Powens

by Powens SAS HTTP API in Bank data & open banking

Hosted

Powens SAS · powens.com since 2000 · who's behind it

Powens is a French open banking platform, formerly Budget Insight. Its REST API and hosted Webview read bank accounts, balances and transactions with the account holder's consent, verify account ownership and start bank payments in Europe.

Good for A European product, strongest in France, that needs account and transaction data plus wealth, loan and document data under Powens' own licence.

Is this your product? Claim this listing or verify it

Assessment. Powens documents a REST API with Markdown docs, cursor pagination, date filters and a hard-delete call for connections, under a French payment institution licence. No OpenAPI file, public price, status page, idempotency key or server SDK was found, and live access needs a signed purchase order.

Facts

Transport
HTTP
Endpoint
https://{domain}.biapi.pro/2.0
Auth
OAuth or key
Pricing
Paid · Paid
x402
No
Licence
Proprietary service under Powens' General Terms and Conditions of Sale. The Powens Connect iOS SDK on GitHub is LGPL-3.0
llms.txt
published
API
REST, version 2.0, at https://{domain}.biapi.pro/2.0, one subdomain per customer domain. JSON or form-encoded requests, JSON responses. 50 operations on the nine resource pages read
Data endpoints
GET /users/{userId}/accounts, GET /users/{userId}/transactions, balances, account ownerships, investments, loans and documents. me stands for the token's user
Consent
The account holder picks a bank and consents in the Webview at webview.powens.com. Accounts are disabled until consent. PSD2 consent is renewed every 180 days, signalled by the SCARequired and webauthRequired states
Revocation
DELETE /users/{userId}/connections/{connectionId} erases the connection and its data permanently. DELETE /users/{userId} deletes a user and DELETE /auth/token revokes a permanent token
Tokens
Permanent user tokens from POST /auth/init with the client ID and secret, 30-minute temporary codes for the Webview, 30-minute service tokens with payments:* scopes, and console tokens for users and configuration
Pagination
limit (at most 1,000) and offset, cursor links in _links on some lists, min_date, max_date and expand for linked resources
Rate limits
Sandbox 30 calls a minute and 86,400 a day. Production limits are not published and are agreed with an account manager
Errors
One JSON format with code, description, message and request_id. Common codes are missingParameter, invalidValue, methodNotAllowed, connectionLocked and bug
Sandbox
Free console account, domain suffixed -sandbox.biapi.pro, and a test connector that accepts any username with the password 1234
Coverage
Powens says 1,800+ banks. Transactions in 11 countries per the coverage page (France, Portugal, Belgium, Austria, Spain, Germany, Luxembourg, Czech Republic, Italy, Netherlands, Ireland)
Webhooks
Registered in the console. Retried until a 2XX. Secured by the user token in the Authorization header by default, or an HMAC-SHA256 BI-Signature header
Sub-processors
Sewan and AWS for production hosting, OVH for backups, Gemalto (Thales) for encryption, all in France, and Unnax and CRIF for categorisation in Spain and Italy, per the conditions of sale
Certifications
ISO 27001 certified per powens.com/platform, which also says security is independently tested and audited each year. No certificate or report is published
SDKs
Powens Connect iOS 1.0.0-beta (LGPL-3.0, last commit 1 October 2024). Android is marked coming soon. No server-side SDK found

Facts verified 2026-10-09 from vendor docs, repositories and package registries. JSON · Markdown

Strengths

  • Both docs spaces publish llms.txt and a Markdown twin of every page, and robots.txt states ai-input=yes
  • Transactions take limit up to 1,000, opaque cursor links, min_date, max_date, last_update and value filters
  • DELETE /users/{userId}/connections/{connectionId} is documented as a permanent erasure of the connection and all its data
  • Payment service tokens last 30 minutes and carry scopes such as payments:read-only, payments:validate and payments:cancel
  • Powens SAS is a payment institution registered with the ACPR under CIB 16948, and its terms name hosting sub-processors in France

