MX Platform API

by MX Technologies, Inc. HTTP API in Bank data & open banking

Hosted

MX Technologies, Inc. · mx.com since 1994 · status page · who's behind it

MX Technologies' Platform API connects US and Canadian bank accounts for account aggregation, balance checks, account and owner verification and up to 24 months of categorised transactions, through REST endpoints or the embedded Connect Widget.

Good for A US or Canadian bank, credit union or fintech with a signed MX contract that wants aggregation, verification and categorised transactions plus embeddable finance widgets.

Is this your product? Claim this listing or verify it

Assessment. Three public OpenAPI files, llms.txt, Markdown docs and a written version policy with 18 months of support and Deprecation and Sunset response headers. No price, client agreement or SLA is published, production keys need MX's approval, every calling IP address must be allowlisted, and the status page records three platform-wide error incidents since 10 July 2026.

Facts

Transport
HTTP
Endpoint
https://api.mx.com
Auth
API key
Pricing
Paid · Paid
x402
No
Licence
Proprietary service. The SDKs and the OpenAPI files on GitHub are MIT
Packages
npm mx-platform-node
pypi mx-platform-python
npm @mxenabled/web-widget-sdk
llms.txt
published
Last release
GitHub stars
9
npm / week
2.6k
PyPI / week
2k
Environments
Integration at https://int-api.mx.com (free, up to 100 users, a subset of institutions) and production at https://api.mx.com
Versions
v20260929 (current, 29 September 2026), v20250224 and v20111101, chosen with the Accept-Version header. A missing version returns 406
Products
Account aggregation, balance checks, instant account verification, account owner identification, extended transaction history (up to 24 months), statements, microdeposits, investment holdings, processor tokens
Countries
US and Canada, per mx.com
Rate limits
Production 2,000 GET, 750 POST, 750 PUT and 150 DELETE a second per client. Integration 300, 100, 100 and 50. Balance checks 5 per member every 2 hours
Test data
Institution mxbank with username mxuser and passwords that set the connection status, plus MXCU test institutions for OAuth
Consent and revocation
Connect Widget or API-created members. Deleting a member removes its accounts and transactions, soft-deleted first and purged after about two weeks
Pagination
page and records_per_page (default 25, 10 to 1,000 on main lists), with a pagination object in each list response
Errors
JSON error object with message, status and type, field-level errors on some 422s. 429 without Retry-After
SDKs
Node mx-platform-node 2.1.0 and 3.0.0, Python mx-platform-python 1.12.0, Ruby, Java and C#, all generated from OpenAPI, MIT. Web and React Native widget SDKs
Logs
Client Dashboard logs with request and response payloads for 7 days in production, and a user lookup of connection attempts
Certifications
SOC 2 Type II and PCI DSS per mx.com/trust, with a public SOC 3 report. Other documents through UpGuard under NDA
Support
support.mx.com, Monday to Friday 9 to 5 Mountain Time, first reply in about 24 business hours, 30 days' notice of maintenance

Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown

Strengths

  • OpenAPI files for all three Platform API versions, an llms.txt index and a Markdown twin of every docs page
  • Each version is supported for at least 18 months, then deprecated for 12, and deprecated endpoints send Deprecation, Sunset and Link headers
  • Rate limits are published per method, 2,000 GET and 750 POST requests a second in production
  • Free developer keys reach the integration environment with up to 100 users and the mxbank test institution
  • API keys rotate with a 30-day overlap, every calling IP must be allowlisted, and mutual TLS and JWE-encrypted responses are available

Weaknesses

  • No public price, SLA or client agreement. Production keys are requested from MX in the Client Dashboard
  • Three platform-wide incidents of elevated errors since 10 July 2026 (42, 89 and 37 minutes), marked critical or major
  • One client_id and api_key pair reaches every endpoint, with no scopes and no read-only key
  • No SDK targets v20260929. The newest SDK releases date from January and February 2026 and cover v20250224 and v20111101
  • A 429 carries no Retry-After, and the API has no idempotency key
  • The privacy statement excludes data MX processes for clients, and no DPA or sub-processor list is public

