Increase: Banking API
increase.com
increase.com
The API allowed you to see balance, transaction history, and make payments.
Before long, the API got quite popular, and lots of people were using it to make lots of payments automatically.
You know what makes money laundering super easy... a banking API so you can split the million dollars you want to launder into 1 million 1 dollar payments. And an API client which lets you treat each login cookie and account as an object in python.
Before long, the API and all users who had ever used it were perma-banned from the bank, because it was determined they posed too high a fraud/money-laundering risk.
I'm still salty because, after spending a week of my life building and refining that API, they banned me and 6 years later still claim they can't return the $350 that was in the account because they are still 'investigating'.
Think about what it teaches children when they hear it? What kind of a world view does it instill? By saying the phrase you are explicitly communicating the idea that it is (at least is some sense) better to not do good deeds.
Kind of like "life's a bitch, and then you die", it's not meant to be taken too seriously.
I know this isn't a forum where we are endangering children by writing stuff like this, but it strikes me as a bizarre sentiment to express (of all the things one can say in an unfortunate situation - to choose summarize the whole scenario with that sentence).
There are too many evil people to willfully ignore the dangers of helping others. You should always, always be aware of the risks you’re putting yourself in any situation. In life, in work, in family, it doesn’t matter. And yes, that’s worth teaching children.
As long as the positives outweigh the dangers, it's worth doing.
Strangers should be distrusted by default, which is a lesson taught to children. It shocks me that some adults forget something so simple. This applies to teachers, cops, and anyone else you can think of. Trust is earned and should never be offered freely.
> "I think this is one of the most unfortunate memes that people for some reason still continue to share."
Even more unfortunate is that so many humans go out of their way to prove it true… Growing up in a small town, I was raised on more wholesome "memes" like "deep down, everyone wants to be a good person" and "sharing is caring" and other such silly lies, but having been out in "the real world" now for several decades, I've learned the error of that sort of thinking (at least here in the USA). The vast majority absolutely do not want to be good. They want to use and abuse everyone around them, and push others down into the gutters of life until they're filled with hatred for humanity. They want to beat every shred of goodness and decency out of everyone they meet, and that's just how life on Planet Earth is… It's a side-effect of having built a society around the idea that money is literally more important than anything else (including even life itself). Humans are mostly monsters and don't even realize it. I'm only happy that we're sure to kill ourselves off as a species before we escape this planet and infect the rest of the Universe with our evil greedy self-centered uncaring ways.> "Think about what it teaches children when they hear it? What kind of a world view does it instill? By saying the phrase you are explicitly communicating the idea that it is (at least is some sense) better to not do good deeds."
I wish I had been taught that most people cannot be trusted, instead of the foolishness I was taught. I'd have had a much easier life than the ongoing "waking nightmare" that I currently live. A more realistic world-view would have protected me from much / most of the abuse and backstabbery I've suffered in this life. And the worst of it for me is knowing that as bad as my life has gone South on me, I've still got it "lucky" compared to those humanity abuses the worst (those in nations where people cannot even protect themselves against the most vile abuses humanity can perpetrate against other humans). I mean, sure, I'm not able to afford the medical care that I need to get back to a semi-"normal" existence, but at least I'm not starving to death or being worked to death in mines somewhere, barely able to live another day.
It's really not that big of a deal. Smart kids will realise they're wading through a sea of bullshit and the rest are already predisposed to whatever bullshit pleases them.
That would be noticed. It's called "structuring" and is itself illegal. Banks watch for this stuff.
The bank typically has a rather simplistic set of rules to decide to investigate transactions (because they need to be able to explain how the rules work in a meeting with the government whenever their rules miss someone). Things like "Transaction was over $1000 to a new payee or the reference contained the word 'bitcoin'". The investigation will typically involve a human calling the customer, and sometimes asking for more evidence of what the transfer was for - for example, please send us the receipt for the car you said you bought. It's quite an expensive process for the bank.
So, when someone via the API sends tens of thousands of transfers, the bank is spending lots of human hours verifying some/all of those. "My script sent $55 to some stranger because I won a fully automated bet on the weather" is far harder to verify with documentation too. And when some slip through the cracks, they get in trouble with the regulator.
I learned the other day that the name on account means shit, because scammers often give $account_details + $catfish_name and receive the money to $bank_details + $real_name.
I don’t see how splitting to 1000 transactions and sending money to yourself helps with money laundering or undercover money sending.
