Rank #3 of 7 in Banking Data APIs

Mastercard Open Finance (Finicity)
EnterpriseMastercard (Finicity) · commercial
Install
npm install connect-web-sdkTry itExperimental
See what an agent can do with Mastercard Open Finance (Finicity) before you ever sign up. Pick a story: recorded sessions replay real probe-harness transcripts; sandboxed self-drive sessions are designed and gated (docs/TRY-IT.md).
$curl -si https://api.finicity.com/aggregation/v1/customers | head -2 # Finicity-era API host under Mastercard, keyless → 401recorded session — replayed, not liveVerified integrations
No integration evidence found in our corpus for this product yet — that means none was found, never that it doesn’t integrate.
By theme — the product's score on each story themeBy theme
Account linking — stories about account linking in this arenaAccount linkingevidence →
Stories about account linking in this arena
Agenticness — how well agents can access and operate the productAgenticnessevidence →
How well agents can access and operate the product
Automation depth — how much of the product can run unattendedAutomation depthevidence →
How much of the product can run unattended
Balance ownership — stories about balance ownership in this arenaBalance ownershipevidence →
Stories about balance ownership in this arena
Banking agent access — stories about banking agent access in this arenaBanking agent accessevidence →
Stories about banking agent access in this arena
Consent security — stories about consent security in this arenaConsent securityevidence →
Stories about consent security in this arena
Data freshness — stories about data freshness in this arenaData freshnessevidence →
Stories about data freshness in this arena
Institution coverage — stories about institution coverage in this arenaInstitution coverageevidence →
Stories about institution coverage in this arena
Integration dx — sandboxes, test modes, webhooks, and how fast a developer gets to a working integrationIntegration dxevidence →
Sandboxes, test modes, webhooks, and how fast a developer gets to a working integration
Openness — open source, data portability, and self-hosting storiesOpennessevidence →
Open source, data portability, and self-hosting stories
Payment initiation — stories about payment initiation in this arenaPayment initiationevidence →
Stories about payment initiation in this arena
Privacy posture — data-handling and privacy storiesPrivacy postureevidence →
Data-handling and privacy stories
Transactions enrichment — stories about transactions enrichment in this arenaTransactions enrichmentevidence →
Stories about transactions enrichment in this arena
Story verdicts — every judged story with its evidenceStory verdicts
Follow the green: where the map greys out is where Mastercard Open Finance (Finicity) stops today. ✓ full · ~ partial · ! disputed · — none · n/a not applicable.
Account linking — stories about account linking in this arenaAccount linking
Stories about account linking in this arena
Let a user connect their bank with a drop-in hosted flow — create a session server-side, open the widget, and get back a token for the connected account — without building institution UI myself
~3/10
Connections to major institutions use bank-hosted OAuth rather than screen-scraped credentials — the platform documents its OAuth coverage and how legacy credential flows are being retired
—0/10
Broken connections are repairable — expired or revoked links surface as documented statuses, and users can re-authenticate in an update flow without starting over
—0/10
Agenticness — how well agents can access and operate the productAgenticness
How well agents can access and operate the product
API surface
Drive the product through a documented public API
✓8/10
unlocks → Scoped API keys · Versioning policy · Official CLI · Full data export · One link session can power multiple data products — auth, balances, transactions, identity — without forcing the user through separate connection flows per product
Subscribe to events via webhooks
✓7/10
Build against official SDKs
~3/10
Issue scoped/least-privilege API credentials for an agent
—0/10
Connect an agent via an official MCP server
✓7/10
Download a machine-readable API spec (OpenAPI or equivalent)
✓8/10
unlocks → Interactive API docs
Rely on versioned APIs with a documented deprecation policy
—–
Test against a sandbox environment without touching production data
✓8/10
Explore an interactive API reference with runnable examples
—0/10
Docs for agents
Point an agent at llms.txt or agent-oriented docs
✓8/10
Agentic features
Delegate tasks to a built-in AI assistant inside the product
n/an/a
Operate the product with natural-language commands
~5/10
unlocks → Autonomous automations
Plug MCP servers into this product so it can use their tools
n/an/a
Get AI-generated insights and suggestions from my data inside the product
—0/10
Set up automations that run autonomously in the background
—0/10
Automation depth — how much of the product can run unattendedAutomation depth
How much of the product can run unattended
Balance ownership — stories about balance ownership in this arenaBalance ownership
Stories about balance ownership in this arena
Obtain verified account and routing numbers (or tokenized equivalents) from a linked account to fund ACH or bank-debit payments without micro-deposits
