{
  "data": {
    "similar": [
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/plaid.json",
        "name": "Plaid",
        "score": 69.8,
        "shared": [
          "bank.accounts",
          "bank.transactions",
          "bank.identity",
          "bank.consent"
        ],
        "slug": "plaid"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/belvo.json",
        "name": "Belvo",
        "score": 63.5,
        "shared": [
          "bank.accounts",
          "bank.transactions",
          "bank.identity",
          "bank.consent"
        ],
        "slug": "belvo"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/mx.json",
        "name": "MX Platform API",
        "score": 62.5,
        "shared": [
          "bank.accounts",
          "bank.transactions",
          "bank.identity",
          "bank.consent"
        ],
        "slug": "mx"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/tink.json",
        "name": "Tink",
        "score": 62.5,
        "shared": [
          "bank.accounts",
          "bank.transactions",
          "bank.consent",
          "bank.identity"
        ],
        "slug": "tink"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/truelayer.json",
        "name": "TrueLayer",
        "score": 62.1,
        "shared": [
          "bank.accounts",
          "bank.transactions",
          "bank.identity",
          "bank.consent"
        ],
        "slug": "truelayer"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/yapily.json",
        "name": "Yapily",
        "score": 57.6,
        "shared": [
          "bank.accounts",
          "bank.transactions",
          "bank.identity",
          "bank.consent"
        ],
        "slug": "yapily"
      }
    ],
    "tool": {
      "slug": "yodlee-financial-data",
      "name": "Yodlee Core API",
      "vendor": "Yodlee, Inc.",
      "vendorUrl": "https://www.yodlee.com",
      "kind": "http-api",
      "category": "banking-data",
      "summary": "Yodlee's Core API (v1.1) aggregates a consumer's bank, card, investment, loan and insurance accounts for balances, categorised transactions, holdings, statements and account-owner details. Consumers link accounts through the embedded FastLink 4 widget.",
      "url": "https://www.anchorterminal.com/tools/yodlee-financial-data",
      "markdownUrl": "https://www.anchorterminal.com/tools/yodlee-financial-data.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/yodlee-financial-data.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/yodlee-financial-data.json",
      "repo": "https://github.com/Yodlee/OpenAPI",
      "license": "Proprietary service. The Swagger file on GitHub is MIT",
      "transports": [
        "http"
      ],
      "packages": [],
      "auth": "oauth",
      "authNotes": "Self-serve for the sandbox. Registering on the developer portal gives a `clientId`, a `secret` and an admin `loginName` on the API dashboard. `POST /auth/token` takes the id and secret in a form body and a `loginName` header, and returns a bearer token that lasts 30 minutes and acts for that user, or for the admin on administrative calls. Every call also sends `Api-Version: 1.1`. Each environment (sandbox, development, production) has its own credentials. How production access is granted is not stated in the public docs. Full account numbers and holder details need Yodlee Security Office approval.",
      "pricing": "paid",
      "pricingNotes": "No public price. `/pricing` returns 404 on yodlee.com and on the developer portal, and product pages ask for a demo. The sandbox is free on registration, with five preconfigured users and sample data only, so an agent's owner can test without a contract (checked 2026-10-08).",
      "priceSummary": "Paid",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs, the Swagger file or yodlee.com (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 17,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developer.yodlee.com/resources/yodlee/yodlee-api-overview/docs",
      "openapi": "https://raw.githubusercontent.com/Yodlee/OpenAPI/main/swagger.yaml",
      "capabilities": [
        "bank.accounts",
        "bank.transactions",
        "bank.identity",
        "bank.consent"
      ],
      "tags": [
        "hosted",
        "oauth",
        "openapi",
        "sandbox",
        "webhooks",
        "sales-led",
        "closed-source",
        "enterprise",
        "soc2"
      ],
      "lastRelease": "2026-07-31",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 41.9,
        "grade": "E",
        "agentReady": false,
        "rank": 796,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 12,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 58,
          "maintenance": 33,
          "payments": 15,
          "reliability": 15,
          "schema": 71,
          "security": 49,
          "transparency": 53
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 15,
            "points": 3,
            "reason": "Graded as a hosted API. No status page is linked from yodlee.com or the developer portal, and status.yodlee.com did not answer (0). With no incident history to read, 5 of 30. No rate limit with numbers was found in the docs or the Swagger file, which lists no 429 response (0). No 429, backoff or idempotency guidance found (0). No public SLA. The Security FAQ mentions only contracted recovery targets for clients' disaster recovery options (0). The Core API v1.1 is generally available (10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 71,
            "points": 11.54,
            "reason": "A public Swagger 2.0 file (`Yodlee/OpenAPI`, MIT) with 70 paths, 98 operations and 267 definitions. Its last update, on 22 April 2026, brought it to the November 2025 release, so fields from the June and July 2026 notes such as `isCrypto` are missing (22 of 25). No llms.txt (404) and no Markdown docs (0). 96 of 98 operations carry a long description with defaults, sandbox limits and, for the seven deprecated ones, the replacement (16 of 20). Definitions hold 204 enums, but query parameters such as `container` and `baseType` are plain strings with allowed values only in the description, and `dataset$filter` is a free expression (9 of 15). The file has no examples. The docs site shows sample requests and responses, and each operation lists its 400 errors by `Y` code, with 401 and 404 undescribed (9 of 15). An `Api-Version` header, dated release notes and spec tags by release month (15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 58,
            "points": 9.43,
            "reason": "`include` adds optional detail, `top` caps list size at 500, count endpoints exist for transactions and providers, and derived endpoints return net worth and transaction summaries (16 of 25). `skip` and `top` paging with next and previous links in the response header, plus date, account, category, keyword and container filters on transactions (17 of 20). Errors return `errorCode`, `errorMessage` and `referenceCode`, and the spec says codes do not change (15 of 20). No idempotency key or retry guidance. Passing an unused `loginName` to the token call creates a user implicitly, which a retry would not duplicate (4 of 20). Two headers and a token per call. No official server SDK, only client generation from the Swagger file, and FastLink guides for iOS, Android, React Native and Flutter (6 of 15)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 49,
            "points": 8.57,
