Open banking allows customers to authorize a bank to share selected account information with an approved third-party provider or initiate a payment through that provider. The connection normally uses secure banking APIs, customer authentication, defined permissions, and revocable consent instead of giving another company unrestricted access to the customer’s online banking account.
Open banking can support:
- financial-management applications;
- account aggregation;
- bank-to-bank payments;
- automated bookkeeping;
- income verification;
- lending decisions;
- cash-flow forecasting;
- financial product comparisons.
The customer remains central to the process.
A bank should not simply publish private account information. The customer decides whether to connect a service, what information may be accessed, why it is needed, and how long the permission should remain active.
What Is Open Banking?
Open banking is a system that enables customers to share financial-account data or authorize account-based services through standardized digital connections.
A typical arrangement includes:
- A customer.
- A bank or account provider.
- An authorized third-party service.
- A secure API connection.
- A consent and authentication process.
The third-party provider may use the connection to retrieve permitted account information, initiate a payment, verify financial details, or provide another approved service.
Open banking does not mean that a bank account becomes publicly accessible.
The word “open” refers to controlled interoperability between banks and external financial-service providers.
Open Banking Meaning in Simple Terms
Open banking gives customers a controlled way to use their banking information outside the original bank’s website or mobile application.
For example, a person with accounts at three different banks may connect them to one budgeting application.
The application may then display:
- balances;
- income;
- spending;
- recurring payments;
- transaction categories;
- cash-flow trends.
The customer no longer needs to download and upload separate statements every month.
The connection can update automatically while the customer’s authorization remains valid.
A business may use the same principle to connect multiple bank accounts to accounting software. Transactions can be imported automatically, reducing manual data entry and helping the company monitor its financial position.
What Open Banking Is Not
Open banking is not:
- a new type of bank account;
- a public database containing customer transactions;
- permission for any company to access financial data;
- automatic sharing without customer approval;
- the same as online banking;
- the same as a bank providing its own mobile application;
- unlimited access to every detail held by a bank.
Access should be limited to the service the customer selected.
A budgeting application may need transaction history but may not need permission to initiate payments. A payment service may need authority to submit one payment but may not need continuing access to previous transactions.
What Is an API in Banking?
An application programming interface, or API, is a structured method that allows two software systems to exchange information or instructions.
In banking, an API may allow an authorized application to request a specific action, such as:
- retrieve an account balance;
- retrieve recent transactions;
- display available accounts;
- confirm the status of a payment;
- initiate a bank transfer;
- verify account ownership;
- revoke an existing permission.
The API defines:
- which requests are permitted;
- how the request must be formatted;
- how the requesting provider identifies itself;
- which customer authorization is required;
- how the bank returns the result;
- how errors and rejected requests are reported.
Official open banking specifications cover identity verification, information sharing, payment initiation, security, participant registration, and reporting.
API Banking Explained with a Simple Example
Assume a customer connects a budgeting application to a current account.
The application does not normally receive unlimited access to the bank’s complete internal system.
Instead, it sends a structured request:
Provide the permitted transactions
for this authorized customer
for the approved time period.
The bank checks:
- the identity of the application;
- the customer’s authorization;
- the requested data;
- the duration of access;
- any applicable security rules.
If the request is valid, the bank returns only the permitted information in a standardized format.
The budgeting application then organizes that information into spending categories and financial reports.
How Open Banking Works Step by Step
Step 1: The customer selects a service
The process begins when a customer chooses a third-party application or payment option.
Examples include:
- a budgeting tool;
- accounting software;
- an income-verification service;
- a payment service;
- a lending application;
- a financial dashboard.
Step 2: The provider explains the requested access
The provider should explain:
- why access is needed;
- which accounts will be connected;
- what information will be retrieved;
- whether payments can be initiated;
- how long access will continue.
Current Open Banking customer-experience standards require explicit consent language to make the purpose, requested information, benefit, and access duration clear.
Step 3: The customer chooses the bank
The customer is redirected to the relevant bank or account provider.
The third-party service should not need the customer to type banking credentials directly into its own application.
Step 4: The bank authenticates the customer
The bank verifies the customer through its normal security process.
Authentication may involve:
- a password or PIN;
- a mobile device;
- a one-time code;
- a fingerprint;
- facial recognition;
- another approved security method.
Step 5: The customer confirms permission
The customer reviews and approves the requested connection.
The authorization may cover:
- selected accounts;
- specific data categories;
- one payment;
- recurring payments;
- a defined access period.
Step 6: The API completes the request
The third-party provider sends an authorized API request.
The bank either returns the permitted data, initiates the approved payment, or rejects the request if the required conditions are not satisfied.
Step 7: The customer can revoke access
A well-designed system allows the customer to view active permissions and cancel access.
