Skip to content

Rank #3 of 7 in Banking Data APIs

Mastercard Open Finance (Finicity) logo

Mastercard Open Finance (Finicity)

Enterprise

Mastercard (Finicity) · commercial

6213/yrnpm 11.7k/wk

Try itExperimental

See what an agent can do with Mastercard Open Finance (Finicity) before you ever sign up. Pick a story: recorded sessions replay real probe-harness transcripts; sandboxed self-drive sessions are designed and gated (docs/TRY-IT.md).

$curl -si https://api.finicity.com/aggregation/v1/customers | head -2 # Finicity-era API host under Mastercard, keyless → 401recorded session — replayed, not live
recorded 2026-09-15 · exit 0 · captured verbatim by our probe harness, secrets redacted

Verified integrations

No integration evidence found in our corpus for this product yet — that means none was found, never that it doesn’t integrate.

By theme — the product's score on each story themeBy theme

Account linking — stories about account linking in this arenaAccount linkingevidence →

Stories about account linking in this arena

7.7/100

Agenticness — how well agents can access and operate the productAgenticnessevidence →

How well agents can access and operate the product

37.4/100

Automation depth — how much of the product can run unattendedAutomation depthevidence →

How much of the product can run unattended

0.0/100

Balance ownership — stories about balance ownership in this arenaBalance ownershipevidence →

Stories about balance ownership in this arena

53.8/100

Banking agent access — stories about banking agent access in this arenaBanking agent accessevidence →

Stories about banking agent access in this arena

36.0/100

Consent security — stories about consent security in this arenaConsent securityevidence →

Stories about consent security in this arena

8.0/100

Data freshness — stories about data freshness in this arenaData freshnessevidence →

Stories about data freshness in this arena

18.0/100

Institution coverage — stories about institution coverage in this arenaInstitution coverageevidence →

Stories about institution coverage in this arena

0.0/100

Integration dx — sandboxes, test modes, webhooks, and how fast a developer gets to a working integrationIntegration dxevidence →

Sandboxes, test modes, webhooks, and how fast a developer gets to a working integration

24.0/100

Openness — open source, data portability, and self-hosting storiesOpennessevidence →

Open source, data portability, and self-hosting stories

10.3/100

Payment initiation — stories about payment initiation in this arenaPayment initiationevidence →

Stories about payment initiation in this arena

0.0/100

Privacy posture — data-handling and privacy storiesPrivacy postureevidence →

Data-handling and privacy stories

0.0/100

Transactions enrichment — stories about transactions enrichment in this arenaTransactions enrichmentevidence →

Stories about transactions enrichment in this arena

30.0/100

Story verdicts — every judged story with its evidenceStory verdicts

?

Sorted by importance (agentic first) (high → low) · 53/53 stories · click a row’s chevron for the rationale and evidence

Drive the product through a documented public API G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness3full8/10T

Connect an agent via an official MCP server G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness3full7/10T

Plug MCP servers into this product so it can use their tools G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness3n/a0/10

Delegate tasks to a built-in AI assistant inside the product G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness3n/auntestednone yet

Download a machine-readable API spec (OpenAPI or equivalent) G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness2full8/10T

Point an agent at llms.txt or agent-oriented docs G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2full8/10T

Subscribe to events via webhooks G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2full7/10C

Run the product headlessly / in CI for automation G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2partial6/10C

Operate the product with natural-language commands G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness2partial5/10T

Build against official SDKs G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2partial3/10C

Explore an interactive API reference with runnable examples G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Get AI-generated insights and suggestions from my data inside the product G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Issue scoped/least-privilege API credentials for an agent G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Set up automations that run autonomously in the background G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Rely on versioned APIs with a documented deprecation policy G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness2noneuntestednone yet

Use an official CLI G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2noneuntestednone yet

Test against a sandbox environment without touching production data G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness1full8/10C

Fetch a real-time balance for a connected account before initiating a payment — a documented balance endpoint intended for NSF and risk checks C