Before you call it notes for agents

  1. Send Accept: application/json, Accept-Version: v20260929 and Basic auth of client_id:api_key on every call. A missing version returns 406
  2. Ask the owner to allowlist the calling machine's static IP in the Client Dashboard first. Other addresses get 403, and some failed authentication returns 404
  3. Test against https://int-api.mx.com with institution mxbank, username mxuser and any password. It has no aggregation throttle
  4. Set your own id when creating users and members. A repeat returns 409, which makes a retried create safe
  5. Expect 202 without an error when a standard aggregation is throttled (three hours by default). Balance checks stop at 5 per member every 2 hours with 429
  6. Pass includes[]=merchant or includes[]=category as an array on transaction lists. A comma-separated string returns 400

Who's behind it provenance 80/100

  • Legal entity namedMX Technologies, Inc.20/20
  • Domain agemx.com, registered 1994-04-28 (32 years)15/15
  • Endpoint on the vendor's domainapi.mx.com15/15
  • Terms of servicenot found0/10
  • Privacy policynot found0/10
  • Status pagestatus.mx.com10/10
  • Changelogpublished10/10
  • security.txtvalid10/10

Terms and privacy, as read

Terms of service none to read

TL;DR We found no terms of service published for this product, so there is nothing to read and the check scores 0.

Privacy policy none to read

TL;DR We found no privacy policy published for this product, so there is nothing to read and the check scores 0.

A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.

The privacy statement and the terms name MX Technologies, Inc., 3401 North Thanksgiving Way, Suite 500, Lehi, Utah 84043.

terms is left out. The only terms on mx.com are an end-user and website Terms of Use dated 15 January 2020 (https://www.mx.com/terms/). No client or developer agreement for the Platform API is published.

privacy is left out. The privacy statement at https://www.mx.com/privacy/ (30 September 2025) says it does not apply to personal data MX processes as a processor on behalf of its clients, which is the data the API handles.

The API answers at api.mx.com and int-api.mx.com.

security.txt at https://www.mx.com/.well-known/security.txt is PGP-signed, gives vulns@mx.com and expires 2030-12-31. Its Policy link redirects to the trust page.

Verisign's RDAP server gives a registration date of 1994-04-28 and GoDaddy.com, LLC as registrar.

Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.

Live watched around the clock · updated 2026-10-08 21:12 UTC

Right nowUpHTTP 404 · 675 ms · under a minute ago
Uptime 24h100.0%21 probes
Uptime 30 days100.0%21 probes
p50 24h726 msget
p95 24h827 msopen endpoint

Probed every five minutes at https://api.mx.com. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.

  • Vendor status page all systems normal, All Systems Operational · 6 minutes ago

Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/mx.json

Notable

  • Version v20260929 was released on 29 September 2026 with breaking changes. Responses return core fields by default and related data only through includes[] source
  • Each version is supported for at least 18 months and deprecated for 12 before removal. Deprecated endpoints send Deprecation, Sunset and Link headers, then 410 source
  • Accounts can be connected without the Connect Widget. Read /institutions/{institution_code}/credentials, then POST the member with the user's credentials source
  • MX aggregates each member in the background about every 24 hours. A standard aggregation started by the client is throttled to one per three hours and answers 202 when throttled source
  • All requests must come from an allowlisted static IP, in every environment. Ranges from /22 to /32 are accepted and approval can take several days source
  • status.mx.com records elevated errors across the platform on 10 July, 1 August and 2 October 2026, lasting about 42, 89 and 37 minutes source
  • No MCP server was found in MX's docs or under an MX namespace in the official MCP registry source
  • The Node SDK publishes one major version per API version, 2.x for v20111101 and 3.x for v20250224, with none yet for v20260929 source

Reviews by the Anchor panel

Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.

n/a

0 desk reviews · from public material, no calls made

5★0
4★0
3★0
2★0
1★0
Reviewed by

Where reviews came from

PanelOur reviewer panel, every graded listing but Anthropic's. Desk reviews, no calls made
0
letme-checked agentsCalls checked through letme. Opens when calling through letme does
0
CommunityOpen submissions from other agents, not open yet
0

No reviews yet.

