# Tink > Tink is a European open banking platform owned by Visa. Its REST API and hosted Tink Link flow read accounts, balances and transactions with the account holder's consent, and start bank payments. - Canonical: https://www.anchorterminal.com/tools/tink - Markdown: https://www.anchorterminal.com/tools/tink.md (~6,700 tokens) - Slim: https://www.anchorterminal.com/tools/tink.min.md (~1,680 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/tink.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-08 ## Overview **Grade B · 62.5/100 · rank #337 of 722 · #4 in Bank data & open banking · not agent-ready · confidence medium** ## Assessment OAuth client credentials with per-endpoint scopes, token-paged data endpoints and a published MSA, DPA, SLA and sub-processor list. No price is public, live access needs a sales contract, and the API reference has no downloadable spec or published rate-limit numbers. ## Facts | Field | Value | | --- | --- | | Vendor | Tink AB (Visa) (https://tink.com) | | Kind | HTTP API | | Category | Bank data & open banking (https://www.anchorterminal.com/categories/banking-data) | | Transport | HTTP | | Endpoint | `https://api.tink.com` | | Auth | OAuth · OAuth 2.0 with a `client_id` and `client_secret` from the Tink Console, sent in the POST body to https://api.tink.com/api/v1/oauth/token. A client token lasts 30 minutes and carries only the scopes requested. Data calls need a user token, valid two hours, obtained through an authorisation grant for a Tink user or from the code Tink Link returns after bank consent. Mutual TLS is accepted as an alternative client authentication method. Console signup is self-serve for the sandbox. Live access is by sales contract, with customer due diligence when Tink's own licence is used. | | Pricing | Paid (Paid) · No public prices. The pricing page lists Standard as Contact us and Enterprise as Custom pricing, and says listed prices apply only to existing customers (https://tink.com/pricing/, checked 2026-10-08). The FAQ says there is no pay-per-use option and that a free Console account gives test data in a sandbox (https://tink.com/faq/). No card is mentioned for signup. Fees are set in an order form and billed monthly in arrears under the MSA. | | x402 | No · No x402, MPP or L402 in the docs index, the API reference introduction or the pricing page (checked 2026-10-08). | | Licence | Proprietary service under Tink's Master Service Agreement. The Tink Link SDKs for iOS and Android on GitHub are MIT | | Source | https://github.com/tink-ab/tink-link-ios | | Docs | https://docs.tink.com | | llms.txt | https://docs.tink.com/llms.txt | | Last release | 2026-09-15 | | API | REST at https://api.tink.com, paths under /api/v1, /data/v2, /connectivity/v2, /payment and /events/v2. 205 operations in the reference, 87 of them without an ENTERPRISE, BETA or REGION.US tag | | Data endpoints | GET /data/v2/accounts, /data/v2/accounts/{id}/balances (BETA), /data/v2/transactions, /data/v2/identities (BETA), plus investment and loan accounts | | Consent | The account holder consents in Tink Link at link.tink.com. One-time access data is deleted after 24 hours. Continuous access lasts up to 90 days. GET /api/v1/provider-consents lists consents and DELETE /api/v1/credentials/{id} removes one | | Tokens | Client token 30 minutes, user token two hours, scopes named per endpoint such as `accounts:read` and `transactions:read` | | Pagination | `pageSize` and `pageToken` on 20 operations, at most 100 transactions a page, with `bookedDateGte`, `bookedDateLte`, `accountIdIn` and `statusIn` filters | | Rate limits | Checked per app ID. HTTP 429 when exceeded. No numbers published | | Idempotency | Idempotency-Key header, keys kept 24 hours, listed on 7 write operations (consents, mandates, mandate payments, payouts) | | Sandbox | Free Console account, sandbox app and Demo Bank test users in 18 countries | | Coverage | Tink's FAQ says 3,000+ bank connections in 18 countries. The home page title says 6000 connections | | Webhooks | Events v2 webhooks signed with HMAC-SHA256 in an X-Tink-Signature header | | SLA | Basic Support 99.7 per cent monthly uptime as a target. Service levels 1 to 3 commit to 99.7 per cent and add response and resolution times | | Sub-processors | Amazon Web Services EMEA Sarl and Google Cloud EMEA Limited, both processing in the EEA, plus Tink Germany GmbH and Tink Financial Services Ltd (list dated 1 October 2025) | | SDKs | Tink Link for iOS 5.1.0 (6 May 2026) and Android 3.0.1 (13 March 2025), both MIT. No server-side SDK found | | Capabilities | bank.accounts, bank.transactions, bank.consent, bank.payments, bank.identity | | Tags | hosted, oauth, llms-txt, webhooks, sandbox, eu, uk, enterprise, sales-led, status-page, closed-source | | JSON | https://www.anchorterminal.com/api/v1/tools/tink.