{
  "data": {
    "similar": [
      {
        "grade": "A",
        "json": "https://www.anchorterminal.com/tools/stripe-mcp.json",
        "name": "Stripe API + MCP",
        "score": 82.4,
        "shared": [
          "payments.card",
          "payments.metering"
        ],
        "slug": "stripe-mcp"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/nevermined.json",
        "name": "Nevermined API + MCP",
        "score": 70.8,
        "shared": [
          "payments.card",
          "payments.metering"
        ],
        "slug": "nevermined"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/lago.json",
        "name": "Lago",
        "score": 65.7,
        "shared": [
          "payments.metering",
          "payments.card"
        ],
        "slug": "lago"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/paid.json",
        "name": "Paid",
        "score": 55.1,
        "shared": [
          "payments.metering",
          "payments.card"
        ],
        "slug": "paid"
      },
      {
        "grade": "E",
        "json": "https://www.anchorterminal.com/tools/atxp.json",
        "name": "ATXP",
        "score": 42.9,
        "shared": [
          "payments.metering",
          "payments.card"
        ],
        "slug": "atxp"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/tempo.json",
        "name": "Tempo",
        "score": 76.6,
        "shared": [
          "payments.metering"
        ],
        "slug": "tempo"
      }
    ],
    "tool": {
      "slug": "orb",
      "name": "Orb",
      "vendor": "Orb, Inc.",
      "vendorUrl": "https://www.withorb.com",
      "kind": "http-api",
      "category": "payment-platforms",
      "summary": "Orb is a hosted billing platform for usage-based, seat-based and hybrid pricing. It ingests usage events, computes metrics, and runs plans, subscriptions, prepaid credits and invoices through a REST API with SDKs in six languages.",
      "url": "https://www.anchorterminal.com/tools/orb",
      "markdownUrl": "https://www.anchorterminal.com/tools/orb.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/orb.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/orb.json",
      "repo": "https://github.com/orbcorp/orb-python",
      "license": "Proprietary service under Orb's Platform Terms and Conditions. The SDKs on GitHub are Apache-2.0",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.withorb.com/v1",
      "packages": [
        {
          "registry": "pypi",
          "name": "orb-billing"
        },
        {
          "registry": "npm",
          "name": "orb-billing"
        },
        {
          "registry": "go",
          "name": "github.com/orbcorp/orb-go"
        }
      ],
      "auth": "api-key",
      "authNotes": "The API takes an API key as a Bearer token. A person creates it in the Orb web app under organisation settings, in test mode or live mode, after Orb's sales team has opened the account. No self-serve sign-up, OAuth flow or programmatic key API was found. Keys can be revoked, which is irreversible, and no scope list was found in the docs.",
      "pricing": "paid",
      "pricingNotes": "No public prices. Core, Advanced and Enterprise all show custom pricing, based on billings and ingested events, with a platform fee on the upper two tiers, and each starts with a sales contact. The terms describe a 30-day free trial that Orb may grant, and test mode works as a sandbox once an account exists. No free tier was found (https://www.withorb.com/pricing, checked 2026-10-09).",
      "priceSummary": "Paid",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the OpenAPI description, the docs index or the pricing page. Orb can charge a Stripe Shared Payment Token granted by a buyer's agent, through the merchant's Stripe account and on request (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 5,
        "npmWeekly": 184768,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://docs.withorb.com",
      "llmsTxt": "https://docs.withorb.com/llms.txt",
      "openapi": "https://docs.withorb.com/api-reference/orb-openapi.json",
      "capabilities": [
        "payments.metering",
        "payments.card"
      ],
      "tags": [
        "hosted",
        "sales-led",
        "enterprise",
        "openapi",
        "llms-txt",
        "webhooks",
        "python",
        "typescript",
        "go",
        "java",
        "kotlin",
        "ruby",
        "status-page",
        "soc2",
        "closed-source"
      ],
      "lastRelease": "2026-10-09",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 66.5,
        "grade": "B",
        "agentReady": false,
        "rank": 289,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 7,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 84,
          "maintenance": 82,
          "payments": 5,
          "reliability": 77,
          "schema": 88,
          "security": 55,
          "transparency": 65
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 77,
            "points": 15.4,
            "reason": "Hosted lines. status.withorb.com runs on Atlassian Statuspage with eight components and 90-day uptime bars (20). The history page covers August to October 2026 and lists four incidents, all in September. Three are rated minor (delayed usage-based invoices on 1 and 2 September, dashboard reporting errors on 16 September, elevated latency on 24 September) and one unrated (15 minutes of elevated latency on shared clusters on 25 September). July was not on the page read (20 of 30). Rate limits are published per category for live, test and trial accounts. The ingest reference still says no hard rate limit is enforced, which contradicts the table (14 of 15). The docs advise exponential backoff on 429 with no `Retry-After` documented, and `Idempotency-Key` on POST and PATCH makes retries safe for 48 hours (13 of 15). The pricing page lists SLAs for Enterprise only, inside the customer's agreement, and the public terms promise reasonable efforts with no figure (0). The v1 API is generally available (10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 88,
            "points": 14.3,
            "reason": "A public OpenAPI 3.1 description with 147 operations, 729 schemas and 79 webhook events (25). llms.txt and a Markdown twin for every docs page (10). 129 of 147 operations carry a description longer than 80 characters, and the ingest, ledger and subscription entries explain when to use each call. Few say when not to (17 of 20). The description has 688 enums and required lists, with free-form maps for `metadata` and event `properties` (13 of 15). Examples appear in about 350 places, and errors follow RFC 7807 with nine documented types and stable `type` URIs. The URIs point at an older docs path (13 of 15). The path is versioned v1 and the description says 1.0, with no dated API versions. API changes are recorded in the SDK changelogs, and the product changelog has 20 entries from October 2025 to August 2026 (10 of 15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 84,
            "points": 13.65,
            "reason": "Graded on the REST API. List calls take `limit` (default 20, maximum 100) and a few view switches such as `include_zero_quantity_line_items`. No field selection was found, and invoice and subscription objects are large (14 of 25). Cursor pagination with `has_more` and `next_cursor`, and filters on status, customer, dates and amounts with comparison suffixes (18 of 20). Errors carry `status`, `title`, a stable `type` URI and `detail`, with a `validation_errors` array on 400 (18 of 20). `Idempotency-Key` with replay and transient-error headers, per-event idempotency keys and a `Dry-Run` header that previews most writes (20 of 20). Creating a customer needs only `name` and `email`, external IDs are accepted as aliases, and official SDKs cover six languages (14 of 15)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 55,
            "points": 9.63,
            "reason": "API keys are Bearer tokens created in the web app, separately for test mode and live mode, and can be revoked. The readiness guide says to scope and rotate keys, and no scope list or read-only key was found in the docs or the API description (20 of 30). Dashboard users have Admin, Editor or Viewer roles, and the `Dry-Run` header and preview calls let a caller check a write before committing it. Nothing limits what an API key can do (8 of 20). The API returns customer-supplied names, metadata and event properties, and no prompt-injection guidance was found (5 of 15). Audit logs name the API key or user, the targets, the IP address and the user agent and can stream to a SIEM, but they are in private preview on the Enterprise plan only (8 of 15). SOC 2 Type 2 and SOC 1 Type 2 per the trust centre, an annual third-party penetration test and a written disclosure policy with a reporting address. security.txt returned 404 and no bounty was found (14 of 20)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 5,
            "points": 0.63,
            "reason": "Payment platforms take the highest step that applies on the 40-point protocol line. No x402, MPP or L402 was found in the API description, the docs index or the pricing page. Orb can collect an invoice with a Stripe Shared Payment Token that a buyer's agent granted, on request and through the merchant's Stripe account. That is a Stripe credential and not one of the three protocols, so we scored it 0 and flag the judgement (0). Core, Advanced and Enterprise all show custom pricing (0). The terms describe a 30-day free trial that Orb may grant and the rate-limit table has a trial column, but the pricing page routes every start through sales and no self-serve sign-up was found (5 of 20). A person contacts sales and creates the key in the web app (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 82,
            "points": 7.18,
            "reason": "The Python SDK 4.83.0, TypeScript SDK 6.27.0 and Go SDK v1.126.0 were all tagged on 9 October 2026, the day of the check (30). The Python repository has 30 tags since 11 July 2026 (20). The product changelog's latest entry is dated 7 August 2026, with two entries in the last 90 days. A support site is linked, the terms name email and Slack support, and the SDK issue queues (four and six open items) were not read (9 of 15). Current official SDKs in six languages. The TypeScript SDK moved to a new repository and major version, with a migration guide (15). The repositories carry CI workflows with lint, build and test jobs, lockfiles and automated releases. CI results were not read (8 of 10)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 65,
            "points": 5.69,
            "note": "editorial 45, provenance 84",
            "reason": "The platform is closed under published Platform Terms and Conditions, and the SDKs are Apache-2.0. The terms page shows no version date (17 of 30). The privacy policy of 7 May 2025 covers product data, the terms allow a data export within 30 days of termination before deletion, and the security page states seven-day snapshot retention and deletion on request. The terms let Orb use aggregated, de-identified customer data to improve the service. The DPA is available only on request (16 of 30). No deprecation policy was found. The API description marks 235 items deprecated with no removal dates, and the SDK changelog shows the ingestion `debug` parameter deprecated on 15 July and removed on 12 September 2026 (6 of 20). The security page names AWS as host and says Orb keeps a sub-processor list, which is not public. The privacy policy lists provider categories and names Stripe. No hosting region was found (6 of 20)."