            "reason": "A `clientId` and `secret` in a form body, never in the URL, are exchanged for a bearer token that expires after 30 minutes and is bound to one user's `loginName` or to the admin. Tokens can be revoked, credentials can be replaced on the dashboard, and each environment has its own. No scopes (22 of 30). A user token reads one user's data, datasets are enabled per customer and the Account Profile dataset needs Yodlee Security Office approval. No read-only credential and no confirmation on deletes (9 of 20). Responses carry bank-written text, and no guidance on untrusted content was found beyond a note on escaped quotes (3 of 15). Consent history endpoints and a `referenceCode` on errors exist. No operator call log was found in public docs, and the dashboard was not read (3 of 15). No security.txt, bug bounty or disclosure address found. The Security FAQ states an annual SOC 2 Type 2 assessment (report under NDA), PCI DSS 4.0.1 Level One and yearly third-party penetration tests (12 of 20)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 15,
            "points": 1.88,
            "reason": "No x402, MPP or L402 (0). No price on yodlee.com or the developer portal, both `/pricing` addresses return 404 and product pages ask for a demo (0). The sandbox is free on registration with five preconfigured users. The registration page is disallowed by robots.txt, so we could not confirm that it asks for no card (15 of 20). A person registers in a browser and takes credentials from a dashboard (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 33,
            "points": 2.89,
            "reason": "The newest release notes, July Week 3 2026, are dated 31 July 2026, 69 days before the check (20 of 30). That is the only dated entry since 10 July, so the three-in-90-days line is not met (0). Release notes are dated and appear about every two months. On GitHub, seven issues and pull requests on `Yodlee/OpenAPI` are open, the oldest from April 2021 and the newest from 20 February 2026 with no reply (6 of 15). No official SDKs, and the Swagger file trails the API by four releases (4 of 15). The spec repository has no CI or tests (3 of 10)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 53,
            "points": 4.64,
            "note": "editorial 32, provenance 73",
            "reason": "Closed service with no published service agreement or developer terms. The Swagger file names a Yodlee Developer Licence at an address that returns 404. The spec itself is MIT (8 of 30). The privacy notice says it covers Yodlee's direct-to-consumer services and websites, and that a client's own practices govern services delivered through a client. The Security FAQ says client data is kept until the client deletes it by API or written request, is encrypted with AES-256, and is not used in non-production environments. No DPA is public (12 of 30). No written deprecation policy. The Swagger file marks seven operations deprecated and names replacements, without dates (6 of 20). The FAQ says most core services run from colocation data centres with a move to AWS under way. No sub-processor list or named data locations (6 of 20)."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "`include` adds optional detail, `top` caps list size at 500, count endpoints exist for transactions and providers, and derived endpoints return net worth and transaction summaries (16 of 25). `skip` and `top` paging with next and previous links in the response header, plus date, account, category, keyword and container filters on transactions (17 of 20). Errors return `errorCode`, `errorMessage` and `referenceCode`, and the spec says codes do not change (15 of 20). No idempotency key or retry guidance. Passing an unused `loginName` to the token call creates a user implicitly, which a retry would not duplicate (4 of 20). Two headers and a token per call. No official server SDK, only client generation from the Swagger file, and FastLink guides for iOS, Android, React Native and Flutter (6 of 15).",
            "maintenance": "The newest release notes, July Week 3 2026, are dated 31 July 2026, 69 days before the check (20 of 30). That is the only dated entry since 10 July, so the three-in-90-days line is not met (0). Release notes are dated and appear about every two months. On GitHub, seven issues and pull requests on `Yodlee/OpenAPI` are open, the oldest from April 2021 and the newest from 20 February 2026 with no reply (6 of 15). No official SDKs, and the Swagger file trails the API by four releases (4 of 15). The spec repository has no CI or tests (3 of 10).",
            "payments": "No x402, MPP or L402 (0). No price on yodlee.com or the developer portal, both `/pricing` addresses return 404 and product pages ask for a demo (0). The sandbox is free on registration with five preconfigured users. The registration page is disallowed by robots.txt, so we could not confirm that it asks for no card (15 of 20). A person registers in a browser and takes credentials from a dashboard (0).",
            "reliability": "Graded as a hosted API. No status page is linked from yodlee.com or the developer portal, and status.yodlee.com did not answer (0). With no incident history to read, 5 of 30. No rate limit with numbers was found in the docs or the Swagger file, which lists no 429 response (0). No 429, backoff or idempotency guidance found (0). No public SLA. The Security FAQ mentions only contracted recovery targets for clients' disaster recovery options (0). The Core API v1.1 is generally available (10).",
            "schema": "A public Swagger 2.0 file (`Yodlee/OpenAPI`, MIT) with 70 paths, 98 operations and 267 definitions. Its last update, on 22 April 2026, brought it to the November 2025 release, so fields from the June and July 2026 notes such as `isCrypto` are missing (22 of 25). No llms.txt (404) and no Markdown docs (0). 96 of 98 operations carry a long description with defaults, sandbox limits and, for the seven deprecated ones, the replacement (16 of 20). Definitions hold 204 enums, but query parameters such as `container` and `baseType` are plain strings with allowed values only in the description, and `dataset$filter` is a free expression (9 of 15). The file has no examples. The docs site shows sample requests and responses, and each operation lists its 400 errors by `Y` code, with 401 and 404 undescribed (9 of 15). An `Api-Version` header, dated release notes and spec tags by release month (15).",
            "security": "A `clientId` and `secret` in a form body, never in the URL, are exchanged for a bearer token that expires after 30 minutes and is bound to one user's `loginName` or to the admin. Tokens can be revoked, credentials can be replaced on the dashboard, and each environment has its own. No scopes (22 of 30). A user token reads one user's data, datasets are enabled per customer and the Account Profile dataset needs Yodlee Security Office approval. No read-only credential and no confirmation on deletes (9 of 20). Responses carry bank-written text, and no guidance on untrusted content was found beyond a note on escaped quotes (3 of 15). Consent history endpoints and a `referenceCode` on errors exist. No operator call log was found in public docs, and the dashboard was not read (3 of 15). No security.txt, bug bounty or disclosure address found. The Security FAQ states an annual SOC 2 Type 2 assessment (report under NDA), PCI DSS 4.0.1 Level One and yearly third-party penetration tests (12 of 20).",
            "transparency": "Closed service with no published service agreement or developer terms. The Swagger file names a Yodlee Developer Licence at an address that returns 404. The spec itself is MIT (8 of 30). The privacy notice says it covers Yodlee's direct-to-consumer services and websites, and that a client's own practices govern services delivered through a client. The Security FAQ says client data is kept until the client deletes it by API or written request, is encrypted with AES-256, and is not used in non-production environments. No DPA is public (12 of 30). No written deprecation policy. The Swagger file marks seven operations deprecated and names replacements, without dates (6 of 20). The FAQ says most core services run from colocation data centres with a move to AWS under way. No sub-processor list or named data locations (6 of 20)."
