# Finch > Finch is a unified API for reading an employer's existing HR and payroll system, run by Profound Platform Inc. in San Francisco. Applications read directory, employment and pay data from 250+ systems and write payroll deductions. - Canonical: https://www.anchorterminal.com/tools/finch - Markdown: https://www.anchorterminal.com/tools/finch.md (~8,650 tokens) - Slim: https://www.anchorterminal.com/tools/finch.min.md (~2,180 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/finch.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-08 ## Overview **Grade BB · 71.6/100 · rank #104 of 722 · #1 in Payroll infrastructure · agent-ready · confidence medium** ## Assessment Graded on the REST API. An employer grants each connection named product permissions, and limits, error codes and a 99.9 per cent uptime SLA are published. Finch reads payroll and writes deductions but cannot run a payroll. Access tokens never expire, no idempotency keys were found, and writes and most providers need a sales-led plan. ## Facts | Field | Value | | --- | --- | | Vendor | Profound Platform Inc. (dba Finch) (https://www.tryfinch.com) | | Kind | HTTP API | | Category | Payroll infrastructure (https://www.anchorterminal.com/categories/payroll) | | Transport | HTTP, stdio | | Endpoint | `https://api.tryfinch.com` | | Auth | OAuth · A person signs up for the Developer Dashboard and receives a `client_id` and `client_secret` for a free sandbox application. Access to an employer's data then needs that employer's administrator to sign in through Finch Connect and approve the requested products. The authorisation code is exchanged at POST /auth/token for a bearer access token tied to that one connection and those products. The token does not expire and is revoked with POST /disconnect. Connect sessions are created with HTTP Basic auth using the client ID and secret. The SSN permission needs Finch's approval, and Gusto and TriNet need a one-time security review before going live. The MCP server reads the access token from `FINCH_ACCESS_TOKEN`. | | Pricing | Paid (Paid) · Starter is $65 a month per connection, month to month, for 24 providers, up to 15 connections and read-only organisation and payroll data. Pro and Premier are sold through sales, with volume discounts from 25 connections a month, all 250+ providers, deduction writes and assisted integrations. A sandbox with mock data is free with a Dashboard signup, so an agent's owner can start without a contract, and Provider Sandboxes allow five connections to provider demo accounts. All production connections are billable (checked 2026-10-08). | | x402 | No · No x402, MPP or L402 in the documentation index, the OpenAPI specification or the pricing page (checked 2026-10-08). | | Licence | Proprietary service under Finch's Master Service Agreement. The SDKs and the MCP server on GitHub are Apache-2.0 | | Tools exposed | 2 | | Packages | npm: `@tryfinch/finch-api`; npm: `@tryfinch/finch-api-mcp`; pypi: `finch-api` | | Source | https://github.com/Finch-API/finch-api-node | | Docs | https://developer.tryfinch.com | | llms.txt | https://developer.tryfinch.com/llms.txt | | Last release | 2026-10-05 | | npm downloads / week | 16,128 | | PyPI downloads / week | 25,524 | | Surface graded | The REST API at https://api.tryfinch.com, which is generally available. The beta MCP server is a second route to the same API. Finch reaches an employer's existing payroll or HR system and does not run payroll itself | | Products | Organisation (company, directory, individual, employment), Payroll (payment, pay statement, pay statement items and rules, pay groups, ledger items), Deductions (read and write), Benefits and Documents (both labelled beta in the reference), Recordkeeper (Connect only) | | Credentials | Application `client_id` and `client_secret` per environment. An employer authorises through Finch Connect, and the authorisation code is exchanged at POST /auth/token for a bearer access token tied to one connection and its approved products. Tokens do not expire. POST /disconnect revokes one | | Integration types | Automated (OAuth, API token or credentials at the provider, 24-hour sync, deduction writes near real time) and assisted (third-party admin credentials, 7-day sync, writes within 2 business days, Pro and Premier only) | | Environments | Finch Sandbox (mock data, 100 connections, all plans), Provider Sandbox (5 connections to provider demo accounts, all plans), Development (Pro and Premier on request) and Production. Each has its own credentials | | Rate limits | Per application and endpoint on a rolling 60 seconds. 20 a minute for company, directory, documents, individual, employment and pay-statement-item. 12 a minute for payment, pay-groups and pay-statement. 