3.1 How open banking APIs work
Mechanically, the relationship between a bank and a third-party provider (TPP) under an open banking model is fairly straightforward, even if the surrounding governance is not. A bank opens defined, secured endpoints into its core banking system; a third-party platform integrates with those endpoints and requests specific data or functions — an account balance, a transaction history, a payment initiation — through what is generally called an API call; and the third-party application then exposes that data to the end user through its own interface (Ann & Iqbal, 2017) (Figure 1). This is, notably, a narrower channel than screen scraping ever was: rather than handing over a password and letting a third party log in as the customer, the customer grants a scoped, revocable authorization, and the bank retains visibility into exactly which parties are calling its APIs and for what purpose.
From the customer's side, the experience is meant to feel almost incidental — a redirect to the bank's own login page, a credential entry, and a confirmation screen, after which the third-party app simply has the access it needs (Sullivan, 2022) (Figure 2). Providers such as Plaid, Yodlee, Apigee, and Xignite have positioned themselves as the connective tissue in this ecosystem, offering pre-built integrations across thousands of institutions so that an individual fintech company does not have to negotiate a bespoke technical relationship with every bank it wants to support (Cope et al., 2018). It is worth noting, too, that this intermediary layer is not merely a convenience; for smaller fintech firms lacking the negotiating leverage of an Apple or a Google, standardized open banking APIs are arguably what makes broad bank connectivity commercially feasible at all.
3.2 The PSD2 regulatory scaffold
None of this would have unfolded quite the way it has without PSD2. Adopted in October 2015 as a successor to the original 2007 directive, PSD2 requires banks operating in the EU and EEA to provide regulated third parties with access to customer account data, provided the customer consents (Gorzala, 2020; Zachariadis, 2020). Among its more consequential provisions is Strong Customer Authentication (SCA), intended to curb online payment fraud — though its rollout was, by most accounts, bumpier than regulators initially hoped, with low consumer awareness and retailer readiness prompting a deferral of full enforcement into 2020 amid concern over lost transactions and cart abandonment (Zachariadis, 2020). Reading across the regulatory commentary, PSD2 comes across less as a single decisive event and more as an ongoing negotiation between the goal of an open, standardized market and the practical difficulty of getting an entire continent's banks, merchants, and customers to move in step (Pike, 2018).
3.3 Stakeholder perspectives: customers, banks, and the anxiety of sharing
The literature on stakeholder response to open banking is, frankly, more cautionary than the technology narrative alone would suggest. On the customer side, adoption-behavior research — much of it conducted in the context of mobile banking rather than open banking specifically, but instructive nonetheless — has found that gender, education, and income shape willingness to adopt digital
Table 1: Reported Indicators of Open Banking Adoption and Investment (as Cited in the Secondary Literature). Note. These figures are reported as they appear in the secondary/industry literature synthesized for this review. No independently auditable primary dataset could be traced for these specific values; they are presented as indicative of the literature's general tone rather than as verified statistics.
|
Indicator
|
Reported Value
|
Verification Status
|
|
Global customer support for API banking adoption
|
~26%
|
Reported in industry literature; primary source not traceable
|
|
Global fintech investment, 2010
|
<$2 billion
|
Reported in industry literature; primary source not traceable
|
|
Global fintech investment, forecast 2019–2021
|
Up to ~$150 billion
|
Reported in industry literature; primary source not traceable
|

Figure 1. The Open API Authorization and Data-Request Flow Between Developers, Customers, and Third Parties. This figure illustrates how a developer connects to a third party's open API, which any developer can access because the API is open by design. It then shows a customer initiating a request (e.g., to view an account balance) from within the developer's app, with the request transmitted via the API. Finally, it depicts the third party receiving the request and its systems automatically returning the requested data through the same API channel. Together, the panels trace the full round-trip of an open banking API transaction from initial connection to data delivery.

