IBANforge published a rubric for choosing an IBAN validation API that is unusually willing to narrow its own product. It opens by dismantling the industry’s default proof of correctness — “a fabricated IBAN can pass mod-97 all day” — and separates a checksum from verification against a national bank-code register, of which they claim authoritative coverage for five countries (CH, LI, DE, AT, BE, with Finland caveated) against 89 covered structurally. That is a vendor publishing the boundary between the thing that sounds impressive and the thing that is true. The same move runs through the compliance criterion, which insists screening here is bank-level and not account-level: “any vendor whose compliance page does not draw that line for you is leaving you to discover it on a false negative, which is the most expensive moment possible.”
Two of the six criteria are the ones worth stealing. The first is source transparency — naming which publisher supplied each block of data and when, with Deutsche Bundesbank, SIX, EBA, NBP and Swift/MIT listed rather than gestured at. The second is freshness stated per source rather than in aggregate, on the grounds that “‘updated regularly’ is not a specification.” Both are demands for machine-readable provenance, and both are the kind of thing a buyer cannot verify after signing. The remaining criteria are more conventional but concretely priced: a 200-request monthly free tier, per-call pricing quoted between $0.003 and $0.02 in USDC, and a machine-access criterion covering whether there is an MCP server at all, framed around the EPC Verification of Payee scheme taking effect on 20 September 2026.
The catalog reads IBANforge as eight API pages, and the rubric maps onto them one criterion at a time. Checksum-versus-register is the IBANforge IBAN API alongside the BIC API; the bank-level screening boundary is the Compliance API; the national-register claim for Switzerland is the Swiss Clearing API; the free tier and the USDC pricing are the Free API and Credits API; and the machine-access criterion is a page in its own right, the IBANforge MCP API.
IBANforge scores 31.7, thin on the Kin Score — discoverability at 85.2, and governance and contract governance both at 0.0. Agent Readiness is 37.8, agent-ready, which is the more interesting number, because it sits above what a thin band usually produces. mcp_server, well_known_catalog and agent_card are all lit, a combination almost no provider this size carries. They pass their own fifth criterion emphatically. The criterion they do not yet pass is their own second one: the provenance they demand a vendor publish — which register, from whom, as of when — is prose on their site rather than a machine-readable claim, and governance at 0.0 is what that looks like from the outside. rate_limit_signal is unlit under a stated 200-a-month tier, and agentic_commerce is unlit while they quote a per-call price in USDC. A company arguing that “updated regularly” is not a specification is three declarations away from proving it about itself.