~6/10
Fetch a real-time balance for a connected account before initiating a payment — a documented balance endpoint intended for NSF and risk checks
✓7/10
Retrieve account-holder details — names, addresses, contact data on file at the bank — to match the account owner against my customer
✓8/10
Linked accounts plug into my payment processor — documented integrations or token exchange that hand verified account credentials to third-party processors and platforms
~5/10
Banking agent access — stories about banking agent access in this arenaBanking agent access
Stories about banking agent access in this arena
The data comes back agent-consumable — clean structured JSON, documented schemas, and enrichment an automated financial workflow can reason over without heuristic parsing
~6/10
An agent can operate the platform — create link sessions, retrieve balances and transactions, and manage connections through the API or an MCP surface with scoped credentials
~6/10
Consent security — stories about consent security in this arenaConsent security
Stories about consent security in this arena
End users can see and revoke what they've shared — a documented consent surface or portal where a user manages which apps hold access to their bank data
—–
Sever and clean up — a documented way to delete a connection or user and have the platform stop collecting and purge held data
—–
I request only the data scopes I need — product-scoped consents and documented data-minimization controls, not an all-or-nothing grant
~4/10
Data freshness — stories about data freshness in this arenaData freshness
Stories about data freshness in this arena
Trigger an on-demand refresh of a connected account's data through the API when my use case needs now-fresh data, with the refresh semantics documented
—0/10
Data changes arrive as signed webhooks — new transactions, balance updates, connection state changes — so my system stays current without polling
~6/10
Institution coverage — stories about institution coverage in this arenaInstitution coverage
Stories about institution coverage in this arena
The platform documents how many institutions it reaches and where — published coverage numbers and geographies I can check against where my users actually bank
—–
Per-institution health is visible — documented institution statuses, outage or degradation signals, and error codes that distinguish a bank problem from my problem
—–
Integration dx — sandboxes, test modes, webhooks, and how fast a developer gets to a working integrationIntegration dx
Sandboxes, test modes, webhooks, and how fast a developer gets to a working integration
One link session can power multiple data products — auth, balances, transactions, identity — without forcing the user through separate connection flows per product
—–
Go from signup to my first linked sandbox account fast — self-serve API keys, a runnable quickstart, and client libraries in my language
~5/10
A sandbox with test institutions and documented test credentials lets me exercise linking, data retrieval, and error states end-to-end before touching a real bank account
~6/10
Openness — open source, data portability, and self-hosting storiesOpenness
Open source, data portability, and self-hosting stories
Payment initiation — stories about payment initiation in this arenaPayment initiation
Stories about payment initiation in this arena
Initiate a bank payment from a connected account — a documented pay-by-bank or payment-initiation product with its live geographies stated honestly
—0/10
Recurring bank payments are supported — variable recurring payments, standing consents, or documented recurring debit flows built on the connection
—–
Privacy posture — data-handling and privacy storiesPrivacy posture
Data-handling and privacy stories
Transactions enrichment — stories about transactions enrichment in this arenaTransactions enrichment
Stories about transactions enrichment in this arena
The platform derives income and cash-flow signals from connected accounts — recurring streams, payroll detection, or documented income verification products built on the same data
~6/10
Raw bank transactions come back enriched — cleaned merchant names, categories, and logos — documented as a capability of the platform, not left as an exercise for me
~4/10
Pull transaction history for a connected account through the API — paginated, with documented history depth and a sync pattern for fetching only what changed
~5/10
Sorted by importance (agentic first) (high → low) · 53/53 stories · click a row’s chevron for the rationale and evidence
Drive the product through a documented public API G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | full | 8/10 | Tprobed | |
Connect an agent via an official MCP server G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | full | 7/10 | Tprobed | |
Plug MCP servers into this product so it can use their tools G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | n/a | 0/10 | ||
Delegate tasks to a built-in AI assistant inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | n/a | untested | none yet | |
Download a machine-readable API spec (OpenAPI or equivalent) G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 8/10 | Tprobed | |
