ApyHub
ApyHub is a Dutch API marketplace that bundles more than 1,500 certified HTTP endpoints — OCR, file conversion, data validation, geocoding, LLM calls — behind a single key and subscription, metered in a usage unit the platform calls atoms.
What is ApyHub?
ApyHub is an API marketplace built on an unusual premise: you subscribe to the catalog, not to individual APIs. One apy-token opens more than 1,500 endpoints spread across 400-plus services, and the allowance you buy is spendable anywhere in that catalog rather than locked to the one API you bought it for. The company frames this against the incumbents it names on its own about page, RapidAPI and APILayer, where a per-API subscription means capacity idles on one endpoint while another hits its ceiling.
Usage is metered in atoms, a deliberately small unit. A cached lookup might cost one atom, a frontier-model generation up to 250, and the publisher sets the figure at the moment it answers the call. The stated aim is that a 200-byte request and a 12 MB OCR job should not cost the same, which request counting cannot express.
The catalog itself is broad and uneven. The largest sections are Artificial Intelligence (89 APIs), Developer Tools and File Conversion (52 each), Data Extraction and Geolocation (38 each) and Data Validation (31), alongside smaller sets for audio, SEO, HR, finance, security and image work. Much of it is genuinely utilitarian — currency dictionaries, JWT decoders, QR generators — and a sizable share of the geolocation coverage is United States only.
The second pitch is trust rather than breadth. Every service is reviewed before it ships and carries machine-readable certification stating where data lives, how long it is kept, which third parties touch it and which standards it claims to meet. ApyHub argues this collapses vendor auditing into one contract, and leans on recent npm supply-chain compromises to make the case.
Every endpoint is also MCP-ready: a streamable MCP server lets Claude, Cursor or any agent runtime discover and call the catalog directly. On the supply side, publishing is self-service and AI-assisted, taking roughly ten minutes, with the author keeping full IP, setting the atom price and owing no exclusivity. ApyHub B.V. operates from the Netherlands and claims 65,000-plus developer workspaces a month.
What it does
- Call more than 1,500 certified HTTP APIs with one apy-token, across 400+ services in a single catalog
- Convert documents, images, audio and archives: PDF, Word, Excel, PowerPoint, WebP, MP3 and dozens more formats
- Extract text and structured data from PDFs, HTML pages, invoices and résumés, including OCR on scanned images
- Validate regulatory and financial data: EU VAT numbers, IBAN, BIN, US routing numbers, IFSC codes, postcodes
- Run language-model calls, from chat completions with tools and structured output to summarization, sentiment and entity extraction
- Process images at scale: upscale, restore, deblur, remove backgrounds, watermark, blur faces, crop and resize
- Expose the whole subscribed catalog to an AI agent as MCP tools, with no wrapper code to write
When to use ApyHub / When not to
A quick filter to help you decide if ApyHub is the right fit.
When to use ApyHub
- Back-end and full-stack developers who would rather call a hardened endpoint than maintain another utility library
- Product teams assembling features quickly — document conversion, OCR, address validation, geocoding — without a separate vendor per capability
- Builders of AI agents: every endpoint is MCP-ready, so Claude, Cursor or any agent runtime can call it without a wrapper
- Startup founders and CTOs validating an idea on the permanent free tier, 150 calls a month with no payment card
- API authors who want to monetize an endpoint: self-service publishing in about ten minutes, full IP retained, no exclusivity
When not to use ApyHub
- Non-developers: there is no no-code interface, every capability is reached through an HTTP call and an apy-token header
- Teams that need a signed customer DPA or a downloadable SOC 2 report, since the site publishes neither
- Organizations requiring data residency outside the EU on a self-serve plan, as US residency is an Enterprise-only option
- Mobile-first users: ApyHub ships no iOS or Android application and no browser extension
- Resellers, because the terms explicitly forbid re-exposing an ApyHub endpoint verbatim as your own product
How to use ApyHub
A typical end-to-end flow, from setup to results.
