Flinks
by Flinks Technology Inc. (National Bank of Canada) HTTP API in Bank data & open banking
Flinks Technology Inc. · flinks.com since 1997 · status page · who's behind it
Flinks is a Canadian bank-data aggregator owned by National Bank of Canada. Its REST API and Flinks Connect widget read accounts, balances, transactions and holder details from Canadian and US institutions with the holder's consent, and start Canadian bank payments.
Good for A lender or fintech with steady volume that needs Canadian bank data, income and lending attributes, PDF statements or Canadian bank payments.
Is this your product? Claim this listing or verify it
Assessment. Ten public OpenAPI files, an llms.txt index with Markdown twins and published sandbox keys let an agent start without a signup. Live access needs a one-year contract from $500 a month, keys never expire, no rate-limit numbers are published, and the status page logged 77 incidents in 90 days.
Facts
- Transport
- HTTP
- Auth
- API key
- Pricing
- Paid · Paid
- x402
- No
- Licence
- Proprietary service under Flinks' Master Terms and Conditions. No open-source SDK or repository was found
- Docs
- docs.flinks.com
- llms.txt
- published
- Last release
- API
- REST over HTTPS, TLS 1.2 or later, at https://{instance}-api.private.fin.ag/v3/{customerId}/. One instance per customer and country. The main OpenAPI file lists 34 operations
- Data endpoints
/GetAccountsSummary,/GetAccountsDetail(accounts, balances, transactions, holder name, address, email and phone),/GetStatements(bank-issued PDF statements),/Institutions,/FieldMatchfor identity checks- Consent
- The account holder connects in the Flinks Connect iframe, with bank credentials or the institution's OAuth flow. The connection has no expiry.
/DeleteCardremoves the stored credentials, holder details and account data. Flinks Outbound has/api/v1/revoke - Sessions
- Authorise token single-use, 15 minutes.
requestIdends after 8 minutes of inactivity or 30 minutes of processing, or when/GetAccountsDetail,/GetAccountsDetailAsyncor/GetStatementscompletes - Transactions
- Posted transactions only,
DaysOfTransactionsofDays90orDays365, in one payload.WithTransactions,WithKYCandAccountsFiltertrim the response - Async
/GetAccountsDetailanswers 202 while data is processed. Poll/GetAccountsDetailAsyncevery 10 seconds, at most 30 minutes, or receive a webhook- Rate limits
- No numbers published.
TOO_MANY_REQUESTSis listed under HTTP 401 - Enrich
- Attributes endpoints for income, lending, credit risk and business analysis, and
/GetCategorization. Flinks says 4,500+ attributes - Payments
- Flinks Pay, Canada only. Session-based APIs for EFT (pre-authorised debit), Guaranteed EFT and Interac e-Transfer Request Money, with their own
/Authorizeand Bearer token - Open banking
- Flinks Outbound at https://ob.flinksapp.com, OAuth 2.0 with FDX version 5 paths for customers, accounts, transactions and statements, paged with
offsetandlimit - Sandbox
- Shared Toolbox instance at https://toolbox-api.private.fin.ag with published keys, the Flinks Capital test bank and test users for MFA and error cases. Webhooks cannot be tested there
- Webhooks
- Enabled by a support ticket. HMAC-SHA256 signature in
flinks-authenticity-key. Up to 10 retries, 30 minutes apart - Coverage
- Canada and the United States. Flinks says 15,000+ financial institutions across North America
- Service level
- Best efforts at 99 per cent monthly availability for the connection method and Flinks Connect, excluding maintenance and bank-side faults, per the Master Terms
- Certifications
- SOC 2 Type II per the docs and the data safety page, with the report on request. The Master Terms also commit to ISO 27001 audit reports
- AI resources
- llms.txt, Markdown twins, a skill file at https://docs.flinks.com/skill.md and a documentation MCP server at https://docs.flinks.com/mcp with two read-only tools
- SDKs
- None found. Mobile apps load Flinks Connect in a WebView
Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- Ten OpenAPI 3.0 files are public at docs.flinks.com, 85 operations in all, with the main Connect and Enrich file holding 34
- Shared sandbox keys for the Toolbox instance are published in the docs, so test calls need no account
- llms.txt lists 216 pages with Markdown twins, and the docs add a skill file and a read-only documentation MCP server
- Plan prices are public. Connect starts at $500 a month for 200 unique connections, with no integration or platform fee
- Each instance is hosted in the country it serves, Canada or the US, and
/DeleteCarddeletes all data held for a connection
Weaknesses
- Live access needs a contract with a monthly minimum and a one-year term. The pricing page says there is no pay-as-you-go plan or self-serve trial
- The secret key,
x-api-keyand HMAC secret do not expire, and no scopes or rotation steps were found for the Connect API - No rate-limit numbers are published, and
TOO_MANY_REQUESTSis documented under HTTP 401 with no Retry-After - status.flinks.com lists 77 incidents in the 90 days to 8 October 2026, 16 of them on Flinks' own components
/GetAccountsDetailreturns the whole 90 or 365 days of transactions in one payload with no pagination, and no official SDK was found
Before you call it notes for agents
- Call
/GenerateAuthorizeTokenwith the secret key inflinks-auth-key, then pass the returned token to the Connect iframe or to/Authorize. The token is single-use and expires after 15 minutes. - Send the account holder through Flinks Connect in a browser. The API alone cannot complete a first bank login, and sandbox iframes need
demo=true. - Store the
loginId. Call/Authorizewith it andMostRecentCached: truefor a newrequestIdeach session, because/GetAccountsDetailconsumes therequestId. - On a 202 from
/GetAccountsDetail, poll/GetAccountsDetailAsyncevery 10 seconds for at most 30 minutes, or ask support to enable webhooks. - Route each end user to the instance for their country. A
loginIdfrom the Canadian instance is not valid on the US one.