Banks rely on a fixed set of rules to trigger an investigation for money laundering. One of these rules is the value of the transaction. I worked in retail whilst at Uni in the UK and we often had people who had lot's of money in their accounts unable to make large purchases due to these checks. Their payment would be automatically blocked and you would get a phone number they had to call to be able to make the payment. It was for example when buying a £5000 kitchen (I worked in the equivalent of home depot in the UK). If they could have split that transaction down to say 10 payments of £500 it wouldn't have triggered anything on the bank side.
Overall these banks process a lot of transactions and so heavily rely on these rules to keep them within the law. They don't always work as can be seen here and the bank noticed that users were able to circumvent their crappy ruleset by split big transactions down to lots of small transactions.
Not sure about sending money to yourself I suspect they mean transferring money between two accounts you control which is different in the banking for from sending money to yourself. If you are in control of both accounts you are laundering the money by transferring it to another account when you secretly control both. It's a basic way people like the mafia and such have laundered money for decades. They will do it through facade companies or suchlike. So they have one of the gang be legit and "clean" setup a shop who deposits cash into their bank account from "sales". The shop is a real place that you could technically buy stuff from. They then transfer their profits to this other account that is the gangsters account. The gangsters is part owner and they are receiving money as they "own" the shop and the shop has made money from sales. The sales though are actually the gangster giving money to his own shop and them claiming that as sales to the bank. The bank doesn't know that the money is actually from selling drugs or robbing stores or w/e illegal stuff they have done. The result is that you have taken "dirty" money i.e. money that has came from some illegal activity and with this strange process you have made it into "clean" money that's come from some legal activity.
So basically all money laundering will be transferring money to "yourself" but it will be via a third party that probably takes a small cut for helping. It's worked like this for years and is super common.
The fixed set of rules they have in bank is because it used to be that making money movements was hard so the criminals would transfer say £250k in a single transaction as sales revenue. So banks could easily spot this and take action. Making money movements easier means they can bypass this check.
Mostly, yes. But there are hundreds of those rules.
>One of these rules is the value of the transaction.
That happened, but I doubt that is the most important rule now. From what I've seen in my experience way bigger focus total value of transactions compared to various metrics.
Very large number of transactions on personal accounts is also one of those rules.
>Their payment would be automatically blocked and you would get a phone number they had to call to be able to make the payment. It was for example when buying a £5000 kitchen (I worked in the equivalent of home depot in the UK). If they could have split that transaction down to say 10 payments of £500 it wouldn't have triggered anything on the bank side.
That sounds like fraud, not money laundering rule.
> Very large number of transactions on personal accounts is also one of those rules.
Yes I suspect 1000's of trx on the accounts is what flag the whole thing to the bank.
> That sounds like fraud, not money laundering rule.
You have to take what I've said in context with the whole comment and not take a single part out of context.
As I said for money laundering you'll get consistent large transactions that don't make sense (say £250k each week from a pizza shop). Banks already know how to spot these large weird transactions so a method to hide them is to split them down into smaller transactions. My example with paying the kitchen was to show that the banks wouldn't notice the £500 transactions rather than the single £5000 transaction.
What is the source of the funds to launder and how/why is it already in the bank?
To be honest, I don't think money laundering is real, or significant. I see most money laundering rules as hidden or mislabeled sanctions on other countries, group of individuals or institutions.
It's just that you and I aren't big enough fish for the banks to look the other way, if we do it.
Gotta be a Mexican drug cartel, or a Russian oligarch to succeed in money laundering.
Heard it all now time for me to get off this site I think.
E.g. here the nonsense is why money that you already have in a bank account needs to be sent to someone else via 1000s of random small transactions. At best that would add a layer of confusion, but you still have the money laundering problems for the sending and final receiving person.
What happens is that banks are trying to cover their ass and please regulators so they don’t get fined.
Of course all regulation does is add complexity. You still have the most common way to launder money: know the top-banker and have connections inside the bank. With the right amount of money you can buy all the KYC you need.
Which means all this regulations is either malicious or plain ignorant. I think it’s malicious.
Money mules; you offer some influentiable kid some money to deposit cash into their account and send it on to someone else. Or an old lady. I'm sure part of the Nigerian prince thing is money laundering.
Second one that is very prevalent is physical stores that never seem to get any customers, e.g. in my neck of the woods there's these mobile phone companies everywhere. I'm sure they sell phones, simcards and accessories on occasion, but I can't see how it would cover the cost of rent, let alone make a profit. Unless once a month someone comes in with a few thousand in cash that then gets added to the books over time.
