My bank has an API so I built online banking
medium.com
medium.com
In order to disrupt the banking industry, you need a huge amount of capital to start and you are regulated in a way to prevent fast growth. These 2 things pretty much rule out the 'standard' way of doing startups.
I would love to see an opensource bank, open code all the way down to the core services that a bank depends on. It would help break up the stranglehold that just a handful of companies have on the market.
Too many things are just 'in the way'. The stagnation would probably need to start with regulatory support instead of using banking regulations to make it difficult for new business and ideas.
As a side project I decided to try and build banking infrastructure from the ground up, learning Go in the process [1], writing about the development along the way [2].
There is so much room for innovation in the traditional banking space, i.e. not using cryptocurrencies. Hopefully there will be innovation, especially when it comes to managing risk.
[1] https://github.com/ksred/bank [2] http://blog.ksred.me/tags/banking-infrastructure/
Tools have been written to extract data from simple's API, but those endpoints have mostly been discovered through unofficial channels, and Simple often changes them without issuing any kind of warning.
So far twitter has been the best route to find about their changing API endpoints, which speaks simultaneously to the disorganization of the API and the massively high quality of their support team.
Mondo have raised 2 million pounds and "are looking to raise around £15-20 million before its full launch" so not that much more than many startups. Not sure about regulation preventing fast growth. I guess it slows it a bit.
"In this year’s Budget the Chancellor committed to delivering an open API standard in UK banking, and setting out a detailed framework for its design by the end of 2015, in order to help drive more competition and innovation in banking for the benefit of consumers."
Once we're a bank, customer funds up to £75k per account will be insured via FSCS.
In the meantime, the customer balances held on our prepaid debit card sit ringfenced in customer-specific accounts. If we went bankrupt, the funds can't be touched by our creditors and will simply be returned to the customers.
Edit: spelling
I wrote a small Python script around ofxclient[0] which downloads daily statements from all of these accounts and then merges them into a GNU Ledger-formatted text file. I was inspired to do this when GNU Ledger was on the front page here about a month ago[1]. I keep the ledger itself version controlled using git. It's been working great -- the script not only downloads the statements but also identifies certain keywords in the payee name and attributes those against the matched expense account.
[0] https://pypi.python.org/pypi/ofxclient/ [1] https://news.ycombinator.com/item?id=10510394
Yeah, no thanks. I would not trust my money with a bank like that. A lot of fraud prevention is based on obscurity, and multiple steps of hurdles to make it easy to reverse a transaction. There's a reason money transfer takes a few days.
Source: I work in a tangential field
That said, money transfers take a couple of days because most interbank clearing houses were modelled after paper-based batch processes where people shuffle through paper a few times a day.
There are several real-time payment schemes in the world. Retail customers in the UK mostly use Faster Payments (FPS) for interbank transfers and they clear within a few seconds.
For instance, reddit provides it's public source code but has all of its anti fraud stuff wrapped into a separate repo that is not public. This provides a lot of flexibility that wouldn't be available if it were all public. And sure, some of it is of temporary value ("we are catching this cheating teqnique specifically, until they realise that it's not working anymore") but the fraud arms race is much easier for the atackee if it is slowed down a bit by such temporary measures
The reason a money transfer takes a few days is because ACH is based on SFTPing back and forth fixed-column ASCII text files.
In other countries there is not this delay.
The hackathon this app was a part of doesn't mention developer-friendly banks: https://getmondo.co.uk/blog/2015/11/22/mondohack/
I'm left to assume these are private APIs. I would love to play around with APIs similarly, but don't want to depend on privatized APIs.
You can find our API documentation here: https://getmondo.co.uk/docs
The APIs will be publicly available to developers and account holders. We've only just started rolling out our first cards, though, so we're not on boarding many third party developers at the moment.
If you'd like to play around with the API, send an email to developers@getmondo.co.uk and we'll see what we can do :)
Sending an email (although I'm based in US, if that matters).
Not that you have it good, but holy he'll did starting a not-bank end up being a can of worms in the US.
This is because online account opening for banks is a very hard problem, and anyone with a bank charter basically can't use the closed loop trick that other services are using to provide money movement and storage without a charter.
Once you are past account opening, it's more about tech politics. No major US bank has publicly pushed an Oauth gateway, for example. But this is more about risk and the politics of contracts with financial aggregators than anything else. You can find hints of these murky waters in the articles surrounding the recent dust up between Chase and Intuit.
Authentication was incredibly easy and they handled security questions very gracefully in my opinion. I was able to build a pretty good Simple Goals clone with a weekend's worth of work.
I haven't used their Plaid Auth product yet.
From their director of API banking, "With API banking we aim to deliver a set of services that allow our customers to interact with the bank securely, programmatically, at high speed and with little (or no) manual intervention." https://www.svb.com/Blogs/Dan_Kimerling/Our_Mission_for_API_...
http://blog.ycombinator.com/standard-treasury-yc-s13-joins-s...
EDIT: teller.io
He's had to do impossible things to make it
A clever way to avoid them handling any of your bank account details, they used a Java applet that stored your creds locally, interacting with their site so as to appear 'on the web'. Actually a great solution vs. giving your banking creds to a third party.
Encouraging that teller.io seems to be architected similarly. Would love to hear more.
- Making breaking changes to their APIs break all in-flight clients. This is poor UX for their regular customers if their first party app stops working every week.
- App store approval time is a choke point
- Internal change control is another choke point
- I can find what's changed and deploy a fix in no time.
From what I saw of the aggregation sites that pulled details from UK banks in the past, this was a major stumbling block...
You can also see some of the other projects are listed here https://getmondo.co.uk/blog/2015/11/22/mondohack/
https://github.com/OpenBankProject/OBP-API/wiki/Sandbox
We're currently introducing a Kafka layer which core banking connectors can interface with in any language. Else you can use Scala / Java code to connect to banking (or blockchain?) interfaces directly.
The core is AGPL plus commercial licenses for banks that don't want to abide by AGPL or get commercial support. SDKs etc are Apache licensed.
Regulation from EU (PSD2) and UK government Open Banking Working Group (OBWG) initiative is starting to move the API needle :-)
cheers, Simon (founder of OBP)
Their site says they are still applying, thus how can they be accepting people's money already?
The cards we're issuing now are prepaid debit cards backed by another firm's license (Wirecard Card Solutions Ltd).
We're aiming to have a full banking license and issue our own cards by the end of next year.
https://selflender.com/blog/why-fintech-innovation-is-broken...
Warm regards, James @ Self Lender
I'd be pretty interested in something like this also.
Edit: looks like they havn't launched. Will keep an eye out. Thanks for posting!
That said, using your account data in that way with third parties is often against the terms of service that a customer has with their bank.
It turns out that the bigger bank has dozens of smaller banks using the very same API, and its a trivial matter of switching a URL slug to make my makeshift API work for these other banks.
It was an interesting learning experience, but I did manage to get myself locked out of my own bank account a few times while replicating the login process.
.. And do you do everything you're told? ;)
I think we put far too much weight into magic documents like Privacy Policies and Terms of Service, etc.
We need to work through a bunch of KYC and AML issues around EU-wide signup, but it's definitely high on our priority list.
That said, our accounts will initially be GBP only, so we'd hold your balance in pound sterling.
If you sign up to our waiting list we'll reach out as soon as we know more :)
BTW @jamesallison The interface looks great. Good work!
I just hope my bank never does this.
1. Truncate user's password to 8 characters
2. Uppercase the entire thing
3. Convert to EBCDICThanks, man!
Now that would be fascinating.