This is good to hear, but also rings a bit hollow given the industry's history with trying to keep data locked up. There are very simple things the industry could have done long ago to make their users more secure and they've done none of it. For instance, banks could have let users create read-only credentials to give to aggregators greatly reducing the potential for fraud. They could've created application-specific passwords, similar to what Google has done, that would allow more intelligent application of MFA and such...every time I log into Mint, I get a text message from Vanguard telling me that an unrecognized device is attempting to log in, requiring me to fix the account in Mint. Instead, they've basically adopted a "let's make it as difficult to scrape as possible" mentality which has contributed to the insecure and buggy situation we have today.
APIs are good, as are OAuth-style permissions requests where users get to at least know what data a service is asking for. But they shouldn't be used as a way to kill off screen scraping. They should be a better option that allows screen scraping to die off normally. The aggregation industry that scrapes hates it even more than the banks do. It costs them a ton of man power to keep it working and each integration needs to be done as a one-off. If the banks provide a better solution, it will get used. Better yet, if they can come up with a single standard API that will work with most/all banks, that would be even better. But if the banks also take measures to prevent scraping, it is going to cause problems and not be a good thing for account holders.