- Create a free account, with no payment card, or sign in through Google, GitHub or Microsoft
- Browse the catalog, filtering by category or by GDPR, SOC 2 and HIPAA tags, and sorting by popularity, newness or name
- Open a service page to read its description, version, endpoint count, publisher and the atom cost of a call
- Test the endpoint straight from the browser with the Try It Live block, which prefills your default key
- Mint an apy-token in one click; the same key authenticates every API in the catalog
- Copy the ready-made snippet in cURL, Node, Python, Go or Java, or generate a typed client locally
- Pass the key in the apy-token header of your HTTP request and read the JSON response
- For agent work, point your runtime at the MCP server and let Claude or Cursor discover the tools; MCP is enabled from Pro+ upward
- Track atom consumption in the dashboard, where history runs 7 days on the free tier and 30 to 90 days on paid plans
- Prepurchase atoms or move up a tier as the quota approaches; once it is exhausted traffic stops rather than overbilling you
Pros & Cons
Pros
- One contract, one key and one invoice for 1,500+ APIs, which collapses the vendor auditing surface
- Pooled allowance: atoms bought against one API are spendable on any other, unlike per-API marketplace plans
- Prices are public and low at the entry point, USD 16 a month, with no sales call and no minimum commitment
- A permanent free tier with no payment card gives full catalog access from day one
- EU hosting by default in Frankfurt with Dublin backups, five named subprocessors and 30 days' notice before changes
- An explicit commitment not to train models on customer data and not to sell it
- Traffic stops when the quota runs out, so there is no surprise overage bill
Cons
- The pricing page renders in JavaScript and shows no amounts without a browser; the figures come from the public plans endpoint that feeds it
- Atoms do not translate cleanly into calls — a request costs 1 to 250 atoms depending on the endpoint — which makes cost forecasting hard
- SOC 2 and ISO 27001 are claimed on the homepage and per endpoint as alignment, with no trust page, report or certificate published
- No customer-facing DPA is offered; the only agreements mentioned are those ApyHub signs with its own subprocessors
- No Enterprise plan appears in the public grid, so US data residency and custom terms require a quote
- Support leads with a Discord community, with email presented as the secondary route and no published response SLA
- Catalog quality is uneven: several sections hold only two APIs, many are thin utilities, and much of the geolocation coverage is US-only
Pricing & Plans
A permanent free plan is available. Starter costs nothing and requires no payment card, providing 1,000 atoms a month capped at five calls a day, which is the 150 monthly calls advertised on the homepage. The cheapest paid tier is Pro at USD 16 per month (EUR 15), raising the allowance to 100,000 atoms. Taxes are added where required, and no time-limited free trial is offered.
- 1
- 000 atoms
- 5 requests per second
- 5 calls per day
- 50 MB per file
- 50 MB storage
- 1 API key
- 1 user
- 100
- 000 atoms
- 5 requests per second
- 100 MB per file
- 5 GB storage
- 10 API keys
- 5 users
- 30-day history
- 500
- 000 atoms
- 10 requests per second
- 300 MB per file
- 10 GB storage
- 10 API keys
- 5 users
- 90-day history
- 2
- 000
- 000 atoms
- 15 requests per second
- 10 users
- 20 API keys
- MCP enabled
- 6
- 000
- 000 atoms
- 50 requests per second
- 20 users
- 40 API keys
- MCP enabled
- Starter
- Pro and Pro+ are presented as the Medium Traffic range
- Team and Scale as Heavy Traffic
- referenced in the terms and privacy policy through a signed order form
- invoice billing and an optional US data-residency region
- Prepurchased atoms are added to the monthly quota
- once the quota is exhausted traffic stops and no further billing occurs
- Self-serve plans renew until cancelled
- with cancellation effective at period end
- no minimum commitment
- and no refund of unused credits on downgrade
Data, GDPR & hosting
A consolidated view of how ApyHub handles your data.
GDPR overview
GDPR implementation is unusually concrete. The privacy policy, version 3.2 effective 18 April 2026, enumerates all seven data-subject rights and wires each into the product: a JSON export for access, profile settings for rectification, a danger zone for erasure, notification settings for objection. The lead supervisory authority for EU users is named, the Dutch Autoriteit Persoonsgegevens, a Data Protection Officer answers at dpo@apyhub.com, and replies are promised within two business days. Five subprocessors are listed by name and region, each under a signed Data Processing Agreement, with 30 days' notice before any change. Analytics cookies are gated behind consent. No Article 27 representative is designated, and none is required: the controller is established in the Netherlands. The homepage badge reads SOC 2 and GDPR, but no trust page or certificate is published.
Who owns the data?
Section 04 of the terms casts ApyHub as a conduit that takes no copyright in what passes through it. Request bodies are forwarded to the underlying API provider, and ApyHub keeps only the metadata needed to bill the call. Response bodies belong to the customer, but under the license of the specific API invoked: some grant full ownership, others license the output for narrow uses only, and each license is surfaced on the catalog page before use. Authors who publish an API keep ownership of it and take 85% of the revenue it earns. Account, workspace, usage and payment data sit with five named subprocessors, and ApyHub states it never sells any of it.