Balances

developerBalance ownership — stories about balance ownership in this arenaBalance ownership3full7/10C

A sandbox with test institutions and documented test credentials lets me exercise linking, data retrieval, and error states end-to-end before touching a real bank account C

Sandbox

developerIntegration dx — sandboxes, test modes, webhooks, and how fast a developer gets to a working integrationIntegration dx3partial6/10C

An agent can operate the platform — create link sessions, retrieve balances and transactions, and manage connections through the API or an MCP surface with scoped credentials C

Agent operations

ai-native userBanking agent access — stories about banking agent access in this arenaBanking agent access3partial6/10T

Obtain verified account and routing numbers (or tokenized equivalents) from a linked account to fund ACH or bank-debit payments without micro-deposits C

Ach details

developerBalance ownership — stories about balance ownership in this arenaBalance ownership3partial6/10C

Pull transaction history for a connected account through the API — paginated, with documented history depth and a sync pattern for fetching only what changed C

Transactions

developerTransactions enrichment — stories about transactions enrichment in this arenaTransactions enrichment3partial5/10C

Let a user connect their bank with a drop-in hosted flow — create a session server-side, open the widget, and get back a token for the connected account — without building institution UI myself C

Hosted flows

developerAccount linking — stories about account linking in this arenaAccount linking3partial3/10C

Define rules that trigger actions automatically on events G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth3none0/10

Export all of my data in open formats and leave G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness3noneuntestednone yet

Prevent my data from being used to train AI models G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture3noneuntestednone yet

Self-host the core product G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness3n/auntestednone yet

The platform documents how many institutions it reaches and where — published coverage numbers and geographies I can check against where my users actually bank C

Coverage

founderInstitution coverage — stories about institution coverage in this arenaInstitution coverage3noneuntestednone yet

Retrieve account-holder details — names, addresses, contact data on file at the bank — to match the account owner against my customer C

Ownership

ops leadBalance ownership — stories about balance ownership in this arenaBalance ownership2full8/10C

Data changes arrive as signed webhooks — new transactions, balance updates, connection state changes — so my system stays current without polling C

Webhooks

developerData freshness — stories about data freshness in this arenaData freshness2partial6/10C

Do everything through the API that I can do in the UI G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness2partial6/10C

The data comes back agent-consumable — clean structured JSON, documented schemas, and enrichment an automated financial workflow can reason over without heuristic parsing C

Agent data

ai-native userBanking agent access — stories about banking agent access in this arenaBanking agent access2partial6/10T

The platform derives income and cash-flow signals from connected accounts — recurring streams, payroll detection, or documented income verification products built on the same data C

Cashflow

finance leadTransactions enrichment — stories about transactions enrichment in this arenaTransactions enrichment2partial6/10C

Go from signup to my first linked sandbox account fast — self-serve API keys, a runnable quickstart, and client libraries in my language C

Quickstart

developerIntegration dx — sandboxes, test modes, webhooks, and how fast a developer gets to a working integrationIntegration dx2partial5/10C

Linked accounts plug into my payment processor — documented integrations or token exchange that hand verified account credentials to third-party processors and platforms C

Processor tokens

developerBalance ownership — stories about balance ownership in this arenaBalance ownership2partial5/10C

I request only the data scopes I need — product-scoped consents and documented data-minimization controls, not an all-or-nothing grant C

Scopes

developerConsent security — stories about consent security in this arenaConsent security2partial4/10C

Raw bank transactions come back enriched — cleaned merchant names, categories, and logos — documented as a capability of the platform, not left as an exercise for me C

Enrichment

developerTransactions enrichment — stories about transactions enrichment in this arenaTransactions enrichment2partial4/10C

Broken connections are repairable — expired or revoked links surface as documented statuses, and users can re-authenticate in an update flow without starting over C

Repair

ops leadAccount linking — stories about account linking in this arenaAccount linking2none0/10

Connections to major institutions use bank-hosted OAuth rather than screen-scraped credentials — the platform documents its OAuth coverage and how legacy credential flows are being retired C

