, cached 90 minutes, not cached for 429 | | Paging and filters | `page` and `pageSize` (default 100, maximum 5,000), a `query` filter language and `orderBy`. Bill Pay lists use a continuation token | | Errors | JSON with statusCode, service, error, correlationId, canBeRetried, detailedErrorCode and a validation object. 402 marks a free trial limit | | SDKs | TypeScript @codat/platform 6.2.1 and Python codat-platform 5.0.1 (23 April 2026), C# Codat.Platform 6.2.1, one package per product. Java archived 2 April 2026, Go 7 May 2026 | | Sandbox | Codat Sandbox integration with sample companies, no credentials, excluded from billing. Test clients are limited to 50 active connected companies | | SLA | Service credits of 10, 30 and 100 per cent of the platform fee when monthly uptime is below 99, 95 and 90 per cent (standard MSA, Schedule 1) | | Certifications | SOC 2 Type II and ISO 27001, audited yearly per codat.io/security. Private bug bounty, yearly penetration test. Hosted on Microsoft Azure | | MCP server | None found | | Capabilities | accounting.unified, accounting.bills, accounting.reports, accounting.ledger, accounting.invoices | | Tags | hosted, paid, sales-led, api-key, openapi, webhooks, async-jobs, idempotency, sandbox, typescript, python, csharp, status-page, soc2, iso27001, closed-source | | JSON | https://www.anchorterminal.com/api/v1/tools/codat.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 80 | 16.0 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 77 | 12.5 | | Agent ergonomics | 13% | 16.2 | 81 | 13.2 | | Security & auth | 14% | 17.5 | 49 | 8.6 | | Payments & pricing | 10% | 12.5 | 10 | 1.2 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 75 | 6.6 | | Transparency & trust (editorial 59, provenance 82) | 7% | 8.8 | 71 | 6.2 | | Negative events | up to −15 | up to −15 | none recorded | 0 | | **Total** | | | | **64.3 → B** | ### Why each score - Reliability 80: Graded on the hosted REST API at api.codat.io. Statuspage at status.codat.io with components per product and per integration (20). In the 90 days to 8 October 2026 the page shows two complete outages of the API and Portal, 14 minutes on 24 July and 12 minutes of errors on 27 July, intermittent Xero failures from 22 to 29 July, and errors on some integrations and sync services for about two hours on 24 August. No single outage of the core API reached an hour, so we scored it as one major (10). Limits published with numbers, 1,000 requests a day times one plus the active connected companies, 10 concurrent per company and 1,000 a minute per IP (15). 429 with Retry-After and X-Rate-Limit headers, and an Idempotency-Key header on POST and PATCH (15). The standard MSA pays service credits below 99 per cent monthly uptime (10). Generally available (10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 77: Public OpenAPI 3 specs for every API in codatio/oas, in JSON and YAML (25). docs.codat.io/llms.txt returns 404. The docs source is Markdown in a public repository, which is not the same as serving it to agents (0). Operation descriptions are long and state prerequisites, useful queries and traps, for example that data must be refreshed before a list call (16). Typed schemas with enums, but filters go through a free-text `query` string and the required fields of a write differ by accounting package and have to be fetched from an options endpoint (11). Response examples per integration on most operations and a documented status code table with sample error bodies (13). Dated changelog at docs.codat.io/updates and a change policy. The API has no version in the path or a header (12). - Agent ergonomics 81: `pageSize` from 1 to 5,000 with a default of 100, and a `query` filter that cuts results. No field selection found (15). Page and pageSize paging with `_links`, a query language, `orderBy` and modifiedDate filters. Bill Pay uses continuation tokens (20). Errors carry statusCode, service, error, correlationId, canBeRetried and detailedErrorCode with a validation object, though the error text is a string an agent has to read (17). Idempotency-Key on POST and PATCH with a 90-minute cache and documented behaviour after a 429. PUT and DELETE are outside the documented scheme (18). Maintained SDKs for TypeScript, Python and C#, one package per product. Writes need a model lookup per integration and most complete asynchronously (11). - Security & auth 49: Plain API keys in a Basic header, up to 10 per client, named, revocable in the Portal or through the API. No scopes and no documented expiry (20). No read-only key and no confirmation step for writes or deletes. Portal users have roles, and only Administrator and Developer roles see keys (4). The API returns ledger text written by third parties, such as invoice descriptions and supplier names, and no injection guidance was found (3). Read and write history