# Flinks > Flinks is a Canadian bank-data aggregator owned by National Bank of Canada. Its REST API and Flinks Connect widget read accounts, balances, transactions and holder details from Canadian and US institutions with the holder's consent, and start Canadian bank payments. - Canonical: https://www.anchorterminal.com/tools/flinks - Markdown: https://www.anchorterminal.com/tools/flinks.md (~8,250 tokens) - Slim: https://www.anchorterminal.com/tools/flinks.min.md (~1,980 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/flinks.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-08 ## Overview **Grade D · 52.7/100 · rank #559 of 722 · #7 in Bank data & open banking · not agent-ready · confidence medium** ## Assessment Ten public OpenAPI files, an llms.txt index with Markdown twins and published sandbox keys let an agent start without a signup. Live access needs a one-year contract from $500 a month, keys never expire, no rate-limit numbers are published, and the status page logged 77 incidents in 90 days. ## Facts | Field | Value | | --- | --- | | Vendor | Flinks Technology Inc. (National Bank of Canada) (https://www.flinks.com) | | Kind | HTTP API | | Category | Bank data & open banking (https://www.anchorterminal.com/categories/banking-data) | | Transport | HTTP | | Auth | API key · Two static keys issued by Flinks at onboarding. The secret key goes in the `flinks-auth-key` header of `/GenerateAuthorizeToken` and returns a single-use authorise token that expires after 15 minutes. Data endpoints take the `requestId` from `/Authorize` plus an `x-api-key` header. Neither key expires, and no scopes were found. Webhooks are signed with HMAC-SHA256 in a `flinks-authenticity-key` header. Flinks Outbound, the open banking product, uses an OAuth 2.0 authorisation code flow with a `client_id` and `client_secret` and Bearer tokens. Sandbox keys for the shared Toolbox instance are published in the docs. Production keys come from a Flinks representative after a contract. | | Pricing | Paid (Paid) · Plans with a monthly minimum and a one-year term (https://www.flinks.com/pricing, checked 2026-10-08). Connect is $500 a month for 200 unique connections, $1,250 for 1,100, and custom from 20,000. Enrich is $250 a month for 100 API calls and $1,100 for 1,250. Upload is $500 a month for 20 documents and $1,500 for 100. Flinks Pay is quoted by sales. The page does not state the currency or the overage rates, and says there is no pay-as-you-go plan and no self-serve trial. The Toolbox sandbox is free, with keys published in the docs and no card. | | x402 | No · No x402, MPP or L402 in the docs index, the ten OpenAPI files or the pricing page (checked 2026-10-08). | | Licence | Proprietary service under Flinks' Master Terms and Conditions. No open-source SDK or repository was found | | Docs | https://docs.flinks.com | | llms.txt | https://docs.flinks.com/llms.txt | | Last release | 2026-09-01 | | API | REST over HTTPS, TLS 1.2 or later, at https://{instance}-api.private.fin.ag/v3/{customerId}/. One instance per customer and country. The main OpenAPI file lists 34 operations | | Data endpoints | `/GetAccountsSummary`, `/GetAccountsDetail` (accounts, balances, transactions, holder name, address, email and phone), `/GetStatements` (bank-issued PDF statements), `/Institutions`, `/FieldMatch` for identity checks | | Consent | The account holder connects in the Flinks Connect iframe, with bank credentials or the institution's OAuth flow. The connection has no expiry. `/DeleteCard` removes the stored credentials, holder details and account data. Flinks Outbound has `/api/v1/revoke` | | Sessions | Authorise token single-use, 15 minutes. `requestId` ends after 8 minutes of inactivity or 30 minutes of processing, or when `/GetAccountsDetail`, `/GetAccountsDetailAsync` or `/GetStatements` completes | | Transactions | Posted transactions only, `DaysOfTransactions` of `Days90` or `Days365`, in one payload. `WithTransactions`, `WithKYC` and `AccountsFilter` trim the response | | Async | `/GetAccountsDetail` answers 202 while data is processed. Poll `/GetAccountsDetailAsync` every 10 seconds, at most 30 minutes, or receive a webhook | | Rate limits | No numbers published. `TOO_MANY_REQUESTS` is listed under HTTP 401 | | Enrich | Attributes endpoints for income, lending, credit risk and business analysis, and `/GetCategorization`. Flinks says 4,500+ attributes | | Payments | Flinks Pay, Canada only. Session-based APIs for EFT (pre-authorised debit), Guaranteed EFT and Interac e-Transfer Request Money, with their own `/Authorize` and Bearer token | | Open banking | Flinks Outbound at https://ob.flinksapp.com, OAuth 2.0 with