Oh, there actually was an article on HN about that recently, that was "american" candy shops in london: https://www.standard.co.uk/news/london/london-news-american-...
[1] https://en.wikipedia.org/wiki/Contaminated_currency
[2] https://cipherblade.com/blog/tainted-bitcoin-isnt-what-you-t...
Cops have used cocaine residue as "cause" to rob people of cash: https://www.youtube.com/watch?v=MkeS_0NQUZs
The other type of transaction they mention in 4.16.13.4 also involves cash payments in the course of a trade or business.
Everything else is what someone might do to try to conceal structuring, but if cash isn't involved, it's not structuring, because there's no covered reporting requirement.
More likely scenario is increase will partner with some chartered bank and try to expose this api functionality. They will soon realise the constraints they need to be under to not allow crazy things like this.
In retrospect, I should have paid a lot more attention when Patric Collison told me he was spending his days reading up banking regulations. Eh, too boring, I thought, what could possibly be in there that a little code couldn't paper over? That mistake cost me the opportunity to be an early hire at Stripe.
Your customers want to be innovative and do things they can't easily do today. On the other side is your financial network that has shut down the three previous attempts to do that exact thing because it causes a random transaction clearing server in France to burst into flames. You are now left holding the bag with both sides upset at you.
The happy fact of the matter is that the vast majority of actors in the economy seem to be pretty well-behaved. The scary thing is that the system seems to depend on this.
Only I'm guessing it doesn't take half as much to create crumble the banking system.
That's mainly because, in most countries, to become a participant in a regulated financial system, you have to meet the 'fit and proper' criteria of qualification [https://www.bis.org/publ/bcbs47c4.pdf].
There are continuous audits and enforcement/disciplinary actions taken to ensure regulatory compliance. Also, digitisation has enabled tech based regulatory/supervisory tooling to reduce the burden of regulatory/supervisory activities.
And, as newer/faster tech based mechanisms/rails have gained adoption older more cumbersome rails are getting retired. This is leading to effective regulatory simplifications.
As someone who doesn't, I'd love to hear more.
Any part of this process that is modernized still has to emulate the old...
I'm glad I quit that job. The only problem is when I tell people how the bank actually move money they don't believe me.
Not only that, but getting a meeting with someone who understands how banking actually works under the hood is nearly impossible. In fact, even finding such a person is nearly impossible. Not only do the front-line people in banks not understand how their industry works, they don't even know who does understand.
There is also a huge disconnect between banking and IT. I once had half a million dollars go missing for two weeks because of a wire transfer snafu. No one could figure out where the money was. The only reason it was recovered is that the person to whom the money had been wired incorrectly noticed and sent it back.
This is great insight though re: money laundering. Something I'd have never expected would be the result of an API.
The guy assigned to my case retired. As did the next guy. And now there is a lady assigned to the case, but she has been out of the office for all of the last 3 years...
Every time I call, I get told they can't discuss cases over the phone, but that they will send me a paper letter as an update... And it isn't a template letter either... But it always just says I need to keep waiting and there is no action I can take to speed the process up...
They got a default judgement, but still couldn't actually collect the amount owed.
So they ended up filing a foreclosure on the actual building - and it worked! The foreclosure went through, and the company almost lost their brick and mortar store.
Took years for the process, but it was nice to see that the courts can and will defend an individual. This all took place in TX IIRC.
The threat was enough to fix the failed transaction. The manager was able to call someone and issue a check, rather than have their branch auctioned off.
I don't see how that's the same problem? They are clearly separate, distinct problems.
There are obviously both advantages and disadvantages to both crypto and banking. As someone who lives in a country that has been through a lot of bullshit, I highly value the fact that the bank can't just take away my money.
The only difference is that crypto fraud is irreversible, and that the blame will be put on you.
Fraud is huge industry, the fraud models and attack vectors in the fiat world is different than in the crypto world. In the end wherever there is enough money, there will be fraud as well.
If you don't trust "the system" as a whole then you are right, I can't argue with mistrust.
I'm interested in learning more about this. Do you have an example of a bank with a cash flow management API I could take a look at?