Figure 2. The Open Banking API Process From the Customer's Perspective, Connecting a Banking App to Multiple Banks. This figure shows a customer-facing banking app displaying account balances (a current account, a second current account, and a credit card) alongside a central user icon representing the customer. Arrows illustrate data flowing bidirectionally between the customer and an API hub, which in turn connects to three separate bank institutions on the right. The diagram demonstrates how a single app can aggregate and display financial data pulled from multiple banks simultaneously through standardized API connections. It visually reinforces the account-aggregation use case that is central to open banking's customer value proposition.

Figure 3. The Functional Domains of Open Banking Within the Fintech Ecosystem (Adapted from FSBT.TECH, "Open API Platform," 2019). This figure presents a wheel diagram with "Open Banking" at its center, surrounded by ten interconnected functional domains: strategy and business model, customer centricity, deals and structure, data management and analytics, technology, tax, cybersecurity, fraud, risk, and regulation. Each segment represents a distinct organizational or operational area that banks and fintechs must address when implementing open banking. The circular, unified layout emphasizes that these domains are interdependent facets of a single ecosystem rather than isolated concerns. The figure is adapted from an industry source (FSBT.TECH, 2019) and is used here to frame the multidimensional scope of open banking adoption discussed in the review.
financial tools, and that trust and security concerns, more than price or convenience, tend to dominate customer hesitation (Palani & Yasodha, 2012; Thakur & Srivastava, 2013). Reported industry figures, cited here with the caveat that a traceable primary dataset could not be located in the available source material, put customer support for API-based banking at a relatively modest level — on the order of roughly a quarter of customers surveyed globally — with the shortfall attributed less to outright opposition than to a lack of visible, tangible value customers can point to in exchange for handing over access to their data (Table 1).
Banks, for their part, do not appear to be uniformly enthusiastic either. The same body of literature that celebrates open banking's innovation potential also documents a real institutional anxiety: banks risk losing some control over the customer relationship and, in the more pessimistic readings, risk a degree of product cannibalization as third parties intermediate services banks once delivered directly (Gorzala, 2020). At the same time, non-bank competitors — pure-digital entrants, large technology firms, and a fast-growing fintech sector — have not been shy about entering the space; industry commentary describes fintech investment climbing from a comparatively modest base around 2010 to figures reported in the tens of billions of dollars by the end of the following decade, though again, as with the customer-adoption figure above, this specific investment trajectory is reported here as it appears in the secondary literature rather than as an independently verified dataset (Omarini, 2018; Zachariadis & Ozcan, 2017).
3.4 Applied use cases across the fintech ecosystem
Despite institutional ambivalence, the range of applications built on open banking APIs has, in practice, grown fairly quickly (Figure 3). Payment processors such as Adyen use open banking APIs for account verification and payment processing, while consumer-facing apps like Tikkie in the Netherlands allow peer-to-peer payments initiated through messaging platforms. Account-aggregation services — Plaid, which by some accounts connects to more than 11,000 financial institutions across the US, UK, Canada, and Australia, and Yodlee, which offers similar aggregation for developers — give customers a single consolidated view of accounts that might otherwise be scattered across several institutions (Cope et al., 2018). Personal finance management tools such as Mint and PocketGuard build on that same aggregated data to help users track spending and set savings goals, and small-business accounting platforms such as Xero and Wave use the same underlying connectivity to reduce the manual data entry that has traditionally burdened bookkeeping. Taken together, these examples suggest that wherever a service depends on knowing, reliably and in near-real time, what is actually happening in a customer's account, open banking APIs have found a foothold.
3.5 Security architecture and the trust problem
It would be a mistake, though, to treat the trust problem as merely a matter of customer perception rather than genuine technical stakes. Providers in this space generally layer several protections — standard encryption, Transport Layer Security, multi-factor authentication, continuous security monitoring, and third-party code review — around the authorization flow, and require credentialing before a financial institution's endpoints can be called at all (Sullivan, 2022). Whether that architecture is sufficient to earn the level of trust screen scraping never quite achieved is, in some sense, an empirical question the industry is still answering in real time; the technical case for open banking's superiority over credential sharing is fairly strong, but technical superiority and perceived trustworthiness do not always move in lockstep, and the modest customer-adoption figures discussed above (Section 3.3) suggest that gap has not yet closed.