APIs.io rates a catalog it is listed in

This page exists so the conflict is stated rather than discovered. It is written to be quotable against us; anything softer would read as legal cover, and the only value a document like this has is that a hostile reader finds nothing in it they could not have found themselves.

The two roles

As a Provider, APIs.io publishes APIs, holds a profile in its own catalog, and carries a Kin Score computed by the same rubric applied to everyone else.

As the Directory, APIs.io holds the register of participants, issues the attestations consumers present to providers, and decides who is enrolled and who is removed.

UK Open Banking held these apart deliberately — OBIE is not a bank. We have chosen differently. The conflict is real, and it is accepted rather than resolved. Those are different words and only the second one would be a claim we could not support.

What the conflict is, specifically

Three places the roles pull against each other, named plainly, because a conflict nobody has enumerated cannot be checked.

  1. Rating a competitor. The Kin Score ranks providers and APIs.io is ranked among them. A scoring decision that advantaged our own record would be invisible to anyone who could not reproduce the score.
  2. Gating enrolment. The Directory decides who is enrolled and who is revoked. Those decisions could be used commercially — to exclude, to pressure, or to advantage a partner.
  3. Attestation as leverage. A consumer’s ability to reach providers depends on facts we publish about it. Withholding or delaying one is a commercial instrument if nobody is watching.

What actually constrains it

Four things, and they are narrower than the four this page used to list. In August 2026 we decided this framework is a product, not a standard — and that decision removed constraints as well as obligations. Listing constraints we no longer have would be worse than having fewer.

What we do not claim

What would resolve it

Nothing that is currently scheduled, and that is the honest answer.

The earlier answer was a second directory: the specification would live in API Commons, this instance would be one implementation, and once providers verified against both the conflict would stop being structural and become a choice participants make. The product decision dropped the requirement that anyone else could implement the Directory, so that route is not being built toward.

What replaces it is weaker as governance and more useful day to day: the rubric is public, every score is recomputable, and correcting an error we made is free. A provider who disagrees can recompute rather than appeal.

If that is not enough for your purposes, it should not be — and the right response is to weight our numbers accordingly rather than to take this page’s word for anything.


Part of the trust layer. The vocabulary behind it is on the seven roles.