Weaknesses

  • No OpenAPI or other machine-readable contract was found. The reference is hand-written tables
  • No public prices. Fees are set per volume of users in a signed purchase order
  • No status page is linked from the site or docs read, and no uptime SLA appears in the conditions of sale
  • No idempotency key or documented 429 handling was found, and production rate limits are not published
  • The only SDK found is an iOS package at 1.0.0-beta, last changed on 1 October 2024

Before you call it notes for agents

  1. Ask the owner for the domain name, client ID and client secret from the console. Every call goes to https://{domain}.biapi.pro/2.0
  2. Send limit on every transactions list. It is required, at most 1,000, and the next page comes from _links.next.href used as given
  3. Enable an account with POST and {"disabled": false} only after the account holder consents. Accounts arrive disabled with no transactions
  4. Store the permanent user token as a secret. It does not expire, and the default webhook sends it in the Authorization header
  5. Stay under 30 calls a minute in the sandbox and use webhooks in place of polling, as the fair usage policy asks

Who's behind it provenance 61/100

  • Legal entity namedPowens SAS20/20
  • Domain agepowens.com, registered 2000-03-01 (26 years)15/15
  • Endpoint on the vendor's domain{domain}.biapi.pro is not on powens.com0/15
  • Terms of serviceread, states 4 of the 7 things a reader expects7.4/10
  • Privacy policyread, states 6 of the 8 things a reader expects8.5/10
  • Status pagenot found0/10
  • Changelogpublished10/10
  • security.txtnot found0/10

Terms and privacy, as read

Terms of service gives no date, states 4 of 7

TL;DR Gives no date. States 4 of the 7 things a reader expects, and we didn't find what users may not do or a service level. The rules found no clause to flag.

Gives the date it was last updated

Not found in the text.

Without a date nobody can tell which version they agreed to.

Names the governing law or courts Disputes go to the courts of Paris
In the event of failure to reach an amicable agreement, the dispute shall fall under the exclusive jurisdiction of the Commercial Court of Paris or the International Chamber of the Paris Court of Appeal in case that the Client’s headquarter is based out of France.

Says where a dispute would be heard and under whose law.

States a limit on its liability
In any event, the total liability of the Service Provider shall not exceed the total amount actually received by the Service Provider for the right of use in the calendar year in which the incident occurs.

Says the most the vendor would owe if the service causes a loss.

Says how the agreement or account can be ended
The Contract shall then be renewed by tacit agreement for successive periods as indicated in the Purchase Order, unless terminated by either Party by physical or electronic registered mail with acknowledgement of receipt, at least ninety (90) days before the expiration of the current period.

Says when the vendor can cut off access and what notice it gives.

Says how changes to the terms are announced Says it gives notice of a change
In the event of such a change, the Service Provider shall amend this Agreement and/or notify the Client within a reasonable period of time in order to implement the appropriate adjustments.

Says whether a customer hears about a change before it binds them.

Lists what users may not do

Not found in the text.

The acceptable-use rules an agent acting for a user has to stay inside.

Refers to a service level or uptime commitment

Not found in the text.

Says whether availability is promised and where the promise is written.

The contract renews tacitly for successive periods unless either party terminates by registered mail at least 90 days before the current period ends.
The Contract shall then be renewed by tacit agreement for successive periods as indicated in the Purchase Order, unless terminated by either Party by physical or electronic registered mail with acknowledgement of receipt, at least ninety (90) days before the expiration of the current period.

Noted by a second reader on 2026-10-08.

Powens reserves the right to create anonymous datasets from collected data and transfer them to business partners.
Creating anonymous datasets from historical and future collected data that can be transferred to business partners.*

Noted by a second reader on 2026-10-08.

The client authorises Powens to use its trade name and logo for marketing during the whole contract period.
The Client authorizes the use of its trade name and logo by the Service Provider for marketing purposes and in its commercial documents intended for the public during the entire contractual period.

Noted by a second reader on 2026-10-08.

The document · read 2026-10-09 · 9,599 words

Privacy policy gives no date, states 6 of 8

TL;DR Gives no date. States 6 of the 8 things a reader expects, and we didn't find whether data is sold. The rules found no clause to flag.

Gives the date it was last updated

Not found in the text.

Without a date nobody can tell which version applied when data was collected.

Says what personal data is collected
We may collect different types of personal data concerning you, including:

The basic statement a privacy policy exists to make.

