Skip to content
LIVEupdated 13:15
Full board

Tech & Fintech · Explainer

Open banking: what sharing your account data actually authorises

A consent screen grants a defined scope for a defined period. Knowing the boundaries is the difference between a tool and an exposure.

Wallcrest Technology DeskPublished 12 Aug 2026, 10:10 UTCUpdated 12 Aug 2026, 10:10 UTC6 min read
Staples Credit Card
Photo: JeepersMedia · BY 2.0

The short answer

  • Access is granted through regulated interfaces, not by handing over passwords.
  • Consent is scoped and time-limited, and can be withdrawn at the bank.
  • Payment initiation is a separate permission from data access.

Open banking frameworks require banks to let licensed third parties access account information, or initiate payments, when the customer consents. The mechanism is an authenticated interface, so the third party never holds the customer's banking credentials.

Two different permissions

  1. Account information: read access to balances and transactions, used for budgeting, accounting and affordability checks.
  2. Payment initiation: the ability to instruct a payment from your account, used at checkout and for account top-ups.

Scope and duration

Consent specifies which accounts, which data, and for how long. Access expires and must be renewed. Both the provider and the bank must offer a way to revoke it, and revocation at the bank works even when the app does not cooperate.

Where it is heading

Successor frameworks extend the same consent architecture beyond payment accounts into savings, investments, pensions and insurance, with clearer liability rules and compensation for interface access.

Sources

Spotted an error? Tell our corrections desk.

Share

open bankingAPIsdataregulation