FDX version 5 paths for customers, accounts, transactions and statements, paged with `offset` and `limit` | | Sandbox | Shared Toolbox instance at https://toolbox-api.private.fin.ag with published keys, the Flinks Capital test bank and test users for MFA and error cases. Webhooks cannot be tested there | | Webhooks | Enabled by a support ticket. HMAC-SHA256 signature in `flinks-authenticity-key`. Up to 10 retries, 30 minutes apart | | Coverage | Canada and the United States. Flinks says 15,000+ financial institutions across North America | | Service level | Best efforts at 99 per cent monthly availability for the connection method and Flinks Connect, excluding maintenance and bank-side faults, per the Master Terms | | Certifications | SOC 2 Type II per the docs and the data safety page, with the report on request. The Master Terms also commit to ISO 27001 audit reports | | AI resources | llms.txt, Markdown twins, a skill file at https://docs.flinks.com/skill.md and a documentation MCP server at https://docs.flinks.com/mcp with two read-only tools | | SDKs | None found. Mobile apps load Flinks Connect in a WebView | | Capabilities | bank.accounts, bank.transactions, bank.identity, bank.payments, bank.consent | | Tags | hosted, api-key, openapi, llms-txt, webhooks, sandbox, canada, us, enterprise, sales-led, status-page, closed-source | | JSON | https://www.anchorterminal.com/api/v1/tools/flinks.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 53 | 10.6 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 83 | 13.5 | | Agent ergonomics | 13% | 16.2 | 54 | 8.8 | | Security & auth | 14% | 17.5 | 50 | 8.8 | | Payments & pricing | 10% | 12.5 | 25 | 3.1 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 31 | 2.7 | | Transparency & trust (editorial 48, provenance 71) | 7% | 8.8 | 60 | 5.2 | | Negative events | up to −15 | up to −15 | none recorded | 0 | | **Total** | | | | **52.7 → D** | ### Why each score - Reliability 53: Graded with the hosted lines. status.flinks.com on incident.io has seven product components plus one per bank, with history (20). In the 90 days to 8 October 2026 the history lists 77 incidents and two maintenance windows. 61 are named for a single institution. 16 are on Flinks' own components, among them Data Aggregation for 26 hours 45 minutes from 12 July, Enrich and the Dashboard for 44 hours from 19 August, and one on 6 August that marked Data Aggregation as a partial outage. None is labelled major. The checklist gives 20 for minor incidents only, and we score 12 of 30 because of their number and length. No rate-limit numbers are published (0). `TOO_MANY_REQUESTS` is documented under HTTP 401 with no Retry-After. The docs give a 10-second polling interval and a 30-minute cap for 202 responses, and no idempotency keys were found (5 of 15). The Master Terms commit to best efforts at 99 per cent monthly availability, with no service credits (6 of 10). The v3 API is generally available (10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 83: Ten OpenAPI 3.0 files are public, 85 operations in all, 34 in the main file. The main file marks `x-api-key` as optional while the authentication guide requires it (23 of 25). llms.txt lists 216 pages with Markdown twins, plus a skill file and a documentation MCP server (10). All 34 operations in the main file carry a description, and the guides say when to use cached mode and when not to (14 of 20). Parameters are typed with defaults, the main file has 10 enums, and `SecurityResponses` is a free-form object (10 of 15). The main file has 116 example values and the error page lists codes with how to reproduce each. The spec says the authorise token lasts 30 minutes and the guide says 15 (11 of 15). The version is in the path (v3) and the changelog has monthly entries back to September 2021 (15). - Agent ergonomics 54: `WithTransactions`, `WithKYC`, `AccountsFilter` and `DaysOfTransactions` trim a response, and `/GetAccountsSummary` is a lighter call. No field selection was found (16 of 25). `/GetAccountsDetail` returns up to 365 days of transactions in one payload with no pagination. `/Institutions` takes `skip` and `take`, and the Outbound FDX paths take `offset`, `limit` and time filters (10 of 20). The error page lists 29 codes with a description and a way to reproduce each, though most sit under HTTP 401, the rate-limit code among them (14 of 20). No idempotency keys were found. Cached-mode reads can be repeated, and a completing call consumes the `requestId` (8 of 20). `RequestId` is the only required body field and defaults are stated, but a first read takes three calls plus a widget session and no official SDK was found (6 of 