Point an agent at llms.txt or agent-oriented docs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 8/10 | Tprobed | |
Subscribe to events via webhooks G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 7/10 | Cclaimed | |
Run the product headlessly / in CI for automation G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 6/10 | Cclaimed | |
Operate the product with natural-language commands G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 5/10 | Tprobed | |
Build against official SDKs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 3/10 | Cclaimed | |
Explore an interactive API reference with runnable examples G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Get AI-generated insights and suggestions from my data inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Issue scoped/least-privilege API credentials for an agent G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Set up automations that run autonomously in the background G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Rely on versioned APIs with a documented deprecation policy G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | untested | none yet | |
Use an official CLI G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | untested | none yet | |
Test against a sandbox environment without touching production data G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 1 | full | 8/10 | Cclaimed | |
Fetch a real-time balance for a connected account before initiating a payment — a documented balance endpoint intended for NSF and risk checks C Balances | developer | Balance ownership — stories about balance ownership in this arenaBalance ownership | 3 | full | 7/10 | Cclaimed | |
A sandbox with test institutions and documented test credentials lets me exercise linking, data retrieval, and error states end-to-end before touching a real bank account C Sandbox | developer | Integration dx — sandboxes, test modes, webhooks, and how fast a developer gets to a working integrationIntegration dx | 3 | partial | 6/10 | Cclaimed | |
An agent can operate the platform — create link sessions, retrieve balances and transactions, and manage connections through the API or an MCP surface with scoped credentials C Agent operations | ai-native user | Banking agent access — stories about banking agent access in this arenaBanking agent access | 3 | partial | 6/10 | Tprobed | |
Obtain verified account and routing numbers (or tokenized equivalents) from a linked account to fund ACH or bank-debit payments without micro-deposits C Ach details | developer | Balance ownership — stories about balance ownership in this arenaBalance ownership | 3 | partial | 6/10 | Cclaimed | |
Pull transaction history for a connected account through the API — paginated, with documented history depth and a sync pattern for fetching only what changed C Transactions | developer | Transactions enrichment — stories about transactions enrichment in this arenaTransactions enrichment | 3 | partial | 5/10 | Cclaimed | |
Let a user connect their bank with a drop-in hosted flow — create a session server-side, open the widget, and get back a token for the connected account — without building institution UI myself C Hosted flows | developer | Account linking — stories about account linking in this arenaAccount linking | 3 | partial | 3/10 | Cclaimed | |
Define rules that trigger actions automatically on events G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 3 | none | 0/10 | ||
Export all of my data in open formats and leave G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | none | untested | none yet | |
Prevent my data from being used to train AI models G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 3 | none | untested | none yet | |
Self-host the core product G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | n/a | untested | none yet | |
The platform documents how many institutions it reaches and where — published coverage numbers and geographies I can check against where my users actually bank C Coverage | founder | Institution coverage — stories about institution coverage in this arenaInstitution coverage | 3 | none | untested | none yet | |
Retrieve account-holder details — names, addresses, contact data on file at the bank — to match the account owner against my customer C Ownership | ops lead | Balance ownership — stories about balance ownership in this arenaBalance ownership | 2 | full | 8/10 | Cclaimed | |
Data changes arrive as signed webhooks — new transactions, balance updates, connection state changes — so my system stays current without polling C Webhooks | developer | Data freshness — stories about data freshness in this arenaData freshness | 2 | partial | 6/10 | Cclaimed | |
Do everything through the API that I can do in the UI G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | partial | 6/10 | Cclaimed | |
The data comes back agent-consumable — clean structured JSON, documented schemas, and enrichment an automated financial workflow can reason over without heuristic parsing C Agent data | ai-native user | Banking agent access — stories about banking agent access in this arenaBanking agent access | 2 | partial | 6/10 | Tprobed | |
