and, to add insult to injury, it's my recollection that one must give those credentials to Plaid, not even entering them into your bank's website like a sane oauth2 dance. I always ensure I go to my bank's website and change my password afterward if I'm forced to use that MITM junk
I'm so jealous of PDS2 in the EU <https://www.berlin-group.org/> (although I guess it's easy for me to be jealous since I don't know if their banks actually implement the standards, but it's still a bunch better than the situation here)
There's "implementations" that allows them to satisfy the requirement and then there are usable implementations. User experience is not great in some cases.
I think you can apply to get access to some sandbox from your bank (at least one of my EU banks does this) where you get access to documentation and fake APIs. Then you can go through a lengthy process to have it approved, but in my case I think it also requires a proper business entity to move it to "production". This might differ from bank to bank.
Or, you can use something like GoCardless which provides a sort of aggregated API and "connection APIs" for making things simpler: https://gocardless.com/bank-account-data/
Not affiliated with them, but I do use GoCardless to automatically import transaction data from a couple of EU bank accounts to my local datastore.
I wish. It's only available to licensed AISPs that carry fun requirements such as:
> The license can be obtained within 6-9 months for the application fee of 6,800 EUR. The minimum capital requirement varies depending on the nature and scale of the AISP’s activities but is typically around 125,000 EUR. The amount is ultimately determined on a case-by-case basis by the Dutch Central Bank which is the regulator of the Dutch financial market.
I recently connected my Chase checking to my work expense system via Plaid, and it appeared to use an real integration - I was sent to a Chase domain to log on, which explained what data I was giving to Plaid _as well as_ what data I was giving to the third (fourth?) party.
I recall a similar experience linking Chase to my Schwab account.
I was pleasantly surprised that I was not asked to give my bank password to anyone but my bank.
PSD2 is a nice idea but nightmarish in practice. I used to use an app to track my finances and it would often fail to properly establish a "link" after successful authentication with mysterious error messages, bank connections would just randomly fail to refresh their data for hours, even days at a time, their services provider (the party sitting between your bank and your budgeting app) SAID it would require re-auth every 90 days, but in practice it seemed to start requesting authentication after a month or so.
To access your own data, it needs to go from your bank, to a licensed Account Information Services Provider (AISP), to your budgeting app of choice, and finally to you. You can't utilize PSD2 without involving all of those 3rd parties because banks don't offer PSD2 APIs to consumers and I've only seen AISP services sold B2B. [1]
I'm someone who has no issues using 2FA everywhere and carrying around a Yubikey, but even I got fed-up with constant re-authentication requirements: Enter bank email & password, next, next, confirm, approve, yes I'm sure, now take out your phone, unlock it, open the bank app, log in there, confirm that prompt, yes, i'm really sure. Then it takes 1-2 minutes to "connect" your account and load the latest data. Repeat for every bank account, every 30 days.
It beats trusting your banking password to some random 3rd party, but it's a pretty terrible experience as an end-user if you ask me.
[1] Someone pointed out GoCardless which seems to accept private customers as well, a welcome surprise.
I'm so jealous of PDS2 in the EU <https://www.berlin-group.org/> (although I guess it's easy for me to be jealous since I don't know if their banks actually implement the standards, but it's still a bunch better than the situation here)