15). - Security & auth 50: A secret key and an `x-api-key`, both issued by Flinks, neither expiring, with no scopes and no documented rotation for the Connect API. The authorise token is single-use and lasts 15 minutes. Outbound has an endpoint to regenerate a client secret. A partner access token travels in the URL path of `/partneraccess/{accesstoken}`, which is not a query string, so no deduction (14 of 30). The Connect data API reads bank data and cannot move money. Flinks Pay has its own authorisation. `/DeleteCard` deletes a connection's data with no confirmation step, and credential-based connections mean Flinks stores bank logins (10 of 20). Responses carry bank-written transaction descriptions, and no guidance on treating them as untrusted was found (7 of 15). The Dashboard's Request Feed lists every request with status, `requestId` and `loginId`, with roles, 2FA and IP allow-listing for staff. No API audit log was found (8 of 15). SOC 2 Type II is stated with the report on request, the Master Terms commit to ISO 27001 audit reports, and the security page gives security@flinks.com for vulnerability reports. No security.txt or bug bounty was found (11 of 20). - Payments & pricing 25: No x402, MPP or L402 (0). Plan prices are public with included volumes, from $500 a month for 200 connections. Overage rates sit in the contract and the currency is not stated (10 of 20). The Toolbox sandbox is free with no card. There is no free live tier or self-serve trial (10 of 20). Sandbox keys are published in the docs, so an agent can make test calls with no signup. Live access needs a sales contract with a one-year term (5 of 20). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 31: The newest changelog entry is dated 1 September 2026, 37 days before the check (20 of 30). Two dated entries fall in the last 90 days, on 1 August and 1 September, so the line for three is not met (0). Closed service with a monthly changelog and a support portal for tickets. Response times were not sampled (8 of 15). No official SDK or package was found. We give 3 of 15 for the current skill file and documentation MCP server, a departure from the checklist. No public package or CI to assess (0 of 10). - Transparency & trust 60: Closed service with public Master Terms dated 3 August 2023 and service schedules. The terms say Flinks may modify them without prior notice (15 of 30). The Services Privacy Statement of 19 April 2024 says data is kept as long as needed for the client's service, the docs say a connection's data is kept until `/DeleteCard` is called, and the terms say end-customer data is deleted in the normal course after termination. No fixed retention periods and no public DPA were found (16 of 30). No deprecation policy was found. The changelog notes that the Pay V1 endpoint stays supported, and the terms let Flinks remove any data source at its discretion (5 of 20). Instances are hosted per country so data stays in Canada or the US, the security page names Microsoft Azure and Google Cloud, and the privacy statement lists most other service providers by category only (12 of 20). Regulatory standing counts here as an addition to the checklist (+5 for a named regulator with a register number, +3 for a named regulator alone). The privacy statement says Flinks reports suspicious Flinks Pay transactions to FINTRAC, and no registration number was found (+0). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (19 items): https://www.anchorterminal.com/fixes/flinks.md (JSON https://www.anchorterminal.com/fixes/flinks.json) ### What we couldn't check - The pricing page shows prices with a dollar sign and no currency. Whether they are Canadian or US dollars was not established, so `unitPrices` is empty - The OpenAPI file says an authorise token is valid for 30 minutes and the guides say 15. Which is right was not tested - unchecked: the Dashboard (signup at dashboard.flinks.com, key rotation, roles, any audit log), which sits behind a login - unchecked: who registered fin.ag, the domain the API instances answer on, and flinksapp.com for Outbound - unchecked: the SOC 2 Type II report and any ISO 27001 certificate, which are on request only - unchecked: whether Flinks is registered with FINTRAC as a money services business. No registration number was found on the pages read - No public DPA, sub-processor list with names, or deprecation policy was found on flinks.com or docs.flinks.com - The lead was right about the vendor, the docs and the interface. It did not mention that the API answers on fin.ag, a second domain ### Sources - docs index for agents, with the list of OpenAPI files: (seen 2026-10-08) - main OpenAPI