Open banking works by letting you share specific bank account data, or authorize specific payments, with an outside app through a secure connection your bank controls. The app never sees your banking password. Instead, you log in on your bank’s own site to approve the connection, choose which accounts and what kind of access to grant, and your bank issues the app a limited digital key that it can revoke at any time. Every connection is time-limited, purpose-limited, and reversible.
The Secure Connection That Replaces Password Sharing
The technology behind open banking is the API, a set of rules that lets two software systems exchange defined pieces of data directly. When a budgeting or payments app needs your transaction history, it sends a structured request to your bank’s API. Your bank checks that you authorized the connection, then returns only the data you approved.
What makes this different from the older approach matters for your protections. Before APIs, most apps used screen scraping: you handed over your online banking username and password, and the app logged in as if it were you. Your bank could not always tell you and the app apart, and if an unauthorized transfer happened, you could lose the fraud protections your bank normally offers.
APIs remove your password from the equation entirely. The app holds a token, a digital key that grants limited access without exposing your login credentials. Your bank always knows which app is connected, what data it can pull, and can cut off that access on request.
How You Authorize a Connection
No data moves until you walk through an authorization flow inside the third-party app. You pick your bank from a list of participating institutions, then select which specific accounts to include. You also choose the scope: read-only access, which lets the app view balances and transactions, or active access, which lets the app initiate payments from your account.
The app then redirects you to your bank’s own secure login page. You enter your credentials there, on your bank’s site, so the third party never sees your password. Your bank displays exactly what data the app is requesting and for how long before you approve.
Access is always time-limited. Under the CFPB’s data rights rule in the United States, a third party’s authorization to collect your data lasts a maximum of one year from your most recent authorization, and the app must ask you to reauthorize before it can keep pulling information.1eCFR. 12 CFR Part 1033 Subpart D – Authorized Third Parties In the European Union and the United Kingdom, the standard re-authentication cycle is 90 days, after which you must re-verify your identity with your bank for the app to maintain access.2Open Banking Standards. Reducing the Negative Impact of 90 Days Re-authentication
What the App Can Do With Your Data
Authorization is not blanket permission. Under the CFPB’s rule, a third party can only collect, use, and retain your financial data to the extent reasonably necessary to provide the specific product or service you requested.3eCFR. 12 CFR Part 1033 – Personal Financial Data Rights A budgeting app can pull your transactions to categorize your spending. It cannot repurpose that data for anything else.
Three uses are prohibited outright, and they apply for the entire time the third party holds your data, not just while your connection is active:1eCFR. 12 CFR Part 1033 Subpart D – Authorized Third Parties
- Using your financial data to serve you targeted advertising.
- Using your data to market other products or services to you.
- Selling your financial data to anyone.
Read-Only vs. Payment-Initiating Connections
Open banking connections generally do one of two things.
An account information service pulls data from one or more of your bank accounts into a single view. A dashboard that shows your checking, savings, and credit card balances together is the common example. It retrieves transaction histories and balances but cannot move funds or change your accounts. It is strictly read-only.4Open Banking. Account Information Service Provider (AISP)
A payment initiation service goes further. Rather than routing a payment through a card network, the app sends an instruction to your bank to transfer money directly. This can settle faster and cost less than a card payment because the transaction bypasses intermediary networks.5European Commission. Payment Services – Revised Rules to Improve Consumer Protection and Competition in Electronic Payments When you approve a payment-initiating connection, you are giving the app permission to move your money, not just look at it, so the scope you approve on the bank’s page matters.
Ending a Connection
You can cut off a third party’s access at any time. Under the CFPB’s rule, the third party must give you a revocation method that is just as easy to use as the original authorization, and it cannot charge you a fee or impose a penalty for revoking.1eCFR. 12 CFR Part 1033 Subpart D – Authorized Third Parties
Your bank may also offer its own revocation tool: a portal or dashboard listing every app with active access. If your bank provides this option, it must revoke the connection and notify the third party in a timely manner.6Federal Register. Required Rulemaking on Personal Financial Data Rights
Once you revoke, or once the authorization period expires without renewal, the third party must stop collecting your data. It must also stop using or retaining data it already collected, unless that data is still reasonably necessary to deliver a product or service you have already requested.1eCFR. 12 CFR Part 1033 Subpart D – Authorized Third Parties
If Money Moves Without Your Permission
If an unauthorized transfer leaves your account through an open banking connection, federal law caps your liability, but the cap depends on how quickly you tell your bank. Under Regulation E, which governs electronic fund transfers:7eCFR. 12 CFR Part 1005 Electronic Fund Transfers (Regulation E)
- Report within two business days of learning about the unauthorized transfer, and your maximum liability is $50.
- Report after two business days but within 60 days of receiving your statement, and your maximum liability rises to $500.
- Report after 60 days, and you could be responsible for the full amount of any unauthorized transfers that happened after that 60-day window, if the bank can show they would not have happened had you reported sooner.
These caps apply regardless of whether you were negligent in some way. There is an important boundary here: the protections apply when you connect through the secure API process, where your bank controls the authorization. If you instead share your actual login credentials through screen scraping, your bank may treat the resulting transactions as authorized by you, which can void your fraud protections entirely.8Canada.ca. Open Banking
The Rules Behind It
In the United States, open banking is governed by Section 1033 of the Dodd-Frank Act. The CFPB finalized a detailed rule in October 2024 that requires banks and other financial data holders to make your account information available through standardized, machine-readable APIs when you authorize a third party.9Consumer Financial Protection Bureau. Required Rulemaking on Personal Financial Data Rights – Final Rule The rule covers checking accounts, savings accounts, and credit cards, and it explicitly bars data providers from complying through screen scraping. The largest banks face an initial compliance deadline of April 1, 2026, with smaller institutions phased in through April 1, 2030.10Consumer Financial Protection Bureau. 12 CFR 1033.121 Compliance Dates
Enforcement is currently on hold. A federal court issued an injunction in 2025 preventing the CFPB from enforcing the rule while the agency reassesses it. The regulation is still on the books, but the compliance deadlines are paused until the legal challenge is resolved.
In the European Union, the framework comes from the revised Payment Services Directive, known as PSD2, which took effect in 2018 and requires banks to provide standardized interfaces for authorized third parties.11EUR-Lex. Revised Rules for Payment Services in the EU A central feature is Strong Customer Authentication, which requires two independent verification factors drawn from three categories: something you know, something you possess, or something inherent to you. Any two of the three must be used together to verify your identity when you log in or authorize a payment.5European Commission. Payment Services – Revised Rules to Improve Consumer Protection and Competition in Electronic Payments In November 2025, the European Parliament and Council reached a deal on PSD3 and a companion Payment Services Regulation that will update consumer protection and fraud prevention rules once formally adopted.12European Parliament. Payment Services Deal – More Protection From Online Fraud and Hidden Fees