Need help with your APIs? I offer API discovery, governance & evangelism services. Explore services →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Ordo

Ordo (operated by The Smart Request Company Ltd, ordohq.com / ordopay.com) is a United Kingdom open-banking payments provider that lets businesses collect money directly from a customer's bank account over the UK Faster Payments rails, avoiding card fees and chargebacks. Built on PSD2 / Open Banking payment initiation, its fully hosted, white-labelled platform delivers Request to Pay, one-off payment requests, e-commerce, Point of Sale / QR code and contact centre payments, plus Variable Recurring Payments (VRP) for fixed, variable and sweeping collections, and account information (AIS) and account verification services. Ordo is FCA-authorised and an Open Banking regulated provider, with a developer surface historically published as a ReadMe.io portal at docs.myordo.com backed by an Azure API Management gateway (test.api.ordopay.com). Ordo has since ceased trading and been acquired by Neonomics; the marketing site at ordopay.com remains live while the developer portal is now offline. Its API posture is documented here honestly from six OpenAPI 3.0.1 definitions harvested verbatim from the archived developer portal.

agent native

Limited machine-readable signal and partial portal coverage — documentation a human can read, but little a machine or agent can consume without scraping.

Kin Score

API Evangelist profiles Ordo the way a machine reads it — 10 machine-readable artifacts across 6 APIs, pulled from the provider's own public surface and indexed so a developer, an analyst, or an AI agent can evaluate it against every other provider on the network.

Every provider in the network is reduced to the same set of machine-readable artifacts — OpenAPI contracts, event specifications, GraphQL schemas, runnable collections, pricing and rate-limit signals, security posture, OAuth scopes, and the agent surfaces (MCP servers and skills) that let software drive the API on its own. We profile them because the interface is the part of a company you can actually inspect: it is a truer signal of what a provider does than any marketing page. From those artifacts we compute the Kin Score — Ordo scores 41.6/100 (thin), with a separate agent-readiness read of 65/100 (agent native). The full breakdown is below, followed by every artifact we hold — each card links through to its machine-readable definition on apis.io.

Kin Score

This is the API Evangelist rating — a single, repeatable read computed from the artifacts on this page. Green fill is points earned; the red track is points possible, so every bar shows earned-versus-possible at a glance.

Kin Score Kin Score How this is scored →
scored 2026-07-27 · rubric v0.5
Composite quality — 41.6/100 · thin
Contract Quality 13.2 / 25
Developer Ergonomics 11.3 / 20
Commercial Clarity 4.2 / 20
Operational Transparency 0.7 / 13
Governance 0.0 / 12
Discoverability 10.0 / 10
Regulatory · Banking & Open Finance 8.1 / 15
Agent readiness — 65/100 · agent native
Machine-Readable Contract 18 / 18
Agentic Access Contract 15 / 15
MCP Server 12 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 8 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 0 / 7
Typed Event Surface 0 / 6
Agent Skills 5 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3

How we profile Ordo

Each block below is one kind of artifact we hold for Ordo. For each we say what it is and why it earns a place in the profile, then list every one we've indexed — capped at two rows, scroll within the panel for the rest.

APIs 6

Each API is captured as its own OpenAPI definition — every operation, parameter, and response. This is the single most useful machine-readable description of what an API does, and it's what lets us score, lint, mock, and generate against it without asking the provider for anything.

Individual APIs this provider publishes, each with its own machine-readable definition.

Ordo Single Payments API

Single, one-off open-banking payment initiation — list supported institutions, create a payment, initiate authorisation, and withdraw a payment. Server base is the Ordo Azure AP...

Ordo Smart Request Manager API

Request to Pay / "Smart Request" management for one-off payment requests — create and manage smart requests and their messages, Biller Delivery Request (BDR) links, extensions a...

Ordo Recurring Payment Mandates (VRP) API

Variable Recurring Payments — create sweeping and non-sweeping VRP mandates, read mandates, execute mandate payments and read VRP transactions. Enables fixed, variable and ad-ho...

Ordo Account Data (Ordo Hosted) API

Ordo-hosted Account Information (AIS) and Account Verification — create and manage account information consents, request and read account data, cancel consents, and run account ...

Ordo Account Data (Client Hosted) API

Client-hosted Account Information (AIS) and Account Verification — the same consent, data-request and verification lifecycle as the Ordo-hosted variant, but with the integrating...

Ordo Registry Manager API

Bank account configuration / registry management — create, read and manage the biller bank accounts into which collected payments settle. 3 documented operations.

MCP Servers 1

Model Context Protocol servers expose these APIs directly to AI agents. We profile them because agent-native access is the fastest-growing way this provider's capabilities actually get used.

Model Context Protocol servers that expose these APIs to AI agents.

ordo-mcp.yml

MCP SERVER

Security Posture 2

Authentication, domain security, vulnerability disclosure, and trust-center signals — the evidence that a provider takes security seriously enough to document it. We profile it because you can't govern what you can't see.

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Ordo Authentication

apiKey · 2 schemes

SECURITY

Ordo Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Agentic Access 1

An x-agentic-access contract marks which operations are safe for an agent to run on its own and which need a human in the loop. It is the difference between an API an agent can use and one it can use safely.

Recommended x-agentic-access execution contracts for AI agents.

Ordo Agentic Access

54 operations · 25 acting

54 operations · 25 acting

AGENTIC

Resources

Every other property we hold for Ordo — documentation, portals, status pages, policies, and corporate surface — grouped by the job it does, following the integrator's arc from getting started to running in production.

Get Started 2

Portal, sign-up, and the first successful call

Documentation 1

Reference material describing how the API behaves

Agent Surfaces 4

MCP servers, agent skills, and machine-readable catalogs

Build 1

SDKs, sample code, and the tooling you integrate with

Access & Security 2

Authentication, authorization, and security posture

Operate 1

Status, limits, changes, and where to get help

Commercial 2

Pricing, plans, and the legal terms of use

Company 2

The organization behind the API

← All providers · Data indexed from github.com/api-evangelist/ordo · machine-readable index on apis.io