Are there any banks moving in that direction? I know of exactly zero in Canada.
Are there any banks moving in that direction? I know of exactly zero in Canada.
The end result, now it's available, is that you have 2 levels of API access. One is for access to account information (I tend to think of this as read-only access), and the other is to allow for "payment initiation" (think of it as write access, although not a perfect analogy).
An account information service provider (AISP) can do things like aggregate bank accounts into one view, across different banks. A payment service initiation provider (PISP) can create payment gateways and initiate payments against a bank account using an authenticated session (enabling direct bank payment online, without needing a debit or credit card and the associated infrastructure around that).
You can't just rock up and access the APIs though - I believe you need to get your application approved and engage with the regulator, which is probably for the better, to avoid the "app store problem" of loads of apps springing up in the API ecosystem, asking for permission, then just leeching data to third parties after you apparently consent on page 46 of their terms.
The result is middle apps that are forced to use sketchy anti-patterns like screen scraping and asking for user/pass instead of each bank issuing a per-app token. The banks are just fine with this because anything that explodes will be the middle app's fault and they want to preserve their otherwise moatless situation. Consumers can't really tell banks apart so they have to force retention.
At least if the bank implements some sort of API that means some thought was probably given toward using tokens instead username/password, and some thought was given toward scoping the APIs - at least into read-only and read-write capable access.
Although if you read between the lines in some of the service descriptions and backend documentation, a lot of what Plaid (and Yodlee, and others) do is now a mix of scraping and private APIs the banks provide, but those APIs are only available to commercial entities they've signed a relationship with.
Obviously the ideal is public standardized APIs all banks provide with established security-focused practices and read-only limited data access as an option. But proprietary per-bank APIs available to the general public would be a good step forward.
Well, I think that would barely change everything on the consumer side. Nobody is going to go through and integrate with the hundreds of credit unions and local banks just for their app - if anything it only encourages a few extra companies enter the battle with Plaid.
Hopefully FedNow fills this void, at least for the U.S. market. https://www.frbservices.org/financial-services/fednow/about....
Banks are so held in last century technology...
Quite a few in Canada.
I'll post a snippet we recently added to our pitch deck:
> Accounts like those catering specifically to the LGBTQ+ community (https://joindaylight.com), the Black community (https://firstboulevard.com), individuals interested in supporting renewable energies (https://www.tomorrow.one/en-EU/), and social media creators (https://www.trykarat.com/) have proliferated. Retail accounts catering to the unique wants and needs of software developers is a natural next step.