Open Banking
Account information, payment initiation, consent and embedded finance — the API layer that turned bank accounts into infrastructure.
Account information
Regulated read access to accounts and transactions, with the customer's consent — the raw material of aggregation, PFM and lending decisions.
Payment initiation
Third parties initiating payments directly from a bank account — card-less checkout and A2A payments.
Consent & identity
Strong customer authentication, scoped and revocable consent, and verified identity — the trust machinery that makes bank APIs safe to open.
Bank APIs
Standardized, versioned interfaces that banks are mandated (or choose) to expose — the difference between open banking and screen-scraping.
Data portability
The principle that account data belongs to the customer and moves with them across providers.
Embedded finance
Banking capabilities delivered inside non-bank products via APIs — the commercial endgame of the open-banking stack.
The consent-first architecture
Every open-banking regime is a variation of the same pattern: a licensed third party, a consenting customer, a standardized bank API, and an auditable trail. The regimes differ in who mandates it — regulation (EU PSD2, UK CMA order, Australia's CDR) or the market (US bilateral + FDX).
Jurisdiction-by-jurisdiction regimes are on the Regulation page.