You write the equivalent info (user+pass+keycode) into a third party app.
Is it me, or does this read like a disaster in the making?
It’s better because going through the same process as the official banking apps means that you should end up using tokens etc rather than actually storing the original credentials.