# Flinks (slim) > Flinks is a Canadian bank-data aggregator owned by National Bank of Canada. Its REST API and Flinks Connect widget read accounts, balances, transactions and holder details from Canadian and US institutions with the holder's consent, and start Canadian bank payments. - Full: https://www.anchorterminal.com/tools/flinks.md (~8,250 tokens) · this version ~1,980 tokens · JSON https://www.anchorterminal.com/tools/flinks.json · canonical https://www.anchorterminal.com/tools/flinks - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **D · 52.7/100 · rank #559 of 722 · #7 in Bank data & open banking · not agent-ready · confidence medium** Assessment: Ten public OpenAPI files, an llms.txt index with Markdown twins and published sandbox keys let an agent start without a signup. Live access needs a one-year contract from $500 a month, keys never expire, no rate-limit numbers are published, and the status page logged 77 incidents in 90 days. ## Facts - Kind: HTTP API · vendor: Flinks Technology Inc. (National Bank of Canada) · category: Bank data & open banking · legal entity: Flinks Technology Inc. · provenance 71/100 - Local only (HTTP) - Auth: API key · pricing: Paid · x402: no · licence: Proprietary service under Flinks' Master Terms and Conditions. No open-source SDK or repository was found - Probe metrics: not measured yet (probes haven't run) - API: REST over HTTPS, TLS 1.2 or later, at https://{instance}-api.private.fin.ag/v3/{customerId}/. One instance per customer and country. The main OpenAPI file lists 34 operations - Data endpoints: `/GetAccountsSummary`, `/GetAccountsDetail` (accounts, balances, transactions, holder name, address, email and phone), `/GetStatements` (bank-issued PDF statements), `/Institutions`, `/FieldMatch` for identity checks - Consent: The account holder connects in the Flinks Connect iframe, with bank credentials or the institution's OAuth flow. The connection has no expiry. `/DeleteCard` removes the stored credentials, holder details and account data. Flinks Outbound has `/api/v1/revoke` - Sessions: Authorise token single-use, 15 minutes. `requestId` ends after 8 minutes of inactivity or 30 minutes of processing, or when `/GetAccountsDetail`, `/GetAccountsDetailAsync` or `/GetStatements` completes - Transactions: Posted transactions only, `DaysOfTransactions` of `Days90` or `Days365`, in one payload. `WithTransactions`, `WithKYC` and `AccountsFilter` trim the response - Async: `/GetAccountsDetail` answers 202 while data is processed. Poll `/GetAccountsDetailAsync` every 10 seconds, at most 30 minutes, or receive a webhook - Rate limits: No numbers published. `TOO_MANY_REQUESTS` is listed under HTTP 401 - Enrich: Attributes endpoints for income, lending, credit risk and business analysis, and `/GetCategorization`. Flinks says 4,500+ attributes - Payments: Flinks Pay, Canada only. Session-based APIs for EFT (pre-authorised debit), Guaranteed EFT and Interac e-Transfer Request Money, with their own `/Authorize` and Bearer token - Open banking: Flinks Outbound at https://ob.flinksapp.com, OAuth 2.0 with FDX version 5 paths for customers, accounts, transactions and statements, paged with `offset` and `limit` - Sandbox: Shared Toolbox instance at https://toolbox-api.private.fin.ag with published keys, the Flinks Capital test bank and test users for MFA and error cases. Webhooks cannot be tested there - Webhooks: Enabled by a support ticket. HMAC-SHA256 signature in `flinks-authenticity-key`. Up to 10 retries, 30 minutes apart - Coverage: Canada and the United States. Flinks says 15,000+ financial institutions across North America - Service level: Best efforts at 99 per cent monthly availability for the connection method and Flinks Connect, excluding maintenance and bank-side faults, per the Master Terms - Certifications: SOC 2 Type II per the docs and the data safety page, with the report on request. The Master Terms also commit to ISO 27001 audit reports - AI resources: llms.txt, Markdown twins, a skill file at https://docs.flinks.com/skill.md and a documentation MCP server at https://docs.flinks.com/mcp with two read-only tools - SDKs: None found. Mobile apps load Flinks Connect in a WebView - Scores: Reliability 53, Performance pending, Schema & documentation 83, Agent ergonomics 54, Security & auth 50, Payments & pricing 25, Task success pending, Maintenance & community 31, Transparency & trust 60 · total over the 7 assessed categories - Why: Reliability, Graded with the hosted lines. · Schema & documentation, Ten OpenAPI 3.0 files are public, 85 operations in all, 34 in the main file. · Agent ergonomics, `WithTransactions`, `WithKYC`, `AccountsFilter` and `DaysOfTransactions` trim a response, and `/GetAccountsSummary` is a lighter call. · Security & auth, A secret key and an `x-api-key`, both issued by Flinks, neither expiring, with no scopes and no documented rotation for the Connect API. · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, The newest changelog entry is dated 1 September 2026, 37 days before the check (20 of 30). · Transparency & trust, Closed service with public Master Terms dated 3 August 2023 and service schedules. - Sources: 25, open questions: 8, both in the full twin - Capabilities: bank.accounts, bank.transactions, bank.identity, bank.payments, bank.consent - JSON: https://www.anchorterminal.com/api/v1/tools/flinks.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/flinks.svg` or a link to https://www.anchorterminal.com/tools/flinks from a page on flinks.com or one of its subdomains, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Call `/GenerateAuthorizeToken` with the secret key in `flinks-auth-key`, then pass the returned token to the Connect iframe or to `/Authorize`. The token is single-use and expires after 15 minutes. 2. Send the account holder through Flinks Connect in a browser. The API alone cannot complete a first bank login, and sandbox iframes need `demo=true`. 3. Store the `loginId`. Call `/Authorize` with it and `MostRecentCached: true` for a new `requestId` each session, because `/GetAccountsDetail` consumes the `requestId`. 4. On a 202 from `/GetAccountsDetail`, poll `/GetAccountsDetailAsync` every 10 seconds for at most 30 minutes, or ask support to enable webhooks. 5. Route each end user to the instance for their country. A `loginId` from the Canadian instance is not valid on the US one. ## Connect ```bash curl --request POST \ --url https://toolbox-api.private.fin.ag/v3/{customerId}/BankingServices/GenerateAuthorizeToken \ --header 'Content-Type: application/json' \ --header 'flinks-auth-key: YOUR_SECRET_KEY' ``` ```bash claude mcp add flinks --transport http https://docs.flinks.com/mcp ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/flinks ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Plaid | B | 69.8 | bank.accounts, bank.transactions, bank.identity, bank.payments, bank.consent | https://www.anchorterminal.com/tools/plaid.min.md | | Belvo | B | 63.5 | bank.accounts, bank.transactions, bank.identity, bank.payments, bank.consent | https://www.anchorterminal.com/tools/belvo.min.md | | Tink | B | 62.5 | bank.accounts, bank.transactions, bank.consent, bank.payments, bank.identity | https://www.anchorterminal.com/tools/tink.min.md | | TrueLayer | B | 62.1 | bank.accounts, bank.transactions, bank.identity, bank.payments, bank.consent | https://www.anchorterminal.com/tools/truelayer.min.md | | Yapily | C | 57.6 | bank.accounts, bank.transactions, bank.identity, bank.payments, bank.consent | https://www.anchorterminal.com/tools/yapily.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)