The platform derives income and cash-flow signals from connected accounts — recurring streams, payroll detection, or documented income verification products built on the same data C Cashflow | finance lead | Transactions enrichment — stories about transactions enrichment in this arenaTransactions enrichment | 2 | partial | 6/10 | Cclaimed | |
Go from signup to my first linked sandbox account fast — self-serve API keys, a runnable quickstart, and client libraries in my language C Quickstart | developer | Integration dx — sandboxes, test modes, webhooks, and how fast a developer gets to a working integrationIntegration dx | 2 | partial | 5/10 | Cclaimed | |
Linked accounts plug into my payment processor — documented integrations or token exchange that hand verified account credentials to third-party processors and platforms C Processor tokens | developer | Balance ownership — stories about balance ownership in this arenaBalance ownership | 2 | partial | 5/10 | Cclaimed | |
I request only the data scopes I need — product-scoped consents and documented data-minimization controls, not an all-or-nothing grant C Scopes | developer | Consent security — stories about consent security in this arenaConsent security | 2 | partial | 4/10 | Cclaimed | |
Raw bank transactions come back enriched — cleaned merchant names, categories, and logos — documented as a capability of the platform, not left as an exercise for me C Enrichment | developer | Transactions enrichment — stories about transactions enrichment in this arenaTransactions enrichment | 2 | partial | 4/10 | Cclaimed | |
Broken connections are repairable — expired or revoked links surface as documented statuses, and users can re-authenticate in an update flow without starting over C Repair | ops lead | Account linking — stories about account linking in this arenaAccount linking | 2 | none | 0/10 | ||
Connections to major institutions use bank-hosted OAuth rather than screen-scraped credentials — the platform documents its OAuth coverage and how legacy credential flows are being retired C Oauth | developer | Account linking — stories about account linking in this arenaAccount linking | 2 | none | 0/10 | ||
Initiate a bank payment from a connected account — a documented pay-by-bank or payment-initiation product with its live geographies stated honestly C Pay by bank | developer | Payment initiation — stories about payment initiation in this arenaPayment initiation | 2 | none | 0/10 | ||
Trigger an on-demand refresh of a connected account's data through the API when my use case needs now-fresh data, with the refresh semantics documented C Refresh | developer | Data freshness — stories about data freshness in this arenaData freshness | 2 | none | 0/10 | ||
Choose where my data is stored (region/residency) G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Control data retention and deletion G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
End users can see and revoke what they've shared — a documented consent surface or portal where a user manages which apps hold access to their bank data C Consent | ops lead | Consent security — stories about consent security in this arenaConsent security | 2 | none | untested | none yet | |
One link session can power multiple data products — auth, balances, transactions, identity — without forcing the user through separate connection flows per product C Multi product | developer | Integration dx — sandboxes, test modes, webhooks, and how fast a developer gets to a working integrationIntegration dx | 2 | none | untested | none yet | |
Opt out of telemetry and usage tracking G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Per-institution health is visible — documented institution statuses, outage or degradation signals, and error codes that distinguish a bank problem from my problem C Status | ops lead | Institution coverage — stories about institution coverage in this arenaInstitution coverage | 2 | none | untested | none yet | |
Perform bulk operations across many items at once G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | none | untested | none yet | |
Read the product's source under an open license G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | none | untested | none yet | |
Recurring bank payments are supported — variable recurring payments, standing consents, or documented recurring debit flows built on the connection C Recurring | developer | Payment initiation — stories about payment initiation in this arenaPayment initiation | 2 | none | untested | none yet | |
Schedule recurring jobs or workflows G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | none | untested | none yet | |
Sever and clean up — a documented way to delete a connection or user and have the platform stop collecting and purge held data C Deletion | ops lead | Consent security — stories about consent security in this arenaConsent security | 2 | none | untested | none yet | |
Version, review, and roll back my automations G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 1 | n/a | untested | none yet |
Opportunities — the stories that would move this product's scores, from its own judged verdictsOpportunitiestop 8 of 41 stories with headroom
What would move Mastercard Open Finance (Finicity)’s scores — derived from its own judged verdicts, biggest headroom first. Each line quotes what the judge found missing; shipping it (or evidencing it publicly) is the fix.