file (34 operations): (seen 2026-10-08) - Outbound OpenAPI file (FDX paths): (seen 2026-10-08) - authentication reference: (seen 2026-10-08) - testing environments and sandbox keys: (seen 2026-10-08) - key concepts (loginId, requestId, retention): (seen 2026-10-08) - instances and data residency: (seen 2026-10-08) - retrieve account data (202 polling): (seen 2026-10-08) - error codes: (seen 2026-10-08) - webhooks guide: (seen 2026-10-08) - Dashboard team management: (seen 2026-10-08) - security and privacy page in the docs: (seen 2026-10-08) - documentation MCP server setup: (seen 2026-10-08) - skill file for AI coding assistants: (seen 2026-10-08) - changelog: (seen 2026-10-08) - pricing page: (seen 2026-10-08) - Master Terms and Conditions: (seen 2026-10-08) - service schedule for connectivity, Canada: (seen 2026-10-08) - privacy statements: (seen 2026-10-08) - security page: (seen 2026-10-08) - data safety page: (seen 2026-10-08) - Connect product page: (seen 2026-10-08) - status history: (seen 2026-10-08) - status incidents feed: (seen 2026-10-08) - RDAP record for flinks.com: (seen 2026-10-08) ## Who's behind it (provenance 71/100, checked 2026-10-08) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Flinks Technology Inc. | 20/20 | | Domain age | flinks.com, registered 1997-06-03 (29 years) | 15/15 | | Endpoint on the vendor's domain | is not on flinks.com | 0/15 | | Terms of service | read, states 6 of the 7 things a reader expects, and has 1 clause that costs points | 7.1/10 | | Privacy policy | read, states 7 of the 8 things a reader expects | 9.3/10 | | Status page | status.flinks.com | 10/10 | | Changelog | published | 10/10 | | security.txt | not found | 0/10 | The terms link is the Master Terms and Conditions, last updated 3 August 2023, which govern use of the Flinks technology under an order form and name Flinks Technology Inc. Service schedules for connectivity, enrichment and upload are separate pages on flinks.com. The privacy link holds the General Privacy Statement (22 September 2022) and the Services Privacy Statement (19 April 2024) on one page. The Services statement covers bank data read through the product and names National Bank of Canada as Flinks' parent company. API calls go to https://{instance}-api.private.fin.ag and the widget to https://{instance}-iframe.private.fin.ag. Flinks Outbound answers at ob.flinksapp.com. Neither is under flinks.com, so the endpoint is recorded as off the vendor's domain. We did not confirm the registrant of fin.ag. flinks.com/.well-known/security.txt, www.flinks.com/.well-known/security.txt and docs.flinks.com/.well-known/security.txt return 404. The security page gives security@flinks.com for vulnerability reports. status.flinks.com runs on incident.io. changelog.flinks.com redirects to docs.flinks.com/changelog. Verisign RDAP gives 1997-06-03 as the registration date of flinks.com and GoDaddy.com, LLC as registrar. No street address for the company was found on the pages read. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://www.flinks.com/terms-and-conditions), read 2026-10-08, dated 2023-08-03, states 6 of the 7 things a reader expects. - To know. Says the terms or the service can change without notice (costs points). "By executing an Order Form, Client agrees and recognizes that Flinks may, from time to time and in its’ sole discretion, modify these Master Terms without prior notice to Client." - To know. Has not been updated for three years or more. "Last update: August 3, 2023" - Gives the date it was last updated. Last updated 2023-08-03. - Names the governing law or courts. The law of the Province of Ontario. - States a limit on its liability. Capped at the fees paid in the 12 months before the claim. - Says how changes to the terms are announced. Says it gives notice of a change. - Not found in the text. Lists what users may not do. - Also in the text (2026-10-08). The client may not make any statement about Flinks, its systems, the services or a security breach, public or otherwise, without prior written authorisation from Flinks. "Client shall not make or publish any representation or statement of any kind, whether public or otherwise, concerning Flinks, Flinks’ Systems, the Services (including any Security Breach), or Client’s use thereof, without the prior written authorization of Flinks." - Also in the text (2026-10-08). The client must take part in one SOC 2 Type II audit each calendar year. "Client shall participate in one (1) SOC 2 Type II (or any successor authoritative guidance for reporting on service organizations) audit each calendar year." - Also in the text (2026-10-08). On expiry or termination, end-customer