Revocation should prevent the third-party provider from making new requests under the cancelled authorization. Open Banking standards specifically require accessible consent-management and revocation controls.
Main Types of Open Banking Services
Account information services
Account information services retrieve permitted financial data.
They can support:
- account aggregation;
- budgeting;
- cash-flow analysis;
- transaction categorization;
- affordability assessments;
- accounting reconciliation;
- financial advice.
The provider reads approved information but does not automatically receive permission to move money.
Payment initiation services
Payment initiation allows a customer to authorize a bank payment through a third-party interface.
For example, a customer may select a “Pay by Bank” option during checkout.
The service sends the payment instruction to the customer’s bank. The customer authenticates and approves the transaction through the bank’s own security process.
Identity and account verification
Open banking data can help confirm:
- account ownership;
- account details;
- regular income;
- recurring expenses;
- transaction history.
This may reduce the need for uploaded bank statements or manual verification.
Product and public-data APIs
Some banking APIs provide non-personal information, such as:
- branch locations;
- product details;
- fees;
- interest rates;
- eligibility rules.
These APIs may not require access to private customer data.
Open Banking Examples
Personal financial management
A financial application can combine information from several accounts and present one consolidated view.
The customer may see:
- total available cash;
- monthly spending;
- subscription payments;
- upcoming bills;
- savings progress.
Business accounting
Bank transactions can be imported directly into accounting software.
The system may match payments with invoices and identify transactions requiring review.
Cash-flow forecasting
A business application can analyze account history and estimate future balances based on expected receipts, payroll, rent, taxes, and supplier payments.
Lending and affordability assessment
With customer permission, a lender can examine verified income and expenditure patterns.
This may provide a more current picture than a manually uploaded statement.
Bank-to-bank payments
A customer can authorize payment directly from a bank account through a merchant or fintech interface.
Account switching and comparisons
Financial applications may use customer-authorized information to compare products based on actual account activity rather than generic assumptions.
Open Banking Payments
An open banking payment generally transfers money directly from the customer’s bank account to the recipient’s bank account.
A simplified payment journey is:
- The customer selects a bank-payment option.
- The payment provider sends the customer to the bank.
- The bank authenticates the customer.
- The customer reviews the amount and recipient.
- The customer approves the transaction.
- The bank processes the payment.
- The merchant receives a confirmation.
Open banking payments may also be described as Pay by Bank, instant bank transfer, or account-to-account payments.
Open Banking Payments vs Card Payments
| Feature | Open banking payment | Card payment |
|---|---|---|
| Funding source | Customer’s bank account | Debit or credit card account |
| Authorization | Through the customer’s bank | Through the card network and issuer |
| Main intermediaries | Banks and payment-initiation provider | Merchant acquirer, card network and issuer |
| Card details required | No | Usually yes |
| Credit availability | Normally no | Possible with credit cards |
| Chargeback structure | Depends on local payment rules | Established card dispute procedures |
| Merchant cost | Can be lower in some arrangements | Includes card-processing fees |
| Settlement | Account-to-account | Through card-network processes |
Neither method is automatically better for every transaction.
Cards may offer mature dispute and credit features. Open banking payments may reduce data entry and provide direct bank authentication.
Open Banking Payments and Stablecoins
Open banking payments move money between bank accounts, while stablecoins transfer value through blockchain-based networks.
The two systems may both support digital payments, but their legal and operational structures are different.
An open banking payment generally moves existing bank money. A stablecoin transfer moves a digital token whose value depends on its issuer, reserves, collateral, network, and redemption arrangement.
Benefits of Open Banking for Consumers
One view of multiple accounts
Customers can combine balances and transactions from different providers.
Easier budgeting
Applications can automatically categorize income and spending.
Faster financial verification
Customers may authorize verified information instead of collecting and uploading documents manually.
More relevant financial products
A service can evaluate the customer’s actual financial activity rather than relying only on broad demographic assumptions.
Greater control over financial data
Customers may decide which provider receives access, which information is shared, and when the permission ends.
Alternative payments
Bank-to-bank payments can provide another option alongside cards, wallets, and manual transfers.
Benefits for Businesses
Automated bookkeeping
Direct transaction feeds can reduce repetitive data entry.
Better cash-flow visibility
A company can monitor several accounts in one system.
Faster reconciliation
Payments may be matched with invoices or customer records automatically.
More efficient credit assessment
A company can share current financial data with a lender instead of relying only on older statements.
Improved payment collection
Account-to-account payment options may simplify customer checkout and reduce failed payments caused by expired card details.
Reduced administrative work
Accounting, payroll, treasury, and reporting systems can receive consistent data through approved integrations.
Benefits for Banks and Fintech Companies
Banks can use APIs to integrate their services with external platforms and business tools.