One example i can think of right off the top of my head: INTEGRATIONS Integrate Increase APIs Modern Treasury’s powerful REST API is the easiest way to integrate your Increase bank accounts with your application for payments, reconciliation and reporting. https://www.moderntreasury.com/integrations
And
"Improve Cash Flow
Managing cash flow requires looking at receivables and payables, accessing liquidity and making accurate forecasts. Cash management APIs improve every facet of the treasury operations." https://www.chase.ca/en/support/insights/six-ways-payment-ap....
and the developer portal:
https://developer.jpmorgan.com/
Other big corp banks have similars. A lot of these TMS platforms just integrate into these banks APIs and ERP systems (Oracle Cloud, SAP, etc) and glue workflows together.
It felt like if Clippy had an addon to it's expert system from Saul.
=> https://www.mybanktracker.com/checking/faq/rules-deposit-100...
Moving $20k fully electronic (eg:ACH) doesn't have that requirement.
But lots of systems have limits based on risk windows.
Had fun ideas of improving the finance sector with ideas like this, that for any other industry would be at worst : 'TODO's to fix later.
Finance sector taught me a lot about security, but also about standards.
Standards are a real PITA to code for, from HTTP to PCI payment compliance. They're so worth it in the end though.
https://ask.fdic.gov/fdicinformationandsupportcenter/s/?lang...
https://www.helpwithmybank.gov/file-a-complaint/index-file-a...
i mean i am talking from an indian POV where every banking customer is KYC approved from the get-go. you send someone money or receive money, there is a proper trail to their identities.
TL;DR my understanding is that if you host a banking API you are going to get a lot of scrutiny on who your customers are.
And you can expect an increasing level of compliance regulations heading your way to help regulate and prevent the problems described in the parent.
Technically known as smurfing, and (as you learned) quickly leads to account bans.
Governments take AML/KYC pretty seriously. Just ask TornadoCash.
Not sure how to take this. With a small tweak like "you can eventually do" I would let it pass without criticism.
I work with bank cores, imaging, BSA and related middleware on a daily basis. The scope and complexity of these systems is incomprehensible to most. Many of our clients don't even try to think about how fucked up their business is. They prefer to hire Deloitte and other vendors like us to be stressed about it for them.
To give you an idea of how comprehensive a "full" banking API is, our combined WSDL and XSD references total ~9 megabytes. This is before codegen. The final reference sources as generated into the .NET codebase total nearly 20 megabytes. This is just the types & method signatures. The actual implementations live in an IBM system manufactured some time during the previous millennium.
But, none of that really matters. Whatever API method you call against a specific bank will have behavior that ultimately depends on a million things specific to them _and the region within which they operate_. So, its not enough to simply integrate with this massive API. You also have to understand a multi-dimensional matrix of regulations, end-customer behaviors, technological constraints, active geopolitical affairs, et. al.
A non-zero amount of that legacy is due to regulations and compliance.
Most of what a bank does is totally invisible to the end customer. A "neobank" is almost always just a shiny consumer-oriented facade in front of a grumpy old bank. Someone still has to follow all of those laws.
This website is operated by Monzo Inc. Monzo reserves the right to restrict or revoke any and all offers at any time. The Monzo mobile banking app facilitates access to banking services through *Sutton Bank*, Member FDIC. The Monzo Mastercard Debit Card is issued by Sutton Bank, pursuant to a license from Mastercard International Incorporated. Monzo accounts are FDIC insured up to $250,000. Mastercard is a registered trademark, and the circles design is a trademark of Mastercard International Incorporated.
That's for the US branch. Monzo in the UK is a real bank.
> Starling Bank
That one is an actual bank. In the UK, it's easier to open a real bank, than in the US. Bank of England has a special division dedicated to guiding "small" companies in becoming a real bank.
Although there's a kernel of truth there, it's far from accurate. Most of the legacy is due to the assumption of regulations and compliance. The truth is that most of the systems are in fact out of compliance, but as long as you don't touch them the likelihood of a serious audit is small. The complexity is more about erecting an impenetrable wall to make the auditor assume it's probably compliant.
It's essentially about overwhelming auditors with details to fatigue them. Not to dissimilar to when lawyers flood each other with documents in tv shows.
Their FDIC charter was issued in 2006.
US banking being largely obsolete as a whole (checks? paid wire transfers that take days to arrive?) probably explains why there are no real neobanks in the US and they're all just a UI in front of a legacy bank. I doubt it has much to do with regulations, because I really doubt US banks are more heavily regulated than EU banks, who also have country differences to deal with if they operate in multiple countries (Revolut, N26), and they also have to check if the customers are American tax residents and handle that case too (or simply refuse them to become customers as some banks do).