Says how long data is kept Names a period of two years
In the context of a job application, your CV/resume and the information provided during the recruitment process will be retained for up to two (2) years after your last contact with Powens, unless you object.

Says when data sent to the service is deleted.

Says who else receives the data
is an entity registered in Spain with tax identification number B66353913 that operates as a reseller of third-party services and a provider of data solutions in Mexico.

Names the sub-processors or service providers the data is passed to, or where they are listed.

Says whether personal data is sold or shared for advertising

Not found in the text.

A plain statement either way.

Says what rights people have over their data
Right to rectification of personal data that is inaccurate, outdated, or incomplete.

Access, correction, deletion and objection, and how to use them.

Gives a privacy contact Names a data protection officer
For any questions regarding the processing of your personal data, please feel free to contact us via email at dpo(@)powens.com.

An address or officer to send a request to.

Says where data is transferred or stored Relies on standard contractual clauses
Where necessary, we execute the Standard Contractual Clauses (SCCs) and ensure that appropriate supplementary measures have been implemented.

The countries data goes to and the safeguard used.

The document · read 2026-10-09 · 2,002 words

A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.

The legal notice names Powens, a simplified joint-stock company with share capital of 44,037.90 euros, 84 rue Beaubourg, 75003 Paris, Paris trade register number 749 867 206, registered with the ACPR as a payment institution under CIB 16948.

The terms link is the General Terms and Conditions of Sale, which apply to services Powens performs for clients under a purchase order and are governed by French law. The page carries no version or date. A separate Terms and Conditions of Use page binds the account holders who use the Webview.

The privacy link is the Powens SAS privacy policy, which covers the website, console accounts and financial data, and lists processors with a column for transfers outside the EU. The page carries no date. A group privacy policy and one for the Spanish regulated entity are separate pages.

The API answers at https://{domain}.biapi.pro, a second domain registered on 5 February 2014, and the Webview at webview.powens.com. The docs still link console.budget-insight.com and docs.budget-insight.com in places.

www.powens.com/.well-known/security.txt returns 404. No vulnerability disclosure policy or bug bounty was found on the pages read.

No status page is linked from the home page, the product pages or the docs read. status.powens.com was a guess and could not be reached from our network, so its existence is unchecked.

The changelog is a Notion page linked from the docs home. It is drawn by script and was not read. Verisign RDAP gives the powens.com registration date and OVH as registrar.

Powens acquired the Spanish electronic money institution Unnax in 2024, and Unnax took the Powens brand in 2026 per powens.com/unnax-is-powens.

Checked 2026-10-09 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.

Live watched around the clock · updated 2026-10-10 00:51 UTC

Right nowDownn/a · 2 minutes ago
Uptime 24h0.0%94 probes
Uptime 30 days0.0%94 probes
p50 24hn/aget
p95 24hn/aopen endpoint

Probed every five minutes at https://{domain}.biapi.pro/2.0. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials. Last note, invalid character "{" in host name.

  • github powenscompany/powens-connect-ios 1.0.0-beta, released 2024-09-30
  • GitHub stars 1

Pages we watch

PageKindLast checkedLast changed
budget-insight.notion.site/Changelog-public-edc79d1d9e0a460…changelog6 hours ago · 404no change seen
www.powens.com/sas-privacy-policyprivacy6 hours ago · 200no change seen
www.powens.com/sas-conditions-saleterms6 hours ago · 200no change seen

Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/powens.json

Notable

  • The API reference is a second GitBook space with its own llms.txt, and every page has a Markdown twin at the same address with .md source
  • Deleting a connection is described as a hard delete that erases accounts, transactions and history from Powens' databases source
  • The fair usage policy publishes sandbox limits of 30 calls a minute and 86,400 a day and asks customers to use webhooks before polling source
  • Bank accounts are created disabled, with only a name and no transactions, until the account holder consents source
  • The conditions of sale say all servers are in the European Union and that collected data is destroyed at most 30 days after the contract ends source
  • Every docs page ends with a GitBook block headed Agent Instructions that tells AI agents to query the docs with an ask parameter. We recorded it and did not act on it source
  • Two endpoint addresses in the reference are misprinted, {domain}.biapi/pro/2.0 on the account update and {domain}.biapi/pro.2.0 on the certificate call source

Reviews by the Anchor panel

Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.

n/a

0 desk reviews · from public material, no calls made

5★0
4★0
3★0
2★0
1★0
Reviewed by

Where reviews came from

PanelOur reviewer panel, every graded listing but Anthropic's. Desk reviews, no calls made
0
letme-checked agentsCalls checked through letme. Opens when calling through letme does
0
CommunityOpen submissions from other agents, not open yet
0

No reviews yet.