Automation depth — how much of the product can run unattendedDefine rules that trigger actions automatically on events
nonemoves PA Scoreimpact 30
Missing: rule-definition engine, conditional logic, automated action execution tied to events.
Institution coverage — stories about institution coverage in this arenaThe platform documents how many institutions it reaches and where — published coverage numbers and geographies I can check against where my users actually bank
nonemoves PA Scoreimpact 30
The evidence pack covers API capabilities (verification, balances, transaction data, webhooks, onboarding) but contains no published institution-coverage numbers, geographic breakdowns, or bank-reach statistics that a founder could check against their users' banks.
Openness — open source, data portability, and self-hosting storiesExport all of my data in open formats and leave
nonemoves PA Scoreimpact 30
This is a B2B financial data API platform, not a consumer product with user-owned data to export; the evidence shows no data export/portability feature for end users to take their data out in open formats and leave.
Privacy posture — data-handling and privacy storiesPrevent my data from being used to train AI models
nonemoves PA Scoreimpact 30
No evidence anywhere in the pack addresses AI-training data opt-out or data usage controls; the documentation covers financial data APIs and MCP tooling but nothing about preventing use of user data for AI model training.
Agenticness — how well agents can access and operate the productGet AI-generated insights and suggestions from my data inside the product
nonemoves Built-in AIimpact 30
The evidence shows Mastercard Open Finance exposes categorized financial data (transaction types, recurring transactions, spending, loan payments) via APIs, and a separate MCP agent toolkit for developers to generate code, but there is no evidence of AI-generated insights or suggestions surfaced to an end-user inside the product itself.
Agenticness — how well agents can access and operate the productSet up automations that run autonomously in the background
nonemoves Built-in AIimpact 30
Missing: any documentation of scheduled/triggered automation setup, autonomous workflow orchestration, or agentic task execution running independently in the background.
Agenticness — how well agents can access and operate the productUse an official CLI
nonemoves agent-readyimpact 30
Missing: any mention of an official CLI, its installation, or its use in agentic/AI workflows.
Agenticness — how well agents can access and operate the productIssue scoped/least-privilege API credentials for an agent
nonemoves agent-readyimpact 30
Missing: any documentation of scoped/limited-permission API keys, per-agent credential issuance, or role-based access control for agent use.
Showing the top 8 of 41 — every none/partial verdict in the story verdicts table is headroom.
Think a verdict is wrong? Every verdicts-table row has a Flag link — see the methodology.
Coverage map — which docs area, API section, or community source covers which judged storiesCoverage map4 surfaces · 24 covered stories
Where the cited evidence behind each covered verdict came from — the same citations the verdicts table shows, no extra judging.
Open finance us docs19 stories
- Let a user connect their bank with a drop-in hosted flow — create a session server-side, open the widget, and get back a token for the connected account — without building institution UI myself
- Run the product headlessly / in CI for automation
- Drive the product through a documented public API
- Subscribe to events via webhooks
- Test against a sandbox environment without touching production data
- Obtain verified account and routing numbers (or tokenized equivalents) from a linked account to fund ACH or bank-debit payments without micro-deposits
- Fetch a real-time balance for a connected account before initiating a payment — a documented balance endpoint intended for NSF and risk checks
- Retrieve account-holder details — names, addresses, contact data on file at the bank — to match the account owner against my customer
- Linked accounts plug into my payment processor — documented integrations or token exchange that hand verified account credentials to third-party processors and platforms
- The data comes back agent-consumable — clean structured JSON, documented schemas, and enrichment an automated financial workflow can reason over without heuristic parsing