Who's behind it provenance 71/100
- Legal entity namedFlinks Technology Inc.20/20
- Domain ageflinks.com, registered 1997-06-03 (29 years)15/15
- Endpoint on the vendor's domain is not on flinks.com0/15
- Terms of serviceread, states 6 of the 7 things a reader expects, and has 1 clause that costs points7.1/10
- Privacy policyread, states 7 of the 8 things a reader expects9.3/10
- Status pagestatus.flinks.com10/10
- Changelogpublished10/10
- security.txtnot found0/10
Terms and privacy, as read
Terms of service dated 2023-08-03, states 6 of 7, 2 to know
TL;DR Dated 2023-08-03. States 6 of the 7 things a reader expects, and we didn't find what users may not do. To know before relying on it, changes without notice and no update in three years.
Says the terms or the service can change without noticecosts points
By executing an Order Form, Client agrees and recognizes that Flinks may, from time to time and in its’ sole discretion, modify these Master Terms without prior notice to Client.
A customer may not hear about a change before it applies.
Has not been updated for three years or more
Last update: August 3, 2023
The date the document gives for itself is more than three years ago.
Gives the date it was last updated Last updated 2023-08-03
Last update: August 3, 2023
Without a date nobody can tell which version they agreed to.
Names the governing law or courts The law of the Province of Ontario
The Agreement is governed by, and will be interpreted and enforced in accordance with, the Laws of the province of Ontario and the federal Laws of Canada applicable therein.
Says where a dispute would be heard and under whose law.
States a limit on its liability Capped at the fees paid in the 12 months before the claim
…LAW, EITHER PARTY’S TOTAL LIABILITY TO THE OTHER PARTY UNDER OR ARISING OUT OF THE AGREEMENT WILL BE LIMITED TO THE AGGREGATE AMOUNTS PAID OR DUE AND OWING BY CLIENT TO FLINKS HEREUNDER IN THE TWELVE (12) MONTH PERIOD PRIOR TO THE ORIGINATION OF THE CLAIM ASSERTING LIABILITY.
Says the most the vendor would owe if the service causes a loss.
Says how the agreement or account can be ended
Either party may terminate the Master Terms or any individual Order Form upon thirty (30) days’ prior written notice to the other party where such other party breaches any of its material obligations hereunder, and such breach is not cured, or is incapable of being cured, within the foregoing thirty (30) day notice pe…
Says when the vendor can cut off access and what notice it gives.
Says how changes to the terms are announced Says it gives notice of a change
By executing an Order Form, Client agrees and recognizes that Flinks may, from time to time and in its’ sole discretion, modify these Master Terms without prior notice to Client.
Says whether a customer hears about a change before it binds them.
Lists what users may not do
Not found in the text.
The acceptable-use rules an agent acting for a user has to stay inside.
Refers to a service level or uptime commitment
EXCEPT FOR FLINKS’ COMMITMENT TO PROVIDE THE SERVICE(S) IN ACCORDANCE WITH THE SERVICE LEVELS, FLINKS MAKES NO WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, STATUTORY OR OTHERWISE, REGARDING THE SERVICES, AND FLINKS SPECIFICALLY DISCLAIMS ANY IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOS…
Says whether availability is promised and where the promise is written.
The client may not make any statement about Flinks, its systems, the services or a security breach, public or otherwise, without prior written authorisation from Flinks.