Even Revolut that you cite was just a frontend until January 2021 where it became a bank, but just in the UK: https://en.wikipedia.org/wiki/Revolut#History
What are you talking about? Revolut is a real bank, same as Monzo, N26, Aumax (part of a larger banking group so it hardly counts), Kard. Specifically regarding Revolut, they are a real bank in multiple countries now - UK, Lithuania, US and a bunch of other European countries.
Revolut's links to Russia are, perhaps, not helping with that.
The neobanks are all very incremental improvements, and is largely just packaging. E.g., Lunar being app-only obviously has a somewhat more modern app than the average bank.
The truth of the matter is that banking is horribly entrenched. Actual business decisions are mostly driven by arbitrary considerations of which laws to follow that day. Although we provide a ton of functionality and business capability, we are still woefully behind on any sort of compliance measure, not because compliance is hard or impossible, but because nobody is actually critically examining the systems.
The problem for the "neobank" is not one of building technology to catch up. It's in cultivating an image where they are seen as systemically critical such that they will be afforded the same leniency in policing that the established sector already has.
It's in Turkish but translate will help you get the idea: https://ohvps.github.io/v1.0.2/contents/odeme-emri-baslatma-...
Here's the api documentation of 25 Danish banks, including the one I'm a part of: https://apiportal.prod.bec.dk/openbanking/sandbox/product/17...
https://www.openbanking.org.uk/api-performance/
These figures only include the “top 9” UK banks that are required to implement open banking, not smaller banks like Monzo.
I’d argue that open banking is already being used for lots of serious stuff. Credit checking, for example. And of course pretty much any accounting/financial software supports open banking now days.
By serious stuff I meant stuff that requires perfect accuracy and integrity - credit checking wouldn't care if you're missing one transaction here or there, or if the timestamps are a little off.
But for accountancy, perfect accuracy is required and OB with legacy banks is far from perfect in that regard - the data quality is bad, you get missing/duplicate transactions, timestamps are off (due to TZ issues). Modern banks are the only ones where the data is any good. For accountancy services, this ends up causing significant support overhead to companies where customers complain their numbers are off and the company can't do anything because the bank sends incorrect data, not to mention engineering overhead where you have to try and clean up the data in-house (the problems are different for each bank, so you have to essentially reverse-engineer how each bank mangles the data and implement bank-specific workarounds).
> Uptime and performance seems to be monitored pretty closely since 2020
Uptime, sure. I too can make a 100% uptime API that returns random data.
When it comes to data quality, there didn't seem to be any authority (in terms of real, practical outcomes - not theoretical powers that never end up being used like the GDPR for example) to complain to - which I find to be a fatal mistake in a situation where banks otherwise have zero incentive to provide a functional & usable OB API (in fact, OB is detrimental to their business as it would allow customers to use a third-party's - often better - service over the bank's own one). Even the OB "gateways" like Plaid, TrueLayer, etc have their hands tied when it comes to this - once the issue is confirmed to be with the bank, the lead time on getting any kind of resolution is often months, during which you have a disgruntled customer breathing down your neck and blaming you for the problem.
Like this Increase, "build your own bank", but themselves it isn't a bank. It's just an API to their partner banks.
For me it was buying a house and realizing that you must be able to wire money.
When the stakes were high, Varo failed me (they promised they could do it, but on the day I needed it they refused) and I had to scramble at my traditional bank to make the payment in time to avoid $20k on penalties.
Other than the most important transaction of my life, though, they've been great!
I don't know Varo but would you imagine continuing using them for other transactions and using the traditional bank for traditional purchases (house, etc.) After all, people don't go through the most important transaction of their life frequently.
As others have mentioned legacy banks here in Scandinavia are slowly catching up, the main reason being the slow trickle of custeos to neobanks.
We're early days and not quite ready for open sign-ups yet (sorry, known bug). We'll be more public over the coming weeks and months.
We're banking for developers; you can programatically create accounts, cards, and move money.
Our users are primarily financial technology companies.
We're a small team from Stripe, Robinhood, and Visa building the bank we always wanted. If this sounds interesting to you we're hiring: jobs@increase.com
If I can be helpful, I'm at darragh@increase.com.
to a distant observer, you look similar, but i'm sure there are real differences between you, so I'd love something like a "top 3 things to note" about Increase vs Column, in a least-getting-you-in-trouble way as possible - its hard to compare because i dont know what I don't know.
I think there are many engineers who are frustrated knowing the data and capabilities that exist in banking that aren't exposed programmatically.