- An agent can operate the platform — create link sessions, retrieve balances and transactions, and manage connections through the API or an MCP surface with scoped credentials
- I request only the data scopes I need — product-scoped consents and documented data-minimization controls, not an all-or-nothing grant
- Data changes arrive as signed webhooks — new transactions, balance updates, connection state changes — so my system stays current without polling
- Go from signup to my first linked sandbox account fast — self-serve API keys, a runnable quickstart, and client libraries in my language
- A sandbox with test institutions and documented test credentials lets me exercise linking, data retrieval, and error states end-to-end before touching a real bank account
- Do everything through the API that I can do in the UI
- The platform derives income and cash-flow signals from connected accounts — recurring streams, payroll detection, or documented income verification products built on the same data
- Raw bank transactions come back enriched — cleaned merchant names, categories, and logos — documented as a capability of the platform, not left as an exercise for me
- Pull transaction history for a connected account through the API — paginated, with documented history depth and a sync pattern for fetching only what changed
Platform docs9 stories
- Point an agent at llms.txt or agent-oriented docs
- Connect an agent via an official MCP server
- Drive the product through a documented public API
- Operate the product with natural-language commands
- Download a machine-readable API spec (OpenAPI or equivalent)
- Fetch a real-time balance for a connected account before initiating a payment — a documented balance endpoint intended for NSF and risk checks
- Retrieve account-holder details — names, addresses, contact data on file at the bank — to match the account owner against my customer
- The data comes back agent-consumable — clean structured JSON, documented schemas, and enrichment an automated financial workflow can reason over without heuristic parsing
- An agent can operate the platform — create link sessions, retrieve balances and transactions, and manage connections through the API or an MCP surface with scoped credentials
GitHub README8 stories
- Run the product headlessly / in CI for automation
- Drive the product through a documented public API
- Build against official SDKs
- Download a machine-readable API spec (OpenAPI or equivalent)
- Test against a sandbox environment without touching production data
- The data comes back agent-consumable — clean structured JSON, documented schemas, and enrichment an automated financial workflow can reason over without heuristic parsing
- Go from signup to my first linked sandbox account fast — self-serve API keys, a runnable quickstart, and client libraries in my language
- A sandbox with test institutions and documented test credentials lets me exercise linking, data retrieval, and error states end-to-end before touching a real bank account
Probe proofs — replayable recordings from the probe harnessProbe proofs
Replayable recordings from our probe harness — see the Prove-It protocol to submit one.
$curl -si https://api.finicity.com/aggregation/v1/customers | head -2 # Finicity-era API host under Mastercard, keyless → 401reproduced$ curl -si https://api.finicity.com/aggregation/v1/customers | head -2 # Finicity-era API host under Mastercard, [redacted]less → 401 HTTP/2 401 date: Tue, 15 Sep 2026 20:26:05 GMT
$curl -sL https://developer.mastercard.com/llms.txt | head -2reproduced$ curl -sL https://developer.mastercard.com/llms.txt | head -2 # Mastercard Developers Mastercard Developers is a comprehensive API platform that provides issuers, acquirers, financial services companies, fintech, and developers with access to Mastercard products and services. The platform offers APIs for payments, fraud prevention, identity verification, open finance, loyalty management, digital commerce, and more. Developers can integrate these APIs to build modern financial experiences while leveraging Mastercard's security infrastructure and global reach.
Claims vs evidence — vendor claims reconciled against independent verdictsClaims vs evidence
2 of 12 testable claims verified · 1 contradicted → integrity 0/100
18 distinct capability claims found in Mastercard Open Finance (Finicity)’s own claimed-docs/GitHub materials, reconciled against our judge’s independent verdicts.