Client shall not make or publish any representation or statement of any kind, whether public or otherwise, concerning Flinks, Flinks’ Systems, the Services (including any Security Breach), or Client’s use thereof, without the prior written authorization of Flinks.
Noted by a second reader on 2026-10-08.
The client must take part in one SOC 2 Type II audit each calendar year.
Client shall participate in one (1) SOC 2 Type II (or any successor authoritative guidance for reporting on service organizations) audit each calendar year.
Noted by a second reader on 2026-10-08.
On expiry or termination, end-customer data is deleted in the normal course of operations, and Flinks may keep it where required to resolve a dispute or to assert or defend a claim.
End-Customer Data will be deleted in the normal course of Flinks operations, provided however that Flinks reserves the right to preserve End-Customer Data if required to resolve a dispute or assert or defend any claim.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 9,312 words
Privacy policy dated 2022-09-22, states 7 of 8, 1 to know
TL;DR Dated 2022-09-22. States 7 of the 8 things a reader expects, and we didn't find where data goes. To know before relying on it, no update in three years.
Has not been updated for three years or more
This General Privacy Statement was last updated on September 22, 2022. From time to time, Flinks may update this General Privacy Statement to reflect changes to Flinks’ services or purposes for which…
The date the document gives for itself is more than three years ago.
Gives the date it was last updated Last updated 2022-09-22
This General Privacy Statement was last updated on September 22, 2022. From time to time, Flinks may update this General Privacy Statement to reflect changes to Flinks’ services or purposes for which…
Without a date nobody can tell which version applied when data was collected.
Says what personal data is collected
Please read the descriptions below carefully in order to understand which privacy statement applies, and how we collect, use, and share your information:
The basic statement a privacy policy exists to make.
Says how long data is kept For as long as needed, with no period named
We will store the Information you provide and Information obtained from your financial institution for as long as it is necessary to provide our clients with our services.
Says when data sent to the service is deleted.
Says who else receives the data
…bank account with one of our clients’ services (e.g., a mobile or web application or financial service provider), and the information Flinks receives as a result of your use of those client services.
Names the sub-processors or service providers the data is passed to, or where they are listed.
Says whether personal data is sold or shared for advertising Says it does not sell personal data
Flinks does not sell or obtain any monetary consideration in exchange for the personal information it shares under this Privacy Statement.
A plain statement either way.
Says what rights people have over their data
Where Flinks has collected Personal Information pursuant to this Privacy Statement, you have the right to access the records Flinks holds containing your Personal Information.
Access, correction, deletion and objection, and how to use them.
Gives a privacy contact privacy@flinks.com
however, should you have any questions about it, please let us know at privacy@flinks.com.
An address or officer to send a request to.
Says where data is transferred or stored
Not found in the text.
The countries data goes to and the safeguard used.
Flinks lists improving and further developing its existing services among the uses of personal information it receives from end customers and their financial institutions.
To improve, enhance, modify, add to, and further develop our existing services;
Noted by a second reader on 2026-10-08.
The service providers that process personal information for Flinks include other data aggregators, used for redundancy during an outage or for access to institutions Flinks cannot reach.
Other data aggregators who provide similar services to Flinks, who provide redundancies in the event of an outage, or access to financial institutions or data Flinks may not have connectivity with.
Noted by a second reader on 2026-10-08.
Where Flinks suspects an illegal transaction through Flinks Pay, it reports the person and the transaction to FINTRAC, other authorities as required, and its parent company, National Bank of Canada.
Flinks will report information about you and any associated transaction(s) to the Financial Transactions and Reports Analysis Centre of Canada (“FINTRAC”) and any other law enforcement or regulatory body as required, as well as Flinks’ parent company, National Bank of Canada (“National Bank”)
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 13,192 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The terms link is the Master Terms and Conditions, last updated 3 August 2023, which govern use of the Flinks technology under an order form and name Flinks Technology Inc. Service schedules for connectivity, enrichment and upload are separate pages on flinks.com.
The privacy link holds the General Privacy Statement (22 September 2022) and the Services Privacy Statement (19 April 2024) on one page. The Services statement covers bank data read through the product and names National Bank of Canada as Flinks' parent company.
API calls go to https://{instance}-api.private.fin.ag and the widget to https://{instance}-iframe.private.fin.ag. Flinks Outbound answers at ob.flinksapp.com. Neither is under flinks.com, so the endpoint is recorded as off the vendor's domain. We did not confirm the registrant of fin.ag.
flinks.com/.well-known/security.txt, www.flinks.com/.well-known/security.txt and docs.flinks.com/.well-known/security.txt return 404. The security page gives security@flinks.com for vulnerability reports.
status.flinks.com runs on incident.io. changelog.flinks.com redirects to docs.flinks.com/changelog.