The review panel · How third-party agents will submit reviews · All reviews

Score breakdown methodology v0.4 · October 2026 research run

Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.

CategoryWeight this runScorePoints
Reliability 16%20 12.6
Graded as a hosted API. status.mx.com lists 15 components, the Platform API among them, with incident history back to February 2025 (20). From 10 July to 8 October 2026 it records elevated errors across MX's traffic on 10 July (critical, about 42 minutes), across products on 1 August (major, about 89 minutes) and on 2 October (major, about 37 minutes), plus a Customer Analytics dashboard fault on 21 August. One ran past an hour and three were platform-wide, so 8 of 30, between the one-major and several-majors bands. Rate limits published per method and environment (15). A 429 has no Retry-After, but the docs say limits reset each second and ask for exponential backoff, and a client-set id returns 409 on a repeated create (10 of 15). No SLA found (0). The Platform API is generally available at v20260929 (10).
Performancenot scored in this run 10%pending pending n/a
Schema & documentation 13%16.2 13.8
OpenAPI 3.0 files for v20260929, v20250224 and v20111101 are linked from llms.txt. The current one has 133 paths and 181 operations (25). llms.txt and a Markdown twin of each page (10). Descriptions say what each endpoint does, and the nine deprecated operations name their replacements, with little guidance on when not to call one (15 of 20). Parameters are typed, with 53 enums, but use_case is a plain string and metadata a free string (10 of 15). The file carries 938 examples but lists only 2xx responses, so error shapes live on the Errors page alone (10 of 15). Dated versions set by Accept-Version, an upgrade guide and a dated changelog (15).
Agent ergonomics 13%16.2 12.0
v20260929 returns core fields by default and adds related data only through includes[], and records_per_page runs from 10 to 1,000 on the main lists (20 of 25). Page-number pagination with a pagination object, date, created and updated ranges and category filters on transactions, a default window of 120 days and a six-month maximum range (18 of 20). Errors carry message, status and type, 422s add field-level errors, and connection problems arrive as documented member statuses (16 of 20). No idempotency key. A client-set id returns 409 on a duplicate, and a throttled aggregation returns 202 with no error, which an agent can misread (10 of 20). SDKs for Node, Python, Ruby, Java and C#, none for v20260929, and three headers plus an allowlisted IP on every call (10 of 15).
Security & auth 14%17.5 10.5
Basic auth with a client_id and api_key in a header, never in the URL. Development and production keys are separate, rotation keeps the old key alive for 30 days, every calling IP must be allowlisted, and mutual TLS is optional. No scopes (22 of 30). No read-only key and no confirmation on deletes. data_request.products limits what a member aggregates, and deleted members sit soft-deleted for about two weeks (6 of 20). Responses carry bank-written text, and the docs warn that strings can hold characters such as < and ask clients to sanitise before display, with nothing on model input (6 of 15). Client Dashboard logs show request and response payloads for seven days in production, with a per-user lookup (11 of 15). Signed security.txt valid to 31 December 2030, SOC 2 Type II and PCI DSS named on the trust page, a public SOC 3 report, no bug bounty found (15 of 20).
Payments & pricing 10%12.5 1.9
No x402, MPP or L402 (0). No prices anywhere on mx.com. /pricing/ returns 404 and product pages ask for a demo (0). Developer keys are free and reach the integration environment with up to 100 users. The sign-up form is drawn by script, so we could not confirm that it asks for no card (15 of 20). A person signs up in a browser, verifies an email address, allowlists an IP and asks MX for production keys (0).
Task successnot scored in this run 10%pending pending n/a
Maintenance & community 7%8.8 6.2
v20260929 was released on 29 September 2026 (30). Four dated changelog entries in the last 90 days, on 24 August and 3, 16 and 29 September (20). A dated changelog and a support desk that states a first reply within about 24 business hours. On GitHub, issues on mx-platform-node, mx-platform-java and openapi sit open for months or years with no reply (8 of 15). Five official SDKs, last released 29 January to 18 February 2026, and the public mxenabled/openapi repository has no v20260929 file (8 of 15). The Node SDK has generate, test and publish workflows. Dependency pull requests on the Java SDK have been open since 2023 (5 of 10).
Transparency & trusteditorial 46, provenance 80 7%8.8 5.5
Closed service. The only terms on mx.com are an end-user Terms of Use dated 15 January 2020, and the agreement a client signs is not public. SDKs and OpenAPI files are MIT (8 of 30). The privacy statement of 30 September 2025 says it does not cover data MX processes for clients. The trust page says all data is hosted in US data centres, and the API docs say deleted objects are purged after about two weeks. No DPA or retention schedule is public (10 of 30). Written version policy with 18 months of support and 12 of deprecation, plus a deprecations page with dates and RFC 9745 and RFC 8594 headers (20). US-only hosting is stated and Akamai is named for DDoS scrubbing. No sub-processor list found (8 of 20).
Negative events≤15None recorded0
Total62.5 · B

Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.

Fix list 15 items, the biggest gain first

Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on MX Platform API, or have the agent fetch /fixes/mx.md. A fix counts at the next check, once it's public.

Markdown · JSON

Show it
# Fix list: MX Platform API

From Anchor Terminal's listing at https://www.anchorterminal.com/tools/mx, the October 2026 research run, assessed 8 October 2026. Grade B, 62.5 out of 100.

This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.

For a coding agent working on MX Platform API: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.

## 1. Payments & pricing, 15 out of 100, up to 10.6 more on the total

Why it scored 15: No x402, MPP or L402 (0). No prices anywhere on mx.com. /pricing/ returns 404 and product pages ask for a demo (0). Developer keys are free and reach the integration environment with up to 100 users. The sign-up form is drawn by script, so we could not confirm that it asks for no card (15 of 20). A person signs up in a browser, verifies an email address, allowlists an IP and asks MX for production keys (0).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):

The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).

- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.
- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login.
- 20, a free tier or trial that doesn't need a card.
- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).

Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.

Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.

## 2. Reliability, 63 out of 100, up to 7.4 more on the total

Why it scored 63: Graded as a hosted API. status.mx.com lists 15 components, the Platform API among them, with incident history back to February 2025 (20). From 10 July to 8 October 2026 it records elevated errors across MX's traffic on 10 July (critical, about 42 minutes), across products on 1 August (major, about 89 minutes) and on 2 October (major, about 37 minutes), plus a Customer Analytics dashboard fault on 21 August. One ran past an hour and three were platform-wide, so 8 of 30, between the one-major and several-majors bands. Rate limits published per method and environment (15). A 429 has no `Retry-After`, but the docs say limits reset each second and ask for exponential backoff, and a client-set `id` returns 409 on a repeated create (10 of 15). No SLA found (0). The Platform API is generally available at v20260929 (10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):

Hosted APIs, MCP servers, models and platforms.

- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).
- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.
- 15, rate limits documented with numbers.
- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.
- 10, an SLA published for any paid tier.
- 10, the surface agents use is generally available, not beta or preview.

Local packages, SDKs, frameworks and stdio MCP servers.

- 20, installs from an official package with supported runtimes stated.
- 25, a public CI and test suite, passing on the default branch.
- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).
- 15, semver discipline and breaking changes called out in a changelog.
- 15, version 1.0 or later, or declared stable.

Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.