1,000 requests in 5 minutes per IP, with a 60-minute penalty | | Batching and pagination | POST /employer/individual and /employer/employment take up to 10,000 IDs, and /employer/pay-statement up to 10 payment IDs. `limit` and `offset` on directory (maximum 10,000), pay-statement (5,000 per payment), documents, plans and jobs | | Errors | JSON with `code`, `name`, `finch_code` and `message`, a published table of 26 error types, and `Finch-Request-Id` on every response. 202 means data is still syncing. Server timeout is 6 minutes | | Versioning | Dated versions through the required `Finch-API-Version` header. The current and only listed version is 2020-09-17. Additive changes ship without a new version | | Webhooks | Account update, job completion and data change events, signed with HMAC-SHA256 in the `Finch-Signature` header, which can carry several signatures during a secret rotation | | MCP server | @tryfinch/finch-api-mcp 10.8.2 on npm, Apache-2.0, generated by Stainless, labelled beta. stdio by default, with a self-run Streamable HTTP mode. Two tools. Flags limit the code tool to GET operations or to allowed and blocked methods | | SDKs | Node @tryfinch/finch-api 10.8.2 (24 August 2026), Python finch-api 2.8.3 (5 October 2026), Java, Kotlin, Go and Ruby, all generated by Stainless under Apache-2.0. Finch Connect SDKs for JavaScript and React | | Plans | Starter $65 a month per connection (24 providers, 15 connections, organisation and payroll data, read-only, month to month). Pro and Premier by sales with volume discounts from 25 connections, all 250+ providers and deduction writes. Uptime SLA on Premier | | Certifications | SOC 2 Type II (2025 report on request), HIPAA, GDPR, CCPA and Data Privacy Framework self-certification per the trust centre. Federacy penetration test, 2025 | | Status | status.tryfinch.com with components for the API, Connect, the Dashboard and 26 provider integrations | | Sub-processors | Amazon Web Services (us-west-2, Oregon), Bright Data, Browserless, Datadog, Sentry and Sigma Computing per the trust centre. The DPA promises 10 days' notice before a new one is added | | Capabilities | payroll.employees, payroll.contractors, hr.employees, hr.org, hr.documents | | Tags | hosted, unified-api, payroll-data, hris, oauth, openapi, llms-txt, mcp, sandbox, webhooks, python, typescript, java, go, ruby, status-page, sla, soc2 | | JSON | https://www.anchorterminal.com/api/v1/tools/finch.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 84 | 16.8 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 87 | 14.1 | | Agent ergonomics | 13% | 16.2 | 71 | 11.5 | | Security & auth | 14% | 17.5 | 66 | 11.6 | | Payments & pricing | 10% | 12.5 | 30 | 3.8 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 84 | 7.3 | | Transparency & trust (editorial 65, provenance 82) | 7% | 8.8 | 74 | 6.5 | | Negative events | up to −15 | up to −15 | none recorded | 0 | | **Total** | | | | **71.6 → BB** | ### Why each score - Reliability 84: Read with the hosted lines and scored on the REST API. status.tryfinch.com lists components for the API, Connect, the Dashboard and 26 provider integrations, with incident history (20). Four incidents between 9 July and 8 October 2026, three marked minor and one with no impact. They were elevated Connect errors for QuickBooks Payroll (9 to 27 July), delayed syncs for Gusto (27 July), delayed data syncs (10 August) and missing start dates on Justworks connections (24 September). None was an outage of the core API, so this reads as minor incidents only (20). Limits with numbers, 20 or 12 requests a minute per endpoint and application and 1,000 per five minutes per IP (15). 429 errors carry a `finch_code` naming the limit, and the docs say to wait 60 seconds and back off exponentially. No `Retry-After` header is documented and no idempotency keys were found for deduction writes (9 of 15). A Service Level Description commits to 99.90 per cent monthly uptime with credits, for customers whose order form includes it, which the pricing page puts on Premier (10). The REST API carries no beta label. Benefits and Documents endpoints and the MCP server are labelled beta (10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 87: One OpenAPI 3.1 file at developer.tryfinch.com/openapi.json with 55 operations and 144 schemas (25). llms.txt indexes 127 lines of guides and reference, and each page is served as Markdown (10). Guides say which endpoint to use for automated and assisted connections and how to read a 202. Operation descriptions in the specification are one line on most operations, and eight sandbox operations have none (13 of 20). Schemas carry 116 enums and required fields. POST /forward takes a free-form request for the provider (12 of 15). Curl and JSON examples in