          }
        ],
        "assessment": {
          "date": "2026-10-09",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "Graded on the REST API. List calls take `limit` (default 20, maximum 100) and a few view switches such as `include_zero_quantity_line_items`. No field selection was found, and invoice and subscription objects are large (14 of 25). Cursor pagination with `has_more` and `next_cursor`, and filters on status, customer, dates and amounts with comparison suffixes (18 of 20). Errors carry `status`, `title`, a stable `type` URI and `detail`, with a `validation_errors` array on 400 (18 of 20). `Idempotency-Key` with replay and transient-error headers, per-event idempotency keys and a `Dry-Run` header that previews most writes (20 of 20). Creating a customer needs only `name` and `email`, external IDs are accepted as aliases, and official SDKs cover six languages (14 of 15).",
            "maintenance": "The Python SDK 4.83.0, TypeScript SDK 6.27.0 and Go SDK v1.126.0 were all tagged on 9 October 2026, the day of the check (30). The Python repository has 30 tags since 11 July 2026 (20). The product changelog's latest entry is dated 7 August 2026, with two entries in the last 90 days. A support site is linked, the terms name email and Slack support, and the SDK issue queues (four and six open items) were not read (9 of 15). Current official SDKs in six languages. The TypeScript SDK moved to a new repository and major version, with a migration guide (15). The repositories carry CI workflows with lint, build and test jobs, lockfiles and automated releases. CI results were not read (8 of 10).",
            "payments": "Payment platforms take the highest step that applies on the 40-point protocol line. No x402, MPP or L402 was found in the API description, the docs index or the pricing page. Orb can collect an invoice with a Stripe Shared Payment Token that a buyer's agent granted, on request and through the merchant's Stripe account. That is a Stripe credential and not one of the three protocols, so we scored it 0 and flag the judgement (0). Core, Advanced and Enterprise all show custom pricing (0). The terms describe a 30-day free trial that Orb may grant and the rate-limit table has a trial column, but the pricing page routes every start through sales and no self-serve sign-up was found (5 of 20). A person contacts sales and creates the key in the web app (0).",
            "reliability": "Hosted lines. status.withorb.com runs on Atlassian Statuspage with eight components and 90-day uptime bars (20). The history page covers August to October 2026 and lists four incidents, all in September. Three are rated minor (delayed usage-based invoices on 1 and 2 September, dashboard reporting errors on 16 September, elevated latency on 24 September) and one unrated (15 minutes of elevated latency on shared clusters on 25 September). July was not on the page read (20 of 30). Rate limits are published per category for live, test and trial accounts. The ingest reference still says no hard rate limit is enforced, which contradicts the table (14 of 15). The docs advise exponential backoff on 429 with no `Retry-After` documented, and `Idempotency-Key` on POST and PATCH makes retries safe for 48 hours (13 of 15). The pricing page lists SLAs for Enterprise only, inside the customer's agreement, and the public terms promise reasonable efforts with no figure (0). The v1 API is generally available (10).",
            "schema": "A public OpenAPI 3.1 description with 147 operations, 729 schemas and 79 webhook events (25). llms.txt and a Markdown twin for every docs page (10). 129 of 147 operations carry a description longer than 80 characters, and the ingest, ledger and subscription entries explain when to use each call. Few say when not to (17 of 20). The description has 688 enums and required lists, with free-form maps for `metadata` and event `properties` (13 of 15). Examples appear in about 350 places, and errors follow RFC 7807 with nine documented types and stable `type` URIs. The URIs point at an older docs path (13 of 15). The path is versioned v1 and the description says 1.0, with no dated API versions. API changes are recorded in the SDK changelogs, and the product changelog has 20 entries from October 2025 to August 2026 (10 of 15).",
            "security": "API keys are Bearer tokens created in the web app, separately for test mode and live mode, and can be revoked. The readiness guide says to scope and rotate keys, and no scope list or read-only key was found in the docs or the API description (20 of 30). Dashboard users have Admin, Editor or Viewer roles, and the `Dry-Run` header and preview calls let a caller check a write before committing it. Nothing limits what an API key can do (8 of 20). The API returns customer-supplied names, metadata and event properties, and no prompt-injection guidance was found (5 of 15). Audit logs name the API key or user, the targets, the IP address and the user agent and can stream to a SIEM, but they are in private preview on the Enterprise plan only (8 of 15). SOC 2 Type 2 and SOC 1 Type 2 per the trust centre, an annual third-party penetration test and a written disclosure policy with a reporting address. security.txt returned 404 and no bounty was found (14 of 20).",
            "transparency": "The platform is closed under published Platform Terms and Conditions, and the SDKs are Apache-2.0. The terms page shows no version date (17 of 30). The privacy policy of 7 May 2025 covers product data, the terms allow a data export within 30 days of termination before deletion, and the security page states seven-day snapshot retention and deletion on request. The terms let Orb use aggregated, de-identified customer data to improve the service. The DPA is available only on request (16 of 30). No deprecation policy was found. The API description marks 235 items deprecated with no removal dates, and the SDK changelog shows the ingestion `debug` parameter deprecated on 15 July and removed on 12 September 2026 (6 of 20). The security page names AWS as host and says Orb keeps a sub-processor list, which is not public. The privacy policy lists provider categories and names Stripe. No hosting region was found (6 of 20)."