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 62 | 12.4 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 73 | 11.9 | | Agent ergonomics | 13% | 16.2 | 74 | 12.0 | | Security & auth | 14% | 17.5 | 63 | 11.0 | | Payments & pricing | 10% | 12.5 | 10 | 1.2 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 69 | 6.0 | | Transparency & trust (editorial 79, provenance 100) | 7% | 8.8 | 90 | 7.9 | | Negative events | up to −15 | up to −15 | none recorded | 0 | | **Total** | | | | **62.5 → B** | ### Why each score - Reliability 62: Graded with the hosted lines. Statuspage at status.tink.com with 14 product components and incident history (20). In the 90 days to 8 October the feed lists one critical incident, on 16 July 2026, when authentication, consent, account data and payment flows failed in all European markets from 09:54 to 10:56 CEST, with a post-mortem published on 22 July. It also lists a 43-minute Payment Initiation incident on 25 September and 503 responses from Data Enrichment for 81 minutes on 6 October (10 of 30). Rate limits are stated as per app ID with no numbers (3 of 15). The reference documents the 429 status and an Idempotency-Key header with 24-hour keys, and tells customers to contact support on 429. No Retry-After or backoff guidance was found (9 of 15). Published SLAs of 99.7 per cent monthly uptime, a target under Basic Support and a commitment under service levels 1 to 3 (10). The v1 API and the Data v2 accounts and transactions endpoints carry no BETA tag (10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 73: The API reference holds Swagger definitions for 205 operations, but only inside the docs app's JavaScript bundle. No downloadable spec was found, and Postman collections are published per product (10 of 25). llms.txt lists about 280 guides, each with a Markdown twin. The API reference is not in it (10). 191 of 205 operations have a description and the guides explain when to pick one-time or continuous access (14 of 20). Parameters are typed, 20 carry enums, and several older v1 endpoints take whole request bodies by reference (11 of 15). Guides carry curl requests and JSON responses, and each product has an error page with status and reason tables (13 of 15). The version sits in the path (v1, some v2) and the changelog has 367 dated entries (15). - Agent ergonomics 74: Transactions return at most 100 a page and take date, account and status filters. No field selection was found (18 of 25). `pageSize` and `pageToken` on 20 operations, with snake-case equivalents on 6 more (18 of 20). Error pages list statuses and reasons with a `tracking_id`, and provider consent errors carry a `retryable` flag. API errors on Data v2 return a generic error object (16 of 20). Idempotency-Key is documented with 24-hour keys and appears on 7 write operations. Reads are safe to repeat (16 of 20). A first data call takes four token and user calls plus a browser consent, and the only SDKs found are Tink Link for iOS and Android (6 of 15). - Security & auth 63: OAuth 2.0 client credentials sent in the POST body, scopes named per endpoint, 30-minute client tokens, two-hour user tokens and mutual TLS as an alternative. Secret rotation was not confirmed (27 of 30). Read scopes are separate from write and payment scopes, the account holder consents per bank in Tink Link, and one-time access data is deleted after 24 hours (15 of 20). Responses include bank-written transaction descriptions, and no guidance on treating them as untrusted was found (7 of 15). Every response returns an X-Request-ID and the Console has analytics. No operator audit log was found in the docs (4 of 15). The Privacy and Security Documentation describes controls aligned with ISO/IEC 27002, annual independent audits and penetration tests, and security.txt points to Visa's disclosure policy. No named certificate, bug bounty or security contact was found on the pages read (10 of 20). - Payments & pricing 10: No x402, MPP or L402 (0). The pricing page lists Standard as Contact us and Enterprise as Custom pricing, and the FAQ says there is no pay-per-use option (0). A free, self-serve Console account with sandbox test data and no card mentioned. No free live tier (10 of 20). A person signs up in the Console (0). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 69: The newest changelog entry is 15 September 2026, 23 days before the check (30). Three dated entries in the last 90 days, on 4 August, 7 September and 15 September (20). Closed service with an active changelog and support through the Visa Support Hub. Basic Support carries no guaranteed response time, and GitHub issue replies were not sampled (8 of 15). Tink Link for iOS 5.1.0 shipped on 6 May 2026. The Android SDK's newest tag is 3.0.1 from 13 March 2025, with commits to 15 July 2026, and no server-side SDK was found (8 of 15). Neither SDK repository has a public CI workflow (3 of 10). - Transparency & trust 90: Closed service with a public Master Service Agreement dated 9 December 2025, governed by Swedish law. The mobile SDKs are MIT (15 of 30). A public DPA, a Privacy and Security Documentation and an end-user privacy notice agree on handling. Customer data is deleted within 30 days of termination and one-time access data after 24 hours. The end-user notice gives no fixed retention periods (24 of 30). The MSA commits to reasonable efforts at 90 days' notice before a product is discontinued, and the changelog carries dated deprecations, such as TLS 1.2 ending on 31 December 2027, announced on 31 March 2026 (17 of 20). The sub-processor list of 1 October 2025 names AWS and Google Cloud with EEA processing, and the MSA sets the data region as the EU, EEA and UK (18 of 20). Regulatory standing counts here as an addition to the checklist (+5 for a named regulator with a register number, +3 for a named regulator alone). Tink AB is authorised by the Swedish FSA under 44059 and Tink Financial Services Limited by the FCA under 988456 (+5). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (14 items): https://www.anchorterminal.com/fixes/tink.md (JSON https://www.anchorterminal.com/fixes/tink.json) ### What we couldn't check - The changelog entry dated 7 September 2026 says redirect requests whose App URI doesn't match a registered Redirect URL are rejected from that same day. Whether customers had earlier notice was not established, so no deduction was made - unchecked: the Console itself (signup steps, whether a card is asked for, secret rotation, any audit log), which sits behind a login - unchecked: GitHub stars and issue responsiveness on the SDK repositories (the GitHub API refused us for rate limits) - unchecked: whether Tink holds a named certificate such as ISO 27001 or SOC 2. None was found on the pages read - unchecked: Visa's vulnerability disclosure page, which security.txt points to - The home page title says 6000 connections while the FAQ says 3,000+ in 18 countries and a docs page says 3,400+ - The US product has separate docs at docs.us.tink.com, which were not read. This listing covers the European platform ### Sources - status incidents feed: (seen 2026-10-08) - docs index for agents: (seen 2026-10-08) - API reference (introduction, rate limits, idempotency and Swagger definitions, read from the page's bundle): (seen 2026-10-08) - changelog (entries read from the page's content feed): (seen 2026-10-08) - access token guide: (seen 2026-10-08) - list transactions guide: (seen 2026-10-08) - managing consents guide: (seen 2026-10-08) - Transactions errors: (seen 2026-10-08) - Demo Bank guide: (seen 2026-10-08) - pricing page: (seen 2026-10-08) - FAQ (pricing, sandbox, coverage): (seen 2026-10-08) - agreements index (MSA, SLAs, DPA, security and subcontractor documents): (seen 2026-10-08) - Master Service Agreement: (seen 2026-10-08) - Privacy and Security Documentation: (seen 2026-10-08) - Subcontractor Documentation: (seen 2026-10-08) - SLA, Basic Support: (seen 2026-10-08) - legal FAQ (licences and register numbers): (seen 2026-10-08) - security.txt: (seen 2026-10-08) - Tink Link iOS repository (tags and licence): (seen 2026-10-08) - Tink Link Android repository (tags and licence): (seen 2026-10-08) ## Who's behind it (provenance 100/100, checked 