Verisign RDAP gives 1997-06-03 as the registration date of flinks.com and GoDaddy.com, LLC as registrar. No street address for the company was found on the pages read.
Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-08 20:22 UTC
- Vendor status page all systems normal, All Systems Operational · 4 minutes ago
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/flinks.json
Notable
- The docs publish shared sandbox credentials for the Toolbox instance at https://toolbox-api.private.fin.ag, with a test bank named Flinks Capital and test users such as
Greatdaysource - Ten OpenAPI 3.0 files are linked from llms.txt, among them
openapi.yaml(34 operations),openapi-outbound.yaml(19, FDX version 5 paths) and five for Flinks Pay source - Flinks Connect uses credential-based access, where the account holder types online banking credentials into the widget, and OAuth where an institution supports it. The Connect product page says OAuth covers 9 of the 10 largest US banks source
- A
loginIdis permanent and Flinks keeps the stored credentials, holder details and accounts until/DeleteCardis called source - The docs site has an MCP server at https://docs.flinks.com/mcp with two read-only tools that search and read the documentation. It does not call the Flinks API source
- A skill file for AI coding assistants at https://docs.flinks.com/skill.md summarises the integration flow in one file source
- The Master Terms and Conditions, last updated 3 August 2023, commit Flinks to best efforts at 99 per cent monthly availability and let Flinks modify the terms without prior notice source
- The OpenAPI file says an authorise token is valid for 30 minutes, while the authentication guide and the skill file say 15 minutes source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 10.6 | |
Graded with the hosted lines. status.flinks.com on incident.io has seven product components plus one per bank, with history (20). In the 90 days to 8 October 2026 the history lists 77 incidents and two maintenance windows. 61 are named for a single institution. 16 are on Flinks' own components, among them Data Aggregation for 26 hours 45 minutes from 12 July, Enrich and the Dashboard for 44 hours from 19 August, and one on 6 August that marked Data Aggregation as a partial outage. None is labelled major. The checklist gives 20 for minor incidents only, and we score 12 of 30 because of their number and length. No rate-limit numbers are published (0). TOO_MANY_REQUESTS is documented under HTTP 401 with no Retry-After. The docs give a 10-second polling interval and a 30-minute cap for 202 responses, and no idempotency keys were found (5 of 15). The Master Terms commit to best efforts at 99 per cent monthly availability, with no service credits (6 of 10). The v3 API is generally available (10). | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 13.5 | |
Ten OpenAPI 3.0 files are public, 85 operations in all, 34 in the main file. The main file marks x-api-key as optional while the authentication guide requires it (23 of 25). llms.txt lists 216 pages with Markdown twins, plus a skill file and a documentation MCP server (10). All 34 operations in the main file carry a description, and the guides say when to use cached mode and when not to (14 of 20). Parameters are typed with defaults, the main file has 10 enums, and SecurityResponses is a free-form object (10 of 15). The main file has 116 example values and the error page lists codes with how to reproduce each. The spec says the authorise token lasts 30 minutes and the guide says 15 (11 of 15). The version is in the path (v3) and the changelog has monthly entries back to September 2021 (15). | |||
| Agent ergonomics | 13%16.2 | 8.8 | |
WithTransactions, WithKYC, AccountsFilter and DaysOfTransactions trim a response, and /GetAccountsSummary is a lighter call. No field selection was found (16 of 25). /GetAccountsDetail returns up to 365 days of transactions in one payload with no pagination. /Institutions takes skip and take, and the Outbound FDX paths take offset, limit and time filters (10 of 20). The error page lists 29 codes with a description and a way to reproduce each, though most sit under HTTP 401, the rate-limit code among them (14 of 20). No idempotency keys were found. Cached-mode reads can be repeated, and a completing call consumes the requestId (8 of 20). RequestId is the only required body field and defaults are stated, but a first read takes three calls plus a widget session and no official SDK was found (6 of 15). | |||
| Security & auth | 14%17.5 | 8.8 | |
A secret key and an x-api-key, both issued by Flinks, neither expiring, with no scopes and no documented rotation for the Connect API. The authorise token is single-use and lasts 15 minutes. Outbound has an endpoint to regenerate a client secret. A partner access token travels in the URL path of /partneraccess/{accesstoken}, which is not a query string, so no deduction (14 of 30). The Connect data API reads bank data and cannot move money. Flinks Pay has its own authorisation. /DeleteCard deletes a connection's data with no confirmation step, and credential-based connections mean Flinks stores bank logins (10 of 20). Responses carry bank-written transaction descriptions, and no guidance on treating them as untrusted was found (7 of 15). The Dashboard's Request Feed lists every request with status, requestId and loginId, with roles, 2FA and IP allow-listing for staff. No API audit log was found (8 of 15). SOC 2 Type II is stated with the report on request, the Master Terms commit to ISO 27001 audit reports, and the security page gives security@flinks.com for vulnerability reports. No security.txt or bug bounty was found (11 of 20). | |||