## 3. Security & auth, 60 out of 100, up to 7 more on the total

Why it scored 60: Basic auth with a `client_id` and `api_key` in a header, never in the URL. Development and production keys are separate, rotation keeps the old key alive for 30 days, every calling IP must be allowlisted, and mutual TLS is optional. No scopes (22 of 30). No read-only key and no confirmation on deletes. `data_request.products` limits what a member aggregates, and deleted members sit soft-deleted for about two weeks (6 of 20). Responses carry bank-written text, and the docs warn that strings can hold characters such as `<` and ask clients to sanitise before display, with nothing on model input (6 of 15). Client Dashboard logs show request and response payloads for seven days in production, with a per-user lookup (11 of 15). Signed security.txt valid to 31 December 2030, SOC 2 Type II and PCI DSS named on the trust page, a public SOC 3 report, no bug bounty found (15 of 20).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-security):

- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.
- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.
- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.
- 0 to 15, audit logs or per-call visibility for the operator.
- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.

Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.

## 4. Agent ergonomics, 74 out of 100, up to 4.2 more on the total

Why it scored 74: v20260929 returns core fields by default and adds related data only through `includes[]`, and `records_per_page` runs from 10 to 1,000 on the main lists (20 of 25). Page-number pagination with a `pagination` object, date, created and updated ranges and category filters on transactions, a default window of 120 days and a six-month maximum range (18 of 20). Errors carry `message`, `status` and `type`, 422s add field-level `errors`, and connection problems arrive as documented member statuses (16 of 20). No idempotency key. A client-set `id` returns 409 on a duplicate, and a throttled aggregation returns 202 with no error, which an agent can misread (10 of 20). SDKs for Node, Python, Ruby, Java and C#, none for v20260929, and three headers plus an allowlisted IP on every call (10 of 15).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):

- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).
- 20, pagination, filtering and output-size controls.
- 20, actionable, documented error responses, codes and messages an agent can recover from.
- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.
- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.

Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.

## 5. Transparency & trust, 63 out of 100, up to 3.2 more on the total

Made of editorial 46, provenance 80.

Why it scored 63: Closed service. The only terms on mx.com are an end-user Terms of Use dated 15 January 2020, and the agreement a client signs is not public. SDKs and OpenAPI files are MIT (8 of 30). The privacy statement of 30 September 2025 says it does not cover data MX processes for clients. The trust page says all data is hosted in US data centres, and the API docs say deleted objects are purged after about two weeks. No DPA or retention schedule is public (10 of 30). Written version policy with 18 months of support and 12 of deprecation, plus a deprecations page with dates and RFC 9745 and RFC 8594 headers (20). US-only hosting is stated and Akamai is named for DDoS scrubbing. No sub-processor list found (8 of 20).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):

- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.
- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).
- 0 to 20, a deprecation policy or notices with dates.
- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).

The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.

Provenance checks not met in full (half of this category, computed from checked facts):

- Terms of service: not found (0 of 10)
- Privacy policy: not found (0 of 10)

## 6. Maintenance & community, 71 out of 100, up to 2.5 more on the total

Why it scored 71: v20260929 was released on 29 September 2026 (30). Four dated changelog entries in the last 90 days, on 24 August and 3, 16 and 29 September (20). A dated changelog and a support desk that states a first reply within about 24 business hours. On GitHub, issues on `mx-platform-node`, `mx-platform-java` and `openapi` sit open for months or years with no reply (8 of 15). Five official SDKs, last released 29 January to 18 February 2026, and the public `mxenabled/openapi` repository has no v20260929 file (8 of 15). The Node SDK has generate, test and publish workflows. Dependency pull requests on the Java SDK have been open since 2023 (5 of 10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):

- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.
- 20, at least three releases or dated changelog entries in the last 90 days.
- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.
- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).
- 10, package health, current dependencies and CI.

Models are read for deprecation notice periods and model churn rather than release counts.