There are at least four (and I'm undoubtedly missing many!) interesting companies aiming to combine technology and a bank charter:
- Luna[0].
- M1 Finance[1].
- Column[2].
- Increase[3].
Building a bank involves reading, understanding, and respecting regulation. It invovles integrating with large financial networks. It involves rallying a team for a years-long adventure. Each of these is early days and it'll be a few years before any of us understands how this super large and important problem will be solved.
0. https://www.americanbanker.com/news/former-square-exec-leads...
Column is an actual bank, and offers exhaustive developer-first APIs. I suspect you can do a lot of things with them you cannot do with Plaid, and at highly reduced cost comparatively. Increase doesn't seem to be a bank but is a much lower-level API than Plaid and allows things like opening accounts, FWICT.
BTW, bunq (https://www.bunq.com/) is a cool nl-based bank which offers an incredibly in-depth API. But I would not call it dev-centric, the DX is awful.
As a developer, I'd love to have some more information about the typical problems that inspired Increase's value proposition. If I was meeting with a financial tech CEO tomorrow, should I assume that they probably have these problems or need this service? Are there resources that I could peruse to learn more about these common problems?
When we built Stripe, one of the largest points of friction was getting a banking partner. It took months and only after signing were we even able to start assessing the technology. There are so many potential companies that simply don't make it past the partnership step. We want to fix that.
The US needs a bank (holding a bank charter) that's also a technology company. Increase certainly isn't there yet (patches welcome: jobs@increase.com) but we already have integrations with the Federal Reserve, Visa, and The Clearing House. Our API already serves businesses you know and love.
Do you have plans on becoming a bank and getting a bank charter then? I've worked with several payment processors and BaaS providers that are most definitely not on that path. (CTO at neo bank).
We took the approach of starting with an intentionally bad name (in our case, bnk.dev) and using it until a good domain became available to purchase for a reasonable price.
Related: http://www.paulgraham.com/name.html
Or something like credit karma has?
Do you need a large amount of money upfront?
This is an extremely niche use case of course, but it's not the first time they popped up on HN at least.
In mobile ISPs, MVNOs are quite common, and there is a large amount of customer base because they simplify KYC, sales, and customer on-boarding. Technically, this API should provide the platform to build a similar "Virtual bank". I do not think anybody without a significant technical and financial resources will be able to pull it off.
Another use case I can think of are market places like ebay, Amazon, Aliexpress, etc. Each seller receive a bank account that they get their payments deposited to, and can be withdrawn from their branded card. I do not see this being a commercially viable option for many, because pretty much every country has free or almost free systems in place to simply transfer money, and not take the unnecessary burden of issue cards, maintaining bank accounts, etc. Payoneer used to run a similar program, with branded cards, custom fee structures, etc, but it eventually failed as far as I know.
curl -X "POST" \
--url https://api.increase.com/check_transfers \
-H "Authorization: Bearer ${INCREASE_API_KEY}" \
-H "Content-Type: application/json" \
-d $'{
"account_id": "account0",
"address_line1": "33 Liberty Street",
"address_city": "New York",
"address_state": "NY",
"address_zip": "10045",
"amount": 1000,
"message": "Check payment",
"recipient_name": "Ian Crease"
}'
Well it would certainly be nice if I can send a rent check from my command line!...until you accidentally do it again when trying to re-invoke some other command from your command history.
you do not have an address line 3
the amount data type is not clear (is that an integer representing pennies, is it a floating point? shouldnt be using floating point for banking)
recipient name is not broken up into first name, middle name, last name. are you users going to be putting "last, first" as well as "first last"?
if you sent that from the command line, then your banking information would be in your bash history, saved on disk
etc etc etc etc
Bash history can be cleared about as easily as other places people routinely put similar information.
There are a number of competitors in this "Banking as a Service" API space like Treasury Prime and Galileo.
I think while others have commented on how beautiful your creations are, I rather admire you for the care and detail you put on UI. Beautiful things are not always easy to use, and things that are well-laid-out and easy-to-use are not always beautiful. You have somehow arrived at the magical place where you've got them both down.
(For the anecdote and because you mentioned it, it always annoyed me that we had a pretty different visual language at Stripe between the site and the dashboard. I designed Stripe's homepage but not its dashboard, whereas I did both at the same time for Increase. Consistency is really hard to achieve between multiple products as the optimal visual treatment is different for a site and an information-dense UI.)