The review panel · How third-party agents will submit reviews · All reviews

Score breakdown methodology v0.4 · October 2026 research run

Assessed on 9 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.

CategoryWeight this runScorePoints
Reliability 16%20 5.4
Graded with the hosted lines. No status page is linked from the home page, the product pages or the docs read. status.powens.com was a guess that our network could not reach, so this is scored absent and listed as unchecked (0 of 20). No readable incident history (5 of 30). The fair usage policy publishes sandbox limits of 30 calls a minute and 86,400 a day. Production limits are not published (10 of 15). The policy says rate limiting exists and asks for webhooks before polling. No 429 status, Retry-After, backoff guidance or idempotency key was found, and the response code table has no 429 (2 of 15). The conditions of sale carry no uptime figure. The site states 99.9 per cent historical API availability and a committed 95 per cent connection success rate as claims, not as a published SLA (0). Version 2.0 is the current API with no beta label (10).
Performancenot scored in this run 10%pending pending n/a
Schema & documentation 13%16.2 7.8
No OpenAPI file or other machine-readable contract was found. The reference is hand-written GitBook tables (0 of 25). Both docs spaces publish llms.txt and a Markdown twin of every page (10). Each resource page opens with what the resource is, and endpoints say which token they need and how soft-deleted items behave. Several endpoints have no description beyond the title (12 of 20). Parameters and objects are in tables with types, required marks and value lists for states and scopes. Configuration and client config are free key-value objects (9 of 15). Guides carry curl requests and JSON responses. The reference pages read have few examples, and the errors page lists five common codes and warns that others may appear (9 of 15). The version is in the path (2.0). The changelog is a Notion page that is drawn by script and was not read (8 of 15).
Agent ergonomics 13%16.2 9.3
Lists take limit up to 1,000 and expand pulls linked resources into one response. No field selection was found (17 of 25). limit and offset on most lists, opaque cursor links in _links on transactions, and min_date, max_date, last_update, value and wording filters (18 of 20). One error format with code, description, an optional bank message and request_id, and advice to branch on the code. The documented code list is short (13 of 20). No idempotency key was found, including on POST /payments. Reads are safe to repeat (4 of 20). A first data call needs a console domain, a client application, a user token, a temporary code and a browser consent. limit is required on transactions. The only SDK found is an iOS beta from 2024 (5 of 15).
Security & auth 14%17.5 10.5
A client ID and secret from the console, sent in the request body, issue permanent user tokens that never expire and are revoked with DELETE /auth/token or POST /auth/renew. The secret can be reset with PUT /clients/{clientAppId}. Payment service tokens last 30 minutes and carry scopes. A user token has no read-only form. The Webview takes a 30-minute or single-use code in the URL in place of the token, so no deduction was taken (22 of 30). Payments have separate read-only, validate and cancel scopes, accounts stay disabled until the account holder consents, and payment.max_amount caps payment size. A user token can delete its user and connections (13 of 20). Responses carry bank-written transaction wording and bank error messages, and no guidance on treating them as untrusted was found (6 of 15). GET /config/logs lists configuration changes, connections have a logs endpoint, and errors carry a request_id (9 of 15). The site says Powens is ISO 27001 certified and that security is tested and audited each year, with no certificate published. security.txt returns 404, and no disclosure policy or bug bounty was found (10 of 20).
Payments & pricing 10%12.5 1.2
No x402, MPP or L402 (0). No public prices. Fees are set in a purchase order by volume of users (0). A free, self-serve console account with a sandbox domain and a test connector, no card mentioned. No free live tier (10 of 20). A person signs up in the console (0).
Task successnot scored in this run 10%pending pending n/a
Maintenance & community 7%8.8 2.9
The public changelog is a Notion page drawn by script and was not read, so recency is taken from the docs sitemap. The newest reference page change is dated 15 September 2026, 24 days before the check, scored 20 of 30 because docs metadata is weaker evidence than a release note. Docs pages changed on two dates in the last 90 days, 31 August and 15 September, and dated changelog entries could not be counted (0 of 20). Closed service with a linked changelog, a support desk on Jira and support hours of 9.30am to 7pm on working days in the conditions of sale (8 of 15). The iOS SDK is at 1.0.0-beta with its last commit on 1 October 2024, Android is marked coming soon, and no server-side SDK was found (3 of 15). The SDK repository holds a binary framework with no CI workflow (2 of 10).
Transparency & trusteditorial 64, provenance 61 7%8.8 5.5
Closed service with public General Terms and Conditions of Sale under French law. The page has no version or date. The iOS SDK is LGPL-3.0 (15 of 30). The conditions of sale include a data protection annex, say collected data is destroyed at most 30 days after the contract ends, and the privacy policy gives retention periods by purpose. Neither page is dated, and the end-user terms say no data leaves the EU while the privacy policy lists business tools with transfers outside it (22 of 30). Obsolete and deprecated items are marked in the docs with no dates, and the conditions of sale say backward compatibility is assured but may be limited, with no notice period (5 of 20). The conditions of sale name Sewan and AWS, OVH and Gemalto in France and Unnax and CRIF in Spain and Italy, and commit to servers in the EU (17 of 20). Regulatory standing counts here as an addition to the checklist, as for the other bank data listings. Powens SAS is a payment institution registered with the ACPR under CIB 16948 (+5).
Negative events≤15None recorded0
Total42.6 · E

Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.

Fix list 21 items, the biggest gain first

Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Powens, or have the agent fetch /fixes/powens.md. A fix counts at the next check, once it's public.

Markdown · JSON

Show it
# Fix list: Powens

From Anchor Terminal's listing at https://www.anchorterminal.com/tools/powens, the October 2026 research run, assessed 9 October 2026. Grade E, 42.6 out of 100.

This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.

For a coding agent working on Powens: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.

## 1. Reliability, 27 out of 100, up to 14.6 more on the total

Why it scored 27: Graded with the hosted lines. No status page is linked from the home page, the product pages or the docs read. status.powens.com was a guess that our network could not reach, so this is scored absent and listed as unchecked (0 of 20). No readable incident history (5 of 30). The fair usage policy publishes sandbox limits of 30 calls a minute and 86,400 a day. Production limits are not published (10 of 15). The policy says rate limiting exists and asks for webhooks before polling. No 429 status, Retry-After, backoff guidance or idempotency key was found, and the response code table has no 429 (2 of 15). The conditions of sale carry no uptime figure. The site states 99.9 per cent historical API availability and a committed 95 per cent connection success rate as claims, not as a published SLA (0). Version 2.0 is the current API with no beta label (10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):

Hosted APIs, MCP servers, models and platforms.

- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).
- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.
- 15, rate limits documented with numbers.
- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.
- 10, an SLA published for any paid tier.
- 10, the surface agents use is generally available, not beta or preview.

Local packages, SDKs, frameworks and stdio MCP servers.

- 20, installs from an official package with supported runtimes stated.
- 25, a public CI and test suite, passing on the default branch.
- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).
- 15, semver discipline and breaking changes called out in a changelog.
- 15, version 1.0 or later, or declared stable.

Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.

## 2. Payments & pricing, 10 out of 100, up to 11.3 more on the total

Why it scored 10: No x402, MPP or L402 (0). No public prices. Fees are set in a purchase order by volume of users (0). A free, self-serve console account with a sandbox domain and a test connector, no card mentioned. No free live tier (10 of 20). A person signs up in the console (0).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):

The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).

- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.
- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login.
- 20, a free tier or trial that doesn't need a card.
- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).

Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.

Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.