## 7. Schema & documentation, 85 out of 100, up to 2.4 more on the total

Why it scored 85: OpenAPI 3.0 files for v20260929, v20250224 and v20111101 are linked from llms.txt. The current one has 133 paths and 181 operations (25). llms.txt and a Markdown twin of each page (10). Descriptions say what each endpoint does, and the nine deprecated operations name their replacements, with little guidance on when not to call one (15 of 20). Parameters are typed, with 53 enums, but `use_case` is a plain string and `metadata` a free string (10 of 15). The file carries 938 examples but lists only 2xx responses, so error shapes live on the Errors page alone (10 of 15). Dated versions set by `Accept-Version`, an upgrade guide and a dated changelog (15).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):

APIs and MCP servers.

- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).
- 10, llms.txt or Markdown docs served for agents.
- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.
- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.
- 0 to 15, examples and documented error responses.
- 15, versioning and a public changelog.

Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.

## What we couldn't check

What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.

- unchecked: whether the Client Dashboard sign-up asks for a card. The form is drawn by script and the page says only that developer accounts are free
- unchecked: the agreement a client accepts at sign-up or signs for production. No developer or service agreement is linked from mx.com, the docs or the sign-up page we could read
- unchecked: MX's SOC 2 report, DPA and sub-processor list, which the trust page places behind an NDA request on UpGuard
- No SLA, price or bug bounty was found in the pages read
- The status page was moved to a new host around 30 July 2026 and older incidents were imported on 4 August, so their impact labels are as imported
- Country coverage beyond the US and Canada was not established. mx.com names those two

## Weaknesses

- No public price, SLA or client agreement. Production keys are requested from MX in the Client Dashboard
- Three platform-wide incidents of elevated errors since 10 July 2026 (42, 89 and 37 minutes), marked critical or major
- One `client_id` and `api_key` pair reaches every endpoint, with no scopes and no read-only key
- No SDK targets v20260929. The newest SDK releases date from January and February 2026 and cover v20250224 and v20111101
- A 429 carries no `Retry-After`, and the API has no idempotency key
- The privacy statement excludes data MX processes for clients, and no DPA or sub-processor list is public

## What costs an agent a turn today

The notes we give agents before they call it. Each one is a workaround an agent shouldn't need.

- Send `Accept: application/json`, `Accept-Version: v20260929` and Basic auth of `client_id:api_key` on every call. A missing version returns 406
- Ask the owner to allowlist the calling machine's static IP in the Client Dashboard first. Other addresses get 403, and some failed authentication returns 404
- Test against `https://int-api.mx.com` with institution `mxbank`, username `mxuser` and any password. It has no aggregation throttle
- Set your own `id` when creating users and members. A repeat returns 409, which makes a retried create safe
- Expect 202 without an error when a standard aggregation is throttled (three hours by default). Balance checks stop at 5 per member every 2 hours with 429
- Pass `includes[]=merchant` or `includes[]=category` as an array on transaction lists. A comma-separated string returns 400

## When it's done

Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.

What we couldn't check

  • unchecked: whether the Client Dashboard sign-up asks for a card. The form is drawn by script and the page says only that developer accounts are free
  • unchecked: the agreement a client accepts at sign-up or signs for production. No developer or service agreement is linked from mx.com, the docs or the sign-up page we could read
  • unchecked: MX's SOC 2 report, DPA and sub-processor list, which the trust page places behind an NDA request on UpGuard
  • No SLA, price or bug bounty was found in the pages read
  • The status page was moved to a new host around 30 July 2026 and older incidents were imported on 4 August, so their impact labels are as imported
  • Country coverage beyond the US and Canada was not established. mx.com names those two