Oauth

developerAccount linking — stories about account linking in this arenaAccount linking2none0/10

Initiate a bank payment from a connected account — a documented pay-by-bank or payment-initiation product with its live geographies stated honestly C

Pay by bank

developerPayment initiation — stories about payment initiation in this arenaPayment initiation2none0/10

Trigger an on-demand refresh of a connected account's data through the API when my use case needs now-fresh data, with the refresh semantics documented C

Refresh

developerData freshness — stories about data freshness in this arenaData freshness2none0/10

Choose where my data is stored (region/residency) G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture2noneuntestednone yet

Control data retention and deletion G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture2noneuntestednone yet

End users can see and revoke what they've shared — a documented consent surface or portal where a user manages which apps hold access to their bank data C

Consent

ops leadConsent security — stories about consent security in this arenaConsent security2noneuntestednone yet

One link session can power multiple data products — auth, balances, transactions, identity — without forcing the user through separate connection flows per product C

Multi product

developerIntegration dx — sandboxes, test modes, webhooks, and how fast a developer gets to a working integrationIntegration dx2noneuntestednone yet

Opt out of telemetry and usage tracking G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture2noneuntestednone yet

Per-institution health is visible — documented institution statuses, outage or degradation signals, and error codes that distinguish a bank problem from my problem C

Status

ops leadInstitution coverage — stories about institution coverage in this arenaInstitution coverage2noneuntestednone yet

Perform bulk operations across many items at once G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth2noneuntestednone yet

Read the product's source under an open license G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness2noneuntestednone yet

Recurring bank payments are supported — variable recurring payments, standing consents, or documented recurring debit flows built on the connection C

Recurring

developerPayment initiation — stories about payment initiation in this arenaPayment initiation2noneuntestednone yet

Schedule recurring jobs or workflows G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth2noneuntestednone yet

Sever and clean up — a documented way to delete a connection or user and have the platform stop collecting and purge held data C

Deletion

ops leadConsent security — stories about consent security in this arenaConsent security2noneuntestednone yet

Version, review, and roll back my automations G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth1n/auntestednone yet

Opportunities — the stories that would move this product's scores, from its own judged verdictsOpportunitiestop 8 of 41 stories with headroom

What would move Mastercard Open Finance (Finicity)’s scores — derived from its own judged verdicts, biggest headroom first. Each line quotes what the judge found missing; shipping it (or evidencing it publicly) is the fix.

  1. Automation depth — how much of the product can run unattendedDefine rules that trigger actions automatically on events

    nonemoves PA Scoreimpact 30

    Missing: rule-definition engine, conditional logic, automated action execution tied to events.

  2. Institution coverage — stories about institution coverage in this arenaThe platform documents how many institutions it reaches and where — published coverage numbers and geographies I can check against where my users actually bank

    nonemoves PA Scoreimpact 30

    The evidence pack covers API capabilities (verification, balances, transaction data, webhooks, onboarding) but contains no published institution-coverage numbers, geographic breakdowns, or bank-reach statistics that a founder could check against their users' banks.

  3. Openness — open source, data portability, and self-hosting storiesExport all of my data in open formats and leave

    nonemoves PA Scoreimpact 30

    This is a B2B financial data API platform, not a consumer product with user-owned data to export; the evidence shows no data export/portability feature for end users to take their data out in open formats and leave.

  4. Privacy posture — data-handling and privacy storiesPrevent my data from being used to train AI models

    nonemoves PA Scoreimpact 30

    No evidence anywhere in the pack addresses AI-training data opt-out or data usage controls; the documentation covers financial data APIs and MCP tooling but nothing about preventing use of user data for AI model training.

  5. Agenticness — how well agents can access and operate the productGet AI-generated insights and suggestions from my data inside the product

    nonemoves Built-in AIimpact 30

    The evidence shows Mastercard Open Finance exposes categorized financial data (transaction types, recurring transactions, spending, loan payments) via APIs, and a separate MCP agent toolkit for developers to generate code, but there is no evidence of AI-generated insights or suggestions surfaced to an end-user inside the product itself.

