Banking.Foundation
Consent-first bank APIs

Open Banking

Account information, payment initiation, consent and embedded finance — the API layer that turned bank accounts into infrastructure.

AIS

Account information

Regulated read access to accounts and transactions, with the customer's consent — the raw material of aggregation, PFM and lending decisions.

PIS

Payment initiation

Third parties initiating payments directly from a bank account — card-less checkout and A2A payments.

Consent

Consent & identity

Strong customer authentication, scoped and revocable consent, and verified identity — the trust machinery that makes bank APIs safe to open.

APIs

Bank APIs

Standardized, versioned interfaces that banks are mandated (or choose) to expose — the difference between open banking and screen-scraping.

Portability

Data portability

The principle that account data belongs to the customer and moves with them across providers.

Embedded

Embedded finance

Banking capabilities delivered inside non-bank products via APIs — the commercial endgame of the open-banking stack.

The consent-first architecture

# the canonical open-banking flow Customer → grants consent (SCA, scoped, revocable) → Third-party provider (licensed AISP / PISP) → Bank API (standardized: Berlin Group / UK OB / FDX) → Core banking # accounts, balances, payments → Response with provenance + consent reference

Every open-banking regime is a variation of the same pattern: a licensed third party, a consenting customer, a standardized bank API, and an auditable trail. The regimes differ in who mandates it — regulation (EU PSD2, UK CMA order, Australia's CDR) or the market (US bilateral + FDX).

Jurisdiction-by-jurisdiction regimes are on the Regulation page.

Standards of this layer

PSD2UK Open Banking StandardBerlin Group NextGenPSD2FDX APIFAPI (Financial-grade API)

Providers of this layer

PlaidTinkTrueLayer