          },
          "sources": [
            {
              "what": "docs index for agents",
              "url": "https://docs.withorb.com/llms.txt",
              "seen": "2026-10-09"
            },
            {
              "what": "OpenAPI 3.1 description, read as the file and not as rendered reference pages",
              "url": "https://docs.withorb.com/api-reference/orb-openapi.json",
              "seen": "2026-10-09"
            },
            {
              "what": "rate limits",
              "url": "https://docs.withorb.com/api-reference/rate-limits.md",
              "seen": "2026-10-09"
            },
            {
              "what": "request idempotency",
              "url": "https://docs.withorb.com/api-reference/idempotency.md",
              "seen": "2026-10-09"
            },
            {
              "what": "error responses",
              "url": "https://docs.withorb.com/api-reference/error-responses.md",
              "seen": "2026-10-09"
            },
            {
              "what": "pagination",
              "url": "https://docs.withorb.com/api-reference/pagination.md",
              "seen": "2026-10-09"
            },
            {
              "what": "reliability and scaling",
              "url": "https://docs.withorb.com/api-reference/reliability.md",
              "seen": "2026-10-09"
            },
            {
              "what": "dry run requests",
              "url": "https://docs.withorb.com/essentials/dry-run.md",
              "seen": "2026-10-09"
            },
            {
              "what": "dashboard authentication and user roles",
              "url": "https://docs.withorb.com/essentials/authentication.md",
              "seen": "2026-10-09"
            },
            {
              "what": "audit logs",
              "url": "https://docs.withorb.com/essentials/audit-logs.md",
              "seen": "2026-10-09"
            },
            {
              "what": "SDK list",
              "url": "https://docs.withorb.com/essentials/sdk.md",
              "seen": "2026-10-09"
            },
            {
              "what": "production readiness review",
              "url": "https://docs.withorb.com/essentials/production-readiness-review.md",
              "seen": "2026-10-09"
            },
            {
              "what": "quickstart, API key creation and test mode",
              "url": "https://docs.withorb.com/quickstart/ingest.md",
              "seen": "2026-10-09"
            },
            {
              "what": "event ingestion",
              "url": "https://docs.withorb.com/events-and-metrics/event-ingestion.md",
              "seen": "2026-10-09"
            },
            {
              "what": "webhooks",
              "url": "https://docs.withorb.com/integrations-and-exports/webhooks.md",
              "seen": "2026-10-09"
            },
            {
              "what": "Stripe Shared Payment Tokens",
              "url": "https://docs.withorb.com/integrations-and-exports/stripe-shared-payment-tokens.md",
              "seen": "2026-10-09"
            },
            {
              "what": "pricing",
              "url": "https://www.withorb.com/pricing",
              "seen": "2026-10-09"
            },
            {
              "what": "Platform Terms and Conditions",
              "url": "https://www.withorb.com/terms",
              "seen": "2026-10-09"
            },
            {
              "what": "website terms of use",
              "url": "https://www.withorb.com/website-terms-of-use",
              "seen": "2026-10-09"
            },
            {
              "what": "privacy policy",
              "url": "https://www.withorb.com/privacy-policy",
              "seen": "2026-10-09"
            },
            {
              "what": "security page and disclosure policy",
              "url": "https://www.withorb.com/security",
              "seen": "2026-10-09"
            },
            {
              "what": "trust centre",
              "url": "https://security.withorb.com/",
              "seen": "2026-10-09"
            },
            {
              "what": "status page",
              "url": "https://status.withorb.com/",
              "seen": "2026-10-09"
            },
            {
              "what": "status history",
              "url": "https://status.withorb.com/history",
              "seen": "2026-10-09"
            },
            {
              "what": "product changelog feed",
              "url": "https://changelog.withorb.com/rss.xml",
              "seen": "2026-10-09"
            },
            {
              "what": "Python SDK repository, tags, changelog and CI workflow",
              "url": "https://github.com/orbcorp/orb-python",
              "seen": "2026-10-09"
            },
            {
              "what": "TypeScript SDK repository and tags",
              "url": "https://github.com/orbcorp/orb-typescript",
              "seen": "2026-10-09"
            },
            {
              "what": "earlier Node SDK repository and tags",
              "url": "https://github.com/orbcorp/orb-node",
              "seen": "2026-10-09"
            },
            {
              "what": "Go SDK repository and tags",
              "url": "https://github.com/orbcorp/orb-go",
              "seen": "2026-10-09"
            },
            {
              "what": "npm latest version",
              "url": "https://registry.npmjs.org/orb-billing/latest",
              "seen": "2026-10-09"
            },
            {
              "what": "npm weekly downloads",
              "url": "https://api.npmjs.org/downloads/point/last-week/orb-billing",
              "seen": "2026-10-09"
            },
            {
              "what": "domain registration",
              "url": "https://rdap.org/domain/withorb.com",
              "seen": "2026-10-09"
            }
          ],
          "openQuestions": [
            "unchecked: the DPA, SOC 1 and SOC 2 reports, the penetration test report and the sub-processor list. The trust centre at security.withorb.com lists them behind an access request",
            "unchecked: whether API keys can be scoped or made read-only. The readiness guide says to scope keys, and no page or schema describing scopes was found",
            "unchecked: status history before August 2026. The history page read shows three months, and the status site's robots.txt disallows `/api/`, so the incident feed was not requested",
            "unchecked: `https://api.withorb.com/spec.json`, the address the SDK page gives for the OpenAPI file. The host answered 403 to its robots.txt request, so nothing else was asked of it. The copy linked from the docs index was read once",
            "unchecked: demo.withorb.com, the demo environment the docs and pricing page link, and app.withorb.com. Whether the demo needs an account was not established",
            "unchecked: how a trial is granted and whether it needs a card. The terms say Orb may grant a 30-day trial, and the pricing page has only Contact Sales buttons",
            "unchecked: PyPI download counts (PyPI's robots.txt closes the path), CI results and the SDK issue threads",
            "unchecked: the effective date of the Platform Terms and Conditions. The page shows a Version label with no value in the text we read",
            "unchecked: whether the API still accepts the `debug` parameter on ingestion. The SDK changelog records its removal on 12 September 2026 and the reliability page still mentions `debug=True`. No deduction was taken because the SDK changelog marked it deprecated first",
            "No MCP server was found in the docs index, the home page or the SDK repositories. The earlier Node SDK changelog has MCP fixes dated December 2025, and neither TypeScript repository contains an MCP package today",
            "Neither the Platform Terms nor the website terms of use (effective 21 April 2025) were found to forbid automated access or benchmarking",
            "changelog.withorb.com has no robots.txt (the address returns the changelog page). The entries were read from the RSS feed the page links",
            "The lead listed SDKs for Python, Node, Ruby and Go. The docs also list Java and Kotlin. The lead's other points held"
          ]
        },
        "negative": 0,
        "verdict": "Orb suits a company that bills on usage and wants one API for events, plans, credits and invoices. It publishes an OpenAPI 3.1 file, numeric rate limits, idempotency keys and a dry-run header. Every plan is priced on request and access starts with sales. No scope list for API keys or public sub-processor list was found.",
        "bestFor": "A software or AI company that bills on usage and needs event metering, plan versioning, prepaid credits, invoicing and revenue reporting behind one API, with Stripe or Adyen collecting the money.",
        "strengths": [
          "Public OpenAPI 3.1 description with 147 operations and 79 webhook events, plus llms.txt and a Markdown twin of every docs page",
          "`Idempotency-Key` on every POST and PATCH for 48 hours, with `Idempotent-Replayed` and `Transient-Error` response headers",
          "A `Dry-Run: True` header validates most write requests and returns the would-be result without saving it",
          "Rate limits are published per category for live, test and trial accounts, from 10 analytics queries a second to 100 reads a second in live mode",
          "SDKs for Python, TypeScript and Go were each released on 9 October 2026, with 30 Python releases since 11 July"
        ],
        "weaknesses": [
          "All three plans (Core, Advanced, Enterprise) show custom pricing only, and the pricing page sends new customers to sales",
          "No list of API key scopes or a read-only key was found. Keys are created in the web app and revocation is irreversible",
          "Audit logs are in private preview and limited to the Enterprise plan",
          "The DPA and SOC reports sit behind an access request, and no public sub-processor list or hosting region was found",
          "The SDK changelog shows the ingestion `debug` parameter removed on 12 September 2026 while the reliability page still refers to it, and the product changelog has no entry"
        ],
        "agentNotes": [
          "Call `https://api.withorb.com/v1` with `Authorization: Bearer \u003ckey\u003e`. A person creates the key in the Orb web app under organisation settings, in test mode or live mode",
          "Send an `Idempotency-Key` of at most 64 characters on every POST and PATCH. A 409 means the first request is still running or the body changed",
          "Add `Dry-Run: True` to check a write first, and confirm `Orb-Dry-Run: true` in the response. Ingest, amend and deprecate event calls ignore it and run for real",
          "Do not send `Idempotency-Key` with `Dry-Run`. Orb returns a validation error",
          "Page with `limit` (default 20, maximum 100) and pass `next_cursor` back as `cursor` while `has_more` is true",
          "Back off exponentially on 429. Test mode allows 5 writes a second and 2,000 ingested events a minute"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 66.5
          }
        ],
        "editorialScores": {
          "ergonomics": 84,
          "maintenance": 82,
          "payments": 5,
          "reliability": 77,
          "schema": 88,
          "security": 55,
          "transparency": 45
        },
        "provenanceScore": 84
      },
      "connect": {
        "install": "pip install orb-billing",
        "http": "curl --request POST \\\n     --url https://api.withorb.com/v1/subscriptions \\\n     --header 'Dry-Run: True' \\\n     --header 'Accept: application/json' \\\n     --header 'Authorization: Bearer \u003cTOKEN\u003e' \\\n     --header 'Content-Type: application/json'"
      },
      "letme": {
        "capability": "https://letme.dev/payments.metering",
        "tool": "https://letme.dev/orb"