  6. Agenticness — how well agents can access and operate the productSet up automations that run autonomously in the background

    nonemoves Built-in AIimpact 30

    Missing: any documentation of scheduled/triggered automation setup, autonomous workflow orchestration, or agentic task execution running independently in the background.

  7. Agenticness — how well agents can access and operate the productUse an official CLI

    nonemoves agent-readyimpact 30

    Missing: any mention of an official CLI, its installation, or its use in agentic/AI workflows.

  8. Agenticness — how well agents can access and operate the productIssue scoped/least-privilege API credentials for an agent

    nonemoves agent-readyimpact 30

    Missing: any documentation of scoped/limited-permission API keys, per-agent credential issuance, or role-based access control for agent use.

Showing the top 8 of 41 — every none/partial verdict in the story verdicts table is headroom.

Think a verdict is wrong? Every verdicts-table row has a Flag link — see the methodology.

Coverage map — which docs area, API section, or community source covers which judged storiesCoverage map4 surfaces · 24 covered stories

Where the cited evidence behind each covered verdict came from — the same citations the verdicts table shows, no extra judging.

Open finance us docs19 stories

Probe proofs — replayable recordings from the probe harnessProbe proofs

Replayable recordings from our probe harness — see the Prove-It protocol to submit one.

$curl -si https://api.finicity.com/aggregation/v1/customers | head -2 # Finicity-era API host under Mastercard, keyless → 401reproduced
$ curl -si https://api.finicity.com/aggregation/v1/customers | head -2  # Finicity-era API host under Mastercard, [redacted]less → 401
HTTP/2 401

date: Tue, 15 Sep 2026 20:26:05 GMT
$curl -sL https://developer.mastercard.com/llms.txt | head -2reproduced
$ curl -sL https://developer.mastercard.com/llms.txt | head -2
# Mastercard Developers
Mastercard Developers is a comprehensive API platform that provides issuers, acquirers, financial services companies, fintech, and developers with access to Mastercard products and services. The platform offers APIs for payments, fraud prevention, identity verification, open finance, loyalty management, digital commerce, and more. Developers can integrate these APIs to build modern financial experiences while leveraging Mastercard's security infrastructure and global reach.

Claims vs evidence — vendor claims reconciled against independent verdictsClaims vs evidence

2 of 12 testable claims verified · 1 contradictedintegrity 0/100

18 distinct capability claims found in Mastercard Open Finance (Finicity)’s own claimed-docs/GitHub materials, reconciled against our judge’s independent verdicts.

2

Verified

9

Unverified

1

Contradicted

13

Undersold

Verified (2)
Unverified (12)
Contradicted (1)
Undersold (13)
Claims outside our story set (3)

Real capability claims found in Mastercard Open Finance (Finicity)’s own materials, but no story in this arena’s taxonomy covers them yet — that’s feedback on the taxonomy, not a mark against the product.

  • Predicts the likelihood of a payment succeeding before it's initiated

    source ↗
  • Switches direct deposits and recurring bill payments to a newly linked account

    source ↗
  • Offers APIs supporting credit decisioning reports

    source ↗
Suggest a story for these →

Business model

enterprise-custom

Sales-only: the Test Drive sandbox plan is free and unlimited on all endpoints, but production access is a 'Request Production access' upgrade with billing by invoice — no public numbers.

pricing ↗

Score trend

How this product’s scores have moved as evidence and verdicts are re-derived — a point per change, not per day.

PA Scoretracked since Sep 15 '26 — no movement recorded yet
Agent-readytracked since Sep 15 '26 — no movement recorded yet

Try Experimental

Run it in the microterminal →

Recorded agent sessions — and a live MCP handshake where the vendor ships one.

Flag

⚑ Flag a verdict

Think a verdict is wrong? Opens a prefilled GitHub issue — or use the ⚑ next to any verdict above.

Badge

Embed this product's score badge →

Hotlinked SVG — always shows the live current score.

For agents

Data