the guides, an error schema and a table of error types. The specification documents an error response on 30 of 55 operations (12 of 15). Dated versions through the `Finch-API-Version` header, and a public changelog with 344 dated entries (15). - Agent ergonomics 71: `limit` and `offset` size directory, pay statement, documents and plans responses, and batch endpoints take many IDs in one call. No per-request field selection was found. Data Access Controls remove fields for a whole application on Pro and Premier. The MCP server exposes two tools (18 of 25). Offset pagination on five list endpoints, date ranges on payments and name, type and category filters on pay statement items. Most reads have no filters (14 of 20). Errors carry `code`, `name`, `finch_code` and `message` with a published table, and `Finch-Request-Id` is on every response. We saw this shape on a live unauthenticated request (17 of 20). No idempotency keys. Deduction writes return a `job_id` to poll, and enrolment is documented as an overwrite. The MCP `search_docs` tool sets readOnlyHint, and no annotations were found on the code tool (8 of 20). SDKs in six languages. Every request needs the version header (14 of 15). - Security & auth 66: An employer authorises each connection through Finch Connect, and the resulting bearer token is tied to that connection and to named products such as `directory`, `payment` and `ssn`. POST /disconnect revokes it. The token never expires and no rotation method was found (24 of 30). Product permissions separate reads from deduction writes, Starter is read-only, SSN needs Finch's approval, and the MCP server can be limited to GET operations. Its source notes that method blocking is a string match and can be evaded. No confirmation step for writes was found (14 of 20). Responses carry employer-entered text such as names and custom fields. The MCP page advises read-only tokens and care over which model receives the data, with no guidance on injected text (5 of 15). The Dashboard has an activity log of requests, and every response carries a request ID. No log export or API was found (10 of 15). SOC 2 Type II and a 2025 penetration test per the trust centre. No security.txt, bug bounty or disclosure policy was found (13 of 20). - Payments & pricing 30: Read with the hosted rubric. No x402, MPP or L402 (0). Starter is published at $65 a month per connection. Pro and Premier, which cover most providers and all writes, are priced through sales (15 of 20). A sandbox with mock data is free with a Dashboard signup and no card step is described. It reaches no real employer, so partial credit (15 of 20). A person signs up in a browser, and an employer's administrator must sign in through Finch Connect for every connection (0). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 84: The changelog's latest entry is 30 September 2026, and the Python SDK 2.8.3 was published on 5 October 2026 (30). Nineteen dated changelog entries since 10 July, and ten Node SDK releases in the same period (20). Closed service with a dated changelog and support by email and help centre, plus Slack on Pro and Premier. We could not read the SDK repositories' issue replies (11 of 15). Official SDKs in six languages are current. The official MCP registry has no Finch entry (15). The SDK repositories run CI, release through release-please and have lock files. We could not confirm the CI result (8 of 10). - Transparency & trust 74: Closed service. The Master Service Agreement (7 August 2026), Terms of Service (24 March 2022), DPA and Service Level Description are public, and the SDKs and MCP server are Apache-2.0 (18 of 30). The privacy policy (31 July 2025) says Finch processes end-user data only on the developer customer's behalf, and the DPA commits to return or deletion at termination. Retention is described as for as long as the account is open, with no periods. The MSA lets Finch use data about the service, including data derived from customer data, to improve its services and disclose it in aggregate or de-identified form (20 of 30). A versioning page defines which changes are backward compatible and says breaking changes get a new dated version. No notice period was found, and the terms allow discontinuing any part of the service at Finch's discretion (9 of 20). The trust centre names six sub-processors with AWS us-west-2 as the hosting location, and the DPA promises 10 days' notice of additions (18 of 20). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (19 items): https://www.anchorterminal.com/fixes/finch.md (JSON https://www.anchorterminal.com/fixes/finch.json) ### What we couldn't check - unchecked: live API behaviour beyond two unauthenticated requests. We had no sandbox credentials, so limits, 202 handling and writes are as documented - unchecked: the pricing page's plan comparison table. Its cells render as icons our reader could not tell apart, so plan contents are taken from the plan cards and the docs - unchecked: whether Starter production credentials are issued without contacting Finch. The Dashboard sits behind a login - unchecked: the sub-processor list linked from the DPA, a Notion page our reader could not render. The six names come from the trust centre - unchecked: the SOC 2 report and penetration test, which the trust centre releases on request - unchecked: GitHub stars, open issues and CI results for the SDK repositories. The GitHub API refused our requests for a rate limit - unchecked: whether 429 responses carry a `Retry-After` header in practice. None is documented - The lead called Finch a way to reach an employer's payroll with an official MCP server. Both hold, but the MCP server is beta and local, and Finch cannot run a payroll, so `payroll.run` is not claimed ### Sources - documentation index for agents: (seen 2026-10-08) - OpenAPI specification: (seen 2026-10-08) - quickstart: (seen 2026-10-08) - permissions (product scopes): (seen 2026-10-08) - rate limits: (seen 2026-10-08) - error types: (seen 2026-10-08) - handling 202 and null responses: (seen 2026-10-08) - rate limit and batch error guidance: (seen 2026-10-08) - headers and versioning: (seen 2026-10-08) - API changes policy: (seen 2026-10-08) - environments and sandbox: (seen 2026-10-08) - developer account and dashboard: (seen 2026-10-08) - integration types and sync cadence: (seen 2026-10-08) - developer FAQs (token lifetime, encryption): (seen 2026-10-08) - reading data, pagination: (seen 2026-10-08) - writing deductions: (seen 2026-10-08) - MCP server page: (seen 2026-10-08) - webhooks: (seen 2026-10-08) - changelog: (seen 2026-10-08) - Node SDK and MCP server source: (seen 2026-10-08) - Python SDK source: (seen 2026-10-08) - npm package: (seen 2026-10-08) - PyPI package: (seen 2026-10-08) - pricing: (seen 2026-10-08) - Master Service Agreement: (seen 2026-10-08) - Terms of Service: (seen 2026-10-08) - privacy policy: (seen 2026-10-08) - DPA: (seen 2026-10-08) - Service Level Description: (seen 2026-10-08) - security page: (seen 2026-10-08) - trust centre: (seen 2026-10-08) - status incidents: (seen 2026-10-08) - official MCP registry search: (seen 2026-10-08) - domain registration: (seen 2026-10-08) ## Who's behind it (provenance 82/100, checked 2026-10-08) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Profound Platform Inc. (dba Finch) | 20/20 | | Domain age | tryfinch.com, registered 2020-03-30 (6 years) | 11/15 | | Endpoint on the vendor's domain | api.tryfinch.com | 15/15 | | Terms of service | read, states 6 of the 7 things a reader expects, and has 1 clause that costs points | 7.1/10 | | Privacy policy | read, states 6 of the 8 things a reader expects | 8.5/10 | | Status page | status.tryfinch.com | 10/10 | | Changelog | published | 10/10 | | security.txt | not found | 0/10 | The Master Service Agreement (last updated 7 August 2026) names Profound Platform Inc. (dba Finch), a Delaware corporation. The site footer reads Finch Inc. The site also publishes Terms of Service dated 24 March 2022 at tryfinch.com/legal/terms, which cover the website and self-serve use, a DPA dated 7 August 2026 at /legal/dpa and a Service Level Description at /legal/sla. The privacy policy (effective 31 July 2025) gives the address 2261 Market Street #4127, San Francisco, CA 94114, and says Finch processes developer customers' end-user data only on their behalf. www.tryfinch.com/.well-known/security.txt and tryfinch.com/.well-known/security.txt return 404. The API answers at api.tryfinch.com and Finch Connect at connect.tryfinch.com. RDAP for tryfinch.com gives a registration date of 2020-03-30 and Squarespace Domains II LLC as registrar. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://www.tryfinch.com/legal/msa), read 2026-10-08, dated 2026-08-07, states 6 of the 7 things a reader expects. - To know. Restricts benchmarking or competitive use (costs points). "clone or otherwise use the Services to build an application programming interface, application or product that is competitive with any Finch product or service" - Gives the date it was last updated. Last updated 2026-08-07. - Names the governing law or courts. The law of the State of California. - States a limit on its liability. Capped at the fees paid in the 12 months before the claim. - Not found in the text. Says how changes to the terms are announced. - Also in the text (2026-10-08). Finch may collect and analyse information concerning Customer Data and data derived from it, and use it during and after the term to improve its services and other Finch products. "use such