      },
      "notable": [
        "The rate-limit table gives live, test and trial limits per category, for example 50 write operations a second live, 5 in test mode and 1 on a trial (https://docs.withorb.com/api-reference/rate-limits.md)",
        "Idempotency keys are honoured for 48 hours on POST and PATCH, and a replayed response carries `Idempotent-Replayed: true` (https://docs.withorb.com/api-reference/idempotency.md)",
        "The `Dry-Run: True` header is not supported on `POST /v1/ingest`, `PUT /v1/events/\u003cevent_id\u003e` and `PUT /v1/events/\u003cevent_id\u003e/deprecate`, where the request runs normally (https://docs.withorb.com/essentials/dry-run.md)",
        "Orb can collect an invoice with a Stripe Shared Payment Token granted by a customer's AI agent, through `POST /v1/invoices/{invoice_id}/pay`. The feature needs enabling by Orb's account team and a Stripe Connect integration (https://docs.withorb.com/integrations-and-exports/stripe-shared-payment-tokens.md)",
        "The status history page lists four incidents in September 2026, three rated minor and one unrated, and none in August or October to date (https://status.withorb.com/history)",
        "The pricing page lists Core, Advanced and Enterprise at custom pricing, charged on billings and events, with a platform fee on the upper two tiers (https://www.withorb.com/pricing)",
        "The npm package `orb-billing` is now built from orbcorp/orb-typescript (6.27.0). The older orbcorp/orb-node repository stopped at v5.76.0 on 14 July 2026 (https://github.com/orbcorp/orb-typescript)",
        "Every docs Markdown page opens with a block telling the reader to fetch llms.txt before exploring further. We record it as a fact and did not treat it as an instruction (https://docs.withorb.com/overview.md)"
      ],
      "area": "payments",
      "details": [
        {
          "label": "API",
          "value": "REST at `https://api.withorb.com/v1`. The OpenAPI 3.1 description (version 1.0) has 147 operations on 115 paths, 729 schemas and 79 webhook events, across customers, events, metrics, plans, prices, subscriptions, invoices, credit notes, credits, coupons, alerts and items"
        },
        {
          "label": "Credentials",
          "value": "API key as a Bearer token, created in the web app under organisation settings, separately for test mode and live mode. Revocation is irreversible. No scope list was found. Dashboard users are Admin, Editor or Viewer, with password, Google, Microsoft or SAML sign-in"
        },
        {
          "label": "Rate limits",
          "value": "Live mode, per second, 10 analytics queries, 10 ledger queries, 100 other reads, 50 writes and 100 ingestion requests, with 10,000 ingested events a minute by default. Test mode 5, 5, 50, 5 and 10, with 2,000 events a minute. Trial 1, 1, 10, 1 and 2, with 100 events a minute"
        },
        {
          "label": "Retries",
          "value": "`Idempotency-Key` on POST and PATCH, up to 64 characters, kept 48 hours. `Idempotent-Replayed: true` on a replay, 409 on a concurrent or changed retry, `Transient-Error: true` on retryable 500s. Each usage event carries its own `idempotency_key`. Exponential backoff advised on 429, with no `Retry-After` documented"
        },
        {
          "label": "Dry run",
          "value": "`Dry-Run: True` request header on most writes, confirmed by `Orb-Dry-Run: true` in the response. Not supported on ingest, amend event and deprecate event"
        },
        {
          "label": "Errors",
          "value": "RFC 7807 bodies with `status`, `title`, `type` and `detail`. Nine documented types across 400, 401, 404, 409, 429 and 500, each with a stable `type` URI, and a `validation_errors` array on 400"
        },
        {
          "label": "Pagination",
          "value": "Cursor-based. `limit` defaults to 20 with a maximum of 100, and responses carry `pagination_metadata` with `has_more` and `next_cursor`. List calls filter on dates and amounts with `[gt]`, `[gte]`, `[lt]` and `[lte]` suffixes"
        },
        {
          "label": "SDKs",
          "value": "Python `orb-billing` 4.83.0, TypeScript `orb-billing` 6.27.0 and Go `orb-go` v1.126.0, all tagged 9 October 2026, plus Java, Kotlin and Ruby. Generated by Stainless under Apache-2.0. The Python SDK retries twice by default on connection errors, 408, 409, 429 and 5xx"
        },
        {
          "label": "Webhooks",
          "value": "79 event types in the API description. Signed with HMAC-SHA256 in `X-Orb-Signature` over `v1:`, the `X-Orb-Timestamp` value and the body, one secret per endpoint. At-least-once delivery, a five-second response window and a retry schedule that starts at 5 seconds, 5 minutes, 30 minutes and 2 hours"
        },
        {
          "label": "Payment collection",
          "value": "Invoices are collected through connected Stripe or Adyen accounts, with dunning. Stripe Shared Payment Tokens for agent-granted payment are supported on request. Invoicing and accounting sync to QuickBooks, NetSuite and Bill.com, and tax through Anrok, Avalara, Numeral, Sphere, Stripe Tax or TaxJar"
        },
        {
          "label": "Plans",
          "value": "Core, Advanced and Enterprise, each at custom pricing based on billings and ingested events, with a platform fee on Advanced and Enterprise. The terms describe a 30-day free trial that Orb may grant. SLAs are listed for Enterprise only, in the customer's agreement"
        },
        {
          "label": "Audit",
          "value": "Audit logs record the action, time, actor (API key or user), targets, IP address and user agent, without request bodies, and can stream to a SIEM. Private preview, Enterprise plan only"
        },
        {
          "label": "Certifications",
          "value": "SOC 2 Type 2 and SOC 1 Type 2 per the trust centre, an annual third-party penetration test, and a disclosure policy with security@withorb.com. Reports and the DPA need an access request"
        },
        {
          "label": "Status",
          "value": "status.withorb.com on Atlassian Statuspage with eight components (API, Reads, Writes, Analytics, Ingest, Real-time alerting, Webhooks, Invoicing) and 90-day uptime bars. Dedicated enterprise deployments are not covered"
        }
      ],
      "provenance": {
        "legalEntity": "Orb, Inc.",
        "domain": "withorb.com",
        "domainRegistered": "2019-10-12",
        "endpointOnVendorDomain": true,
        "terms": "https://www.withorb.com/terms",
        "privacy": "https://www.withorb.com/privacy-policy",
        "statusPage": "https://status.withorb.com",
        "changelog": "https://changelog.withorb.com",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The website terms of use (effective 21 April 2025) give Orb, Inc., 2261 Market Street #5171, San Francisco, CA 94114. The trust centre and the API description's contact block also name Orb, Inc.",
          "The Platform Terms and Conditions at /terms govern the Orb Platform and Orb API to the extent an Order Form refers to them, under California law. No version date was read on the page.",
          "The privacy policy was last updated on 7 May 2025 and covers data collected through the website and the product, including end customers' names and billing addresses.",
          "The API answers at api.withorb.com and the web app at app.withorb.com, both on the vendor's domain.",
          "www.withorb.com/.well-known/security.txt returned 404. The security page gives security@withorb.com and a written disclosure scope.",
          "RDAP for withorb.com gives a registration date of 2019-10-12 and Squarespace Domains II LLC as registrar.",
          "The DPA is available on request by email or through the trust centre at security.withorb.com, and was not read."
        ],
        "score": 84,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Orb, Inc.",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "withorb.com, registered 2019-10-12 (6 years)",
            "points": 11,
            "max": 15,
            "state": "part"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "api.withorb.com",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 5 of the 7 things a reader expects",
            "points": 8.3,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 7 of the 8 things a reader expects",
            "points": 9.3,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Status page",
            "value": "status.withorb.com",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://www.withorb.com/terms",
            "state": "read",
            "readAt": "2026-10-09",
            "statedDate": "2024-11-13",
            "words": 5459,
            "points": 8.3,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "‍These terms were last updated on November 13, 2024.",
                "says": "Last updated 2024-11-13"
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "This Agreement will be governed by the laws of the State of California without regard to its conflict of laws provisions.",
                "says": "The law of the State of California"
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "…negligence) or otherwise, and Orb’s liability for all claims arising under a Trial or beta use will not exceed $100.00.",
                "says": "Capped at $100.00"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "In addition, if any past due payment has not been received by Orb within ten (10) days from the time such payment is due, Orb may suspend Customer’s access to the Orb Platform until such payment is made."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": false
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "Unless Customer provides evidence of an exemption from the relevant Taxes, Customer will pay and be solely responsible for all Taxes and will gross up any payment to include such Taxes, and Customer will not withhold any Taxes from any amounts due to Orb."
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": false
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Orb may change the fees or terms that apply to a renewal term before that term starts.",
                "quote": "Orb reserves the right to modify the fees or terms applicable to any Renewal Term prior to commencement of the Renewal Term."
              },
              {
                "date": "2026-10-08",
                "text": "Orb may name the customer and show its trademark on its website and in other marketing and advertising material.",
                "quote": "Customer agrees that Orb may (a) list and/or identify Customer’s name (including by displaying any Customer trademark) to identify the business relationship between the parties on Orb’s website and in other marketing and advertising collateral"
              },
              {
                "date": "2026-10-08",
                "text": "The licence the customer grants over Customer Data is worldwide and sublicensable, and includes the right to publish, display and aggregate that data.",
                "quote": "Customer hereby grants Orb the nonexclusive, worldwide, royalty-free, fully paid up, sublicensable, right and license to access, use, publish, process, display, aggregate, and store Customer Data"
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://www.withorb.com/privacy-policy",
            "state": "read",
            "readAt": "2026-10-09",
            "statedDate": "2025-05-07",
            "words": 3982,
            "points": 9.3,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last updated: May 7, 2025",
                "says": "Last updated 2025-05-07"
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "It is Orb's policy to respect your privacy and comply with any applicable law and regulation regarding any personal information we may collect about you, including across our website, https://www.withorb.com/, and other sites we own and operate."