per company and data type in the Portal and through the data history and push endpoints. No log of calls per API key was found (7). Annual SOC 2 Type II and ISO 27001 audits, a yearly penetration test, a private bug bounty and a disclosure form on codat.io/security. No security.txt. The trust centre page did not render for us (15). - Payments & pricing 10: No x402, MPP or L402 (0). No price is published. The pricing page returns 404 and the MSA leaves the platform fee and the per-company unit fee to an order form (0). The docs describe a free trial of up to 50 companies for 365 days and a sandbox excluded from billing, but the docs say to get in touch to create an account, so half credit (10). Access starts with a person contacting Codat (0). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 75: Latest changelog entry on 1 October 2026 (30). Seven dated entries since 3 August 2026 (20). A dated changelog, a Zendesk help centre and a support address. No public issue tracker for the service was reviewed (10). TypeScript, Python and C# SDKs were last published between April and June 2026. The Java and Go SDKs were archived in April and May 2026 with a month's notice (10). The specs repository runs lint in CI and was last changed on 4 August 2026 (5). - Transparency & trust 71: Closed service with a published Master Services Agreement, versioned and dated, naming Codat Limited and its company number (15). The MSA has a data processing schedule and deletes company data five business days after termination. The privacy notice of April 2025 is written mainly for website visitors and gives general retention wording, with six years for customer records (16). A change policy with at least three months' notice of breaking changes, a deprecation calendar, quarterly emails, defined lifecycle states and dated notices (20). The privacy notice names Microsoft Azure in the UK as a sub-processor and the MSA promises 10 days' notice of changes. No fuller list or choice of data location was found (8). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (17 items): https://www.anchorterminal.com/fixes/codat.md (JSON https://www.anchorterminal.com/fixes/codat.json) ### What we couldn't check - unchecked: whether app.codat.io/signup still opens a free account without sales contact. The page is a JavaScript app we could not read, and the docs say to get in touch - unchecked: the trust centre at trust.codat.io, which did not render, so the sub-processor list and certificates there were not read - unchecked: the official MCP registry for a Codat server. A search returned unrelated results and none was found in Codat's docs - Whether a new client can still buy read access to the full accounting data model outside the Lending product - The enterprise MSA and the Start-up Plan terms were not read in full, and current fees are in order forms only - Idempotency-Key is documented for POST and PATCH, while the Bill Pay spec also lists it on two PUT operations ### Sources - status incidents (Statuspage API): (seen 2026-10-08) - rate limits and 429 handling: (seen 2026-10-08) - authentication and API keys: (seen 2026-10-08) - status codes and errors, free trial limits: (seen 2026-10-08) - idempotency: (seen 2026-10-08) - paging: (seen 2026-10-08) - writes and supported data types: (seen 2026-10-08) - change policy: (seen 2026-10-08) - changelog: (seen 2026-10-08) - product lifecycle changes: (seen 2026-10-08) - OpenAPI specs (cloned, last commit 4 August 2026): (seen 2026-10-08) - docs source (cloned, last commit 1 October 2026): (seen 2026-10-08) - first steps, account prerequisite: (seen 2026-10-08) - testing and sandbox: (seen 2026-10-08) - standard MSA, SLA schedule and data processing: (seen 2026-10-08) - privacy notice: (seen 2026-10-08) - security page: (seen 2026-10-08) - home page and fintech page: (seen 2026-10-08) - pricing page (404): (seen 2026-10-08) - llms.txt (404): (seen 2026-10-08) - npm @codat/platform: (seen 2026-10-08) - PyPI codat-platform: (seen 2026-10-08) - domain registration (RDAP): (seen 2026-10-08) ## Who's behind it (provenance 82/100, checked 2026-10-08) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Codat Limited | 20/20 | | Domain age | codat.io, registered 2016-10-17 (9 years) | 11/15 | | Endpoint on the vendor's domain | api.codat.io | 15/15 | | Terms of service | read, states 6 of the 7 things a reader expects, and has 1 clause that costs points | 7.1/10 | | Privacy policy | read, states 7 of the 8 things a reader expects | 9.3/10 | | Status page | status.codat.io | 10/10 | | Changelog | published | 10/10 | | security.txt | not found | 0/10 | The standard MSA (version 2.0, 5 September 2022) names Codat Limited, registered in England and Wales, number 10480375, 6-7 St. Cross Street, London EC1N 8UB, for clients in the UK and the rest of the world outside the USA. The privacy notice also names Codat, Inc., a Delaware corporation. codat.io/legals lists two agreements, the Master Services Agreement (standard and enterprise versions) and the Start-up Plan terms. The standard MSA is the one recorded here. The Codat Global Privacy Notice was last updated in April 2025. It is written mainly for website visitors, and the MSA points to the same page for the sub-processor list. codat.io, app.codat.io and api.codat.io all return 404 for /.well-known/security.txt. codat.io/security has a disclosure form. RDAP for codat.io gives a registration date of 2016-10-17. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://codat.io/msa-standard/), read 2026-10-08, dated 2022-09-05, states 6 of the 7 things a reader expects. - To know. Restricts benchmarking or competitive use (costs points). "(c) access all or any part of Codat Products in order to build a product or service which competes with the Codat Products and/or Codat Services;" - To know. Has not been updated for three years or more. "Agreement Version: v2.0 dated 5 September 2022." - Gives the date it was last updated. Last updated 2022-09-05. - States a limit on its liability. Capped at the greater of £50,000 and the fees paid in the 12 months before the claim. - Says how changes to the terms are announced. Gives 20 days of notice before a change. - Not found in the text. Lists what users may not do. - Also in the text (2026-10-08). The client must not use the Codat Products in a way that, in Codat's reasonable opinion, exceeds reasonable request volume or is excessive or abusive. "(c) not use the Codat Products in a manner that in Codat’s reasonable opinion exceeds reasonable request volume, constitutes excessive or abusive usage, or otherwise fails to comply or is inconsistent with any part of this Agreement;" - Also in the text (2026-10-08). The client has 5 business days after termination or expiry to export Company Data, after which Codat deletes it. "Codat shall afford the Client 5 Business Days following the date of termination or expiry of this Agreement within which the Client may download/export the Company Data, following which time Codat shall delete the Company Data." - Also in the text (2026-10-08). If Codat terminates for the client's breach or insolvency, the client pays the unpaid fees for the rest of the term of all order forms. "If this Agreement is terminated by Codat in accordance with clause 7.3 above, Client will pay any unpaid Fees covering the remainder of the term of all Order Forms to the extent permitted by applicable law." **Privacy policy** (https://codat.io/privacy-policy/), read 2026-10-08, dated 2025-04-01, states 7 of the 8 things a reader expects. - Gives the date it was last updated. Last updated 2025-04-01. - Says how long data is kept. For as long as needed, with no period named. - Not found in the text. Says whether personal data is sold or shared for advertising. ## Live (updated 2026-10-08 19:52 UTC) - Right now: up, HTTP 404, 77 ms, checked 2026-10-08 19:52 UTC (get on `https://api.codat.io`) - Uptime 24h 100.0% (27 probes) · 30 days 100.0% (27 probes) · p50 70 ms · p95 157 ms - Vendor status page: none, All Systems Operational - Watching changelog - Watching privacy - Watching terms - Always current: https://www.anchorterminal.com/api/v1/live/codat.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Strengths - Public OpenAPI 3 specs for every API in codatio/oas, with long operation descriptions and per-integration response examples - Idempotency-Key header on POST and PATCH, cached for 90 minutes, and released after a 429 so the same key can be retried - 429 responses carry Retry-After, and every response carries X-Rate-Limit-Limit, Remaining and Reset headers - Breaking changes are posted at least three months ahead, with a deprecation calendar and quarterly emails - Annual SOC 2 Type II and ISO 27001 audits and a private bug bounty, per codat.io/security ## Weaknesses - No public price. The pricing page returns 404 and fees are set in an order form - No self-serve signup found. The docs and the site ask new users to get in touch - The general Accounting API spec says it is relevant only to existing clients, and the status page labels it Legacy - API keys have no scopes or read-only mode, and one key reaches every connected company - Two complete API outages in July 2026, of 14 and 12 minutes, and intermittent Xero failures from 22 to 29 July - The Java and Go SDKs were archived in April and May 2026 ## Before you call it (notes for agents) 1. Send `Authorization: Basic ` to https://api.codat.io. The Portal shows the ready-made header value 2. Send a new GUID as `Idempotency-Key` on every POST and PATCH, and reuse the same key when retrying after a 429 3. Treat writes as asynchronous on most APIs. Keep the push operation key and wait for the `{dataType}.write.successful` or `.unsuccessful` webhook 4. Call the Get model (options) endpoint for the connection before a create or update, because required fields differ by accounting package 5. Filter with `query=modifiedDate>...