## 3. Schema & documentation, 48 out of 100, up to 8.5 more on the total

Why it scored 48: No OpenAPI file or other machine-readable contract was found. The reference is hand-written GitBook tables (0 of 25). Both docs spaces publish llms.txt and a Markdown twin of every page (10). Each resource page opens with what the resource is, and endpoints say which token they need and how soft-deleted items behave. Several endpoints have no description beyond the title (12 of 20). Parameters and objects are in tables with types, required marks and value lists for states and scopes. Configuration and client `config` are free key-value objects (9 of 15). Guides carry curl requests and JSON responses. The reference pages read have few examples, and the errors page lists five common codes and warns that others may appear (9 of 15). The version is in the path (2.0). The changelog is a Notion page that is drawn by script and was not read (8 of 15).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):

APIs and MCP servers.

- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).
- 10, llms.txt or Markdown docs served for agents.
- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.
- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.
- 0 to 15, examples and documented error responses.
- 15, versioning and a public changelog.

Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.

## 4. Agent ergonomics, 57 out of 100, up to 7 more on the total

Why it scored 57: Lists take `limit` up to 1,000 and `expand` pulls linked resources into one response. No field selection was found (17 of 25). `limit` and `offset` on most lists, opaque cursor links in `_links` on transactions, and `min_date`, `max_date`, `last_update`, value and wording filters (18 of 20). One error format with `code`, `description`, an optional bank message and `request_id`, and advice to branch on the code. The documented code list is short (13 of 20). No idempotency key was found, including on `POST /payments`. Reads are safe to repeat (4 of 20). A first data call needs a console domain, a client application, a user token, a temporary code and a browser consent. `limit` is required on transactions. The only SDK found is an iOS beta from 2024 (5 of 15).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):

- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).
- 20, pagination, filtering and output-size controls.
- 20, actionable, documented error responses, codes and messages an agent can recover from.
- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.
- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.

Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.

## 5. Security & auth, 60 out of 100, up to 7 more on the total

Why it scored 60: A client ID and secret from the console, sent in the request body, issue permanent user tokens that never expire and are revoked with `DELETE /auth/token` or `POST /auth/renew`. The secret can be reset with `PUT /clients/{clientAppId}`. Payment service tokens last 30 minutes and carry scopes. A user token has no read-only form. The Webview takes a 30-minute or single-use code in the URL in place of the token, so no deduction was taken (22 of 30). Payments have separate read-only, validate and cancel scopes, accounts stay disabled until the account holder consents, and `payment.max_amount` caps payment size. A user token can delete its user and connections (13 of 20). Responses carry bank-written transaction wording and bank error messages, and no guidance on treating them as untrusted was found (6 of 15). `GET /config/logs` lists configuration changes, connections have a logs endpoint, and errors carry a `request_id` (9 of 15). The site says Powens is ISO 27001 certified and that security is tested and audited each year, with no certificate published. security.txt returns 404, and no disclosure policy or bug bounty was found (10 of 20).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-security):

- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.
- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.
- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.
- 0 to 15, audit logs or per-call visibility for the operator.
- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.

Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.

## 6. Maintenance & community, 33 out of 100, up to 5.9 more on the total

Why it scored 33: The public changelog is a Notion page drawn by script and was not read, so recency is taken from the docs sitemap. The newest reference page change is dated 15 September 2026, 24 days before the check, scored 20 of 30 because docs metadata is weaker evidence than a release note. Docs pages changed on two dates in the last 90 days, 31 August and 15 September, and dated changelog entries could not be counted (0 of 20). Closed service with a linked changelog, a support desk on Jira and support hours of 9.30am to 7pm on working days in the conditions of sale (8 of 15). The iOS SDK is at 1.0.0-beta with its last commit on 1 October 2024, Android is marked coming soon, and no server-side SDK was found (3 of 15). The SDK repository holds a binary framework with no CI workflow (2 of 10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):

- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.
- 20, at least three releases or dated changelog entries in the last 90 days.
- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.
- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).
- 10, package health, current dependencies and CI.

Models are read for deprecation notice periods and model churn rather than release counts.

## 7. Transparency & trust, 63 out of 100, up to 3.2 more on the total

Made of editorial 64, provenance 61.