data is deleted in the normal course of operations, and Flinks may keep it where required to resolve a dispute or to assert or defend a claim. "End-Customer Data will be deleted in the normal course of Flinks operations, provided however that Flinks reserves the right to preserve End-Customer Data if required to resolve a dispute or assert or defend any claim." **Privacy policy** (https://www.flinks.com/privacy-policy), read 2026-10-08, dated 2022-09-22, states 7 of the 8 things a reader expects. - To know. Has not been updated for three years or more. "This General Privacy Statement was last updated on September 22, 2022. From time to time, Flinks may update this General Privacy Statement to reflect changes to Flinks’ services or purposes for which…" - Gives the date it was last updated. Last updated 2022-09-22. - Says how long data is kept. For as long as needed, with no period named. - Says whether personal data is sold or shared for advertising. Says it does not sell personal data. - Gives a privacy contact. privacy@flinks.com. - Not found in the text. Says where data is transferred or stored. - Also in the text (2026-10-08). Flinks lists improving and further developing its existing services among the uses of personal information it receives from end customers and their financial institutions. "To improve, enhance, modify, add to, and further develop our existing services;" - Also in the text (2026-10-08). The service providers that process personal information for Flinks include other data aggregators, used for redundancy during an outage or for access to institutions Flinks cannot reach. "Other data aggregators who provide similar services to Flinks, who provide redundancies in the event of an outage, or access to financial institutions or data Flinks may not have connectivity with." - Also in the text (2026-10-08). Where Flinks suspects an illegal transaction through Flinks Pay, it reports the person and the transaction to FINTRAC, other authorities as required, and its parent company, National Bank of Canada. "Flinks will report information about you and any associated transaction(s) to the Financial Transactions and Reports Analysis Centre of Canada (“FINTRAC”) and any other law enforcement or regulatory body as required, as well as Flinks’ parent company, National Bank of Canada (“National Bank”)" ## Live (updated 2026-10-08 21:06 UTC) - Vendor status page: none, All Systems Operational - Always current: https://www.anchorterminal.com/api/v1/live/flinks.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Strengths - Ten OpenAPI 3.0 files are public at docs.flinks.com, 85 operations in all, with the main Connect and Enrich file holding 34 - Shared sandbox keys for the Toolbox instance are published in the docs, so test calls need no account - llms.txt lists 216 pages with Markdown twins, and the docs add a skill file and a read-only documentation MCP server - Plan prices are public. Connect starts at $500 a month for 200 unique connections, with no integration or platform fee - Each instance is hosted in the country it serves, Canada or the US, and `/DeleteCard` deletes all data held for a connection ## Weaknesses - Live access needs a contract with a monthly minimum and a one-year term. The pricing page says there is no pay-as-you-go plan or self-serve trial - The secret key, `x-api-key` and HMAC secret do not expire, and no scopes or rotation steps were found for the Connect API - No rate-limit numbers are published, and `TOO_MANY_REQUESTS` is documented under HTTP 401 with no Retry-After - status.flinks.com lists 77 incidents in the 90 days to 8 October 2026, 16 of them on Flinks' own components - `/GetAccountsDetail` returns the whole 90 or 365 days of transactions in one payload with no pagination, and no official SDK was found ## Before you call it (notes for agents) 1. Call `/GenerateAuthorizeToken` with the secret key in `flinks-auth-key`, then pass the returned token to the Connect iframe or to `/Authorize`. The token is single-use and expires after 15 minutes. 2. Send the account holder through Flinks Connect in a browser. The API alone cannot complete a first bank login, and sandbox iframes need `demo=true`. 3. Store the `loginId`. Call `/Authorize` with it and `MostRecentCached: true` for a new `requestId` each session, because `/GetAccountsDetail` consumes the `requestId`. 4. On a 202 from `/GetAccountsDetail`, poll `/GetAccountsDetailAsync` every 10 seconds for at most 30 minutes, or ask support to enable webhooks. 