I would be willing to use a script which I can audit and run myself, but nobody offers that for my bank.
I would be willing to use a script which I can audit and run myself, but nobody offers that for my bank.
Disclaimer: I work for them. What I'm saying here is 100% personal and does not reflect the views of my employer, yada yada...
To be honest, we're doing an excellent job of protecting our customers' data. It's one of our core concern, and I have absolutely zero issue putting my own data in there.
We do _NOT_ store your credentials or even receive them at any point. Quite frankly, we don't want them. Any authorisation you would give us automatically expires after some time anyway, enforced by the banks.
The primary offer of Ponto is one API to interact with all your own bank accounts. No license needed, we handle all of that. We also provide a unified interface to all the banks.
The API is well thought out. All of our managers are highly skilled devs, so they understand what it takes to build good software (= time).
Check it out, we have a great support directly via Slack. I'm not answering that myself, but the guys who do it are super dedicated and will go a long way to help you.
Honestly I can't say enough good things about this product and our team! A product you can rely on, long term.
So the answer is a clear no then, please be up front about it instead :)
The topic is GnuCash, parent said "The biggest problem with it as far as I can tell is the requirement for manual entry" whereas someone replied "To use these APIs in Europe you need a license" and you said "There's Ponto", and I asked you if I can use Ponto to connect to GnuCash.
I think it's understandable to think that if someone is suggesting Ponto (in a submission about GnuCash), then you should reasonably be able to use Ponto to connect to GnuCash, since that's the entire point of this submission. Otherwise your comment just reads as trying to shoehorn in your own product wherever it's only slightly related to the topic at hand.
Fintech might be overall more security focused in their software development practices, but 10 years is still a very long time to entrust someone with your data.
The apps which don't have a deal with these aggregators request you to provide credentials (now fortunately most of them are defunct due to MFA)
I'll concede that it's only for business accounts. But, that includes small single owner businesses and I've been considering to switch to ABN to automate the accounting of my small side business.
The PSD2 APIs (also for consumers) indeed need a PSD2 license and an EIDAS certificate.
Technically, for consumer data, I think you could use GDPR to request a computer-readable extract of your transaction data. However, I think most banks would then redirect you to some CSV/MT940 export option in the web interface that is hard to automate.
Aggregators to require you to provide credentials are just web-scraping the websites or have reverse engineered the banks (internal) APIs.
I have been playing with the idea to use its API for my personal finance but the API with MFA is not so simple. At least not simple enough for me to spend much time for writing a customized interface. So I am still using their web interface which works well for my personal needs.
[1] https://support.n26.com/en-eu/security/open-banking-psd2/psd...
I don't know what I was thinking. This is Europe and there is very little chance a good idea won't be ruined with some sort of bureaucracy, licensing requirements, utterly vapid credentialism, or as a last resort, some other form of obtuse gatekeeping.