To build a startup like that, you need to build a product layer on top of a banking API, which lets you avoid having to write code that hooks into payment rails, interfaces with credit card manufacturers, stores credit card numbers, etc. Now you can focus on the differentiating aspects of your user base instead of building common banking infra.
There are a bunch of companies that offer banking APIs as a service already. The most popular of these is Galileo, a 20 year old company that was recently acquired by SoFi [1]. The developer experience of Galileo is absolute trash. I haven't used any other companies first hand but I've heard they're not much better. So presumably Increase is trying to provide an actually good developer experience for devs building banking products.
[0] https://www.ycombinator.com/companies/seis [1] https://www.sofi.com/press/sofi-to-acquire-galileo
The precise segment doesnt matter, my question is - how much of the banking capital requirements do i need to put up? because a bank isn't just about payment rails and credit cards, its also about having literal cash in the bank right?
So you would have to go through Sutton bank or another bank, but I think there are enough of these companies now that there's a fairly tried and true path. If you're seriously investigating this I can connect you to people who know more about it than I do.
[0] https://robinhood.com/us/en/support/articles/robinhood-debit... and ctrl+f "Sutton"
If you want to start an actual bank, you need a charter from the FDIC. This is commonly referred to as a De Novo bank. Also known as "virtually impossible".
"Bank accounts and banking services are provided by Increase’s partner banks, members FDIC."
The only way they can provide all this functionality is to do all the hard work of integrating with whatever legacy junk the partner bank is running (along with all the Visa stuff, Stripe stuff, and whatever else they are using here). You could actually do this yourself, and some fintechs are attempting that, but it's very hard and expensive due to the PCI-DSS requirements, among other things.
I'll be curious to see if they will require their customers to have PCI-DSS or if they'll be able to tokenize everything in a way that doesn't require it. When I worked at Visa the big issue was that handling card data, even after tokenization, required PCI-DSS, which of course makes no sense, but the immune systems around the payments industry takes a long time to change.
Depending on who "manages the program" you'll probably still have significant work to do our your side related to KYC and Compliance. You can offload this to the BaaS if they have a pre-existing relationship with a sponsoring bank but then you have very limited latitude to change how your perform KYC etc.
For context, when we started, straight out of YC we worked with a company called Synapse (synapsefi.com) who had a pre-existing relationship with Evolve (sponsor bank) and managed our entire program. They were responsible for KYC, fraud, compliance etc. We basically built an app on top of their APIs.
As we grew we needed more control and a direct relationship with a bank (this also improves the unit economics). We now manage the entire program and the payment rails part and banking APIs are maybe only 5% of the work involved (even within engineering a huge portion of our time is on fraud/compliance/kyc etc).
Shooting you an email now.
honestly i dont think its their fault, this is such an alien space to most of us that we just need more handholding than normal
Neobanks sometimes use this notion of a virtual bank account. My understanding is that it's a single FDIC insured account that they subdivide using their own ledger.
For cards, you can use Stripe Treasury or Lithic to issue your own virtual cards and their dev limits are pretty friendly. I think privacy.com does this as a consumer experience really well. Note you said `checking accounts at will with different card numbers`. Depository accounts are a totally different notion and resource than cards.
However should you do this? I can't think of a reason why you'd want to for your own purposes. The reason fintech is so annoying is not because banks/tech players don't want you to have nice things, is that there is a ridiculous amount of regulatory overhead.
It's quite simple. For argument's sake let's say I am an individual with limited willpower. Say I budget $200 per month on restaurants, and I need to stick to this to meet some other financial goal. How, as someone with limited willpower, do I enforce this?
Option 1 is to keep track of and categorize all bank transactions, either manually or via a third party budgeting app, and check my "restaurant" balance each time before I order food. This is unlikely to happen because I am lazy and assume I have the money.
Option 2 is to keep a physical envelope of cash that I put $200 in. When the money runs out, I don't have any to buy restaurant food. This works, but is very inconvenient. How can I use Doordash, Venmo a friend, etc with this?
Option 3 is to have a debit card that only has restaurant money on it. Now the card simply doesn't work anymore when I'm out of money. It's effectively the same as the envelope, but now I can use it online as well.
Virtual debit cards are another ubiquitous solution, but they cost a lot more despite being free. Your option 3 subsidizes smarter consumers when you pay full price (which has interchange fees built-in) on everything without getting any fees returned to you in the form of cashback.