5. Route each end user to the instance for their country. A `loginId` from the Canadian instance is not valid on the US one. ## Connect First request: ```bash curl --request POST \ --url https://toolbox-api.private.fin.ag/v3/{customerId}/BankingServices/GenerateAuthorizeToken \ --header 'Content-Type: application/json' \ --header 'flinks-auth-key: YOUR_SECRET_KEY' ``` Claude Code: ```bash claude mcp add flinks --transport http https://docs.flinks.com/mcp ``` Through letme (picks today, calling later): https://letme.dev/flinks. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Plaid | B | 69.8 | 147 | bank.accounts, bank.transactions, bank.identity, bank.payments, bank.consent | no | https://www.anchorterminal.com/tools/plaid.md | | Belvo | B | 63.5 | 309 | bank.accounts, bank.transactions, bank.identity, bank.payments, bank.consent | no | https://www.anchorterminal.com/tools/belvo.md | | Tink | B | 62.5 | 337 | bank.accounts, bank.transactions, bank.consent, bank.payments, bank.identity | no | https://www.anchorterminal.com/tools/tink.md | | TrueLayer | B | 62.1 | 347 | bank.accounts, bank.transactions, bank.identity, bank.payments, bank.consent | no | https://www.anchorterminal.com/tools/truelayer.md | | Yapily | C | 57.6 | 469 | bank.accounts, bank.transactions, bank.identity, bank.payments, bank.consent | no | https://www.anchorterminal.com/tools/yapily.md | | Salt Edge Account Information | D | 46.7 | 643 | bank.accounts, bank.transactions, bank.identity, bank.payments, bank.consent | no | https://www.anchorterminal.com/tools/salt-edge.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - The docs publish shared sandbox credentials for the Toolbox instance at https://toolbox-api.private.fin.ag, with a test bank named Flinks Capital and test users such as `Greatday` (source: ) - Ten OpenAPI 3.0 files are linked from llms.txt, among them `openapi.yaml` (34 operations), `openapi-outbound.yaml` (19, FDX version 5 paths) and five for Flinks Pay (source: ) - Flinks Connect uses credential-based access, where the account holder types online banking credentials into the widget, and OAuth where an institution supports it. The Connect product page says OAuth covers 9 of the 10 largest US banks (source: ) - A `loginId` is permanent and Flinks keeps the stored credentials, holder details and accounts until `/DeleteCard` is called (source: ) - The docs site has an MCP server at https://docs.flinks.com/mcp with two read-only tools that search and read the documentation. It does not call the Flinks API (source: ) - A skill file for AI coding assistants at https://docs.flinks.com/skill.md summarises the integration flow in one file (source: ) - The Master Terms and Conditions, last updated 3 August 2023, commit Flinks to best efforts at 99 per cent monthly availability and let Flinks modify the terms without prior notice (source: ) - The OpenAPI file says an authorise token is valid for 30 minutes, while the authentication guide and the skill file say 15 minutes (source: ) ## Compare - [Akoya vs Flinks](https://www.anchorterminal.com/compare/akoya-vs-flinks.md): D 48.3 vs D 52.7 - [Belvo vs Flinks](https://www.anchorterminal.com/compare/belvo-vs-flinks.md): B 63.5 vs D 52.7 - [Enable Banking vs Flinks](https://www.anchorterminal.com/compare/enable-banking-vs-flinks.md): D 47.1 vs D 52.7 - [Flinks vs GoCardless Bank Account Data](https://www.anchorterminal.com/compare/flinks-vs-gocardless-bank-account-data.md): D 52.7 vs E 41.7 - [Flinks vs MX Platform API](https://www.anchorterminal.com/compare/flinks-vs-mx.md): D 52.7 vs B 62.5 - [Flinks vs Plaid](https://www.anchorterminal.com/compare/flinks-vs-plaid.md): D 52.7 vs B 69.8 - [Flinks vs Salt Edge Account Information](https://www.anchorterminal.com/compare/flinks-vs-salt-edge.md): D 52.7 vs D 46.7 - [Flinks vs Teller](https://www.anchorterminal.com/compare/flinks-vs-teller.md): D 52.7 vs E 42.7 - [Flinks vs Tink](https://www.anchorterminal.com/compare/flinks-vs-tink.md): D 52.7 vs B 62.5 - [Flinks vs TrueLayer](https://www.anchorterminal.com/compare/flinks-vs-truelayer.md): D 52.7 vs B 62.1 - [Flinks vs Yapily](https://www.anchorterminal.com/compare/flinks-vs-yapily.md): D 52.7 vs C 57.6 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on flinks.com or one of its subdomains. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "flinks", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Flinks on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Flinks on Anchor Terminal](https://www.anchorterminal.com/badges/flinks.svg)](https://www.anchorterminal.com/tools/flinks) ``` Plain link: ```html Flinks on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Flinks is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/flinks-dark.png - Light: https://www.anchorterminal.com/assets/share/flinks-light.png