          },
          "sources": [
            {
              "what": "developer portal home",
              "url": "https://developer.yodlee.com/",
              "seen": "2026-10-08"
            },
            {
              "what": "Yodlee API overview and datasets",
              "url": "https://developer.yodlee.com/resources/yodlee/yodlee-api-overview/docs",
              "seen": "2026-10-08"
            },
            {
              "what": "account aggregation getting started and sandbox",
              "url": "https://developer.yodlee.com/products/yodlee/account-aggregation/docs",
              "seen": "2026-10-08"
            },
            {
              "what": "aggregation API reference",
              "url": "https://developer.yodlee.com/products/yodlee/account-aggregation/docs/api-reference",
              "seen": "2026-10-08"
            },
            {
              "what": "Core APIs reference",
              "url": "https://developer.yodlee.com/products/yodlee/core-apis/docs",
              "seen": "2026-10-08"
            },
            {
              "what": "examples",
              "url": "https://developer.yodlee.com/products/yodlee/account-aggregation/docs/examples",
              "seen": "2026-10-08"
            },
            {
              "what": "account lifecycle",
              "url": "https://developer.yodlee.com/products/yodlee/account-aggregation/docs/account-lifecycle",
              "seen": "2026-10-08"
            },
            {
              "what": "additional resources",
              "url": "https://developer.yodlee.com/products/yodlee/account-aggregation/docs/additional-resources",
              "seen": "2026-10-08"
            },
            {
              "what": "client credentials authorisation",
              "url": "https://developer.yodlee.com/resources/yodlee/client-credentials-authorization/docs/overview",
              "seen": "2026-10-08"
            },
            {
              "what": "environments",
              "url": "https://developer.yodlee.com/resources/yodlee/client-credentials-authorization/docs/environments",
              "seen": "2026-10-08"
            },
            {
              "what": "FastLink 4 overview",
              "url": "https://developer.yodlee.com/resources/yodlee/fastlink-4/docs",
              "seen": "2026-10-08"
            },
            {
              "what": "FastLink API integrations",
              "url": "https://developer.yodlee.com/resources/yodlee/fastlink-4/docs/api_integrations",
              "seen": "2026-10-08"
            },
            {
              "what": "webhooks",
              "url": "https://developer.yodlee.com/resources/yodlee/webhooks/docs",
              "seen": "2026-10-08"
            },
            {
              "what": "data extracts",
              "url": "https://developer.yodlee.com/resources/yodlee/data-extracts/docs/overview",
              "seen": "2026-10-08"
            },
            {
              "what": "US open banking",
              "url": "https://developer.yodlee.com/products/yodlee/us-open-banking/docs",
              "seen": "2026-10-08"
            },
            {
              "what": "generating clients from the Swagger file",
              "url": "https://developer.yodlee.com/resources/yodlee/open-api-swagger/docs",
              "seen": "2026-10-08"
            },
            {
              "what": "release notes index",
              "url": "https://developer.yodlee.com/resources/yodlee",
              "seen": "2026-10-08"
            },
            {
              "what": "July Week 3 2026 release notes",
              "url": "https://developer.yodlee.com/resources/yodlee/july-week-3-2026-release-notes",
              "seen": "2026-10-08"
            },
            {
              "what": "June 2026 release notes",
              "url": "https://developer.yodlee.com/resources/yodlee/june-2026-release-notes",
              "seen": "2026-10-08"
            },
            {
              "what": "April 2026 release notes",
              "url": "https://developer.yodlee.com/resources/yodlee/april-2026-release-notes",
              "seen": "2026-10-08"
            },
            {
              "what": "February 2026 release notes",
              "url": "https://developer.yodlee.com/resources/yodlee/february-2026-release-notes",
              "seen": "2026-10-08"
            },
            {
              "what": "Swagger file repository, history and tags",
              "url": "https://github.com/Yodlee/OpenAPI",
              "seen": "2026-10-08"
            },
            {
              "what": "repository statistics and open issues",
              "url": "https://api.github.com/repos/Yodlee/OpenAPI",
              "seen": "2026-10-08"
            },
            {
              "what": "developer terms address from the Swagger file, 404",
              "url": "https://developer.yodlee.com/terms/condition",
              "seen": "2026-10-08"
            },
            {
              "what": "llms.txt, 404",
              "url": "https://developer.yodlee.com/llms.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "security page",
              "url": "https://www.yodlee.com/legal/yodlee-security",
              "seen": "2026-10-08"
            },
            {
              "what": "Security FAQ, version 1.0",
              "url": "https://www.yodlee.com/wp-content/uploads/2025-08/Yodlee-Security-FAQ-V1.pdf",
              "seen": "2026-10-08"
            },
            {
              "what": "privacy notice",
              "url": "https://www.yodlee.com/legal/privacy-notice",
              "seen": "2026-10-08"
            },
            {
              "what": "company history",
              "url": "https://www.yodlee.com/company",
              "seen": "2026-10-08"
            },
            {
              "what": "pricing address, 404",
              "url": "https://www.yodlee.com/pricing",
              "seen": "2026-10-08"
            },
            {
              "what": "security.txt address, returns the home page",
              "url": "https://www.yodlee.com/.well-known/security.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP registry search",
              "url": "https://registry.modelcontextprotocol.io/v0.1/servers?search=yodlee",
              "seen": "2026-10-08"
            },
            {
              "what": "domain registration (RDAP)",
              "url": "https://rdap.verisign.com/com/v1/domain/yodlee.com",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "unchecked: the API host for each environment. The public docs give paths such as `/ysl/accounts` and say credentials and endpoints are on the dashboard, which needs a login",
            "unchecked: whether registration asks for a card and which agreement a developer accepts. `/user/register` is disallowed by the developer portal's robots.txt and was not fetched",
            "unchecked: the Postman quick start guide linked from the docs, which is hosted by Postman and drawn by script",
            "unchecked: the SOC 2 Type 2 report, which the Security FAQ places under NDA",
            "No price, service agreement, SLA, status page, rate limit, bug bounty or sub-processor list was found in the pages read",
            "status.yodlee.com did not answer from our network and no status page is linked from the site, so the status page is scored as absent",
            "Production and development environments are named in the docs, but how access to them is granted was not established",
            "Some pages were fetched shortly after midnight on 9 October 2026. The batch date of 8 October is used throughout, as the brief requires"
          ]
        },
        "negative": 0,
        "verdict": "A public Swagger 2.0 file covers 98 operations with per-operation error codes, and tokens last 30 minutes and are bound to one end user. No price, service terms, status page, rate limit or SLA is published, there is no official server SDK, and the sandbox is limited to five preconfigured users with sample data.",
        "bestFor": "A bank, wealth firm or fintech with a Yodlee contract that needs wide account coverage, including investment holdings, loans and insurance, in the US, UK, Australia and India.",
        "strengths": [
          "Public Swagger 2.0 file on GitHub (MIT) with 98 operations, 267 definitions and `Y`-prefixed error codes listed per operation",
          "Access tokens expire after 30 minutes, are bound to one end user's `loginName`, and can be revoked with `DELETE /auth/token`",
          "Free sandbox on registration with five preconfigured test users, per the docs",
          "Consent endpoints list, renew and record open banking consents, and `DELETE /user/unregister` removes a user and their data",