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "Data Retention: We keep personal information as long as needed for our purposes, legal requirements, or fraud prevention.",
                "says": "For as long as needed, with no period named"
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "third-party service providers for the purpose of enabling them to provide their services, including (without limitation) IT service providers, data storage, hosting and server providers, analytics, error loggers, debt collectors, maintenance or problem-solving providers, marketing providers, professional advisors, and…"
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "We do not sell or share your personal information for cross-context behavioral advertising, as defined by state privacy laws.",
                "says": "Says it does not sell personal data"
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "Your Rights: If you are in Europe, you have the right to:"
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "If you wish to request the deletion of your personal data, please contact us at privacy@withorb.com.",
                "says": "privacy@withorb.com"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": false
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/orb.json",
      "live": {
        "slug": "orb",
        "probe": {
          "target": "https://api.withorb.com/v1",
          "method": "get",
          "lastAt": "2026-10-10T01:38:01.612632632Z",
          "lastOk": true,
          "lastStatus": 403,
          "lastMs": 252,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 258,
          "p95ms24h": 369,
          "samples24h": 102,
          "samples30d": 102,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 85,
              "ok": 85
            },
            {
              "date": "2026-10-10",
              "probes": 17,
              "ok": 17
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.withorb.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-10T01:34:02.855150172Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "orbcorp/orb-python",
            "version": "v4.83.0",
            "released": "2026-10-09",
            "seenAt": "2026-10-09T17:11:19.948988838Z"
          },
          {
            "registry": "npm",
            "name": "orb-billing",
            "version": "6.27.0",
            "seenAt": "2026-10-09T17:11:19.103890585Z"
          },
          {
            "registry": "pypi",
            "name": "orb-billing",
            "version": "4.83.0",
            "released": "2026-10-09",
            "seenAt": "2026-10-09T17:11:18.985061165Z"
          }
        ],
        "githubStars": 5,
        "npmWeekly": 184768,
        "pypiWeekly": 334816,
        "pages": [
          {
            "url": "https://changelog.withorb.com",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:33:43.924244658Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "2f5e7d2a385a"
          },
          {
            "url": "https://www.withorb.com/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-09T18:55:42.770953537Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "a352af138f81"
          },
          {
            "url": "https://www.withorb.com/privacy-policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-09T18:55:45.239973302Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "1516bbe57809"
          },
          {
            "url": "https://www.withorb.com/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-09T18:55:47.191671669Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "4e15ade75c2a"
          }
        ],
        "updatedAt": "2026-10-10T01:38:01.612632632Z"
      }
    },
    "verify": {
      "accepts": "a page on withorb.com or one of its subdomains, or the README of github.com/orbcorp/orb-python",
      "badgeUrl": "https://www.anchorterminal.com/badges/orb.svg",
      "body": {
        "slug": "orb",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/orb",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/orb\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/orb.svg\" alt=\"Orb on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Orb on Anchor Terminal](https://www.anchorterminal.com/badges/orb.svg)](https://www.anchorterminal.com/tools/orb)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/orb\"\u003eOrb on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/orb",
    "json": "https://www.anchorterminal.com/tools/orb.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/orb.md",
    "slim": "https://www.anchorterminal.com/tools/orb.min.md"
  },
  "markdown": "## Overview\n\n**Grade B · 66.5/100 · rank #289 of 950 · #7 in Payment \u0026 monetisation platforms · not agent-ready · confidence medium**\n\n\n## Assessment\n\nOrb suits a company that bills on usage and wants one API for events, plans, credits and invoices. It publishes an OpenAPI 3.1 file, numeric rate limits, idempotency keys and a dry-run header. Every plan is priced on request and access starts with sales. No scope list for API keys or public sub-processor list was found.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Orb, Inc. (https://www.withorb.com) |\n| Kind | HTTP API |\n| Category | Payment \u0026 monetisation platforms (https://www.anchorterminal.com/categories/payment-platforms) |\n| Transport | HTTP |\n| Endpoint | `https://api.withorb.com/v1` |\n| Auth | API key · The API takes an API key as a Bearer token. A person creates it in the Orb web app under organisation settings, in test mode or live mode, after Orb's sales team has opened the account. No self-serve sign-up, OAuth flow or programmatic key API was found. Keys can be revoked, which is irreversible, and no scope list was found in the docs. |\n| Pricing | Paid (Paid) · No public prices. Core, Advanced and Enterprise all show custom pricing, based on billings and ingested events, with a platform fee on the upper two tiers, and each starts with a sales contact. The terms describe a 30-day free trial that Orb may grant, and test mode works as a sandbox once an account exists. No free tier was found (https://www.withorb.com/pricing, checked 2026-10-09). |\n| x402 | No · No x402, MPP or L402 in the OpenAPI description, the docs index or the pricing page. Orb can charge a Stripe Shared Payment Token granted by a buyer's agent, through the merchant's Stripe account and on request (checked 2026-10-09). |\n| Licence | Proprietary service under Orb's Platform Terms and Conditions. The SDKs on GitHub are Apache-2.0 |\n| Packages | pypi: `orb-billing`; npm: `orb-billing`; go: `github.com/orbcorp/orb-go` |\n| Source | https://github.com/orbcorp/orb-python |\n| Docs | https://docs.withorb.com |\n| llms.txt | https://docs.withorb.com/llms.txt |\n| Last release | 2026-10-09 |\n| GitHub stars | 5 (as of 2026-10-09) |\n| npm downloads / week | 184,768 |\n| API | REST at `https://api.withorb.com/v1`. The OpenAPI 3.1 description (version 1.0) has 147 operations on 115 paths, 729 schemas and 79 webhook events, across customers, events, metrics, plans, prices, subscriptions, invoices, credit notes, credits, coupons, alerts and items |\n| Credentials | API key as a Bearer token, created in the web app under organisation settings, separately for test mode and live mode. Revocation is irreversible. No scope list was found. Dashboard users are Admin, Editor or Viewer, with password, Google, Microsoft or SAML sign-in |\n| Rate limits | Live mode, per second, 10 analytics queries, 10 ledger queries, 100 other reads, 50 writes and 100 ingestion requests, with 10,000 ingested events a minute by default. Test mode 5, 5, 50, 5 and 10, with 2,000 events a minute. Trial 1, 1, 10, 1 and 2, with 100 events a minute |\n| Retries | `Idempotency-Key` on POST and PATCH, up to 64 characters, kept 48 hours. `Idempotent-Replayed: true` on a replay, 409 on a concurrent or changed retry, `Transient-Error: true` on retryable 500s. Each usage event carries its own `idempotency_key`. Exponential backoff advised on 429, with no `Retry-After` documented |\n| Dry run | `Dry-Run: True` request header on most writes, confirmed by `Orb-Dry-Run: true` in the response. Not supported on ingest, amend event and deprecate event |\n| Errors | RFC 7807 bodies with `status`, `title`, `type` and `detail`. Nine documented types across 400, 401, 404, 409, 429 and 500, each with a stable `type` URI, and a `validation_errors` array on 400 |\n| Pagination | Cursor-based. `limit` defaults to 20 with a maximum of 100, and responses carry `pagination_metadata` with `has_more` and `next_cursor`. List calls filter on dates and amounts with `[gt]`, `[gte]`, `[lt]` and `[lte]` suffixes |\n| SDKs | Python `orb-billing` 4.83.0, TypeScript `orb-billing` 6.27.0 and Go `orb-go` v1.126.0, all tagged 9 October 2026, plus Java, Kotlin and Ruby. Generated by Stainless under Apache-2.0. The Python SDK retries twice by default on connection errors, 408, 409, 429 and 5xx |\n| Webhooks | 79 event types