I’m sure this is a reasonably common flow, but it’s only a slice of what Plaid does. They additionally do transaction parsing/normalization across a wide variety of accounts. I’ve been using Plaid for years as part of my ledger-cli workflow, to automate importing of account transactions.
The security flow is horrible, but the security flow for banks was already horrible: the reason I trust banks with my money is because of strong ability to reverse malicious activity, and regulatory oversight, not because I trust their infosec practices.
Pre-Plaid, I had some local scraping tools to pull transactions, and ran into several instances where the “MFA” step for banks allowed my “browser” to pick its own unique identifier. If I set it to “hahalol”, that was fine, and as long as I kept sending that ID, I never had to MFA again.
If we somehow had a world where there was an actual standard way to fetch data from my banks, I’d love that. I’d switch immediately. But in the current world, Plaid is pretty far down my list of financial-service-related risks.