` and keep `pageSize` at 100. The daily quota is 1,000 requests times one plus the number of active connected companies ## Connect Install: ```bash npm install @codat/platform ``` First request: ```bash curl https://api.codat.io/companies \ -H "Authorization: Basic $CODAT_ENCODED_API_KEY" ``` Through letme (picks today, calling later): https://letme.dev/codat. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Apideck Accounting API + MCP | BB | 72.9 | 83 | accounting.unified, accounting.ledger, accounting.invoices, accounting.bills, accounting.reports | no | https://www.anchorterminal.com/tools/apideck-accounting.md | | Merge Accounting API | BB | 70 | 143 | accounting.unified, accounting.ledger, accounting.invoices, accounting.bills, accounting.reports | no | https://www.anchorterminal.com/tools/merge-accounting.md | | Rutter Accounting API | C | 55.6 | 506 | accounting.unified, accounting.ledger, accounting.invoices, accounting.bills, accounting.reports | no | https://www.anchorterminal.com/tools/rutter.md | | Xero API + MCP | B | 67.2 | 213 | accounting.ledger, accounting.invoices, accounting.bills, accounting.reports | no | https://www.anchorterminal.com/tools/xero.md | | FreeAgent API | C | 57.2 | 481 | accounting.ledger, accounting.invoices, accounting.bills, accounting.reports | no | https://www.anchorterminal.com/tools/freeagent.md | | QuickBooks Online API + MCP | D | 49.2 | 612 | accounting.ledger, accounting.invoices, accounting.bills, accounting.reports | no | https://www.anchorterminal.com/tools/quickbooks-online.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - Codat rebranded on 20 April 2026 around insight products for commercial banks, and says existing connections, integrations and APIs are unaffected (source: ) - The Accounting, Banking, Commerce, Assess and Files API specs open with a notice that they are relevant only to existing clients. New clients are sold Bill Pay, Expenses, Bank Feeds, Lending and Spend Insights (source: ) - Rate limits are 1,000 requests a day times (1 + active connected companies), 10 concurrent requests per active connected company and 1,000 a minute per IP, with Retry-After on 429 (source: ) - Idempotency-Key is accepted on POST and PATCH across the APIs, with a 90-minute cache, 422 for a reused key with a different body and 409 for one still in progress (source: ) - Sync for Payables v1, Sync for Expenses v1 and Sync for Payroll entered a 12-month maintenance period on 1 May 2026 and lose API access from 1 May 2027 (source: ) - The standard MSA of 5 September 2022 pays service credits when monthly uptime falls below 99 per cent, and gives five business days to export data after termination before deletion (source: ) - No MCP server, llms.txt at docs.codat.io or machine payment protocol was found in the docs repository or on the site (source: ) ## Compare - [Codat vs FreeAgent API](https://www.anchorterminal.com/compare/codat-vs-freeagent.md): B 64.3 vs C 57.2 - [Codat vs FreshBooks API](https://www.anchorterminal.com/compare/codat-vs-freshbooks.md): B 64.3 vs E 45.4 - [Codat vs Odoo External API](https://www.anchorterminal.com/compare/codat-vs-odoo.md): B 64.3 vs C 55.9 - [Codat vs QuickBooks Online API + MCP](https://www.anchorterminal.com/compare/codat-vs-quickbooks-online.md): B 64.3 vs D 49.2 - [Codat vs Xero API + MCP](https://www.anchorterminal.com/compare/codat-vs-xero.md): B 64.3 vs B 67.2 - [Codat vs Zoho Books](https://www.anchorterminal.com/compare/codat-vs-zoho-books.md): B 64.3 vs C 61.1 - [Codat vs Invoice Ninja API](https://www.anchorterminal.com/compare/codat-vs-invoice-ninja.md): B 64.3 vs D 52.1 - [Apideck Accounting API + MCP vs Codat](https://www.anchorterminal.com/compare/apideck-accounting-vs-codat.md): BB 72.9 vs B 64.3 - [Codat vs Merge Accounting API](https://www.anchorterminal.com/compare/codat-vs-merge-accounting.md): B 64.3 vs BB 70 - [Codat vs Rutter Accounting API](https://www.anchorterminal.com/compare/codat-vs-rutter.md): B 64.3 vs C 55.6 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on codat.io or one of its subdomains, or the README of github.com/codatio/oas. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "codat", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Codat on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Codat on Anchor Terminal](https://www.anchorterminal.com/badges/codat.svg)](https://www.anchorterminal.com/tools/codat) ``` Plain link: ```html Codat on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Codat is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/codat-dark.png - Light: https://www.anchorterminal.com/assets/share/codat-light.png