in the API description. Signed with HMAC-SHA256 in `X-Orb-Signature` over `v1:`, the `X-Orb-Timestamp` value and the body, one secret per endpoint. At-least-once delivery, a five-second response window and a retry schedule that starts at 5 seconds, 5 minutes, 30 minutes and 2 hours |\n| Payment collection | Invoices are collected through connected Stripe or Adyen accounts, with dunning. Stripe Shared Payment Tokens for agent-granted payment are supported on request. Invoicing and accounting sync to QuickBooks, NetSuite and Bill.com, and tax through Anrok, Avalara, Numeral, Sphere, Stripe Tax or TaxJar |\n| Plans | Core, Advanced and Enterprise, each at custom pricing based on billings and ingested events, with a platform fee on Advanced and Enterprise. The terms describe a 30-day free trial that Orb may grant. SLAs are listed for Enterprise only, in the customer's agreement |\n| Audit | Audit logs record the action, time, actor (API key or user), targets, IP address and user agent, without request bodies, and can stream to a SIEM. Private preview, Enterprise plan only |\n| Certifications | SOC 2 Type 2 and SOC 1 Type 2 per the trust centre, an annual third-party penetration test, and a disclosure policy with security@withorb.com. Reports and the DPA need an access request |\n| Status | status.withorb.com on Atlassian Statuspage with eight components (API, Reads, Writes, Analytics, Ingest, Real-time alerting, Webhooks, Invoicing) and 90-day uptime bars. Dedicated enterprise deployments are not covered |\n| Capabilities | payments.metering, payments.card |\n| Tags | hosted, sales-led, enterprise, openapi, llms-txt, webhooks, python, typescript, go, java, kotlin, ruby, status-page, soc2, closed-source |\n| JSON | https://www.anchorterminal.com/api/v1/tools/orb.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-09 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 77 | 15.4 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 88 | 14.3 |\n| Agent ergonomics | 13% | 16.2 | 84 | 13.7 |\n| Security \u0026 auth | 14% | 17.5 | 55 | 9.6 |\n| Payments \u0026 pricing | 10% | 12.5 | 5 | 0.6 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 82 | 7.2 |\n| Transparency \u0026 trust (editorial 45, provenance 84) | 7% | 8.8 | 65 | 5.7 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **66.5 → B** |\n\n### Why each score\n\n- Reliability 77: Hosted lines. status.withorb.com runs on Atlassian Statuspage with eight components and 90-day uptime bars (20). The history page covers August to October 2026 and lists four incidents, all in September. Three are rated minor (delayed usage-based invoices on 1 and 2 September, dashboard reporting errors on 16 September, elevated latency on 24 September) and one unrated (15 minutes of elevated latency on shared clusters on 25 September). July was not on the page read (20 of 30). Rate limits are published per category for live, test and trial accounts. The ingest reference still says no hard rate limit is enforced, which contradicts the table (14 of 15). The docs advise exponential backoff on 429 with no `Retry-After` documented, and `Idempotency-Key` on POST and PATCH makes retries safe for 48 hours (13 of 15). The pricing page lists SLAs for Enterprise only, inside the customer's agreement, and the public terms promise reasonable efforts with no figure (0). The v1 API is generally available (10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 88: A public OpenAPI 3.1 description with 147 operations, 729 schemas and 79 webhook events (25). llms.txt and a Markdown twin for every docs page (10). 129 of 147 operations carry a description longer than 80 characters, and the ingest, ledger and subscription entries explain when to use each call. Few say when not to (17 of 20). The description has 688 enums and required lists, with free-form maps for `metadata` and event `properties` (13 of 15). Examples appear in about 350 places, and errors follow RFC 7807 with nine documented types and stable `type` URIs. The URIs point at an older docs path (13 of 15). The path is versioned v1 and the description says 1.0, with no dated API versions. API changes are recorded in the SDK changelogs, and the product changelog has 20 entries from October 2025 to August 2026 (10 of 15).\n- Agent ergonomics 84: Graded on the REST API. List calls take `limit` (default 20, maximum 100) and a few view switches such as `include_zero_quantity_line_items`. No field selection was found, and invoice and subscription objects are large (14 of 25). Cursor pagination with `has_more` and `next_cursor`, and filters on status, customer, dates and amounts with comparison suffixes (18 of 20). Errors carry `status`, `title`, a stable `type` URI and `detail`, with a `validation_errors` array on 400 (18 of 20). `Idempotency-Key` with replay and transient-error headers, per-event idempotency keys and a `Dry-Run` header that previews most writes (20 of 20). Creating a customer needs only `name` and `email`, external IDs are accepted as aliases, and official SDKs cover six languages (14 of 15).\n- Security \u0026 auth 55: API keys are Bearer tokens created in the web app, separately for test mode and live mode, and can be revoked. The readiness guide says to scope and rotate keys, and no scope list or read-only key was found in the docs or the API description (20 of 30). Dashboard users have Admin, Editor or Viewer roles, and the `Dry-Run` header and preview calls let a caller check a write before committing it. Nothing limits what an API key can do (8 of 20). The API returns customer-supplied names, metadata and event properties, and no prompt-injection guidance was found (5 of 15). Audit logs name the API key or user, the targets, the IP address and the user agent and can stream to a SIEM, but they are in private preview on the Enterprise plan only (8 of 15). SOC 2 Type 2 and SOC 1 Type 2 per the trust centre, an annual third-party penetration test and a written disclosure policy with a reporting address. security.txt returned 404 and no bounty was found (14 of 20).\n- Payments \u0026 pricing 5: Payment platforms take the highest step that applies on the 40-point protocol line. No x402, MPP or L402 was found in the API description, the docs index or the pricing page. Orb can collect an invoice with a Stripe Shared Payment Token that a buyer's agent granted, on request and through the merchant's Stripe account. That is a Stripe credential and not one of the three protocols, so we scored it 0 and flag the judgement (0). Core, Advanced and Enterprise all show custom pricing (0). The terms describe a 30-day free trial that Orb may grant and the rate-limit table has a trial column, but the pricing page routes every start through sales and no self-serve sign-up was found (5 of 20). A person contacts sales and creates the key in the web app (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 82: The Python SDK 4.83.0, TypeScript SDK 6.27.0 and Go SDK v1.126.0 were all tagged on 9 October 2026, the day of the check (30). The Python repository has 30 tags since 11 July 2026 (20). The product changelog's latest entry is dated 7 August 2026, with two entries in the last 90 days. A support site is linked, the terms name email and Slack support, and the SDK issue queues (four and six open items) were not read (9 of 15). Current official SDKs in six languages. The TypeScript SDK moved to a new repository and major version, with a migration guide (15). The repositories carry CI workflows with lint, build and test jobs, lockfiles and automated releases. CI results were not read (8 of 10).\n- Transparency \u0026 trust 65: The platform is closed under published Platform Terms and Conditions, and the SDKs are Apache-2.0. The terms page shows no version date (17 of 30). The privacy policy of 7 May 2025 covers product data, the terms allow a data export within 30 days of termination before deletion, and the security page states seven-day snapshot retention and deletion on request. The terms let Orb use aggregated, de-identified customer data to improve the service. The DPA is available only on request (16 of 30). No deprecation policy was found. The API description marks 235 items deprecated with no removal dates, and the SDK changelog shows the ingestion `debug` parameter deprecated on 15 July and removed on 12 September 2026 (6 of 20). The security page names AWS as host and says Orb keeps a sub-processor list, which is not public. The privacy policy lists provider categories and names Stripe. No hosting region was found (6 of 20).