information and data to improve and enhance the Services and for other development, diagnostic and corrective purposes in connection with the Services and other Finch products and services" - Also in the text (2026-10-08). The agreement renews automatically unless the customer gives 60 days' written notice, and Finch may change fees at the end of a term with any increase being at least five per cent. "to institute new charges and Fees at the end of the then-current Term (as defined below), upon sixty (60) days’ prior notice to Customer (which may be sent by email), with any such increase being a minimum of five percent (5%) based on the Fees for the prior Term." - Also in the text (2026-10-08). Finch may include the customer's name and logo in its customer list, marketing and pitch materials, and the parties are to issue a joint press release within 30 days. "Finch shall be permitted to include Customer’s name and logo in its customer list, marketing and pitch materials." **Privacy policy** (https://www.tryfinch.com/legal/privacy), read 2026-10-08, gives no date, states 6 of the 8 things a reader expects. - To know. Says it sells personal data or shares it for advertising. "Depending on state laws that may be applicable to you, some of these disclosures may constitute a “sale” of your Personal Data." - Not found in the text. Gives the date it was last updated. - Says how long data is kept. For as long as needed, with no period named. - Says whether personal data is sold or shared for advertising. Says it does not sell personal data. - Not found in the text. Gives a privacy contact. - Says where data is transferred or stored. Relies on the Data Privacy Framework. - Also in the text (2026-10-08). Finch states that it processes personal data collected by its developer customers from their end users only on behalf of each developer customer. "We process this Developer Customer Personal Data only on behalf of each Developer Customer." ## Live (updated 2026-10-08 20:22 UTC) - Right now: up, HTTP 400, 425 ms, checked 2026-10-08 20:21 UTC (get on `https://api.tryfinch.com`) - Uptime 24h 100.0% (32 probes) · 30 days 100.0% (32 probes) · p50 452 ms · p95 542 ms - Vendor status page: none, All Systems Operational - Watching changelog - Watching privacy - Watching terms - Always current: https://www.anchorterminal.com/api/v1/live/finch.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Prices | Item | Price | Unit | Note | | --- | --- | --- | --- | | Starter, one employer connection | $65 | per connected account per month | read-only, 24 providers, up to 15 connections. Pro and Premier priced by sales | Across all listings: https://www.anchorterminal.com/prices/index.md ## Strengths - One OpenAPI 3.1 file covers 55 operations, and llms.txt indexes the documentation with every page served as Markdown - Each access token is tied to one employer connection and limited to the products that employer approved, with SSN as a separate permission needing Finch's approval - Rate limits are published per endpoint (20 or 12 requests a minute per application), with 429 errors that name which limit was hit - A 99.90 per cent monthly uptime SLA with service credits is published for plans whose order form includes it - Official SDKs for Node, Python, Java, Kotlin, Go and Ruby, with Node 10.8.2 and Python 2.8.3 released in the last 50 days - A public DPA dated 7 August 2026, and a trust centre naming six sub-processors with hosting in AWS us-west-2 ## Weaknesses - Finch cannot create, preview or approve a payroll. Writes are limited to deductions and contributions, on Pro and Premier plans - An access token does not expire until the connection is disconnected, and no rotation method was found in the reviewed documentation - No idempotency keys were found, and no `Retry-After` header is documented on 429 responses - Data is synced, not live. Automated integrations refresh every 24 hours and assisted integrations every 7 days - Starter is $65 a month per connection for 24 providers and 15 connections. The other 250+ providers and deduction writes have no public price - The MCP server is labelled beta, runs locally over stdio and is not in the official MCP registry ## Before you call it (notes for agents) 1. Send `Finch-API-Version: 2020-09-17` and `Authorization: Bearer ` on every request. A request without the version header fails with 400 2. Call GET /introspect first to see the connection's products, status and whether it is automated or assisted before choosing endpoints 3. Treat a 202 response as data not ready, not as data. Retry with backoff, and expect up to 14 days for an assisted connection's first sync 4. Stay under 20 requests a minute on organisation endpoints and 12 on pay endpoints across all tokens. Batch