          "The Security FAQ states an annual SOC 2 Type 2 assessment, PCI DSS 4.0.1 Level One certification and yearly third-party penetration tests"
        ],
        "weaknesses": [
          "No public price, service agreement or developer terms. The terms address named in the Swagger file returns 404",
          "No status page, rate limit, 429 guidance, idempotency key or SLA was found in the pages read",
          "No official server SDK. Yodlee's docs tell developers to generate a client from the Swagger file",
          "The Swagger file was last updated on 22 April 2026 to the November 2025 release and lacks fields added in June and July 2026, such as `isCrypto`",
          "The sandbox cannot register new users, and full account numbers and holder details need Yodlee Security Office approval",
          "The privacy notice covers only Yodlee's own consumer services and websites, and no DPA or sub-processor list is public"
        ],
        "agentNotes": [
          "Get a token with `POST /auth/token`, sending `Api-Version: 1.1` and the end user's `loginName` as headers and `clientId` and `secret` in a form body. Reuse it for up to 30 minutes",
          "Use the admin `loginName` only for administrative calls such as webhook subscriptions. A token made with a user's `loginName` reads only that user's data",
          "In the sandbox, pick one of the five preconfigured users. Registering new users is not supported there",
          "Page `GET /transactions` with `skip` and `top` (1 to 500). Without dates it returns the last 30 days, and at most two years with `fromDate` and `toDate`",
          "A person must link accounts in FastLink 4 first. Then read `GET /providerAccounts` for link status before `GET /accounts`",
          "Subscribe to `DATA_UPDATES` or `REFRESH` webhooks, or poll `GET /dataExtracts/events` in windows of at most 60 minutes, and do not poll accounts in a loop"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "E",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 41.9
          }
        ],
        "editorialScores": {
          "ergonomics": 58,
          "maintenance": 33,
          "payments": 15,
          "reliability": 15,
          "schema": 71,
          "security": 49,
          "transparency": 32
        },
        "provenanceScore": 73
      },
      "connect": {
        "http": "POST /auth/token\nApi-Version: 1.1\nloginName: \u003cloginName\u003e\nContent-Type: application/x-www-form-urlencoded\n\nclientId=\u003cclientId\u003e\u0026secret=\u003csecret\u003e"
      },
      "letme": {
        "capability": "https://letme.dev/bank.accounts",
        "tool": "https://letme.dev/yodlee-financial-data"
      },
      "notable": [
        "The sandbox is free on registration and holds five preconfigured users. New users cannot be registered there and access is limited to sample data (https://developer.yodlee.com/products/yodlee/account-aggregation/docs)",
        "Access tokens expire after 30 minutes and are tied to one `loginName`. Yodlee replaced JSON Web Tokens with client credentials (https://developer.yodlee.com/resources/yodlee/client-credentials-authorization/docs/overview)",
        "The API is built on datasets. Basic Aggregation Data covers balances, transactions, holdings and statements, and the Account Profile dataset (full account number, holder names, bank transfer code) needs Yodlee Security Office approval (https://developer.yodlee.com/resources/yodlee/yodlee-api-overview/docs)",
        "Yodlee says the core API supports 90 per cent of the top-volume sites in the United States, United Kingdom, Australia and India, and FastLink lists the United States, Canada, Latin America, the United Kingdom, Australia and New Zealand, and South Africa as regions (https://developer.yodlee.com/resources/yodlee/fastlink-4/docs)",
        "The Swagger 2.0 file has 98 operations and was last updated on 22 April 2026 to the November 2025 release (https://github.com/Yodlee/OpenAPI)",
        "The June 2026 release lets `POST /auth/token` accept optional user name, phone and email fields, and the July Week 3 2026 release adds an `isCrypto` flag on investment transactions (https://developer.yodlee.com/resources/yodlee/june-2026-release-notes)",
        "The Security FAQ states an annual SOC 2 Type 2 assessment with the report under NDA, PCI DSS 4.0.1 Level One certification, and retention of client data until the client deletes it or is decommissioned (https://www.yodlee.com/wp-content/uploads/2025-08/Yodlee-Security-FAQ-V1.pdf)",
        "No MCP server was found in Yodlee's docs or in the official MCP registry (https://registry.modelcontextprotocol.io/v0.1/servers?search=yodlee)"
      ],
      "area": "domain-data",
      "details": [
        {
          "label": "Environments",
          "value": "Sandbox (free, five preconfigured users, sample data), development and production, each with its own credentials. The docs print paths such as `/ysl/accounts` without a host"
        },
        {
          "label": "Version",
          "value": "Core API v1.1, set with the `Api-Version: 1.1` header, designed to work with FastLink 4"
        },
        {
          "label": "Products",
          "value": "Account aggregation, account verification (including challenge deposits in the US), transaction data enrichment, holdings, statements and documents, derived net worth and summaries, processor tokens, open banking consents"
        },
        {
          "label": "Countries",
          "value": "Yodlee names the United States, United Kingdom, Australia and India for the core API. FastLink regions add Canada, Latin America, New Zealand and South Africa, with open banking flows for the US, UK, EU and Australia"
        },
        {
          "label": "Rate limits",
          "value": "Not found in the docs or the Swagger file"
        },
        {
          "label": "Test data",
          "value": "Five pre-registered sandbox users and Yodlee's Dummy Account Generator site"
        },
        {
          "label": "Consent and revocation",
          "value": "FastLink 4 handles linking and open banking consent. `GET /consents`, consent renewal and consent history endpoints, `DELETE /providerAccounts/{providerAccountId}`, `DELETE /accounts/{accountId}` and `DELETE /user/unregister`"
        },
        {
          "label": "Pagination",
          "value": "`skip` and `top` (1 to 500) with next and previous links in the response header. Transactions default to the last 30 days and reach back two years"
        },
        {
          "label": "Errors",
          "value": "JSON with `errorCode` (format `YNNN`), `errorMessage` and `referenceCode`. The Swagger file lists 400 errors per operation and no 429"
        },
        {
          "label": "Webhooks",
          "value": "`REFRESH`, `DATA_UPDATES`, `AUTO_REFRESH_UPDATES`, `LATEST_BALANCE_UPDATES`, account verification events and open banking consent events"
        },
        {
          "label": "SDKs",
          "value": "No official server SDK. Clients are generated from the Swagger file. FastLink 4 guides cover web, iOS, Android, React Native and Flutter"
        },
        {
          "label": "Certifications",
          "value": "SOC 2 Type 2 assessed yearly (report under NDA) and PCI DSS 4.0.1 Level One, per the Security FAQ"
        }
      ],
      "provenance": {
        "legalEntity": "Yodlee, Inc.",
        "domain": "yodlee.com",
        "domainRegistered": "1999-02-09",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://developer.yodlee.com/resources/yodlee",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The privacy notice names Yodlee, Inc. and its subsidiaries Yodlee Credit, LLC, Yodlee Data Services, LLC and Yodlee Infotech Private Limited. The company page says Yodlee was acquired by Envestnet in 2015 and joined the STG portfolio in 2025.",
          "`terms` is left out. No service agreement or developer terms are published. The Swagger file gives https://developer.yodlee.com/terms/condition as its terms of service, and that address returns 404.",
          "`privacy` is left out. The privacy notice at https://www.yodlee.com/legal/privacy-notice says it applies to Yodlee's direct-to-consumer services and websites, and that a client's own privacy practices apply to services delivered through a Yodlee client, which is how API data is handled.",
          "`endpointOnVendorDomain` is null. The public docs print API paths without a host, and the host is given with the credentials on a dashboard we did not read.",
          "No status page is linked from yodlee.com or the developer portal, and status.yodlee.com did not answer.",
          "https://www.yodlee.com/.well-known/security.txt returns the home page, and the same path on developer.yodlee.com returns 404.",
          "Verisign's RDAP server gives a registration date of 1999-02-09 and CSC Corporate Domains, Inc. as registrar."