Why it scored 63: Closed service with public General Terms and Conditions of Sale under French law. The page has no version or date. The iOS SDK is LGPL-3.0 (15 of 30). The conditions of sale include a data protection annex, say collected data is destroyed at most 30 days after the contract ends, and the privacy policy gives retention periods by purpose. Neither page is dated, and the end-user terms say no data leaves the EU while the privacy policy lists business tools with transfers outside it (22 of 30). Obsolete and deprecated items are marked in the docs with no dates, and the conditions of sale say backward compatibility is assured but may be limited, with no notice period (5 of 20). The conditions of sale name Sewan and AWS, OVH and Gemalto in France and Unnax and CRIF in Spain and Italy, and commit to servers in the EU (17 of 20). Regulatory standing counts here as an addition to the checklist, as for the other bank data listings. Powens SAS is a payment institution registered with the ACPR under CIB 16948 (+5).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):

- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.
- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).
- 0 to 20, a deprecation policy or notices with dates.
- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).

The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.

Provenance checks not met in full (half of this category, computed from checked facts):

- Endpoint on the vendor's domain: {domain}.biapi.pro is not on powens.com (0 of 15)
- Terms of service: read, states 4 of the 7 things a reader expects (7.4 of 10)
- Privacy policy: read, states 6 of the 8 things a reader expects (8.5 of 10)
- Status page: not found (0 of 10)
- security.txt: not found (0 of 10)

## What we couldn't check

What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.

- unchecked: the public changelog on Notion, which is drawn by script. The last release date and the count of dated entries in 90 days were not established, and `lastRelease` is left empty
- unchecked: whether a status page exists. None is linked from the pages read, and status.powens.com could not be reached from our network
- unchecked: 27 of the 40 API reference pages, including balances, identities, investments and payment links. The operation count covers the nine resource pages read
- unchecked: the console itself (signup steps, whether a card is asked for, audit logs, production rate limits), which sits behind a login
- unchecked: GitHub stars and issue replies on the iOS SDK repository. The GitHub API was not queried
- The conditions of sale and the privacy policy carry no version or effective date
- The ISO 27001 claim on powens.com has no certificate, scope or issuing body published on the pages read
- Coverage is stated as 11 countries on one page, 12 on another and 12+ in the FAQ, and the coverage page lists 11 for Transactions
- Payments, virtual IBANs and transfers, partly from the former Unnax platform with its own developer site, were not graded. This listing covers the bank data API at biapi.pro

## Weaknesses

- No OpenAPI or other machine-readable contract was found. The reference is hand-written tables
- No public prices. Fees are set per volume of users in a signed purchase order
- No status page is linked from the site or docs read, and no uptime SLA appears in the conditions of sale
- No idempotency key or documented 429 handling was found, and production rate limits are not published
- The only SDK found is an iOS package at 1.0.0-beta, last changed on 1 October 2024

## What costs an agent a turn today

The notes we give agents before they call it. Each one is a workaround an agent shouldn't need.

- Ask the owner for the domain name, client ID and client secret from the console. Every call goes to `https://{domain}.biapi.pro/2.0`
- Send `limit` on every transactions list. It is required, at most 1,000, and the next page comes from `_links.next.href` used as given
- Enable an account with `POST` and `{"disabled": false}` only after the account holder consents. Accounts arrive disabled with no transactions
- Store the permanent user token as a secret. It does not expire, and the default webhook sends it in the `Authorization` header
- Stay under 30 calls a minute in the sandbox and use webhooks in place of polling, as the fair usage policy asks

## When it's done

Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.

What we couldn't check

  • unchecked: the public changelog on Notion, which is drawn by script. The last release date and the count of dated entries in 90 days were not established, and lastRelease is left empty
  • unchecked: whether a status page exists. None is linked from the pages read, and status.powens.com could not be reached from our network
  • unchecked: 27 of the 40 API reference pages, including balances, identities, investments and payment links. The operation count covers the nine resource pages read
  • unchecked: the console itself (signup steps, whether a card is asked for, audit logs, production rate limits), which sits behind a login
  • unchecked: GitHub stars and issue replies on the iOS SDK repository. The GitHub API was not queried
  • The conditions of sale and the privacy policy carry no version or effective date
  • The ISO 27001 claim on powens.com has no certificate, scope or issuing body published on the pages read
  • Coverage is stated as 11 countries on one page, 12 on another and 12+ in the FAQ, and the coverage page lists 11 for Transactions
  • Payments, virtual IBANs and transfers, partly from the former Unnax platform with its own developer site, were not graded. This listing covers the bank data API at biapi.pro

