What is open banking, and is it safe?
Open banking lets an app you choose see your accounts or start a payment, with your permission and without your password. Here is how it works in Europe, and what protects you.
Open banking in one paragraph
Since the EU's second Payment Services Directive (PSD2), banks in Europe must let licensed third-party providers access a customer's account, if the customer agrees. Access happens through secure bank interfaces (APIs), not by handing over your login. You approve it on your bank's own page, and you can withdraw it at any time.
The two kinds of access
Account information (AIS)
Read-only access to balances and transaction history. This is what lets one app show accounts from several banks together, sort spending into categories or spot subscriptions.
Payment initiation (PIS)
The app prepares a payment, such as a SEPA transfer, and sends you to your bank to approve it. The money moves directly from your bank account; the app never holds it.
Who is allowed to do this
Only providers authorised by a national financial regulator in the EU or EEA (or the FCA in the UK), and listed in public registers. Many apps, including Sapthan Pay, connect through such a licensed provider rather than holding a licence themselves. You can check any provider's licence in the European Banking Authority's register or your national regulator's register.
What keeps it safe
- Your password never leaves your bank. You log in on your bank's own page. The app receives a permission token, not your credentials.
- Strong customer authentication (SCA). Your bank confirms it is you with two factors, such as your phone plus a fingerprint or PIN, before access is granted and before each payment.
- Consent is limited and expires. You choose which accounts to share. Account access must be re-confirmed regularly (typically every 180 days), and you can cancel it in the app or at your bank at any time.
- Read-only means read-only. Account information access cannot move money. Payments need a separate approval at your bank each time.
- Data protection law applies. Under the GDPR, providers may use your data only for the service you agreed to, and you can ask what they hold and have it deleted.
Open banking vs "screen scraping"
Older apps asked for your online banking username and password and logged in as you. PSD2 replaced that with dedicated bank interfaces. If an app ever asks you to type your bank password into the app itself, rather than on your bank's page, be cautious.
Five checks before you connect an app
- Does the login open on your bank's own page or app?
- Is the provider (or its open-banking partner) named and licensed?
- Does it say clearly what data it reads, and why?
- Can you disconnect a bank inside the app?
- Does it have a readable privacy policy?
How Sapthan Pay uses it
Sapthan Pay uses open banking to bring your European accounts into one place, and to let you pay by SEPA with every payment approved at your bank. We never see your banking password. Read more in our privacy policy.