# Ocrolus

**Canonical:** https://apis.io/providers/ocrolus/  
**Website:** https://ocrolus.com  
**APIs profiled:** 16

Ocrolus is a fintech document-automation and analytics platform that helps lenders analyze financial documents - bank statements, pay stubs, tax forms and more - with high accuracy. Its API covers Classify, Capture, Detect and Analyze: document classification and data extraction, fraud and authenticity detection, cash-flow analytics, income calculation for mortgage and SMB/consumer lending, business verification, tag management and webhooks. Authentication is OAuth 2.0 client credentials issuing JWT access tokens, over a REST API at api.ocrolus.com.

## Kin Score — 58.7 / 100 (strong)

Scored 2026-08-17 under rubric 0.11.0. Trend: flat (+0.0 from 58.7).

| Facet | Score |
|---|---|
| Discoverability | 81.5 |
| Contract Quality | 67.2 |
| Governance | 20.8 |
| Operational Transparency | 76.3 |
| Developer Ergonomics | 60.3 |
| Commercial Clarity | 50.0 |

Regulatory layer — **Insurance**: 54.5 (matched via tags).

## Agent readiness — 53.4 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| MCP Server | derived |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | verified |
| OpenAPI Examples | verified |
| Rate Limit Signal | documented |
| Event Surface Described | yes |
| Agent Skills | derived |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Self-serve signup — onboarding: self-serve, pricing: unknown, trial: no (confidence: medium).

## APIs (16)

- **Ocrolus Book Commands API** — The Book Commands API from Ocrolus — 3 operation(s) for book commands.
- **Ocrolus Book Queries API** — The Book Queries API from Ocrolus — 5 operation(s) for book queries.
- **Ocrolus Business history API** — The Business history API from Ocrolus — 4 operation(s) for business history.
- **Ocrolus Business Verification (Deprecated) API** — The Business Verification (Deprecated) API from Ocrolus — 3 operation(s) for business verification (deprecated).
- **Ocrolus Capture API** — The Capture API from Ocrolus — 7 operation(s) for capture.
- **Ocrolus Cash Flow Analytics API** — The Cash Flow Analytics API from Ocrolus — 10 operation(s) for cash flow analytics.
- **Ocrolus Detect API** — The Detect API from Ocrolus — 4 operation(s) for detect.
- **Ocrolus Encore API** — The Encore API from Ocrolus — 5 operation(s) for encore.
- **Ocrolus File Uploads API** — The File Uploads API from Ocrolus — 7 operation(s) for file uploads.
- **Ocrolus Income API** — The Income API from Ocrolus — 5 operation(s) for income.
- **Ocrolus Legacy Cash Flow Analytics (Deprecated) API** — The Legacy Cash Flow Analytics (Deprecated) API from Ocrolus — 4 operation(s) for legacy cash flow analytics (deprecated).
- **Ocrolus Oauth API** — The Oauth API from Ocrolus — 1 operation(s) for oauth.
- **Ocrolus Org Level Webhooks API** — The Org Level Webhooks API from Ocrolus — 8 operation(s) for org level webhooks.
- **Ocrolus Tag Management API** — The Tag Management API from Ocrolus — 4 operation(s) for tag management.
- **Ocrolus User management API** — The User management API from Ocrolus — 2 operation(s) for user management.
- **Ocrolus Webhooks API** — The Webhooks API from Ocrolus — 4 operation(s) for webhooks.

## MCP servers (1)

- **ocrolus-mcp.yml**

## Agentic access (1)

- **Ocrolus Agentic Access** — 82 operations · 34 acting · 1 human-in-the-loop

## Security (4)

- **Ocrolus Authentication** — oauth2 · 1 scheme
- **Ocrolus Domain Security** — TLSv1.3 · HSTS · DMARC
- **Ocrolus Vulnerability Disclosure** — contact published
- **Ocrolus Trust Center** — SOC 2, ISO 27001, PCI DSS, GDPR, CSA STAR

## Tags

Company, Fintech, Document Automation, Lending, Underwriting, OCR, Fraud Detection, Income Verification, Bank Statement Analysis, Mortgage, Machine Learning, Cash Flow Analytics

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/ocrolus/). Scores are computed from the provider's own public artifacts under a published rubric.