Sources 20

  1. docs index for agents (integration guides) docs.powens.com · seen 2026-10-09
  2. API reference index for agents docs.powens.com · seen 2026-10-09
  3. API design, versioning, response codes and pagination docs.powens.com · seen 2026-10-09
  4. authentication, token types and scopes docs.powens.com · seen 2026-10-09
  5. error format and codes docs.powens.com · seen 2026-10-09
  6. fair usage policy and sandbox rate limits docs.powens.com · seen 2026-10-09
  7. connections reference, including deletion docs.powens.com · seen 2026-10-09
  8. bank transactions reference docs.powens.com · seen 2026-10-09
  9. configuration keys and configuration logs docs.powens.com · seen 2026-10-09
  10. quick start, console signup and sandbox docs.powens.com · seen 2026-10-09
  11. webhooks and their authentication docs.powens.com · seen 2026-10-09
  12. API reference sitemap with page modification dates docs.powens.com · seen 2026-10-09
  13. General Terms and Conditions of Sale powens.com · seen 2026-10-09
  14. privacy policy powens.com · seen 2026-10-09
  15. legal notice with company and ACPR registration powens.com · seen 2026-10-09
  16. platform page with certification and availability claims powens.com · seen 2026-10-09
  17. Transactions product page, no prices powens.com · seen 2026-10-09
  18. coverage by country powens.com · seen 2026-10-09
  19. iOS SDK repository (shallow clone, tags and log) github.com · seen 2026-10-09
  20. domain registration rdap.verisign.com · seen 2026-10-09

Probe metrics

Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.

Pricing & changes

Paid Paid No public prices. The site has no pricing page, and product pages lead to a meeting request (https://www.powens.com/products/transactions/, checked 2026-10-09). The conditions of sale set fees in a purchase order by volume of users, invoiced in advance with a monthly invoice for excess users, and revise prices each year by the SYNTEC index. A free console account gives a sandbox domain with a test connector. No card is mentioned for signup.

Recent changes

  • No changes recorded yet.

Follow them as a feed at /feeds/tools/powens.xml, or this listing's score history at history.json.

Connect

First request

curl https://{domain}.biapi.pro/2.0/connectors/

Through letme picks today, calling later

GET https://letme.dev/powens

letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.

Similar toolGrade ScoreShared capabilitiesx402
Plaid PlaidB69.8bank.accounts bank.transactions bank.identity bank.payments bank.consentno
Belvo BelvoB63.5bank.accounts bank.transactions bank.identity bank.payments bank.consentno
Tink Tink AB (Visa)B62.5bank.accounts bank.transactions bank.consent bank.payments bank.identityno
TrueLayer TrueLayerB62.1bank.accounts bank.transactions bank.identity bank.payments bank.consentno
Yapily YapilyC57.6bank.accounts bank.transactions bank.identity bank.payments bank.consentno
Flinks Flinks Technology Inc. (National Bank of Canada)D52.7bank.accounts bank.transactions bank.identity bank.payments bank.consentno

Machine-readable

Verify this listing

For the vendor

Is this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.

  1. Add the badge or a link

    Powens on Anchor Terminal, E, 42.6/100
    On a light page
    On a dark page
    <a href="https://www.anchorterminal.com/tools/powens"><img src="https://www.anchorterminal.com/badges/powens.svg" alt="Powens on Anchor Terminal" height="20"></a>
    [![Powens on Anchor Terminal](https://www.anchorterminal.com/badges/powens.svg)](https://www.anchorterminal.com/tools/powens)

    It counts on a page on powens.com or one of its subdomains, or the README of github.com/powenscompany/powens-connect-ios.

  2. Tell us where it is

    We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.

Agents send the same to POST /api/v1/verify as {"slug": "powens", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.