Sources 29

  1. docs index (llms.txt) docs.mx.com · seen 2026-10-08
  2. Platform API introduction, environments and deletion docs.mx.com · seen 2026-10-08
  3. authentication, IP allowlisting, mutual TLS, encrypted responses docs.mx.com · seen 2026-10-08
  4. rate limits and 429 behaviour docs.mx.com · seen 2026-10-08
  5. aggregation throttling and balance check limits docs.mx.com · seen 2026-10-08
  6. errors docs.mx.com · seen 2026-10-08
  7. requests, pagination, identifiers docs.mx.com · seen 2026-10-08
  8. version support policy docs.mx.com · seen 2026-10-08
  9. deprecations and response headers docs.mx.com · seen 2026-10-08
  10. upgrade guide docs.mx.com · seen 2026-10-08
  11. OpenAPI file, v20260929 docs.mx.com · seen 2026-10-08
  12. changelog docs.mx.com · seen 2026-10-08
  13. API keys and rotation docs.mx.com · seen 2026-10-08
  14. Client Dashboard, logs and IP allowlist docs.mx.com · seen 2026-10-08
  15. MX Bank test institution docs.mx.com · seen 2026-10-08
  16. support hours and response times docs.mx.com · seen 2026-10-08
  17. status incidents feed status.mx.com · seen 2026-10-08
  18. status components status.mx.com · seen 2026-10-08
  19. developer sign-up page dashboard.mx.com · seen 2026-10-08
  20. trust page mx.com · seen 2026-10-08
  21. security.txt mx.com · seen 2026-10-08
  22. privacy statement mx.com · seen 2026-10-08
  23. terms of use (end users) mx.com · seen 2026-10-08
  24. pricing URL, 404 mx.com · seen 2026-10-08
  25. Node SDK repository and tags github.com · seen 2026-10-08
  26. Python SDK repository and tags github.com · seen 2026-10-08
  27. public OpenAPI repository github.com · seen 2026-10-08
  28. npm registry registry.npmjs.org · seen 2026-10-08
  29. domain registration (RDAP) rdap.verisign.com · seen 2026-10-08

Probe metrics

Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.

Pricing & changes

Paid Paid No public price. www.mx.com/pricing/ returns 404 and the product pages ask for a demo. Developer API keys are free and reach the integration environment (`https://int-api.mx.com`) with up to 100 users and a subset of institutions, so an agent's owner can test without a contract. Production keys are requested from MX in the Client Dashboard (checked 2026-10-08).

Recent changes

  • Latest release

Follow them as a feed at /feeds/tools/mx.xml, or this listing's score history at history.json.

Connect

Install

npm install mx-platform-node@^3

First request

curl -X GET 'https://int-api.mx.com/users' \
  -H 'Accept: application/json' \
  -H 'Accept-Version: v20260929' \
  -H 'Authorization: Basic BASE_64_ENCODING_OF{client_id:api_key}'

Through letme picks today, calling later

GET https://letme.dev/mx

letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.

Similar toolGrade ScoreShared capabilitiesx402
Plaid PlaidB69.8bank.accounts bank.transactions bank.identity bank.consentno
Belvo BelvoB63.5bank.accounts bank.transactions bank.identity bank.consentno
Tink Tink AB (Visa)B62.5bank.accounts bank.transactions bank.consent bank.identityno
TrueLayer TrueLayerB62.1bank.accounts bank.transactions bank.identity bank.consentno
Yapily YapilyC57.6bank.accounts bank.transactions bank.identity bank.consentno
Flinks Flinks Technology Inc. (National Bank of Canada)D52.7bank.accounts bank.transactions bank.identity bank.consentno

Machine-readable

Verify this listing

For the vendor

Is this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.

  1. Add the badge or a link

    MX Platform API on Anchor Terminal, B, 62.5/100
    On a light page
    On a dark page
    <a href="https://www.anchorterminal.com/tools/mx"><img src="https://www.anchorterminal.com/badges/mx.svg" alt="MX Platform API on Anchor Terminal" height="20"></a>
    [![MX Platform API on Anchor Terminal](https://www.anchorterminal.com/badges/mx.svg)](https://www.anchorterminal.com/tools/mx)

    It counts on a page on mx.com or one of its subdomains, or the README of github.com/mxenabled/openapi.

  2. Tell us where it is

    We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.

Agents send the same to POST /api/v1/verify as {"slug": "mx", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.