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (24 items): https://www.anchorterminal.com/fixes/orb.md (JSON https://www.anchorterminal.com/fixes/orb.json)\n\n### What we couldn't check\n\n- unchecked: the DPA, SOC 1 and SOC 2 reports, the penetration test report and the sub-processor list. The trust centre at security.withorb.com lists them behind an access request\n- unchecked: whether API keys can be scoped or made read-only. The readiness guide says to scope keys, and no page or schema describing scopes was found\n- unchecked: status history before August 2026. The history page read shows three months, and the status site's robots.txt disallows `/api/`, so the incident feed was not requested\n- unchecked: `https://api.withorb.com/spec.json`, the address the SDK page gives for the OpenAPI file. The host answered 403 to its robots.txt request, so nothing else was asked of it. The copy linked from the docs index was read once\n- unchecked: demo.withorb.com, the demo environment the docs and pricing page link, and app.withorb.com. Whether the demo needs an account was not established\n- unchecked: how a trial is granted and whether it needs a card. The terms say Orb may grant a 30-day trial, and the pricing page has only Contact Sales buttons\n- unchecked: PyPI download counts (PyPI's robots.txt closes the path), CI results and the SDK issue threads\n- unchecked: the effective date of the Platform Terms and Conditions. The page shows a Version label with no value in the text we read\n- unchecked: whether the API still accepts the `debug` parameter on ingestion. The SDK changelog records its removal on 12 September 2026 and the reliability page still mentions `debug=True`. No deduction was taken because the SDK changelog marked it deprecated first\n- No MCP server was found in the docs index, the home page or the SDK repositories. The earlier Node SDK changelog has MCP fixes dated December 2025, and neither TypeScript repository contains an MCP package today\n- Neither the Platform Terms nor the website terms of use (effective 21 April 2025) were found to forbid automated access or benchmarking\n- changelog.withorb.com has no robots.txt (the address returns the changelog page). The entries were read from the RSS feed the page links\n- The lead listed SDKs for Python, Node, Ruby and Go. The docs also list Java and Kotlin. The lead's other points held\n\n### Sources\n\n- docs index for agents: \u003chttps://docs.withorb.com/llms.txt\u003e (seen 2026-10-09)\n- OpenAPI 3.1 description, read as the file and not as rendered reference pages: \u003chttps://docs.withorb.com/api-reference/orb-openapi.json\u003e (seen 2026-10-09)\n- rate limits: \u003chttps://docs.withorb.com/api-reference/rate-limits.md\u003e (seen 2026-10-09)\n- request idempotency: \u003chttps://docs.withorb.com/api-reference/idempotency.md\u003e (seen 2026-10-09)\n- error responses: \u003chttps://docs.withorb.com/api-reference/error-responses.md\u003e (seen 2026-10-09)\n- pagination: \u003chttps://docs.withorb.com/api-reference/pagination.md\u003e (seen 2026-10-09)\n- reliability and scaling: \u003chttps://docs.withorb.com/api-reference/reliability.md\u003e (seen 2026-10-09)\n- dry run requests: \u003chttps://docs.withorb.com/essentials/dry-run.md\u003e (seen 2026-10-09)\n- dashboard authentication and user roles: \u003chttps://docs.withorb.com/essentials/authentication.md\u003e (seen 2026-10-09)\n- audit logs: \u003chttps://docs.withorb.com/essentials/audit-logs.md\u003e (seen 2026-10-09)\n- SDK list: \u003chttps://docs.withorb.com/essentials/sdk.md\u003e (seen 2026-10-09)\n- production readiness review: \u003chttps://docs.withorb.com/essentials/production-readiness-review.md\u003e (seen 2026-10-09)\n- quickstart, API key creation and test mode: \u003chttps://docs.withorb.com/quickstart/ingest.md\u003e (seen 2026-10-09)\n- event ingestion: \u003chttps://docs.withorb.com/events-and-metrics/event-ingestion.md\u003e (seen 2026-10-09)\n- webhooks: \u003chttps://docs.withorb.com/integrations-and-exports/webhooks.md\u003e (seen 2026-10-09)\n- Stripe Shared Payment Tokens: \u003chttps://docs.withorb.com/integrations-and-exports/stripe-shared-payment-tokens.md\u003e (seen 2026-10-09)\n- pricing: \u003chttps://www.withorb.com/pricing\u003e (seen 2026-10-09)\n- Platform Terms and Conditions: \u003chttps://www.withorb.com/terms\u003e (seen 2026-10-09)\n- website terms of use: \u003chttps://www.withorb.com/website-terms-of-use\u003e (seen 2026-10-09)\n- privacy policy: \u003chttps://www.withorb.com/privacy-policy\u003e (seen 2026-10-09)\n- security page and disclosure policy: \u003chttps://www.withorb.com/security\u003e (seen 2026-10-09)\n- trust centre: \u003chttps://security.withorb.com/\u003e (seen 2026-10-09)\n- status page: \u003chttps://status.withorb.com/\u003e (seen 2026-10-09)\n- status history: \u003chttps://status.withorb.com/history\u003e (seen 2026-10-09)\n- product changelog feed: \u003chttps://changelog.withorb.com/rss.xml\u003e (seen 2026-10-09)\n- Python SDK repository, tags, changelog and CI workflow: \u003chttps://github.com/orbcorp/orb-python\u003e (seen 2026-10-09)\n- TypeScript SDK repository and tags: \u003chttps://github.com/orbcorp/orb-typescript\u003e (seen 2026-10-09)\n- earlier Node SDK repository and tags: \u003chttps://github.com/orbcorp/orb-node\u003e (seen 2026-10-09)\n- Go SDK repository and tags: \u003chttps://github.com/orbcorp/orb-go\u003e (seen 2026-10-09)\n- npm latest version: \u003chttps://registry.npmjs.org/orb-billing/latest\u003e (seen 2026-10-09)\n- npm weekly downloads: \u003chttps://api.npmjs.org/downloads/point/last-week/orb-billing\u003e (seen 2026-10-09)\n- domain registration: \u003chttps://rdap.org/domain/withorb.com\u003e (seen 2026-10-09)\n\n## Who's behind it (provenance 84/100, checked 2026-10-09)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Orb, Inc. | 20/20 |\n| Domain age | withorb.com, registered 2019-10-12 (6 years) | 11/15 |\n| Endpoint on the vendor's domain | api.withorb.com | 15/15 |\n| Terms of service | read, states 5 of the 7 things a reader expects | 8.3/10 |\n| Privacy policy | read, states 7 of the 8 things a reader expects | 9.3/10 |\n| Status page | status.withorb.com | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | not found | 0/10 |\n\nThe website terms of use (effective 21 April 2025) give Orb, Inc., 2261 Market Street #5171, San Francisco, CA 94114. The trust centre and the API description's contact block also name Orb, Inc.\n\nThe Platform Terms and Conditions at /terms govern the Orb Platform and Orb API to the extent an Order Form refers to them, under California law. No version date was read on the page.\n\nThe privacy policy was last updated on 7 May 2025 and covers data collected through the website and the product, including end customers' names and billing addresses.\n\nThe API answers at api.withorb.com and the web app at app.withorb.com, both on the vendor's domain.\n\nwww.withorb.com/.well-known/security.txt returned 404. The security page gives security@withorb.com and a written disclosure scope.\n\nRDAP for withorb.com gives a registration date of 2019-10-12 and Squarespace Domains II LLC as registrar.\n\nThe DPA is available on request by email or through the trust centre at security.withorb.com, and was not read.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://www.withorb.com/terms), read 2026-10-09, dated 2024-11-13, states 5 of the 7 things a reader expects.\n\n- Gives the date it was last updated. Last updated 2024-11-13.\n- Names the governing law or courts. The law of the State of California.\n- States a limit on its liability. Capped at $100.00.\n- Not found in the text. Says how changes to the terms are announced.\n- Not found in the text. Refers to a service level or uptime commitment.\n- Also in the text (2026-10-08). Orb may change the fees or terms that apply to a renewal term before that term starts. \"Orb reserves the right to modify the fees or terms applicable to any Renewal Term prior to commencement of the Renewal Term.\"\n- Also in the text (2026-10-08). Orb may name the customer and show its trademark on its website and in other marketing and advertising material. \"Customer agrees that Orb may (a) list and/or identify Customer’s name (including by displaying any Customer trademark) to identify the business relationship between the parties on Orb’s website and in other marketing and advertising collateral\"\n- Also in the text (2026-10-08). The licence the customer grants over Customer Data is worldwide and sublicensable, and includes the right to publish, display and aggregate that data. \"Customer hereby grants Orb the nonexclusive, worldwide, royalty-free, fully paid up, sublicensable, right and license to access, use, publish, process, display, aggregate, and store Customer Data\"\n\n**Privacy policy** (https://www.withorb.com/privacy-policy), read 2026-10-09, dated 2025-05-07, states 7 of the 8 things a reader expects.\n\n- Gives the date it was last updated. Last updated 2025-05-07.\n- Says how long data is kept. For as long as needed, with no period named.\n- Says whether personal data is sold or shared for advertising. Says it does not sell personal data.\n- Gives a privacy contact. privacy@withorb.com.\n- Not found in the text. Says where data is transferred or stored.