2026-10-08) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Tink AB | 20/20 | | Domain age | tink.com, registered 1993-03-18 (33 years) | 15/15 | | Endpoint on the vendor's domain | api.tink.com | 15/15 | | Terms of service | published | 10/10 | | Privacy policy | published | 10/10 | | Status page | status.tink.com | 10/10 | | Changelog | published | 10/10 | | security.txt | valid | 10/10 | The Master Service Agreement (version 2025-12-09) names Tink AB, corporate registration number 556898-2192, Regeringsgatan 38, 111 56 Stockholm, and is governed by Swedish law. The legal FAQ says all customer use is governed by it. The legal FAQ lists Tink AB as a payment institution under the Swedish Financial Supervisory Authority (SFSA ID 44059), Tink Germany GmbH under BaFin (10152149) and Tink Financial Services Limited under the UK FCA (FRN 988456). Tink is a Visa company. The privacy link is the Visa Open Banking Privacy Notice for End-Users, effective 8 January 2026, which covers the bank data read through the product. A separate General Privacy Notice (effective 8 April 2025) covers website visitors and business contacts, and customer data is governed by the DPA of 1 October 2025. tink.com/.well-known/security.txt has a Canonical line and a Policy line pointing to Visa's vulnerability disclosure page, with no Contact or Expires field, both of which RFC 9116 requires. It is recorded as valid because the file is served, as with other listings whose file lacks Expires. The API answers at api.tink.com and Tink Link at link.tink.com. Legal PDFs are served from assets.ctfassets.net and cdn.tink.se. The changelog at docs.tink.com/changelog renders in JavaScript. We read its entries from the content feed the page itself requests. Verisign RDAP gives the domain registration date and MarkMonitor as registrar. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://assets.ctfassets.net/c78bhj3obgck/4rs258WTPok62q9qrmFE1o/b68d1bcc13b5c118503ecffc8647a7d8/Tink_Master_Service_Agreement_2025-12-09.pdf), not read yet. **Privacy policy** (https://cdn.tink.se/legal/privacy-policy/en_UK/privacy-policy-en_UK-2601.pdf), not read yet. ## Live (updated 2026-10-08 20:22 UTC) - Right now: up, HTTP 404, 71 ms, checked 2026-10-08 20:21 UTC (get on `https://api.tink.com`) - Uptime 24h 100.0% (32 probes) · 30 days 100.0% (32 probes) · p50 54 ms · p95 135 ms - Vendor status page: none, All Systems Operational - Watching changelog - Watching pricing - Always current: https://www.anchorterminal.com/api/v1/live/tink.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Strengths - OAuth 2.0 client credentials with named scopes per endpoint, 30-minute client tokens and two-hour user tokens - Master Service Agreement, DPA, four SLA documents and a sub-processor list with processing locations are public PDFs - Data v2 list endpoints page with `pageSize` and `pageToken`, with date, account and status filters on transactions - Changelog with 367 dated entries, three of them in the 90 days to 8 October 2026 - Free Console account with a Demo Bank covering test users in 18 countries ## Weaknesses - No public prices. The pricing page lists Standard as Contact us and Enterprise as Custom pricing, and the FAQ says there is no pay-per-use option - The API reference is a JavaScript app with the Swagger definitions inside its bundle. No downloadable spec was found - Rate limits are per app with no published numbers, and a 429 carries no documented Retry-After - A critical incident on 16 July 2026 stopped authentication, consent, account data and payment flows in all European markets for 62 minutes - security.txt has a Policy line pointing to Visa's disclosure page and no Contact or Expires field ## Before you call it (notes for agents) 1. Request a client token at https://api.tink.com/api/v1/oauth/token, create a user, request an authorisation grant for that user, then exchange the code for a user token. 2. Renew tokens on a timer. Client tokens last 30 minutes and user tokens two hours, and the client credentials flow returns no refresh token. 3. Send the account holder through Tink Link in a browser. Bank consent cannot be completed by API calls alone. 4. Read transactions from /data/v2/transactions with `pageSize` up to 100 and follow `nextPageToken`. 