        ],
        "score": 73,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Yodlee, Inc.",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "yodlee.com, registered 1999-02-09 (27 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "no hosted endpoint",
            "points": 0,
            "max": 0,
            "state": "na"
          },
          {
            "check": "Terms of service",
            "value": "nothing hosted, so the Proprietary service. The Swagger file on GitHub is MIT licence stands in",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Privacy policy",
            "value": "nothing hosted, not scored",
            "points": 0,
            "max": 0,
            "state": "na"
          },
          {
            "check": "Status page",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/yodlee-financial-data.json"
    },
    "verify": {
      "accepts": "a page on yodlee.com or one of its subdomains, or the README of github.com/Yodlee/OpenAPI",
      "badgeUrl": "https://www.anchorterminal.com/badges/yodlee-financial-data.svg",
      "body": {
        "slug": "yodlee-financial-data",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/yodlee-financial-data",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/yodlee-financial-data\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/yodlee-financial-data.svg\" alt=\"Yodlee Core API on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Yodlee Core API on Anchor Terminal](https://www.anchorterminal.com/badges/yodlee-financial-data.svg)](https://www.anchorterminal.com/tools/yodlee-financial-data)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/yodlee-financial-data\"\u003eYodlee Core API on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/yodlee-financial-data",
    "json": "https://www.anchorterminal.com/tools/yodlee-financial-data.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/yodlee-financial-data.md",
    "slim": "https://www.anchorterminal.com/tools/yodlee-financial-data.min.md"
  },
  "markdown": "## Overview\n\n**Grade E · 41.9/100 · rank #796 of 842 · #12 in Bank data \u0026 open banking · not agent-ready · confidence medium**\n\n\n## Assessment\n\nA public Swagger 2.0 file covers 98 operations with per-operation error codes, and tokens last 30 minutes and are bound to one end user. No price, service terms, status page, rate limit or SLA is published, there is no official server SDK, and the sandbox is limited to five preconfigured users with sample data.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Yodlee, Inc. (https://www.yodlee.com) |\n| Kind | HTTP API |\n| Category | Bank data \u0026 open banking (https://www.anchorterminal.com/categories/banking-data) |\n| Transport | HTTP |\n| Auth | OAuth · Self-serve for the sandbox. Registering on the developer portal gives a `clientId`, a `secret` and an admin `loginName` on the API dashboard. `POST /auth/token` takes the id and secret in a form body and a `loginName` header, and returns a bearer token that lasts 30 minutes and acts for that user, or for the admin on administrative calls. Every call also sends `Api-Version: 1.1`. Each environment (sandbox, development, production) has its own credentials. How production access is granted is not stated in the public docs. Full account numbers and holder details need Yodlee Security Office approval. |\n| Pricing | Paid (Paid) · No public price. `/pricing` returns 404 on yodlee.com and on the developer portal, and product pages ask for a demo. The sandbox is free on registration, with five preconfigured users and sample data only, so an agent's owner can test without a contract (checked 2026-10-08). |\n| x402 | No · No x402, MPP or L402 in the developer docs, the Swagger file or yodlee.com (checked 2026-10-08). |\n| Licence | Proprietary service. The Swagger file on GitHub is MIT |\n| Source | https://github.com/Yodlee/OpenAPI |\n| Docs | https://developer.yodlee.com/resources/yodlee/yodlee-api-overview/docs |\n| llms.txt | not found |\n| Last release | 2026-07-31 |\n| GitHub stars | 17 (as of 2026-10-08) |\n| Environments | Sandbox (free, five preconfigured users, sample data), development and production, each with its own credentials. The docs print paths such as `/ysl/accounts` without a host |\n| Version | Core API v1.1, set with the `Api-Version: 1.1` header, designed to work with FastLink 4 |\n| Products | Account aggregation, account verification (including challenge deposits in the US), transaction data enrichment, holdings, statements and documents, derived net worth and summaries, processor tokens, open banking consents |\n| Countries | Yodlee names the United States, United Kingdom, Australia and India for the core API. FastLink regions add Canada, Latin America, New Zealand and South Africa, with open banking flows for the US, UK, EU and Australia |\n| Rate limits | Not found in the docs or the Swagger file |\n| Test data | Five pre-registered sandbox users and Yodlee's Dummy Account Generator site |\n| Consent and revocation | FastLink 4 handles linking and open banking consent. `GET /consents`, consent renewal and consent history endpoints, `DELETE /providerAccounts/{providerAccountId}`, `DELETE /accounts/{accountId}` and `DELETE /user/unregister` |\n| Pagination | `skip` and `top` (1 to 500) with next and previous links in the response header. Transactions default to the last 30 days and reach back two years |\n| Errors | JSON with `errorCode` (format `YNNN`), `errorMessage` and `referenceCode`. The Swagger file lists 400 errors per operation and no 429 |\n| Webhooks | `REFRESH`, `DATA_UPDATES`, `AUTO_REFRESH_UPDATES`, `LATEST_BALANCE_UPDATES`, account verification events and open banking consent events |\n| SDKs | No official server SDK. Clients are generated from the Swagger file. FastLink 4 guides cover web, iOS, Android, React Native and Flutter |\n| Certifications | SOC 2 Type 2 assessed yearly (report under NDA) and PCI DSS 4.0.1 Level One, per the Security FAQ |\n| Capabilities | bank.accounts, bank.transactions, bank.identity, bank.consent |\n| Tags | hosted, oauth, openapi, sandbox, webhooks, sales-led, closed-source, enterprise, soc2 |\n| JSON | https://www.anchorterminal.com/api/v1/tools/yodlee-financial-data.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 15 | 3.0 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 71 | 11.5 |\n| Agent ergonomics | 13% | 16.2 | 58 | 9.4 |\n| Security \u0026 auth | 14% | 17.5 | 49 | 8.6 |\n| Payments \u0026 pricing | 10% | 12.5 | 15 | 1.9 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 33 | 2.9 |\n| Transparency \u0026 trust (editorial 32, provenance 73) | 7% | 8.8 | 53 | 4.6 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **41.9 → E** |\n\n### Why each score\n\n- Reliability 15: Graded as a hosted API. No status page is linked from yodlee.com or the developer portal, and status.yodlee.com did not answer (0). With no incident history to read, 5 of 30. No rate limit with numbers was found in the docs or the Swagger file, which lists no 429 response (0). No 429, backoff or idempotency guidance found (0). No public SLA. The Security FAQ mentions only contracted recovery targets for clients' disaster recovery options (0). The Core API v1.1 is generally available (10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 71: A public Swagger 2.0 file (`Yodlee/OpenAPI`, MIT) with 70 paths, 98 operations and 267 definitions. Its last update, on 22 April 2026, brought it to the November 2025 release, so fields from the June and July 2026 notes such as `isCrypto` are missing (22 of 25). No llms.txt (404) and no Markdown docs (0). 