# MX Platform API > MX Technologies' Platform API connects US and Canadian bank accounts for account aggregation, balance checks, account and owner verification and up to 24 months of categorised transactions, through REST endpoints or the embedded Connect Widget. - Canonical: https://www.anchorterminal.com/tools/mx - Markdown: https://www.anchorterminal.com/tools/mx.md (~6,750 tokens) - Slim: https://www.anchorterminal.com/tools/mx.min.md (~1,680 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/mx.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-08 ## Overview **Grade B · 62.5/100 · rank #336 of 722 · #3 in Bank data & open banking · not agent-ready · confidence medium** ## Assessment Three public OpenAPI files, llms.txt, Markdown docs and a written version policy with 18 months of support and `Deprecation` and `Sunset` response headers. No price, client agreement or SLA is published, production keys need MX's approval, every calling IP address must be allowlisted, and the status page records three platform-wide error incidents since 10 July 2026. ## Facts | Field | Value | | --- | --- | | Vendor | MX Technologies, Inc. (https://www.mx.com) | | Kind | HTTP API | | Category | Bank data & open banking (https://www.anchorterminal.com/categories/banking-data) | | Transport | HTTP | | Endpoint | `https://api.mx.com` | | Auth | API key · Self-serve for development, MX approval for production. Every request sends Basic auth of `client_id:api_key` from the Client Dashboard, plus `Accept-Version`. Development and production keys are separate, and a rotated key stays valid for 30 days. All calling IP addresses must be allowlisted in the dashboard, and MX reviews addresses outside the US. Mutual TLS is optional. Four processor endpoints take a Bearer token exchanged from an authorisation code. OAuth institutions appear only after MX registers the client with them. | | Pricing | Paid (Paid) · No public price. www.mx.com/pricing/ returns 404 and the product pages ask for a demo. Developer API keys are free and reach the integration environment (`https://int-api.mx.com`) with up to 100 users and a subset of institutions, so an agent's owner can test without a contract. Production keys are requested from MX in the Client Dashboard (checked 2026-10-08). | | x402 | No · No x402, MPP or L402 in the docs index, the OpenAPI file or mx.com (checked 2026-10-08). | | Licence | Proprietary service. The SDKs and the OpenAPI files on GitHub are MIT | | Packages | npm: `mx-platform-node`; pypi: `mx-platform-python`; npm: `@mxenabled/web-widget-sdk` | | Source | https://github.com/mxenabled/openapi | | Docs | https://docs.mx.com/ | | llms.txt | https://docs.mx.com/llms.txt | | Last release | 2026-09-29 | | GitHub stars | 9 (as of 2026-10-08) | | npm downloads / week | 2,631 | | PyPI downloads / week | 1,997 | | Environments | Integration at https://int-api.mx.com (free, up to 100 users, a subset of institutions) and production at https://api.mx.com | | Versions | v20260929 (current, 29 September 2026), v20250224 and v20111101, chosen with the `Accept-Version` header. A missing version returns 406 | | Products | Account aggregation, balance checks, instant account verification, account owner identification, extended transaction history (up to 24 months), statements, microdeposits, investment holdings, processor tokens | | Countries | US and Canada, per mx.com | | Rate limits | Production 2,000 GET, 750 POST, 750 PUT and 150 DELETE a second per client. Integration 300, 100, 100 and 50. Balance checks 5 per member every 2 hours | | Test data | Institution `mxbank` with username `mxuser` and passwords that set the connection status, plus MXCU test institutions for OAuth | | Consent and revocation | Connect Widget or API-created members. Deleting a member removes its accounts and transactions, soft-deleted first and purged after about two weeks | | Pagination | `page` and `records_per_page` (default 25, 10 to 1,000 on main lists), with a `pagination` object in each list response | | Errors | JSON `error` object with `message`, `status` and `type`, field-level `errors` on some 422s. 429 without `Retry-After` | | SDKs | Node `mx-platform-node` 2.1.0 and 3.0.0, Python `mx-platform-python` 1.12.0, Ruby, Java and C#, all generated from OpenAPI, MIT. Web and React Native widget