Publicly accessible API then.
Best and easiest security to achieve and maintain is no public access at all (something like physically separated networks vs authenticated ones)
The alternative to open APIs is that third parties ask customers for online banking passwords. This practice is significantly less secure than, say, OAuth2 or similar and is generally against a bank's TOS, which makes the customer liable.