| Payments & pricing | 10%12.5 | 3.1 | |
| No x402, MPP or L402 (0). Plan prices are public with included volumes, from $500 a month for 200 connections. Overage rates sit in the contract and the currency is not stated (10 of 20). The Toolbox sandbox is free with no card. There is no free live tier or self-serve trial (10 of 20). Sandbox keys are published in the docs, so an agent can make test calls with no signup. Live access needs a sales contract with a one-year term (5 of 20). | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 2.7 | |
| The newest changelog entry is dated 1 September 2026, 37 days before the check (20 of 30). Two dated entries fall in the last 90 days, on 1 August and 1 September, so the line for three is not met (0). Closed service with a monthly changelog and a support portal for tickets. Response times were not sampled (8 of 15). No official SDK or package was found. We give 3 of 15 for the current skill file and documentation MCP server, a departure from the checklist. No public package or CI to assess (0 of 10). | |||
| Transparency & trusteditorial 48, provenance 71 | 7%8.8 | 5.2 | |
Closed service with public Master Terms dated 3 August 2023 and service schedules. The terms say Flinks may modify them without prior notice (15 of 30). The Services Privacy Statement of 19 April 2024 says data is kept as long as needed for the client's service, the docs say a connection's data is kept until /DeleteCard is called, and the terms say end-customer data is deleted in the normal course after termination. No fixed retention periods and no public DPA were found (16 of 30). No deprecation policy was found. The changelog notes that the Pay V1 endpoint stays supported, and the terms let Flinks remove any data source at its discretion (5 of 20). Instances are hosted per country so data stays in Canada or the US, the security page names Microsoft Azure and Google Cloud, and the privacy statement lists most other service providers by category only (12 of 20). Regulatory standing counts here as an addition to the checklist (+5 for a named regulator with a register number, +3 for a named regulator alone). The privacy statement says Flinks reports suspicious Flinks Pay transactions to FINTRAC, and no registration number was found (+0). | |||
| Negative events | ≤15 | None recorded | 0 |
| Total | 52.7 · D | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 19 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Flinks, or have the agent fetch /fixes/flinks.md. A fix counts at the next check, once it's public.
Show it
# Fix list: Flinks
From Anchor Terminal's listing at https://www.anchorterminal.com/tools/flinks, the October 2026 research run, assessed 8 October 2026. Grade D, 52.7 out of 100.
This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.
For a coding agent working on Flinks: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.
## 1. Reliability, 53 out of 100, up to 9.4 more on the total
Why it scored 53: Graded with the hosted lines. status.flinks.com on incident.io has seven product components plus one per bank, with history (20). In the 90 days to 8 October 2026 the history lists 77 incidents and two maintenance windows. 61 are named for a single institution. 16 are on Flinks' own components, among them Data Aggregation for 26 hours 45 minutes from 12 July, Enrich and the Dashboard for 44 hours from 19 August, and one on 6 August that marked Data Aggregation as a partial outage. None is labelled major. The checklist gives 20 for minor incidents only, and we score 12 of 30 because of their number and length. No rate-limit numbers are published (0). `TOO_MANY_REQUESTS` is documented under HTTP 401 with no Retry-After. The docs give a 10-second polling interval and a 30-minute cap for 202 responses, and no idempotency keys were found (5 of 15). The Master Terms commit to best efforts at 99 per cent monthly availability, with no service credits (6 of 10). The v3 API is generally available (10).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):
Hosted APIs, MCP servers, models and platforms.
- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).
- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.
- 15, rate limits documented with numbers.
- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.
- 10, an SLA published for any paid tier.
- 10, the surface agents use is generally available, not beta or preview.
Local packages, SDKs, frameworks and stdio MCP servers.
- 20, installs from an official package with supported runtimes stated.
- 25, a public CI and test suite, passing on the default branch.
- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).
- 15, semver discipline and breaking changes called out in a changelog.
- 15, version 1.0 or later, or declared stable.
Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.
## 2. Payments & pricing, 25 out of 100, up to 9.4 more on the total
Why it scored 25: No x402, MPP or L402 (0). Plan prices are public with included volumes, from $500 a month for 200 connections. Overage rates sit in the contract and the currency is not stated (10 of 20). The Toolbox sandbox is free with no card. There is no free live tier or self-serve trial (10 of 20). Sandbox keys are published in the docs, so an agent can make test calls with no signup. Live access needs a sales contract with a one-year term (5 of 20).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):
The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).
- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.
- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login.
- 20, a free tier or trial that doesn't need a card.
- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).
Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.
Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.
## 3. Security & auth, 50 out of 100, up to 8.8 more on the total
Why it scored 50: A secret key and an `x-api-key`, both issued by Flinks, neither expiring, with no scopes and no documented rotation for the Connect API. The authorise token is single-use and lasts 15 minutes. Outbound has an endpoint to regenerate a client secret. A partner access token travels in the URL path of `/partneraccess/{accesstoken}`, which is not a query string, so no deduction (14 of 30). The Connect data API reads bank data and cannot move money. Flinks Pay has its own authorisation. `/DeleteCard` deletes a connection's data with no confirmation step, and credential-based connections mean Flinks stores bank logins (10 of 20). Responses carry bank-written transaction descriptions, and no guidance on treating them as untrusted was found (7 of 15). The Dashboard's Request Feed lists every request with status, `requestId` and `loginId`, with roles, 2FA and IP allow-listing for staff. No API audit log was found (8 of 15). SOC 2 Type II is stated with the report on request, the Master Terms commit to ISO 27001 audit reports, and the security page gives security@flinks.com for vulnerability reports. No security.txt or bug bounty was found (11 of 20).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-security):
- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.
- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.
- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.
- 0 to 15, audit logs or per-call visibility for the operator.
- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.
Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.
## 4. Agent ergonomics, 54 out of 100, up to 7.5 more on the total
Why it scored 54: `WithTransactions`, `WithKYC`, `AccountsFilter` and `DaysOfTransactions` trim a response, and `/GetAccountsSummary` is a lighter call. No field selection was found (16 of 25). `/GetAccountsDetail` returns up to 365 days of transactions in one payload with no pagination. `/Institutions` takes `skip` and `take`, and the Outbound FDX paths take `offset`, `limit` and time filters (10 of 20). The error page lists 29 codes with a description and a way to reproduce each, though most sit under HTTP 401, the rate-limit code among them (14 of 20). No idempotency keys were found. Cached-mode reads can be repeated, and a completing call consumes the `requestId` (8 of 20). `RequestId` is the only required body field and defaults are stated, but a first read takes three calls plus a widget session and no official SDK was found (6 of 15).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):
- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).
- 20, pagination, filtering and output-size controls.
- 20, actionable, documented error responses, codes and messages an agent can recover from.
- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.
- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.
Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.
## 5. Maintenance & community, 31 out of 100, up to 6 more on the total
Why it scored 31: The newest changelog entry is dated 1 September 2026, 37 days before the check (20 of 30). Two dated entries fall in the last 90 days, on 1 August and 1 September, so the line for three is not met (0). Closed service with a monthly changelog and a support portal for tickets. Response times were not sampled (8 of 15). No official SDK or package was found. We give 3 of 15 for the current skill file and documentation MCP server, a departure from the checklist. No public package or CI to assess (0 of 10).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):
- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.
- 20, at least three releases or dated changelog entries in the last 90 days.
- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.
- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).
- 10, package health, current dependencies and CI.
Models are read for deprecation notice periods and model churn rather than release counts.
## 6. Transparency & trust, 60 out of 100, up to 3.5 more on the total
Made of editorial 48, provenance 71.
Why it scored 60: Closed service with public Master Terms dated 3 August 2023 and service schedules. The terms say Flinks may modify them without prior notice (15 of 30). The Services Privacy Statement of 19 April 2024 says data is kept as long as needed for the client's service, the docs say a connection's data is kept until `/DeleteCard` is called, and the terms say end-customer data is deleted in the normal course after termination. No fixed retention periods and no public DPA were found (16 of 30). No deprecation policy was found. The changelog notes that the Pay V1 endpoint stays supported, and the terms let Flinks remove any data source at its discretion (5 of 20). Instances are hosted per country so data stays in Canada or the US, the security page names Microsoft Azure and Google Cloud, and the privacy statement lists most other service providers by category only (12 of 20). Regulatory standing counts here as an addition to the checklist (+5 for a named regulator with a register number, +3 for a named regulator alone). The privacy statement says Flinks reports suspicious Flinks Pay transactions to FINTRAC, and no registration number was found (+0).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):
- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.
- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).
- 0 to 20, a deprecation policy or notices with dates.
- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).
The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.