Reuse rights
Whether an output can be reused depends on the license attached to the endpoint that produced it, not on a single marketplace rule, so the answer changes from one API to the next and the terms point customers to the catalog page before they build on a result. Building products on top of ApyHub is expressly permitted; reselling raw API access, or re-exposing an endpoint verbatim as your own product, is not. Section 03 also rules out illegal content, denial-of-service traffic, scraping behind authentication, credential stuffing, malware, spam, phishing and infringing material. Enforcement suspends first and investigates second, with a reversal and a credit if ApyHub got it wrong. Usage data serves billing and debugging only, and marketing email is opt-in with the default off.
Data retention & training
Hosting summary
Primary data is stored on AWS in eu-central-1 (Frankfurt, Germany), with backups replicated to eu-west-1 (Dublin, Ireland) on a rolling 30-day window. Edge caching runs globally through Cloudflare, where cached data lives for seconds to minutes and, ApyHub states, never contains personal information. Signing up from the United States does not change the location: data is stored in the EU by default, and US residency is offered only as an Enterprise option, the stated reason being that GDPR protects everyone regardless of where they signed up. Five subprocessors are named with their regions: AWS in the EU, Cloudflare globally, Stripe across the US and EU, Postmark in the US and a self-hosted Sentry in the EU. Card details never reach ApyHub's servers, as Stripe holds them and ApyHub sees only a customer ID and the last four digits. The domain resolves to a Cloudflare anycast node geolocated in the United States, which is a CDN point of presence and not a storage location. Data is disclosed on legally binding request, with prior notice to the customer unless prohibited.
Things to keep in mind
Risks and trade-offs to weigh before adopting ApyHub.
- Single-intermediary dependency: one gateway outage touches every API at once, and the uptime target explicitly excludes the upstream APIs themselves
- The publisher sets the atom cost when it answers and may raise it without renegotiation, so cost per call can climb after you integrate
- Traffic halts the moment the quota is exhausted, which can take a production service down through nothing worse than a busy week
- Certification is asserted without a verifiable document, so trust rests on the vendor's own statement rather than an audit you can read
- Request bodies are forwarded to a third-party provider, so sending personal or confidential data means first reading that specific API's license
- Output ownership varies by API; assuming one uniform rule across the catalog is a genuine legal risk
- The habit of never writing a utility function again erodes in-house skill and makes an exit expensive if a provider disappears or reprices
Setup & Integrations
Technical difficulty
Low for anyone comfortable with HTTP. Account creation needs no payment card and accepts Google, GitHub or Microsoft sign-in; a single apy-token then goes in a request header, with no OAuth flow and no request signing. Endpoints can be tested in the browser before writing code, and snippets ship in cURL, Node, Python, Go and Java, with a first call advertised inside 60 seconds. The real prerequisite is issuing an HTTP request and reading JSON, since there is no no-code interface. The harder task is not technical: estimating how many atoms a workload will consume.
Deployment
Integrations
Supported languages
Behind ApyHub
Social
Resources
All the official URLs gathered for verification and reference.
Alternatives
Tools that compete with or complement ApyHub.
Frequently asked questions
What is an atom on ApyHub?
Is there a free plan, and does it need a card?
How much does the cheapest paid plan cost?
Do I need a separate key for each API?
Can an AI agent call ApyHub endpoints?
Where is my data stored?
Is my data used to train AI models?
What happens if I exhaust my monthly quota?
What uptime is committed, and is there a minimum age?
How do I get support, and can I publish my own API?
Should you pick ApyHub?
ApyHub answers a real and specific complaint: that buying APIs one subscription at a time leaves teams paying for headroom on one endpoint while rationing another. Subscribing to the catalog instead, with a pooled allowance and a billing unit scaled to the work each call actually does, is a coherent fix rather than a repackaging, and the entry price is low enough that testing the claim costs almost nothing.
The governance is stronger than the category average. EU hosting by default, five subprocessors named with their regions, 30 days' notice before any change, retention periods stated category by category, a reachable Data Protection Officer and an explicit refusal to train on customer data are all published rather than implied. Traffic stopping at the quota, instead of generating an overage invoice, is a genuinely customer-favouring default.
Two gaps deserve attention before anyone commits production traffic. SOC 2 and ISO 27001 appear as a homepage badge and as per-endpoint alignment, with no trust page, audit report or certificate to inspect — and alignment is not certification. There is likewise no customer-facing DPA, which will stall any procurement review that requires one. The pricing page also depends on JavaScript to show its own figures, which is an odd weak point for a product that sells reliability.
The catalog is broad but uneven: alongside solid OCR, conversion and validation work sit thin utilities, two-entry sections and geolocation coverage largely confined to the United States. Atoms bring fairness at the cost of predictability, since a call can range from 1 to 250 of them. This is a developer product, and without HTTP integration skills there is nothing here to use. For teams that fit, it is a credible way to stop maintaining the boring middle of their own stack.
- Choosing a selection results in a full page refresh.
- Opens in a new window.