IDs, and on 429 wait 60 seconds 5. After a deduction write, poll the job by `job_id` until it completes before enrolling individuals. Enrolment overwrites an existing enrolment 6. Start the MCP server with `--code-allow-http-gets` or a token without the benefits product when only reads are intended ## Connect Install: ```bash pip install finch-api ``` First request: ```bash curl https://api.tryfinch.com/employer/directory \ -H 'Authorization: Bearer ' \ -H 'Finch-API-Version: 2020-09-17' ``` MCP client configuration: ```json { "mcpServers": { "finch_api": { "args": [ "-y", "@tryfinch/finch-api-mcp" ], "command": "npx", "env": { "FINCH_ACCESS_TOKEN": "\u003ca specific connection's access token\u003e" } } } } ``` Through letme (picks today, calling later): https://letme.dev/finch (letme picks it for hr.documents, the top-graded tool for the job, letme picks it for hr.employees, the top-graded tool for the job, letme picks it for hr.org, the top-graded tool for the job, letme picks it for payroll.contractors, the top-graded tool for the job, letme picks it for payroll.employees, the top-graded tool for the job). letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Paychex | E | 44.8 | 666 | payroll.employees, hr.employees, hr.documents, hr.org | no | https://www.anchorterminal.com/tools/paychex.md | | Deel | B | 69.1 | 168 | hr.employees, hr.org, hr.documents | no | https://www.anchorterminal.com/tools/deel.md | | Factorial | B | 66.3 | 239 | hr.employees, hr.org, hr.documents | no | https://www.anchorterminal.com/tools/factorial.md | | BambooHR | C | 61.7 | 357 | hr.employees, hr.org, hr.documents | no | https://www.anchorterminal.com/tools/bamboohr.md | | Rippling | C | 60.8 | 386 | hr.employees, hr.org, hr.documents | no | https://www.anchorterminal.com/tools/rippling.md | | HiBob | C | 57 | 484 | hr.employees, hr.org, hr.documents | no | https://www.anchorterminal.com/tools/hibob.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - The API reads company, directory, individual, employment, payment, pay statement, pay group and ledger data, and writes only deductions and pay statement item rules (source: ) - Automated integrations sync every 24 hours and assisted integrations every 7 days, with a one-time set-up period of one to two weeks for assisted connections (source: ) - An access token does not expire unless the connection is disconnected (source: ) - Starter is $65 a month per connection, read-only, with 24 providers and up to 15 connections. Pro and Premier are priced through sales (source: ) - The MCP server is labelled beta. It is the npm package @tryfinch/finch-api-mcp, run over stdio, with two tools (`search_docs` and a code tool that runs TypeScript against the SDK in a local Deno sandbox) (source: ) - The SLA commits to 99.90 per cent monthly uptime with credits of 5 to 20 per cent of the monthly fee, where the order form includes it. Provider outages are excluded (source: ) - status.tryfinch.com lists four incidents between 9 July and 8 October 2026, three marked minor and one with no impact, each tied to a provider integration or to delayed syncs (source: ) - The trust centre lists a SOC 2 Type II report for 2025, a Federacy penetration test for 2025 and six sub-processors, with hosting in AWS us-west-2 (source: ) ## Compare - [Argyle vs Finch](https://www.anchorterminal.com/compare/argyle-vs-finch.md): B 63.7 vs BB 71.6 - [Check vs Finch](https://www.anchorterminal.com/compare/check-payroll-vs-finch.md): B 67.5 vs BB 71.6 - [Employment Hero Payroll vs Finch](https://www.anchorterminal.com/compare/employment-hero-vs-finch.md): D 50.4 vs BB 71.6 - [Everee vs Finch](https://www.anchorterminal.com/compare/everee-vs-finch.md): C 55.1 vs BB 71.6 - [Finch vs Gusto](https://www.anchorterminal.com/compare/finch-vs-gusto.md): BB 71.6 vs B 63.3 - [Finch vs Paychex](https://www.anchorterminal.com/compare/finch-vs-paychex.md): BB 71.6 vs E 44.8 - [Finch vs Salsa](https://www.anchorterminal.com/compare/finch-vs-salsa.md): BB 71.6 vs D 46.1 - [Finch vs Zeal](https://www.anchorterminal.com/compare/finch-vs-zeal.md): BB 71.6 vs E 45.4 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on tryfinch.com or one of its subdomains, or the README of github.com/Finch-API/finch-api-node. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "finch", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Finch on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Finch on Anchor Terminal](https://www.anchorterminal.com/badges/finch.svg)](https://www.anchorterminal.com/tools/finch) ``` Plain link: ```html Finch on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Finch is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/finch-dark.png - Light: https://www.anchorterminal.com/assets/share/finch-light.png