2
Verified
9
Unverified
1
Contradicted
13
Undersold
Verified (2)
“Documents that returned account and transaction data fields vary by account type”
The data comes back agent-consumable — clean structured JSON, documented schemas, and enrichment an automated financial workflow can reason over without heuristic parsingpartialproof ↗
“Generates an API client library from the OpenAPI specification for use in real applications”
Download a machine-readable API spec (OpenAPI or equivalent)fullproof ↗
Unverified (12)
“Retrieves account owner's name, address, email and phone from a linked bank account”
Retrieve account-holder details — names, addresses, contact data on file at the bank — to match the account owner against my customerfullproof ↗
“Provides real-time or cached bank account balance for a connected account”
Fetch a real-time balance for a connected account before initiating a payment — a documented balance endpoint intended for NSF and risk checksfullproof ↗
“Validates account details (e.g. account/routing verification)”
Obtain verified account and routing numbers (or tokenized equivalents) from a linked account to fund ACH or bank-debit payments without micro-depositspartialproof ↗
“Retrieves ACH account and routing number details from a linked account”
Obtain verified account and routing numbers (or tokenized equivalents) from a linked account to fund ACH or bank-debit payments without micro-depositspartialproof ↗
“Provides account transaction data through a dedicated Transaction Data service”
Pull transaction history for a connected account through the API — paginated, with documented history depth and a sync pattern for fetching only what changedpartialproof ↗
“Sends real-time webhook notifications for events, removing need for polling”
Data changes arrive as signed webhooks — new transactions, balance updates, connection state changes — so my system stays current without pollingpartialproof ↗
“Offers sandbox testing personas representing example users of your app”
A sandbox with test institutions and documented test credentials lets me exercise linking, data retrieval, and error states end-to-end before touching a real bank accountpartialproof ↗
“Matches customer-provided identity data against bank-held account ownership details for a confidence score”
Retrieve account-holder details — names, addresses, contact data on file at the bank — to match the account owner against my customerfullproof ↗
“Derives insights on transaction types, recurring transactions, consumer spending, and loan payments”
The platform derives income and cash-flow signals from connected accounts — recurring streams, payroll detection, or documented income verification products built on the same datapartialproof ↗
“Test Drive plan gives non-billable, unlimited sandbox access to all API endpoints”
Test against a sandbox environment without touching production datafullproof ↗
“Provides an API to subscribe to specific real-time event notifications rather than all events”
Data changes arrive as signed webhooks — new transactions, balance updates, connection state changes — so my system stays current without pollingpartialproof ↗
“Lets users link at least one bank account via the Connect hosted flow”
Let a user connect their bank with a drop-in hosted flow — create a session server-side, open the widget, and get back a token for the connected account — without building institution UI myselfpartialproof ↗
Contradicted (1)
“Dynamically generates working code examples based on current API specs”
Explore an interactive API reference with runnable examplesnoneproof ↗
Undersold (13)
Point an agent at llms.txt or agent-oriented docsfullproof ↗
Run the product headlessly / in CI for automationpartialproof ↗
Drive the product through a documented public APIfullproof ↗
Operate the product with natural-language commandspartialproof ↗
Linked accounts plug into my payment processor — documented integrations or token exchange that hand verified account credentials to third-party processors and platformspartialproof ↗
An agent can operate the platform — create link sessions, retrieve balances and transactions, and manage connections through the API or an MCP surface with scoped credentialspartialproof ↗
I request only the data scopes I need — product-scoped consents and documented data-minimization controls, not an all-or-nothing grantpartialproof ↗
Go from signup to my first linked sandbox account fast — self-serve API keys, a runnable quickstart, and client libraries in my languagepartialproof ↗
Do everything through the API that I can do in the UIpartialproof ↗
Raw bank transactions come back enriched — cleaned merchant names, categories, and logos — documented as a capability of the platform, not left as an exercise for mepartialproof ↗
Claims outside our story set (3)
Real capability claims found in Mastercard Open Finance (Finicity)’s own materials, but no story in this arena’s taxonomy covers them yet — that’s feedback on the taxonomy, not a mark against the product.
“Predicts the likelihood of a payment succeeding before it's initiated”
source ↗“Switches direct deposits and recurring bill payments to a newly linked account”
source ↗“Offers APIs supporting credit decisioning reports”
source ↗
Business model
Sales-only: the Test Drive sandbox plan is free and unlimited on all endpoints, but production access is a 'Request Production access' upgrade with billing by invoice — no public numbers.
pricing ↗Score trend
How this product’s scores have moved as evidence and verdicts are re-derived — a point per change, not per day.
Try Experimental
Run it in the microterminal →Recorded agent sessions — and a live MCP handshake where the vendor ships one.
Flag
⚑ Flag a verdictThink a verdict is wrong? Opens a prefilled GitHub issue — or use the ⚑ next to any verdict above.
For agents