Fintech providers can build specialized services without becoming full banks.
Potential services include:
- personal finance tools;
- accounting automation;
- lending platforms;
- payment services;
- fraud monitoring;
- financial dashboards;
- savings applications.
Open banking can increase competition and innovation, but it also expands connectivity between banks, technology providers, and data users. The Basel Committee identifies cybersecurity, data governance, reputation, and third-party risk as important consequences of this increased connectivity.
Is Open Banking Safe?
Open banking can be safer than methods that require customers to disclose their bank credentials directly to another company.
In an API-based connection:
- the bank authenticates the customer;
- the third party receives only approved access;
- the permission can be limited;
- the authorization can expire;
- access can be revoked.
Open Banking guidance states that customers should authenticate through their bank and should not provide their banking password or PIN to the third-party application. It also emphasizes controlled permissions and minimum necessary data sharing.
Secure technology does not make every provider or transaction risk-free.
Users must still verify the service, review the requested permissions, and monitor their accounts.
Consent and Data Minimization
Consent is one of the most important parts of open banking.
A useful consent request should explain:
- the provider requesting access;
- the purpose of the request;
- the accounts involved;
- the information requested;
- the intended benefit;
- the duration of access;
- how to revoke access.
The provider should request only the data required for the service.
A payment application processing one purchase may not need twelve months of transaction history.
A budgeting application may need transactions but not authority to initiate payments.
Broad access creates more risk than narrowly defined permission.
Main Open Banking Risks
Data privacy risk
Financial transaction data can reveal:
- income;
- location;
- subscriptions;
- health-related spending;
- political donations;
- personal relationships;
- business activity.
Even when access is authorized, the provider may collect or retain more information than the customer expects.
Cybersecurity risk
Banks, fintech companies, API gateways, identity systems, and service providers may become targets for attackers.
Third-party risk
The bank may have strong security while the connected provider has weaker controls.
Phishing and impersonation
Fraudsters may create fake payment pages or applications that imitate legitimate providers.
Excessive permissions
A customer may approve more access than the service actually needs.
Operational outages
API failures can interrupt data feeds, verification, and payments.
Incorrect or incomplete data
Different banks may classify transactions differently or provide inconsistent fields.
Liability uncertainty
Customers may be unsure whether to contact the bank, payment provider, merchant, or application when a transaction or data-sharing problem occurs.
Concentration risk
Many applications may depend on the same API intermediary or technology provider. A failure at one provider can affect several services.
Open Banking APIs vs Screen Scraping
Before standardized APIs became widely available, some financial applications relied on screen scraping.
Screen scraping may require a customer to provide online banking credentials to a third party, which then logs into the account and extracts information from the bank’s website.
API-based access is more structured.
| Factor | Banking API | Screen scraping |
|---|---|---|
| Access method | Documented software interface | Recreates customer website access |
| Credentials | Usually entered only with the bank | May be shared with the third party |
| Permissions | Can be limited by data type and purpose | May expose broader account access |
| Reliability | Based on an agreed specification | Can break when a website changes |
| Revocation | Managed through consent controls | May require changing credentials |
| Monitoring | Requests can be logged and categorized | Activity may resemble customer login |
BIS research defines screen scraping as third-party access using customer banking credentials and contrasts it with standardized API-based data sharing.
What Is Open Finance?
Open finance expands the customer-permissioned data-sharing model beyond payment and bank-account information.
It may cover:
- savings;
- investments;
- pensions;
- insurance;
- mortgages;
- loans;
- securities;
- other financial products.
The BIS describes open finance as customer-permissioned access to a broader range of financial data than open banking, including investments, insurance, and pensions.
A customer could eventually use one application to view:
- current accounts;
- credit;
- investments;
- retirement savings;
- insurance coverage;
- loan obligations.
Open Banking vs Open Finance
| Feature | Open banking | Open finance |
|---|---|---|
| Main scope | Bank and payment-account information | Broader financial products |
| Common data | Balances and transactions | Banking, investments, insurance, pensions and loans |
| Common services | Budgeting, payments and account aggregation | Broader financial planning and product comparison |
| Participants | Banks and third-party providers | Banks, insurers, investment firms, lenders and other institutions |
| Complexity | Relatively focused data model | More diverse data, rights and regulatory obligations |
Open banking is normally considered a foundation for open finance.
Open finance requires broader participation, more extensive data standards, and stronger coordination between institutions that may use very different systems.
Open Finance and Digital Assets
Open finance may also connect users with investments and some digital assets through permissioned financial-data services.
This does not mean that every blockchain wallet or token automatically forms part of an open finance framework.
The connection depends on:
- provider participation;
- reliable identity;
- standardized data;
- customer authorization;
- legal access rights;
- compatible APIs.