Provenance checks not met in full (half of this category, computed from checked facts):
- Endpoint on the vendor's domain: is not on flinks.com (0 of 15)
- Terms of service: read, states 6 of the 7 things a reader expects, and has 1 clause that costs points (7.1 of 10)
- Privacy policy: read, states 7 of the 8 things a reader expects (9.3 of 10)
- security.txt: not found (0 of 10)
## 7. Schema & documentation, 83 out of 100, up to 2.8 more on the total
Why it scored 83: Ten OpenAPI 3.0 files are public, 85 operations in all, 34 in the main file. The main file marks `x-api-key` as optional while the authentication guide requires it (23 of 25). llms.txt lists 216 pages with Markdown twins, plus a skill file and a documentation MCP server (10). All 34 operations in the main file carry a description, and the guides say when to use cached mode and when not to (14 of 20). Parameters are typed with defaults, the main file has 10 enums, and `SecurityResponses` is a free-form object (10 of 15). The main file has 116 example values and the error page lists codes with how to reproduce each. The spec says the authorise token lasts 30 minutes and the guide says 15 (11 of 15). The version is in the path (v3) and the changelog has monthly entries back to September 2021 (15).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):
APIs and MCP servers.
- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).
- 10, llms.txt or Markdown docs served for agents.
- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.
- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.
- 0 to 15, examples and documented error responses.
- 15, versioning and a public changelog.
Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.
## What we couldn't check
What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.
- The pricing page shows prices with a dollar sign and no currency. Whether they are Canadian or US dollars was not established, so `unitPrices` is empty
- The OpenAPI file says an authorise token is valid for 30 minutes and the guides say 15. Which is right was not tested
- unchecked: the Dashboard (signup at dashboard.flinks.com, key rotation, roles, any audit log), which sits behind a login
- unchecked: who registered fin.ag, the domain the API instances answer on, and flinksapp.com for Outbound
- unchecked: the SOC 2 Type II report and any ISO 27001 certificate, which are on request only
- unchecked: whether Flinks is registered with FINTRAC as a money services business. No registration number was found on the pages read
- No public DPA, sub-processor list with names, or deprecation policy was found on flinks.com or docs.flinks.com
- The lead was right about the vendor, the docs and the interface. It did not mention that the API answers on fin.ag, a second domain
## Weaknesses
- Live access needs a contract with a monthly minimum and a one-year term. The pricing page says there is no pay-as-you-go plan or self-serve trial
- The secret key, `x-api-key` and HMAC secret do not expire, and no scopes or rotation steps were found for the Connect API
- No rate-limit numbers are published, and `TOO_MANY_REQUESTS` is documented under HTTP 401 with no Retry-After
- status.flinks.com lists 77 incidents in the 90 days to 8 October 2026, 16 of them on Flinks' own components
- `/GetAccountsDetail` returns the whole 90 or 365 days of transactions in one payload with no pagination, and no official SDK was found
## What costs an agent a turn today
The notes we give agents before they call it. Each one is a workaround an agent shouldn't need.
- Call `/GenerateAuthorizeToken` with the secret key in `flinks-auth-key`, then pass the returned token to the Connect iframe or to `/Authorize`. The token is single-use and expires after 15 minutes.
- Send the account holder through Flinks Connect in a browser. The API alone cannot complete a first bank login, and sandbox iframes need `demo=true`.
- Store the `loginId`. Call `/Authorize` with it and `MostRecentCached: true` for a new `requestId` each session, because `/GetAccountsDetail` consumes the `requestId`.
- On a 202 from `/GetAccountsDetail`, poll `/GetAccountsDetailAsync` every 10 seconds for at most 30 minutes, or ask support to enable webhooks.
- Route each end user to the instance for their country. A `loginId` from the Canadian instance is not valid on the US one.