SDKs | | Logs | Client Dashboard logs with request and response payloads for 7 days in production, and a user lookup of connection attempts | | Certifications | SOC 2 Type II and PCI DSS per mx.com/trust, with a public SOC 3 report. Other documents through UpGuard under NDA | | Support | support.mx.com, Monday to Friday 9 to 5 Mountain Time, first reply in about 24 business hours, 30 days' notice of maintenance | | Capabilities | bank.accounts, bank.transactions, bank.identity, bank.consent | | Tags | hosted, openapi, llms-txt, typescript, python, ruby, java, csharp, webhooks, sales-led, enterprise, status-page, soc2 | | JSON | https://www.anchorterminal.com/api/v1/tools/mx.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 63 | 12.6 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 85 | 13.8 | | Agent ergonomics | 13% | 16.2 | 74 | 12.0 | | Security & auth | 14% | 17.5 | 60 | 10.5 | | Payments & pricing | 10% | 12.5 | 15 | 1.9 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 71 | 6.2 | | Transparency & trust (editorial 46, provenance 80) | 7% | 8.8 | 63 | 5.5 | | Negative events | up to −15 | up to −15 | none recorded | 0 | | **Total** | | | | **62.5 → B** | ### Why each score - Reliability 63: Graded as a hosted API. status.mx.com lists 15 components, the Platform API among them, with incident history back to February 2025 (20). From 10 July to 8 October 2026 it records elevated errors across MX's traffic on 10 July (critical, about 42 minutes), across products on 1 August (major, about 89 minutes) and on 2 October (major, about 37 minutes), plus a Customer Analytics dashboard fault on 21 August. One ran past an hour and three were platform-wide, so 8 of 30, between the one-major and several-majors bands. Rate limits published per method and environment (15). A 429 has no `Retry-After`, but the docs say limits reset each second and ask for exponential backoff, and a client-set `id` returns 409 on a repeated create (10 of 15). No SLA found (0). The Platform API is generally available at v20260929 (10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 85: OpenAPI 3.0 files for v20260929, v20250224 and v20111101 are linked from llms.txt. The current one has 133 paths and 181 operations (25). llms.txt and a Markdown twin of each page (10). Descriptions say what each endpoint does, and the nine deprecated operations name their replacements, with little guidance on when not to call one (15 of 20). Parameters are typed, with 53 enums, but `use_case` is a plain string and `metadata` a free string (10 of 15). The file carries 938 examples but lists only 2xx responses, so error shapes live on the Errors page alone (10 of 15). Dated versions set by `Accept-Version`, an upgrade guide and a dated changelog (15). - Agent ergonomics 74: v20260929 returns core fields by default and adds related data only through `includes[]`, and `records_per_page` runs from 10 to 1,000 on the main lists (20 of 25). Page-number pagination with a `pagination` object, date, created and updated ranges and category filters on transactions, a default window of 120 days and a six-month maximum range (18 of 20). Errors carry `message`, `status` and `type`, 422s add field-level `errors`, and connection problems arrive as documented member statuses (16 of 20). No idempotency key. A client-set `id` returns 409 on a duplicate, and a throttled aggregation returns 202 with no error, which an agent can misread (10 of 20). SDKs for Node, Python, Ruby, Java and C#, none for v20260929, and three headers plus an allowlisted IP on every call (10 of 15). - Security & auth 60: Basic auth with a `client_id` and `api_key` in a header, never in the URL. Development and production keys are separate, rotation keeps the old key alive for 30 days, every calling IP must be allowlisted, and mutual TLS is optional. No scopes (22 of 30). No read-only key and no confirmation on deletes. `data_request.products` limits what a member aggregates, and deleted members sit soft-deleted for about two weeks (6 of 20). Responses carry bank-written text, and the docs warn that strings can hold characters such as `<` and ask clients to sanitise before display, with nothing on model input (6 of 15). Client Dashboard logs show request and response payloads for seven days in production, with a per-user lookup (11 of 15). Signed security.txt valid to 31 December 2030, SOC 2 Type II and PCI DSS named on the trust page, a public SOC 3 report, no bug bounty found (15 of 20). - Payments & pricing 15: No x402, MPP or L402 (0). No prices anywhere on mx.com. /pricing/ returns 404 and product pages ask for a demo (0). Developer keys are free and reach the integration environment with up to 100 users. The sign-up form is drawn by script, so we could not confirm that it asks for no card (15 of 20). A person signs up in a browser, verifies an email address, allowlists an IP and asks MX for production keys (0). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 71: v20260929 was released on 29 September 2026 (30). Four dated changelog entries in the last 90 days, on 24 August and 3, 16 and 29 September (20). A dated changelog and a support desk that states a first reply within about 24 business hours. On GitHub, issues on `mx-platform-node`, `mx-platform-java` and `openapi` sit open for months or years with no reply (8 of 15). Five official SDKs, last released 29 January to 18 February 2026, and the public `mxenabled/openapi` repository has no v20260929 file (8 of 15). The Node SDK has generate, test and publish workflows. Dependency pull requests on the Java SDK have been open since 2023 (5 of 10). - Transparency & trust 63: Closed service. The only terms on mx.com are an end-user Terms of Use dated 15 January 2020, and the agreement a client signs is not public. SDKs and OpenAPI files are MIT (8 of 30). The privacy statement of 30 September 2025 says it does not cover data MX processes for clients. The trust page says all data is hosted in US data centres, and the API docs say deleted objects are purged after about two weeks. No DPA or retention schedule is public (10 of 30). Written version policy with 18 months of support and 12 of deprecation, plus a deprecations page with dates and RFC 9745 and RFC 8594 headers (20). US-only hosting is stated and Akamai is named for DDoS scrubbing. No sub-processor list found (8 of 20). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (15 items): https://www.anchorterminal.com/fixes/mx.md (JSON https://www.anchorterminal.com/fixes/mx.json) ### What we couldn't check - unchecked: whether the Client Dashboard sign-up asks for a card. The form is drawn by script and the page says only that developer accounts are free - unchecked: the agreement a client accepts at sign-up or signs for production. No developer or service agreement is linked from mx.com, the docs or the sign-up page we could read - unchecked: MX's SOC 2 report, DPA and sub-processor list, which the trust page places behind an NDA request on UpGuard - No SLA, price or bug bounty was found in the pages read - The status page was moved to a new host around 30 July 2026 and older incidents were imported on 4 August, so their impact labels are as imported - Country coverage beyond the US and Canada was not established. mx.com names those two ### Sources - docs index (llms.txt): (seen 2026-10-08) - Platform API introduction, environments and deletion: (seen 2026-10-08) - authentication, IP allowlisting, mutual TLS, encrypted responses: (seen 2026-10-08) - rate limits and 429 behaviour: (seen 2026-10-08) - aggregation throttling and balance check limits: (seen 2026-10-08) - errors: (seen 2026-10-08) - requests, pagination, identifiers: (seen 2026-10-08) - version support policy: (seen 2026-10-08) - deprecations and response headers: (seen 2026-10-08) - upgrade guide: (seen 2026-10-08) - OpenAPI file, v20260929: (seen 2026-10-08) - changelog: (seen 2026-10-08) - API keys and rotation: (seen 2026-10-08) - Client Dashboard, logs and IP allowlist: (seen 2026-10-08) - MX Bank test institution: (seen 2026-10-08) - support hours and response times: (seen 2026-10-08) - status incidents feed: (seen 2026-10-08) - status components: (seen 2026-10-08) - developer sign-up page: (seen 2026-10-08) - trust page: (seen 2026-10-08) - security.txt: (seen 2026-10-08) - privacy statement: (seen 2026-10-08) - terms of use (end users): (seen 2026-10-08) - pricing URL, 404: (seen 2026-10-08) - Node SDK repository and tags: (seen 2026-10-08) - Python SDK repository and tags: (seen 2026-10-08) - public OpenAPI repository: (seen 2026-10-08) - npm registry: (seen 2026-10-08) - domain registration (RDAP): (seen 2026-10-08) ## Who's behind it (provenance 80/100, checked 2026-10-08) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | MX Technologies, Inc. | 20/20 | | Domain age | mx.com, registered 1994-04-28 (32 years) | 15/15 | | Endpoint on the vendor's domain | api.mx.com | 15/15 | | Terms of service | not found | 0/10 | | Privacy policy | not found | 0/10 | | Status page | status.mx.com | 10/10 | | Changelog | published | 10/10 | | security.txt | valid | 10/10 | The privacy statement and the terms name MX Technologies, Inc., 3401 North Thanksgiving Way, Suite 500, Lehi, Utah 84043. `terms` is left out. The only terms on mx.com are an end-user and website Terms of Use dated 15 January 2020 (https://www.mx.com/terms/). No client or developer agreement for the Platform API is published. `privacy` is left out. The privacy statement at https://www.mx.com/privacy/ (30 September 2025) says it does not apply to personal data MX processes as a processor on behalf of its clients, which is the data the API handles. The API answers at api.mx.com and int-api.mx.com. security.txt at https://www.mx.com/.well-known/security.txt is PGP-signed, gives vulns@mx.com and expires 2030-12-31. Its Policy link redirects to the trust page. Verisign's RDAP server gives a registration date of 1994-04-28 and GoDaddy.com, LLC as registrar. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service**. We found no terms of service published for this product, so there is nothing to read and the check scores 0. **Privacy policy**. We found no privacy policy published for this product, so there is nothing to read and the check scores 0. ## Live (updated 2026-10-08 21:41 UTC) - Right now: up, HTTP 404, 747 ms, checked 2026-10-08 21:41 UTC (get on `https://api.mx.com`) - Uptime 24h 100.0% (26 probes) · 30 days 100.0% (26 probes) · p50 722 ms · p95 827 ms - Vendor status page: none, All Systems Operational - Always current: https://www.anchorterminal.com/api/v1/live/mx.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Strengths - OpenAPI files for all three Platform API versions, an llms.txt index and a Markdown twin of every docs page - Each version is supported for at least 18 months, then deprecated for 12, and deprecated endpoints send `Deprecation`, `Sunset` and `Link` headers - Rate limits are published per method, 2,000 GET and 750 POST requests a second in production - Free developer keys reach the integration environment with up to 100 users and the `mxbank` test institution - API keys rotate with a 30-day overlap, every calling IP must be allowlisted, and mutual TLS and JWE-encrypted responses are available ## Weaknesses - No public price, SLA or client agreement. Production keys are requested from MX in the Client Dashboard - Three platform-wide incidents of elevated errors since 10 July 2026 (42, 89 and 37 minutes), marked critical or major - One `client_id` and `api_key` pair reaches every endpoint, with no scopes and no read-only key - No SDK targets v20260929. The newest SDK releases date from January and February 2026 and cover v20250224 and v20111101 - A 429 carries no `Retry-After`, and the API has no idempotency key - The privacy statement excludes data MX processes for clients, and no DPA or sub-processor list is public ## Before you call it (notes for agents) 1. Send `Accept: application/json`, `Accept-Version: v20260929` and Basic auth of `client_id:api_key` on every call. A missing version returns 406 2. Ask the owner to allowlist the calling machine's static IP in the Client Dashboard first. Other addresses get 403, and some failed authentication returns 404 3. Test against `https://int-api.mx.com` with institution `mxbank`, username `mxuser` and any password. It has no aggregation throttle 4. Set your own `id` when creating users and members. A repeat returns 409, which makes a retried create safe 5. Expect 202 without an error when a standard aggregation is throttled (three hours by default). Balance checks stop at 5 per member every 2 hours with 429 6. Pass `includes[]=merchant` or `includes[]=category` as an array on transaction lists. A comma-separated string returns 400 ## Connect Install: ```bash npm install mx-platform-node@^3 ``` First request: ```bash curl -X GET 'https://int-api.mx.com/users' \ -H 'Accept: application/json' \ -H 'Accept-Version: v20260929' \ -H 'Authorization: Basic BASE_64_ENCODING_OF{client_id:api_key}' ``` Through letme (picks today, calling later): https://letme.dev/mx. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Plaid | B | 69.8 | 147 | bank.accounts, bank.transactions, bank.identity, bank.consent | no | https://www.anchorterminal.com/tools/plaid.md | | Belvo | B | 63.5 | 309 | bank.accounts, bank.transactions, bank.identity, bank.consent | no | https://www.anchorterminal.com/tools/belvo.md | | Tink | B | 62.5 | 337 | bank.accounts, bank.transactions, bank.consent, bank.identity | no | https://www.anchorterminal.com/tools/tink.md | | TrueLayer | B | 62.1 | 347 | bank.accounts, bank.transactions, bank.identity, bank.consent | no | https://www.anchorterminal.com/tools/truelayer.md | | Yapily | C | 57.6 | 469 | bank.accounts, bank.transactions, bank.identity, bank.consent | no | https://www.anchorterminal.com/tools/yapily.md | | Flinks | D | 52.7 | 559 | bank.accounts, bank.transactions, bank.identity, bank.consent | no | https://www.anchorterminal.com/tools/flinks.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - Version v20260929 was released on 29 September 2026 with breaking changes. Responses return core fields by default and related data only through `includes[]` (source: ) - Each version is supported for at least 18 months and deprecated for 12 before removal. Deprecated endpoints send `Deprecation`, `Sunset` and `Link` headers, then 410 (source: ) - Accounts can be connected without the Connect Widget. Read `/institutions/{institution_code}/credentials`, then POST the member with the user's credentials (source: ) - MX aggregates each member in the background about every 24 hours. A standard aggregation started by the client is throttled to one per three hours and answers 202 when throttled (source: ) - All requests must come from an allowlisted static IP, in every environment. Ranges from /22 to /32 are accepted and approval can take several days (source: ) - status.mx.com records elevated errors across the platform on 10 July, 1 August and 2 October 2026, lasting about 42, 89 and 37 minutes (source: ) - No MCP server was found in MX's docs or under an MX namespace in the official MCP registry (source: ) - The Node SDK publishes one major version per API version, 2.x for v20111101 and 3.x for v20250224, with none yet for v20260929 (source: ) ## Compare - [Akoya vs MX Platform API](https://www.anchorterminal.com/compare/akoya-vs-mx.md): D 48.3 vs B 62.5 - [Belvo vs MX Platform API](https://www.anchorterminal.com/compare/belvo-vs-mx.md): B 63.5 vs B 62.5 - [Enable Banking vs MX Platform API](https://www.anchorterminal.com/compare/enable-banking-vs-mx.md): D 47.1 vs B 62.5 - [Flinks vs MX Platform API](https://www.anchorterminal.com/compare/flinks-vs-mx.md): D 52.7 vs B 62.5 - [GoCardless Bank Account Data vs MX Platform API](https://www.anchorterminal.com/compare/gocardless-bank-account-data-vs-mx.md): E 41.7 vs B 62.5 - [MX Platform API vs Plaid](https://www.anchorterminal.com/compare/mx-vs-plaid.md): B 62.5 vs B 69.8 - [MX Platform API vs Salt Edge Account Information](https://www.anchorterminal.com/compare/mx-vs-salt-edge.md): B 62.5 vs D 46.7 - [MX Platform API vs Teller](https://www.anchorterminal.com/compare/mx-vs-teller.md): B 62.5 vs E 42.7 - [MX Platform API vs Tink](https://www.anchorterminal.com/compare/mx-vs-tink.md): B 62.5 vs B 62.5 - [MX Platform API vs TrueLayer](https://www.anchorterminal.com/compare/mx-vs-truelayer.md): B 62.5 vs B 62.1 - [MX Platform API vs Yapily](https://www.anchorterminal.com/compare/mx-vs-yapily.md): B 62.5 vs C 57.6 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on mx.com or one of its subdomains, or the README of github.com/mxenabled/openapi. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "mx", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html MX Platform API on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![MX Platform API on Anchor Terminal](https://www.anchorterminal.com/badges/mx.svg)](https://www.anchorterminal.com/tools/mx) ``` Plain link: ```html MX Platform API on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say MX Platform API is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/mx-dark.png - Light: https://www.anchorterminal.com/assets/share/mx-light.png