Why Open Finance Is More Difficult to Build
Bank-account information is already complex, but wider financial products create additional problems.
Different data structures
An insurance policy, investment portfolio, mortgage, and pension account do not use the same data model.
Different update frequencies
Bank transactions may update frequently, while insurance and retirement information may change less often.
Different legal rights
Access, portability, and customer protections vary by product and jurisdiction.
Complex ownership
Some investments may be held through brokers, custodians, nominees, employers, or fund administrators.
Greater privacy sensitivity
Insurance and lending data can contain particularly sensitive personal information.
Interoperability
Institutions may use different API standards, identifiers, formats, and trust systems.
BIS work published in 2026 found that cross-border interoperability remains difficult because domestic open finance systems use different standards, data formats, and trust frameworks.
How to Evaluate an Open Banking Provider
1. Verify the provider
Confirm that the company is authorized, registered, or otherwise permitted to provide the service in the relevant jurisdiction.
2. Review the requested permissions
Check exactly which accounts, data, and payment powers are requested.
3. Confirm the purpose
The requested access should match the service.
4. Review the access period
Avoid indefinite access when a shorter period would be sufficient.
5. Check the authentication journey
Bank credentials should normally be entered only through the bank’s approved interface.
6. Read the privacy policy
Look for information about:
- data use;
- retention;
- sharing;
- deletion;
- security;
- complaints.
7. Understand revocation
The provider should explain how access can be cancelled.
8. Monitor the connected accounts
Review transactions and active permissions regularly.
Practical Note: A trustworthy open banking service should be able to answer four questions clearly: what data it needs, why it needs the data, how long access will last, and how the customer can cancel that access. Unclear answers are a reason not to connect the account.
Common Open Banking Mistakes
Assuming “open” means public
Customer data should remain permissioned rather than publicly available.
Sharing banking credentials directly
A legitimate API connection should normally redirect authentication to the bank.
Approving every permission
Customers should review whether each requested data category is necessary.
Forgetting active connections
Continuing access may remain active after the customer stops using the application.
Assuming regulation eliminates risk
Authorization and standards reduce some risks but do not guarantee that a provider cannot suffer fraud, outages, or security failures.
Confusing open banking with online banking
Online banking is the customer’s direct digital relationship with a bank. Open banking connects the bank with another authorized service.
Confusing open banking with open finance
Open banking focuses mainly on banking and payments. Open finance extends the model to additional financial products.
Frequently Asked Questions
What is open banking?
Open banking is a system that allows customers to authorize banks to share selected financial data or initiate account-based services through secure connections with approved third-party providers.
What is open banking in simple terms?
It allows a person or business to connect a bank account to another financial application without manually transferring account information.
What is an API in banking?
A banking API is a structured software interface that allows approved systems to exchange specific financial information or instructions securely.
Does open banking share my password?
A properly designed API connection should authenticate the customer through the bank. The third-party service should not need to store the customer’s banking password or PIN.
What information can be shared?
Depending on the customer’s permission, information may include account details, balances, transactions, recurring payments, and income patterns.
Can open banking move money?
Yes. Payment-initiation services can submit bank-payment instructions after the customer authenticates and approves the transaction.
Is open banking safe?
Open banking can provide controlled and revocable API access, but users still face phishing, privacy, third-party, cybersecurity, and operational risks.
Can I cancel open banking access?
A functioning consent system should allow customers to review and revoke active permissions.
What is the difference between open banking and online banking?
Online banking lets customers manage accounts directly through their bank. Open banking lets customers connect those accounts to authorized external services.
What is open finance?
Open finance extends permissioned data sharing beyond bank accounts to products such as investments, insurance, pensions, mortgages, and loans.
Is open finance the same as open banking?
No. Open banking is narrower and generally focuses on bank accounts and payments. Open finance covers a broader financial relationship.
Does open banking work in every country?
Availability, provider authorization, data scope, customer rights, and technical standards vary between jurisdictions.
Final Thoughts
Open banking creates a controlled connection between banks and external financial services.
Its value comes from combining:
- customer permission;
- secure authentication;
- standardized APIs;
- limited data access;
- payment initiation;
- revocable consent.
The technology can make financial information more portable and useful.
Consumers may receive better budgeting tools, easier verification, and additional payment options. Businesses may gain automated bookkeeping, faster reconciliation, and stronger cash-flow visibility.
The same connectivity also creates new responsibilities.
Banks, fintech providers, technology vendors, and customers must manage:
- privacy;
- cybersecurity;
- provider access;
- authentication;
- data quality;
- operational resilience;
- fraud.
Open finance takes the same principle further by extending customer-authorized access to additional financial products.
The strongest system is not the one that shares the greatest possible amount of information. It is the one that gives customers useful services while sharing only the data necessary for a clearly defined purpose.