(One issue with my solution is that a lot of banks let you spend 2x your credit limit on visa signature and similar tier cards. In that case you'll have to reduce the limit to $100)
(On a related note, to GP comment, Lithic was actually spun out of Privacy.com)
Wish your team all the best! This sort of innovation / competition is needed in that space.
If you need to know which emoji is most representative of the shop where you used your card 7 seconds ago, you can get sent that (and a lot of other data) in a webhook...
In practice this means that any UK financial app that supports open banking should be able to connect to an account at any UK bank that implements open banking.
It doesn't allow sending money to someone, creating a new bank account, closing an account, changing your email or postal address, setting up a pension or credit card, or any of the other actions you might want to do at your bank.
And open banking does support "sending money to someone" (variable recurring payments), subject of course to some security constraints. You wouldn't want to just let every random app that you let access your bank account initiate any transaction it wanted without an additional authorisation step, would you?
Everything else you mention is a pretty infrequent and specialised transaction and the benefit to having an API would be minimal. (OK, I could see value in an app that automatically updated your address etc with every company you have a relationship with, but that would require a common API across many industries, not just banking)
Interesting. I use an app called JamDoughnut [1] and I can top up through Google Pay or from my bank. I tried the other day to do it from my bank and it then opened a modal asking me which bank I'm with. I selected Starling and then my Starling app opened asking if it would be OK to share information with Jam Doughnut and send a payment to them.
As this was allowing me to use any bank (not just Starling), I assumed that it must be using Open Banking. Is there some other API out there that would allow them to take payment from any bank? I guess its possible that if I selected a different bank then it would just come up with a message like 'coming soon...'. But it seems surprising that they'd implement for Starling which is one of the smaller banks and not the others.
Increase is not a chartered depository institution. We work with our partner banks to provide depository and payment services. When you open an Increase account, you agree to the Increase Terms of Service below. When you use the Increase service to set up a deposit account, the account is with First Internet Bank or Blue Ridge Bank and is subject to your agreement with the Bank Terms below. Finally, Increase's use of your personal information is described in the Privacy Policy below.
Not sure what the exact customer pain is here, could be that banks were the first to adopt IT and now have a large legacy where there is little value in rebuilding it with modern stacks, as it offers little competitive differentiation.
Or maybe there’s a need to quickly bring new banking products to market, and the backend stuff is so standardized that it’s best to buy it off the shelve.
Then there's of course many CBS providers including the more modern ones like Mambu.
Target rate right now is 2.25-2.50%, so i'm guessing that you are subtracting 50 BP from the lower end, so that's 1.75%. That's actually pretty good for a bank right now (not the highest, but certainly on the higher end.
One thing that's unclear... is this a checking account, savings, etc.?
This is one of the reasons why I say that the EU is corrupt.
Ok so I tried to play their game, and asked the BAFIN what I had to do in order to become such an entity. I wrote 5 mails back and forth over the course of 3 months, not a single response had clear, concrete instructions on who to wrote to and what to send them.
I had to read some hard to find article about PSD2 to know that I have to pay the Bundesdruckerei for a certificate, x509, every year, in order to be able to query the XS2A api.
It's dirty, exclusive and corrupt and no one is doing anything about it.
Two questions:
1. How is this different than Open Banking?
2. Why is Visa referenced / why isn’t Mastercard included? (Is it because Mastercard owns Finicity, and Open Banking service)
As for PayPal, some freelancer (especially outside US) do get paid using it, but paypal's fees are outrageous and we try to get anyone we can on an alternative like zelle, ach etc.
Stripe has a banking as a service segment now -
(possibly I'm misreading Stripe marketplaces' offerings, please correct me if I am)
Do you make use of Payoneer API for payouts? How do you find it?
Payoneer is really cagey about how you unlock better features, our account got upgraded to VIP though because we pay a lot through it. We still use their interface, maybe I'll figure out how to get their API someday
Aren't these fundamentals to build trust, especially for a B2B banking product?
For those that don’t know what Column is.
Column
Stripe Treasury
Treasury Prime
Unit
Cross River Bank
Any BaaS I'm missing?
???
[0] https://moov.io
1) What does this provide over other BaaS vendors, for example Treasury Prime, Unit, Synapse, Lithic, etc?
2) Why are the ACH fees so horrifically high? Even a fifth of that is really on the high end.
Who is looking into open a new bank/credit union and like... how much money is needed? How do you compete with Ally or any other "online" bank? How do you build trust and get people to give you their money, and for what benefit to them?
you can programatically create accounts & cards and test with real money - in minutes!