The Platform API connects your app or website to financial institutions so you can aggregate, verify, and enhance your users’ financial data.
The API follows REST conventions. It uses predictable, resource-oriented URLs, returns JSON, and uses standard HTTP status codes to indicate whether a request succeeded.
Environments
MX provides two environments, each with its own base URL:
Examples in this reference use the integration environment.
The integration environment runs the same code and provides the same features as production, so you can build and test your integration. It doesn’t match production’s performance or the number and quality of its institution connections. It provides only the connections needed for testing, and some features, such as OAuth, can be tested only with MX-provided test institutions. For limits on users and members, see Rate Limits.
Make a request
Every request needs your credentials in an Authorization header and an API version in the Accept-Version header:
For details, see Authentication & Security, API Versioning, and Requests & Responses.
Core resources
For the core resources and how they relate to each other, see MX Data Architecture.
Deleting objects
When you delete an object on MX, associated child objects are also removed automatically:
- Deleting a member removes all linked accounts, transactions, and holdings.
- Deleting a user removes all connected members (and their accounts, transactions, and holdings).
Deleting a user is permanent. Deleted users can never be restored.
MX uses a two-phase deletion process. Deleted objects first enter a soft-deleted state, then are permanently purged approximately two weeks later. Soft-deleted items cannot be restored through the API, though MX may manually restore soft-deleted members in limited circumstances before permanent purging occurs.
If a new member is created for the same user and institution with identical credentials, any soft-deleted member will be immediately purged and a fresh record created.
For OAuth members specifically:
- Members in a
PENDING state are immediately purged upon deletion by MX and cannot be recovered.
- Members in other states are soft-deleted and potentially recoverable through MX support before permanent purging.
Once fully purged, all data is permanently lost and cannot be retrieved.
OAuth institutions
Some institutions support OAuth, some don’t, and some support only OAuth. To connect to OAuth institutions, MX must register you with them. MX handles registration for you after you have production access. On the Client Dashboard, request production access and apply for OAuth registration.
OAuth institutions you aren’t registered with don’t appear in any institution endpoint responses.
The integration environment includes two OAuth test institutions. For more about OAuth, see the OAuth guide. For testing, see Testing the Platform API.