# Powens (slim) > Powens is a French open banking platform, formerly Budget Insight. Its REST API and hosted Webview read bank accounts, balances and transactions with the account holder's consent, verify account ownership and start bank payments in Europe. - Full: https://www.anchorterminal.com/tools/powens.md (~7,750 tokens) · this version ~1,830 tokens · JSON https://www.anchorterminal.com/tools/powens.json · canonical https://www.anchorterminal.com/tools/powens - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-10 **E · 42.6/100 · rank #892 of 950 · #13 in Bank data & open banking · not agent-ready · confidence medium** Assessment: Powens documents a REST API with Markdown docs, cursor pagination, date filters and a hard-delete call for connections, under a French payment institution licence. No OpenAPI file, public price, status page, idempotency key or server SDK was found, and live access needs a signed purchase order. ## Facts - Kind: HTTP API · vendor: Powens SAS · category: Bank data & open banking · legal entity: Powens SAS · provenance 61/100 - Endpoint: `https://{domain}.biapi.pro/2.0` (HTTP) - Auth: OAuth or key · pricing: Paid · x402: no · licence: Proprietary service under Powens' General Terms and Conditions of Sale. The Powens Connect iOS SDK on GitHub is LGPL-3.0 - Probe metrics: not measured yet (probes haven't run) - API: REST, version 2.0, at https://{domain}.biapi.pro/2.0, one subdomain per customer domain. JSON or form-encoded requests, JSON responses. 50 operations on the nine resource pages read - Data endpoints: `GET /users/{userId}/accounts`, `GET /users/{userId}/transactions`, balances, account ownerships, investments, loans and documents. `me` stands for the token's user - Consent: The account holder picks a bank and consents in the Webview at webview.powens.com. Accounts are disabled until consent. PSD2 consent is renewed every 180 days, signalled by the `SCARequired` and `webauthRequired` states - Revocation: `DELETE /users/{userId}/connections/{connectionId}` erases the connection and its data permanently. `DELETE /users/{userId}` deletes a user and `DELETE /auth/token` revokes a permanent token - Tokens: Permanent user tokens from `POST /auth/init` with the client ID and secret, 30-minute temporary codes for the Webview, 30-minute service tokens with `payments:*` scopes, and console tokens for users and configuration - Pagination: `limit` (at most 1,000) and `offset`, cursor links in `_links` on some lists, `min_date`, `max_date` and `expand` for linked resources - Rate limits: Sandbox 30 calls a minute and 86,400 a day. Production limits are not published and are agreed with an account manager - Errors: One JSON format with `code`, `description`, `message` and `request_id`. Common codes are `missingParameter`, `invalidValue`, `methodNotAllowed`, `connectionLocked` and `bug` - Sandbox: Free console account, domain suffixed `-sandbox.biapi.pro`, and a test connector that accepts any username with the password 1234 - Coverage: Powens says 1,800+ banks. Transactions in 11 countries per the coverage page (France, Portugal, Belgium, Austria, Spain, Germany, Luxembourg, Czech Republic, Italy, Netherlands, Ireland) - Webhooks: Registered in the console. Retried until a 2XX. Secured by the user token in the `Authorization` header by default, or an HMAC-SHA256 `BI-Signature` header - Sub-processors: Sewan and AWS for production hosting, OVH for backups, Gemalto (Thales) for encryption, all in France, and Unnax and CRIF for categorisation in Spain and Italy, per the conditions of sale - Certifications: ISO 27001 certified per powens.com/platform, which also says security is independently tested and audited each year. No certificate or report is published - SDKs: Powens Connect iOS 1.0.0-beta (LGPL-3.0, last commit 1 October 2024). Android is marked coming soon. No server-side SDK found - Scores: Reliability 27, Performance pending, Schema & documentation 48, Agent ergonomics 57, Security & auth 60, Payments & pricing 10, Task success pending, Maintenance & community 33, Transparency & trust 63 · total over the 7 assessed categories - Why: Reliability, Graded with the hosted lines. · Schema & documentation, No OpenAPI file or other machine-readable contract was found. · Agent ergonomics, Lists take `limit` up to 1,000 and `expand` pulls linked resources into one response. · Security & auth, A client ID and secret from the console, sent in the request body, issue permanent user tokens that never expire and are revoked with… · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, The public changelog is a Notion page drawn by script and was not read, so recency is taken from the docs sitemap. · Transparency & trust, Closed service with public General Terms and Conditions of Sale under French law. - Sources: 20, open questions: 9, both in the full twin - Capabilities: bank.accounts, bank.transactions, bank.consent, bank.identity, bank.payments - JSON: https://www.anchorterminal.com/api/v1/tools/powens.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/powens.svg` or a link to https://www.anchorterminal.com/tools/powens from a page on powens.com or one of its subdomains, or the README of github.com/powenscompany/powens-connect-ios, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Ask the owner for the domain name, client ID and client secret from the console. Every call goes to `https://{domain}.biapi.pro/2.0` 2. Send `limit` on every transactions list. It is required, at most 1,000, and the next page comes from `_links.next.href` used as given 3. Enable an account with `POST` and `{"disabled": false}` only after the account holder consents. Accounts arrive disabled with no transactions 4. Store the permanent user token as a secret. It does not expire, and the default webhook sends it in the `Authorization` header 5. Stay under 30 calls a minute in the sandbox and use webhooks in place of polling, as the fair usage policy asks ## Connect ```bash curl https://{domain}.biapi.pro/2.0/connectors/ ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/powens ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Plaid | B | 69.8 | bank.accounts, bank.transactions, bank.identity, bank.payments, bank.consent | https://www.anchorterminal.com/tools/plaid.min.md | | Belvo | B | 63.5 | bank.accounts, bank.transactions, bank.identity, bank.payments, bank.consent | https://www.anchorterminal.com/tools/belvo.min.md | | Tink | B | 62.5 | bank.accounts, bank.transactions, bank.consent, bank.payments, bank.identity | https://www.anchorterminal.com/tools/tink.min.md | | TrueLayer | B | 62.1 | bank.accounts, bank.transactions, bank.identity, bank.payments, bank.consent | https://www.anchorterminal.com/tools/truelayer.min.md | | Yapily | C | 57.6 | bank.accounts, bank.transactions, bank.identity, bank.payments, bank.consent | https://www.anchorterminal.com/tools/yapily.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)