Would make an interesting experiment to create a website that would 'promise' cash-money based on whatever in exchange of user connecting their email and other accounts. This hoax could then siphon the passwords and accounts directly to Troy Hunt [0] and warn user like SECs fake ICO site[1] does. ;-)
[0] https://haveibeenpwned.com/ [1] https://www.howeycoins.com/
edit: grammar
The example of this application seems just like it wouldn't be too hard to implement with proper accounting (and tagging) of expenses.
You can easily self-host Firefly III in Docker [1], or use GNUCash [2].
I'm going to experiment with the former in the next months.
That is a limitation of the OFX version 1 protocol that is used by banks to exchange that data. OFX v2 does away with real account numbers in the api in exchange for account identifiers. The problem is that not all banks have switched to the new api, which was only finalized back in 2006, so give the big FIs a little time to get with the program.