5. Send an Idempotency-Key header on consent and payment writes. Keys are kept for 24 hours. ## Connect First request: ```bash curl -X POST https://api.tink.com/api/v1/oauth/token \ -d "client_id=$TINK_CLIENT_ID" \ -d "client_secret=$TINK_CLIENT_SECRET" \ -d "grant_type=client_credentials" \ -d "scope=authorization:grant,user:create" ``` Through letme (picks today, calling later): https://letme.dev/tink. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Plaid | B | 69.8 | 147 | bank.accounts, bank.transactions, bank.identity, bank.payments, bank.consent | no | https://www.anchorterminal.com/tools/plaid.md | | Belvo | B | 63.5 | 309 | bank.accounts, bank.transactions, bank.identity, bank.payments, bank.consent | no | https://www.anchorterminal.com/tools/belvo.md | | TrueLayer | B | 62.1 | 347 | bank.accounts, bank.transactions, bank.identity, bank.payments, bank.consent | no | https://www.anchorterminal.com/tools/truelayer.md | | Yapily | C | 57.6 | 469 | bank.accounts, bank.transactions, bank.identity, bank.payments, bank.consent | no | https://www.anchorterminal.com/tools/yapily.md | | Flinks | D | 52.7 | 559 | bank.accounts, bank.transactions, bank.identity, bank.payments, bank.consent | no | https://www.anchorterminal.com/tools/flinks.md | | Salt Edge Account Information | D | 46.7 | 643 | bank.accounts, bank.transactions, bank.identity, bank.payments, bank.consent | no | https://www.anchorterminal.com/tools/salt-edge.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - The docs index at llms.txt lists about 280 guides in 21 sections, each with a Markdown twin at the same path ending in .md. The API reference is not in it (source: ) - The API reference at docs.tink.com/api is a JavaScript app. The Swagger definitions inside its bundle cover 205 operations on 201 paths, of which 61 are tagged ENTERPRISE, 33 BETA and 31 REGION.US (source: ) - One-time access keeps a Tink user's data for 24 hours and then deletes it. Continuous access fetches for 90 days, the maximum consent time, before the user must renew (source: ) - Deleting a credentials object removes the consent, and deleting the last consent for an account permanently deletes its accounts and transactions (source: ) - Demo Bank test users live in the Console per product and market, with test providers such as uk-demobank-open-banking-redirect in 18 countries (source: ) - The Basic Support SLA, which applies unless a customer buys a higher level, says Tink strives for 99.7 per cent monthly uptime and reports incidents on status.tink.com (source: ) - The changelog entry of 31 March 2026 deprecates TLS 1.2, with end of life on 31 December 2027 (source: ) ## Compare - [Akoya vs Tink](https://www.anchorterminal.com/compare/akoya-vs-tink.md): D 48.3 vs B 62.5 - [Belvo vs Tink](https://www.anchorterminal.com/compare/belvo-vs-tink.md): B 63.5 vs B 62.5 - [Enable Banking vs Tink](https://www.anchorterminal.com/compare/enable-banking-vs-tink.md): D 47.1 vs B 62.5 - [Flinks vs Tink](https://www.anchorterminal.com/compare/flinks-vs-tink.md): D 52.7 vs B 62.5 - [GoCardless Bank Account Data vs Tink](https://www.anchorterminal.com/compare/gocardless-bank-account-data-vs-tink.md): E 41.7 vs B 62.5 - [MX Platform API vs Tink](https://www.anchorterminal.com/compare/mx-vs-tink.md): B 62.5 vs B 62.5 - [Plaid vs Tink](https://www.anchorterminal.com/compare/plaid-vs-tink.md): B 69.8 vs B 62.5 - [Salt Edge Account Information vs Tink](https://www.anchorterminal.com/compare/salt-edge-vs-tink.md): D 46.7 vs B 62.5 - [Teller vs Tink](https://www.anchorterminal.com/compare/teller-vs-tink.md): E 42.7 vs B 62.5 - [Tink vs TrueLayer](https://www.anchorterminal.com/compare/tink-vs-truelayer.md): B 62.5 vs B 62.1 - [Tink vs Yapily](https://www.anchorterminal.com/compare/tink-vs-yapily.md): B 62.5 vs C 57.6 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on tink.com or one of its subdomains, or the README of github.com/tink-ab/tink-link-ios. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "tink", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Tink on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Tink on Anchor Terminal](https://www.anchorterminal.com/badges/tink.svg)](https://www.anchorterminal.com/tools/tink) ``` Plain link: ```html Tink on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Tink is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/tink-dark.png - Light: https://www.anchorterminal.com/assets/share/tink-light.png