# Cora

**Canonical:** https://apis.io/providers/cora/  
**Website:** https://www.cora.com.br/  
**APIs profiled:** 1

Cora is a Brazilian digital bank (conta PJ) for small and medium businesses, offering fee-free business checking, Pix, boletos, transfers, payment initiation and financial management. Its developer platform exposes REST APIs for registered boleto and carnê issuance, Pix QR code generation, account data, balance and statement queries, payment and transfer initiation (including DARF and GPS tax payments), webhook notifications, and municipal service invoice (NFS-e) issuance. Cora offers two integration modalities — Direct Integration (mutual-TLS certificate plus OAuth2 client-credentials) and Cora Partnership — with a Stage sandbox for testing. Backed by QED Investors and Ribbit Capital.

## Kin Score — 35.3 / 100 (thin)

Scored 2026-08-30 under rubric 0.17.2. Trend: flat (+0.0 from 35.3).

| Facet | Score |
|---|---|
| Discoverability | 75.9 |
| Contract Quality | 42.7 |
| Governance | 18.2 |
| Contract Governance | 18.2 |
| Operational Transparency | 15.8 |
| Developer Ergonomics | 40.5 |
| Commercial Clarity | 21.1 |
| Access Clarity | 21.1 |

Regulatory layer — **Banking & Open Finance**: 34.2 (matched via tags).

## Agent readiness — 23.0 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | no |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | bearer |
| Idempotency | documented |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | no |
| Event Surface Described | yes |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |
| Delegated Identity | no |
| Protected Resource Metadata | no |
| Dynamic Client Registration | no |
| Agentic Commerce | no |

## Access

Self-serve signup — onboarding: self-serve, pricing: unknown, trial: no (confidence: medium).

## APIs (1)

- **Cora API** — Cora's transactional banking API for Direct Integration: registered boleto and carnê (installment) issuance, Pix QR codes, account data, balance and statement queries, payment a...

## Security (2)

- **Cora Authentication** — oauth2/mutualTLS · 2 schemes
- **Cora Domain Security** — TLSv1.3 · HSTS · DNSSEC · DMARC

## Tags

Company, Banking, Brazil, Payments, Pix, Boleto, Invoicing, SMB, Fintech, Banking-as-a-Service

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/cora/). Scores are computed from the provider's own public artifacts under a published rubric.