\n\n## Live (updated 2026-10-10 01:38 UTC)\n\n- Right now: up, HTTP 403, 252 ms, checked 2026-10-10 01:38 UTC (get on `https://api.withorb.com/v1`, asks for auth)\n- Uptime 24h 100.0% (102 probes) · 30 days 100.0% (102 probes) · p50 258 ms · p95 369 ms\n- Vendor status page: none, All Systems Operational\n- github `orbcorp/orb-python` v4.83.0, released 2026-10-09\n- npm `orb-billing` 6.27.0\n- pypi `orb-billing` 4.83.0, released 2026-10-09\n- Watching changelog \u003chttps://changelog.withorb.com\u003e\n- Watching pricing \u003chttps://www.withorb.com/pricing\u003e\n- Watching privacy \u003chttps://www.withorb.com/privacy-policy\u003e\n- Watching terms \u003chttps://www.withorb.com/terms\u003e\n- Always current: https://www.anchorterminal.com/api/v1/live/orb.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Strengths\n\n- Public OpenAPI 3.1 description with 147 operations and 79 webhook events, plus llms.txt and a Markdown twin of every docs page\n- `Idempotency-Key` on every POST and PATCH for 48 hours, with `Idempotent-Replayed` and `Transient-Error` response headers\n- A `Dry-Run: True` header validates most write requests and returns the would-be result without saving it\n- Rate limits are published per category for live, test and trial accounts, from 10 analytics queries a second to 100 reads a second in live mode\n- SDKs for Python, TypeScript and Go were each released on 9 October 2026, with 30 Python releases since 11 July\n\n## Weaknesses\n\n- All three plans (Core, Advanced, Enterprise) show custom pricing only, and the pricing page sends new customers to sales\n- No list of API key scopes or a read-only key was found. Keys are created in the web app and revocation is irreversible\n- Audit logs are in private preview and limited to the Enterprise plan\n- The DPA and SOC reports sit behind an access request, and no public sub-processor list or hosting region was found\n- The SDK changelog shows the ingestion `debug` parameter removed on 12 September 2026 while the reliability page still refers to it, and the product changelog has no entry\n\n## Before you call it (notes for agents)\n\n1. Call `https://api.withorb.com/v1` with `Authorization: Bearer \u003ckey\u003e`. A person creates the key in the Orb web app under organisation settings, in test mode or live mode\n2. Send an `Idempotency-Key` of at most 64 characters on every POST and PATCH. A 409 means the first request is still running or the body changed\n3. Add `Dry-Run: True` to check a write first, and confirm `Orb-Dry-Run: true` in the response. Ingest, amend and deprecate event calls ignore it and run for real\n4. Do not send `Idempotency-Key` with `Dry-Run`. Orb returns a validation error\n5. Page with `limit` (default 20, maximum 100) and pass `next_cursor` back as `cursor` while `has_more` is true\n6. Back off exponentially on 429. Test mode allows 5 writes a second and 2,000 ingested events a minute\n\n## Connect\n\nInstall:\n\n```bash\npip install orb-billing\n```\n\nFirst request:\n\n```bash\ncurl --request POST \\\n     --url https://api.withorb.com/v1/subscriptions \\\n     --header 'Dry-Run: True' \\\n     --header 'Accept: application/json' \\\n     --header 'Authorization: Bearer \u003cTOKEN\u003e' \\\n     --header 'Content-Type: application/json'\n```\n\nThrough letme (picks today, calling later): https://letme.dev/orb. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Stripe API + MCP | A | 82.4 | 5 | payments.card, payments.metering | no | https://www.anchorterminal.com/tools/stripe-mcp.md |\n| Nevermined API + MCP | BB | 70.8 | 142 | payments.card, payments.metering | no | https://www.anchorterminal.com/tools/nevermined.md |\n| Lago | B | 65.7 | 311 | payments.metering, payments.card | no | https://www.anchorterminal.com/tools/lago.md |\n| Paid | C | 55.1 | 669 | payments.metering, payments.card | no | https://www.anchorterminal.com/tools/paid.md |\n| ATXP | E | 42.9 | 887 | payments.metering, payments.card | no | https://www.anchorterminal.com/tools/atxp.md |\n| Tempo | BB | 76.6 | 27 | payments.metering | no | https://www.anchorterminal.com/tools/tempo.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The rate-limit table gives live, test and trial limits per category, for example 50 write operations a second live, 5 in test mode and 1 on a trial (source: \u003chttps://docs.withorb.com/api-reference/rate-limits.md\u003e)\n- Idempotency keys are honoured for 48 hours on POST and PATCH, and a replayed response carries `Idempotent-Replayed: true` (source: \u003chttps://docs.withorb.com/api-reference/idempotency.md\u003e)\n- The `Dry-Run: True` header is not supported on `POST /v1/ingest`, `PUT /v1/events/\u003cevent_id\u003e` and `PUT /v1/events/\u003cevent_id\u003e/deprecate`, where the request runs normally (source: \u003chttps://docs.withorb.com/essentials/dry-run.md\u003e)\n- Orb can collect an invoice with a Stripe Shared Payment Token granted by a customer's AI agent, through `POST /v1/invoices/{invoice_id}/pay`. The feature needs enabling by Orb's account team and a Stripe Connect integration (source: \u003chttps://docs.withorb.com/integrations-and-exports/stripe-shared-payment-tokens.md\u003e)\n- The status history page lists four incidents in September 2026, three rated minor and one unrated, and none in August or October to date (source: \u003chttps://status.withorb.com/history\u003e)\n- The pricing page lists Core, Advanced and Enterprise at custom pricing, charged on billings and events, with a platform fee on the upper two tiers (source: \u003chttps://www.withorb.com/pricing\u003e)\n- The npm package `orb-billing` is now built from orbcorp/orb-typescript (6.27.0). The older orbcorp/orb-node repository stopped at v5.76.0 on 14 July 2026 (source: \u003chttps://github.com/orbcorp/orb-typescript\u003e)\n- Every docs Markdown page opens with a block telling the reader to fetch llms.txt before exploring further. We record it as a fact and did not treat it as an instruction (source: \u003chttps://docs.withorb.com/overview.md\u003e)\n\n- #7 of 14 in Best payment and monetisation platforms for AI agents: https://www.anchorterminal.com/best/payment-platforms/index.md\n- All 76 platforms comparisons: https://www.anchorterminal.com/compare/payment-platforms/index.md\n\n## Compare\n\n- [ATXP vs Orb](https://www.anchorterminal.com/compare/atxp-vs-orb.md): E 42.9 vs B 66.5\n- [Lago vs Orb](https://www.anchorterminal.com/compare/lago-vs-orb.md): B 65.7 vs B 66.5\n- [Metronome vs Orb](https://www.anchorterminal.com/compare/metronome-vs-orb.md): B 69.7 vs B 66.5\n- [Nevermined API + MCP vs Orb](https://www.anchorterminal.com/compare/nevermined-vs-orb.md): BB 70.8 vs B 66.5\n- [Orb vs Paid](https://www.anchorterminal.com/compare/orb-vs-paid.md): B 66.5 vs C 55.1\n- [Orb vs Stripe API + MCP](https://www.anchorterminal.com/compare/orb-vs-stripe-mcp.md): B 66.5 vs A 82.4\n- [Orb vs Tempo](https://www.anchorterminal.com/compare/orb-vs-tempo.md): B 66.5 vs BB 76.6\n- [Adyen MCP server vs Orb](https://www.anchorterminal.com/compare/adyen-mcp-server-vs-orb.md): C 60.3 vs B 66.5\n- [Crossmint API + Docs MCP vs Orb](https://www.anchorterminal.com/compare/crossmint-vs-orb.md): B 67.1 vs B 66.5\n- [Orb vs Payman Genie MCP](https://www.anchorterminal.com/compare/orb-vs-payman.md): B 66.5 vs D 52.5\n- [Orb vs Skyfire API + MCP](https://www.anchorterminal.com/compare/orb-vs-skyfire.md): B 66.5 vs E 40.3\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on withorb.com or one of its subdomains, or the README of github.com/orbcorp/orb-python. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"orb\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/orb\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/orb.svg\" alt=\"Orb on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Orb on Anchor Terminal](https://www.anchorterminal.com/badges/orb.svg)](https://www.anchorterminal.com/tools/orb)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/orb\"\u003eOrb on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Orb is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/orb-dark.png\n- Light: https://www.anchorterminal.com/assets/share/orb-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Payment \u0026 monetisation platforms",
        "url": "https://www.anchorterminal.com/categories/payment-platforms"
      },
      {
        "name": "Orb",
        "url": ""
      }
    ],
    "description": "Orb is a hosted billing platform for usage-based, seat-based and hybrid pricing. It ingests usage events, computes metrics, and runs plans, subscriptions, prepaid credits and invoices through a REST API with SDKs in six languages.",
    "facts": [
      "rank #289 of 950",
      "API key auth",
      "0 desk reviews"
    ],
    "h1": "Orb",
    "image": "https://www.anchorterminal.com/assets/og/tools-orb.png",
    "path": "/tools/orb",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Orb review (2026): pricing, alternatives and grade B | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-10",
    "url": "https://www.anchorterminal.com/tools/orb"
  },
  "tokens": {
    "markdown": 8350,
    "slim": 2130
  },
  "version": 1
}