96 of 98 operations carry a long description with defaults, sandbox limits and, for the seven deprecated ones, the replacement (16 of 20). Definitions hold 204 enums, but query parameters such as `container` and `baseType` are plain strings with allowed values only in the description, and `dataset$filter` is a free expression (9 of 15). The file has no examples. The docs site shows sample requests and responses, and each operation lists its 400 errors by `Y` code, with 401 and 404 undescribed (9 of 15). An `Api-Version` header, dated release notes and spec tags by release month (15).\n- Agent ergonomics 58: `include` adds optional detail, `top` caps list size at 500, count endpoints exist for transactions and providers, and derived endpoints return net worth and transaction summaries (16 of 25). `skip` and `top` paging with next and previous links in the response header, plus date, account, category, keyword and container filters on transactions (17 of 20). Errors return `errorCode`, `errorMessage` and `referenceCode`, and the spec says codes do not change (15 of 20). No idempotency key or retry guidance. Passing an unused `loginName` to the token call creates a user implicitly, which a retry would not duplicate (4 of 20). Two headers and a token per call. No official server SDK, only client generation from the Swagger file, and FastLink guides for iOS, Android, React Native and Flutter (6 of 15).\n- Security \u0026 auth 49: A `clientId` and `secret` in a form body, never in the URL, are exchanged for a bearer token that expires after 30 minutes and is bound to one user's `loginName` or to the admin. Tokens can be revoked, credentials can be replaced on the dashboard, and each environment has its own. No scopes (22 of 30). A user token reads one user's data, datasets are enabled per customer and the Account Profile dataset needs Yodlee Security Office approval. No read-only credential and no confirmation on deletes (9 of 20). Responses carry bank-written text, and no guidance on untrusted content was found beyond a note on escaped quotes (3 of 15). Consent history endpoints and a `referenceCode` on errors exist. No operator call log was found in public docs, and the dashboard was not read (3 of 15). No security.txt, bug bounty or disclosure address found. The Security FAQ states an annual SOC 2 Type 2 assessment (report under NDA), PCI DSS 4.0.1 Level One and yearly third-party penetration tests (12 of 20).\n- Payments \u0026 pricing 15: No x402, MPP or L402 (0). No price on yodlee.com or the developer portal, both `/pricing` addresses return 404 and product pages ask for a demo (0). The sandbox is free on registration with five preconfigured users. The registration page is disallowed by robots.txt, so we could not confirm that it asks for no card (15 of 20). A person registers in a browser and takes credentials from a dashboard (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 33: The newest release notes, July Week 3 2026, are dated 31 July 2026, 69 days before the check (20 of 30). That is the only dated entry since 10 July, so the three-in-90-days line is not met (0). Release notes are dated and appear about every two months. On GitHub, seven issues and pull requests on `Yodlee/OpenAPI` are open, the oldest from April 2021 and the newest from 20 February 2026 with no reply (6 of 15). No official SDKs, and the Swagger file trails the API by four releases (4 of 15). The spec repository has no CI or tests (3 of 10).\n- Transparency \u0026 trust 53: Closed service with no published service agreement or developer terms. The Swagger file names a Yodlee Developer Licence at an address that returns 404. The spec itself is MIT (8 of 30). The privacy notice says it covers Yodlee's direct-to-consumer services and websites, and that a client's own practices govern services delivered through a client. The Security FAQ says client data is kept until the client deletes it by API or written request, is encrypted with AES-256, and is not used in non-production environments. No DPA is public (12 of 30). No written deprecation policy. The Swagger file marks seven operations deprecated and names replacements, without dates (6 of 20). The FAQ says most core services run from colocation data centres with a move to AWS under way. No sub-processor list or named data locations (6 of 20).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (17 items): https://www.anchorterminal.com/fixes/yodlee-financial-data.md (JSON https://www.anchorterminal.com/fixes/yodlee-financial-data.json)\n\n### What we couldn't check\n\n- unchecked: the API host for each environment. The public docs give paths such as `/ysl/accounts` and say credentials and endpoints are on the dashboard, which needs a login\n- unchecked: whether registration asks for a card and which agreement a developer accepts. `/user/register` is disallowed by the developer portal's robots.txt and was not fetched\n- unchecked: the Postman quick start guide linked from the docs, which is hosted by Postman and drawn by script\n- unchecked: the SOC 2 Type 2 report, which the Security FAQ places under NDA\n- No price, service agreement, SLA, status page, rate limit, bug bounty or sub-processor list was found in the pages read\n- status.yodlee.com did not answer from our network and no status page is linked from the site, so the status page is scored as absent\n- Production and development environments are named in the docs, but how access to them is granted was not established\n- Some pages were fetched shortly after midnight on 9 October 2026. The batch date of 8 October is used throughout, as the brief requires\n\n### Sources\n\n- developer portal home: \u003chttps://developer.yodlee.com/\u003e (seen 2026-10-08)\n- Yodlee API overview and datasets: \u003chttps://developer.yodlee.com/resources/yodlee/yodlee-api-overview/docs\u003e (seen 2026-10-08)\n- account aggregation getting started and sandbox: \u003chttps://developer.yodlee.com/products/yodlee/account-aggregation/docs\u003e (seen 2026-10-08)\n- aggregation API reference: \u003chttps://developer.yodlee.com/products/yodlee/account-aggregation/docs/api-reference\u003e (seen 2026-10-08)\n- Core APIs reference: \u003chttps://developer.yodlee.com/products/yodlee/core-apis/docs\u003e (seen 2026-10-08)\n- examples: \u003chttps://developer.yodlee.com/products/yodlee/account-aggregation/docs/examples\u003e (seen 2026-10-08)\n- account lifecycle: \u003chttps://developer.yodlee.com/products/yodlee/account-aggregation/docs/account-lifecycle\u003e (seen 2026-10-08)\n- additional resources: \u003chttps://developer.yodlee.com/products/yodlee/account-aggregation/docs/additional-resources\u003e (seen 2026-10-08)\n- client credentials