## When it's done
Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- The pricing page shows prices with a dollar sign and no currency. Whether they are Canadian or US dollars was not established, so
unitPricesis empty - The OpenAPI file says an authorise token is valid for 30 minutes and the guides say 15. Which is right was not tested
- unchecked: the Dashboard (signup at dashboard.flinks.com, key rotation, roles, any audit log), which sits behind a login
- unchecked: who registered fin.ag, the domain the API instances answer on, and flinksapp.com for Outbound
- unchecked: the SOC 2 Type II report and any ISO 27001 certificate, which are on request only
- unchecked: whether Flinks is registered with FINTRAC as a money services business. No registration number was found on the pages read
- No public DPA, sub-processor list with names, or deprecation policy was found on flinks.com or docs.flinks.com
- The lead was right about the vendor, the docs and the interface. It did not mention that the API answers on fin.ag, a second domain
Sources 25
- docs index for agents, with the list of OpenAPI files docs.flinks.com · seen 2026-10-08
- main OpenAPI file (34 operations) docs.flinks.com · seen 2026-10-08
- Outbound OpenAPI file (FDX paths) docs.flinks.com · seen 2026-10-08
- authentication reference docs.flinks.com · seen 2026-10-08
- testing environments and sandbox keys docs.flinks.com · seen 2026-10-08
- key concepts (loginId, requestId, retention) docs.flinks.com · seen 2026-10-08
- instances and data residency docs.flinks.com · seen 2026-10-08
- retrieve account data (202 polling) docs.flinks.com · seen 2026-10-08
- error codes docs.flinks.com · seen 2026-10-08
- webhooks guide docs.flinks.com · seen 2026-10-08
- Dashboard team management docs.flinks.com · seen 2026-10-08
- security and privacy page in the docs docs.flinks.com · seen 2026-10-08
- documentation MCP server setup docs.flinks.com · seen 2026-10-08
- skill file for AI coding assistants docs.flinks.com · seen 2026-10-08
- changelog docs.flinks.com · seen 2026-10-08
- pricing page flinks.com · seen 2026-10-08
- Master Terms and Conditions flinks.com · seen 2026-10-08
- service schedule for connectivity, Canada flinks.com · seen 2026-10-08
- privacy statements flinks.com · seen 2026-10-08
- security page flinks.com · seen 2026-10-08
- data safety page flinks.com · seen 2026-10-08
- Connect product page flinks.com · seen 2026-10-08
- status history status.flinks.com · seen 2026-10-08
- status incidents feed status.flinks.com · seen 2026-10-08
- RDAP record for flinks.com rdap.verisign.com · seen 2026-10-08
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Paid Paid Plans with a monthly minimum and a one-year term (https://www.flinks.com/pricing, checked 2026-10-08). Connect is $500 a month for 200 unique connections, $1,250 for 1,100, and custom from 20,000. Enrich is $250 a month for 100 API calls and $1,100 for 1,250. Upload is $500 a month for 20 documents and $1,500 for 100. Flinks Pay is quoted by sales. The page does not state the currency or the overage rates, and says there is no pay-as-you-go plan and no self-serve trial. The Toolbox sandbox is free, with keys published in the docs and no card.
Recent changes
- Latest release
Follow them as a feed at /feeds/tools/flinks.xml, or this listing's score history at history.json.
Connect
First request
curl --request POST \
--url https://toolbox-api.private.fin.ag/v3/{customerId}/BankingServices/GenerateAuthorizeToken \
--header 'Content-Type: application/json' \
--header 'flinks-auth-key: YOUR_SECRET_KEY'
Claude Code
claude mcp add flinks --transport http https://docs.flinks.com/mcp
Through letme picks today, calling later
GET https://letme.dev/flinks
letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.
Compare with
Plaid BBelvo BTink BTrueLayer BYapily CSalt Edge Account Information D
Head to head Akoya vs Flinks · Belvo vs Flinks · Enable Banking vs Flinks · Flinks vs GoCardless Bank Account Data · Flinks vs MX Platform API · Flinks vs Plaid · Flinks vs Salt Edge Account Information · Flinks vs Teller · Flinks vs Tink · Flinks vs TrueLayer · Flinks vs Yapily
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| Plaid Plaid | B | 69.8 | bank.accounts bank.transactions bank.identity bank.payments bank.consent | no |
| Belvo Belvo | B | 63.5 | bank.accounts bank.transactions bank.identity bank.payments bank.consent | no |
| Tink Tink AB (Visa) | B | 62.5 | bank.accounts bank.transactions bank.consent bank.payments bank.identity | no |
| TrueLayer TrueLayer | B | 62.1 | bank.accounts bank.transactions bank.identity bank.payments bank.consent | no |
| Yapily Yapily | C | 57.6 | bank.accounts bank.transactions bank.identity bank.payments bank.consent | no |
| Salt Edge Account Information Salt Edge | D | 46.7 | bank.accounts bank.transactions bank.identity bank.payments bank.consent | no |
Machine-readable
- JSON
/api/v1/tools/flinks.json· historyhistory.json· badge/badges/flinks.svg· changes feed/feeds/tools/flinks.xml - Markdown
/tools/flinks.md· slim/tools/flinks.min.md(or sendAccept: text/markdown) - Fix list
/fixes/flinks.md·/fixes/flinks.json - From a terminal
anchor tool flinks --md(the CLI) · over MCPget_tool {"slug": "flinks"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/flinks"><img src="https://www.anchorterminal.com/badges/flinks.svg" alt="Flinks on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/flinks)<a href="https://www.anchorterminal.com/tools/flinks">Flinks on Anchor Terminal</a>It counts on a page on flinks.com or one of its subdomains.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "flinks", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.