authorisation: \u003chttps://developer.yodlee.com/resources/yodlee/client-credentials-authorization/docs/overview\u003e (seen 2026-10-08)\n- environments: \u003chttps://developer.yodlee.com/resources/yodlee/client-credentials-authorization/docs/environments\u003e (seen 2026-10-08)\n- FastLink 4 overview: \u003chttps://developer.yodlee.com/resources/yodlee/fastlink-4/docs\u003e (seen 2026-10-08)\n- FastLink API integrations: \u003chttps://developer.yodlee.com/resources/yodlee/fastlink-4/docs/api_integrations\u003e (seen 2026-10-08)\n- webhooks: \u003chttps://developer.yodlee.com/resources/yodlee/webhooks/docs\u003e (seen 2026-10-08)\n- data extracts: \u003chttps://developer.yodlee.com/resources/yodlee/data-extracts/docs/overview\u003e (seen 2026-10-08)\n- US open banking: \u003chttps://developer.yodlee.com/products/yodlee/us-open-banking/docs\u003e (seen 2026-10-08)\n- generating clients from the Swagger file: \u003chttps://developer.yodlee.com/resources/yodlee/open-api-swagger/docs\u003e (seen 2026-10-08)\n- release notes index: \u003chttps://developer.yodlee.com/resources/yodlee\u003e (seen 2026-10-08)\n- July Week 3 2026 release notes: \u003chttps://developer.yodlee.com/resources/yodlee/july-week-3-2026-release-notes\u003e (seen 2026-10-08)\n- June 2026 release notes: \u003chttps://developer.yodlee.com/resources/yodlee/june-2026-release-notes\u003e (seen 2026-10-08)\n- April 2026 release notes: \u003chttps://developer.yodlee.com/resources/yodlee/april-2026-release-notes\u003e (seen 2026-10-08)\n- February 2026 release notes: \u003chttps://developer.yodlee.com/resources/yodlee/february-2026-release-notes\u003e (seen 2026-10-08)\n- Swagger file repository, history and tags: \u003chttps://github.com/Yodlee/OpenAPI\u003e (seen 2026-10-08)\n- repository statistics and open issues: \u003chttps://api.github.com/repos/Yodlee/OpenAPI\u003e (seen 2026-10-08)\n- developer terms address from the Swagger file, 404: \u003chttps://developer.yodlee.com/terms/condition\u003e (seen 2026-10-08)\n- llms.txt, 404: \u003chttps://developer.yodlee.com/llms.txt\u003e (seen 2026-10-08)\n- security page: \u003chttps://www.yodlee.com/legal/yodlee-security\u003e (seen 2026-10-08)\n- Security FAQ, version 1.0: \u003chttps://www.yodlee.com/wp-content/uploads/2025-08/Yodlee-Security-FAQ-V1.pdf\u003e (seen 2026-10-08)\n- privacy notice: \u003chttps://www.yodlee.com/legal/privacy-notice\u003e (seen 2026-10-08)\n- company history: \u003chttps://www.yodlee.com/company\u003e (seen 2026-10-08)\n- pricing address, 404: \u003chttps://www.yodlee.com/pricing\u003e (seen 2026-10-08)\n- security.txt address, returns the home page: \u003chttps://www.yodlee.com/.well-known/security.txt\u003e (seen 2026-10-08)\n- MCP registry search: \u003chttps://registry.modelcontextprotocol.io/v0.1/servers?search=yodlee\u003e (seen 2026-10-08)\n- domain registration (RDAP): \u003chttps://rdap.verisign.com/com/v1/domain/yodlee.com\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 73/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Yodlee, Inc. | 20/20 |\n| Domain age | yodlee.com, registered 1999-02-09 (27 years) | 15/15 |\n| Endpoint on the vendor's domain | no hosted endpoint | n/a |\n| Terms of service | nothing hosted, so the Proprietary service. The Swagger file on GitHub is MIT licence stands in | 10/10 |\n| Privacy policy | nothing hosted, not scored | n/a |\n| Status page | not found | 0/10 |\n| Changelog | published | 10/10 |\n| security.txt | not found | 0/10 |\n\nThe privacy notice names Yodlee, Inc. and its subsidiaries Yodlee Credit, LLC, Yodlee Data Services, LLC and Yodlee Infotech Private Limited. The company page says Yodlee was acquired by Envestnet in 2015 and joined the STG portfolio in 2025.\n\n`terms` is left out. No service agreement or developer terms are published. The Swagger file gives https://developer.yodlee.com/terms/condition as its terms of service, and that address returns 404.\n\n`privacy` is left out. The privacy notice at https://www.yodlee.com/legal/privacy-notice says it applies to Yodlee's direct-to-consumer services and websites, and that a client's own privacy practices apply to services delivered through a Yodlee client, which is how API data is handled.\n\n`endpointOnVendorDomain` is null. The public docs print API paths without a host, and the host is given with the credentials on a dashboard we did not read.\n\nNo status page is linked from yodlee.com or the developer portal, and status.yodlee.com did not answer.\n\nhttps://www.yodlee.com/.well-known/security.txt returns the home page, and the same path on developer.yodlee.com returns 404.\n\nVerisign's RDAP server gives a registration date of 1999-02-09 and CSC Corporate Domains, Inc. as registrar.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service**. Nothing is hosted by the vendor, so there are no terms of service to read. The Proprietary service. The Swagger file on GitHub is MIT licence stands in and the check scores in full.\n\n\n**Privacy policy**. Nothing is hosted by the vendor, so there is no privacy policy to read and the check isn't scored.\n\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Strengths\n\n- Public Swagger 2.0 file on GitHub (MIT) with 98 operations, 267 definitions and `Y`-prefixed error codes listed per operation\n- Access tokens expire after 30 minutes, are bound to one end user's `loginName`, and can be revoked with `DELETE /auth/token`\n- Free sandbox on registration with five preconfigured test users, per the docs\n- Consent endpoints list, renew and record open banking consents, and `DELETE /user/unregister` removes a user and their data\n- The Security FAQ states an annual SOC 2 Type 2 assessment, PCI DSS 4.0.1 Level One certification and yearly third-party penetration tests\n\n## Weaknesses\n\n- No public price, service agreement or developer terms. The terms address named in the Swagger file returns 404\n- No status page, rate limit, 429 guidance, idempotency key or SLA was found in the pages read\n- No official server SDK. Yodlee's docs tell developers to generate a client from the Swagger file\n- The Swagger file was last updated on 22 April 2026 to the November 2025 release and lacks fields added in June and July 2026, such as `isCrypto`\n- The sandbox cannot register new users, and full account numbers and holder details need Yodlee Security Office approval\n- The privacy notice covers only Yodlee's own consumer services and websites, and no DPA or sub-processor list is public\n\n## Before you call it (notes for agents)\n\n1. Get a token with `POST /auth/token`, sending `Api-Version: 1.1` and the end user's `loginName` as headers and `clientId` and `secret` in a form body. Reuse it for up to 30 minutes\n2. Use the admin `loginName` only for administrative calls such as webhook subscriptions. A token made with a user's `loginName` reads only that user's data\n3. In the sandbox, pick one of the five preconfigured users. Registering new users is not supported there\n4. Page `GET /transactions` with `skip` and `top` (1 to 500). Without dates it returns the last 30 days, and at most two years with `fromDate` and `toDate`\n5. A person must link accounts in FastLink 4 first. Then read `GET /providerAccounts` for link status before `GET /accounts`\n6. Subscribe to `DATA_UPDATES` or `REFRESH` webhooks, or poll `GET /dataExtracts/events` in windows of at most 60 minutes, and do not poll accounts in a loop\n\n## Connect\n\nFirst request:\n\n```bash\nPOST /auth/token\nApi-Version: 1.1\nloginName: \u003cloginName\u003e\nContent-Type: application/x-www-form-urlencoded\n\nclientId=\u003cclientId\u003e\u0026secret=\u003csecret\u003e\n```\n\nThrough letme (picks today, calling later): https://letme.dev/yodlee-financial-data. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Plaid | B | 69.8 | 161 | bank.accounts, bank.transactions, bank.identity, bank.consent | no | https://www.anchorterminal.com/tools/plaid.md |\n| Belvo | B | 63.5 | 355 | bank.accounts, bank.transactions, bank.identity, bank.consent | no | https://www.anchorterminal.com/tools/belvo.md |\n| MX Platform API | B | 62.5 | 389 | bank.accounts, bank.transactions, bank.identity, bank.consent | no | https://www.anchorterminal.com/tools/mx.md |\n| Tink | B | 62.5 | 390 | bank.accounts, bank.transactions, bank.consent, bank.identity | no | https://www.anchorterminal.com/tools/tink.md |\n| TrueLayer | B | 62.1 | 401 | bank.accounts, bank.transactions, bank.identity, bank.consent | no | https://www.anchorterminal.com/tools/truelayer.md |\n| Yapily | C | 57.6 | 543 | bank.accounts, bank.transactions, bank.identity, bank.consent | no | https://www.anchorterminal.com/tools/yapily.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The sandbox is free on registration and holds five preconfigured users. New users cannot be registered there and access is limited to sample data (source: \u003chttps://developer.yodlee.com/products/yodlee/account-aggregation/docs\u003e)\n- Access tokens expire after 30 minutes and are tied to one `loginName`. Yodlee replaced JSON Web Tokens with client credentials (source: \u003chttps://developer.yodlee.com/resources/yodlee/client-credentials-authorization/docs/overview\u003e)\n- The API is built on datasets. Basic Aggregation Data covers balances, transactions, holdings and statements, and the Account Profile dataset (full account number, holder names, bank transfer code) needs Yodlee Security Office approval (source: \u003chttps://developer.yodlee.com/resources/yodlee/yodlee-api-overview/docs\u003e)\n- Yodlee says the core API supports 90 per cent of the top-volume sites in the United States, United Kingdom, Australia and India, and FastLink lists the United States, Canada, Latin America, the United Kingdom, Australia and New Zealand, and South Africa as regions (source: \u003chttps://developer.yodlee.com/resources/yodlee/fastlink-4/docs\u003e)\n- The Swagger 2.0 file has 98 operations and was last updated on 22 April 2026 to the November 2025 release (source: \u003chttps://github.com/Yodlee/OpenAPI\u003e)\n- The June 2026 release lets `POST /auth/token` accept optional user name, phone and email fields, and the July Week 3 2026 release adds an `isCrypto` flag on investment transactions (source: \u003chttps://developer.yodlee.com/resources/yodlee/june-2026-release-notes\u003e)\n- The Security FAQ states an annual SOC 2 Type 2 assessment with the report under NDA, PCI DSS 4.0.1 Level One certification, and retention of client data until the client deletes it or is decommissioned (source: \u003chttps://www.yodlee.com/wp-content/uploads/2025-08/Yodlee-Security-FAQ-V1.pdf\u003e)\n- No MCP server was found in Yodlee's docs or in the official MCP registry (source: \u003chttps://registry.modelcontextprotocol.io/v0.1/servers?search=yodlee\u003e)\n\n## Compare\n\n- [Akoya vs Yodlee Core API](https://www.anchorterminal.com/compare/akoya-vs-yodlee-financial-data.md): D 48.3 vs E 41.9\n- [Belvo vs Yodlee Core API](https://www.anchorterminal.com/compare/belvo-vs-yodlee-financial-data.md): B 63.5 vs E 41.9\n- [Enable Banking vs Yodlee Core API](https://www.anchorterminal.com/compare/enable-banking-vs-yodlee-financial-data.md): D 47.1 vs E 41.9\n- [Flinks vs Yodlee Core API](https://www.anchorterminal.com/compare/flinks-vs-yodlee-financial-data.md): D 52.7 vs E 41.9\n- [GoCardless Bank Account Data vs Yodlee Core API](https://www.anchorterminal.com/compare/gocardless-bank-account-data-vs-yodlee-financial-data.md): E 41.7 vs E 41.9\n- [MX Platform API vs Yodlee Core API](https://www.anchorterminal.com/compare/mx-vs-yodlee-financial-data.md): B 62.5 vs E 41.9\n- [Plaid vs Yodlee Core API](https://www.anchorterminal.com/compare/plaid-vs-yodlee-financial-data.md): B 69.8 vs E 41.9\n- [Salt Edge Account Information vs Yodlee Core API](https://www.anchorterminal.com/compare/salt-edge-vs-yodlee-financial-data.md): D 46.7 vs E 41.9\n- [Teller vs Yodlee Core API](https://www.anchorterminal.com/compare/teller-vs-yodlee-financial-data.md): E 42.7 vs E 41.9\n- [Tink vs Yodlee Core API](https://www.anchorterminal.com/compare/tink-vs-yodlee-financial-data.md): B 62.5 vs E 41.9\n- [TrueLayer vs Yodlee Core API](https://www.anchorterminal.com/compare/truelayer-vs-yodlee-financial-data.md): B 62.1 vs E 41.9\n- [Yapily vs Yodlee Core API](https://www.anchorterminal.com/compare/yapily-vs-yodlee-financial-data.md): C 57.6 vs E 41.9\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on yodlee.com or one of its subdomains, or the README of github.com/Yodlee/OpenAPI. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"yodlee-financial-data\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/yodlee-financial-data\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/yodlee-financial-data.svg\" alt=\"Yodlee Core API on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Yodlee Core API on Anchor Terminal](https://www.anchorterminal.com/badges/yodlee-financial-data.svg)](https://www.anchorterminal.com/tools/yodlee-financial-data)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/yodlee-financial-data\"\u003eYodlee Core API on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Yodlee Core API is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/yodlee-financial-data-dark.png\n- Light: https://www.anchorterminal.com/assets/share/yodlee-financial-data-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Bank data \u0026 open banking",
        "url": "https://www.anchorterminal.com/categories/banking-data"
      },
      {
        "name": "Yodlee Core API",
        "url": ""
      }
    ],
    "description": "Yodlee's Core API (v1.1) aggregates a consumer's bank, card, investment, loan and insurance accounts for balances, categorised transactions, holdings, statements and account-owner details. Consumers link accounts through the embedded FastLink 4 widget.",
    "facts": [
      "rank #796 of 842",
      "OAuth auth",
      "0 desk reviews"
    ],
    "h1": "Yodlee Core API",
    "image": "https://www.anchorterminal.com/assets/og/tools-yodlee-financial-data.png",
    "path": "/tools/yodlee-financial-data",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Yodlee Core API review for AI agents, grade E (41.9/100)",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/tools/yodlee-financial-data"
  },
  "tokens": {
    "markdown": 7200,
    "slim": 1730
  },
  "version": 1
}
