What Is Open Banking? A Guide for PSPs and Banks

A practical guide to open banking for PSPs and banks: what it is, how the APIs and consent model work, what PSD2 requires, and where the real opportunities sit for payment providers.

July 27, 2026

Open banking is rapidly becoming a critical component of how PSPs and banks design their products and offer their services. The following guide will provide an overview of what an open banking system is, how open banking infrastructure works, its regulatory requirements, and the opportunities it creates for PSPs that seek to build upon the capabilities that it offers.

What is open banking?

Open banking allows banks to share the data within their bank accounts with third parties through Application Programming Interfaces (APIs), as long as the bank customer has provided their consent to that sharing. The bank can no longer hold onto the customer's transaction history and account information exclusively, but can permit access to this information through an API for various third-party applications.

Open banking is often confused with open finance. Open banking allows third parties to access bank and payment account data. Open finance takes this a step further by allowing third parties to access information from bank accounts, investments, loans, insurance, and more.

Build open banking-ready payment infrastructure with DECTA

PSD2-compliant processing, digital banking, and card issuing in one platform.

Explore DECTA's solutions

How open banking works

Open banking permits third parties to access a customer's bank accounts via regulated APIs, tokens that represent consent for a third party to access their bank accounts, and through standardized authentication procedures, as opposed to giving a third party access to their bank login information.

Flowchart showing how open banking connects a bank's core system to a third-party app through consent and API access.

The role of APIs and standardized access

An open banking API allows third-party applications to access a customer's bank account data or initiate a payment from that account. Banks decide what data a third-party application can access, such as account balances, transaction history, the customer's account details, or their ability to initiate a payment from that account. Behind that API sits the bank's core banking system, the internal ledger that actually holds account balances and processes transactions. The API acts as a controlled gateway to that system rather than direct access to it, which is what keeps the third party from touching the bank's internal infrastructure.

The more standardized the API protocols among banks, the easier it will be for a third party to access data from or initiate payments from various banks. On the other hand, if each bank has its own API protocols, a third party will have to program their applications to work with each bank individually.

pro-tips-icon

Tip:

When evaluating a bank or processor to integrate with, check whether their API follows a standardized specification. A non-standard API means your team builds a custom integration for every new connection instead of reusing one.

Consent and authentication

Open banking mandates that customers authenticate themselves to third-party applications via a security protocol called Strong Customer Authentication (SCA). SCA is an authentication protocol that does not require a third party to use a customer's bank login and password. Instead, the bank will authenticate the customer directly, through processes like two-factor authentication, and issue a token to the third party that permits that third party to access the account for a pre-determined period.

The customer will have to provide consent for a third-party application to access their bank account. They can also revoke that consent at any time.

The three types of open banking APIs

  • Data APIs: allow a third-party application to access a bank's account data. This information is usually read-only and does not allow for any initiation of payments from that bank account.
  • Transaction APIs: also known as payment initiation APIs, allow a third-party application to initiate a payment from a bank account. This third-party application would usually be an e-commerce website that would permit a customer to authorize a payment from their bank account to that merchant.
  • Product APIs: provide a third-party application with information on the financial products that a customer has with their bank. These APIs are mostly used by third-party financial comparison websites.

The regulatory foundation: PSD2 and beyond

Open banking, as it exists today, is a regulation mandated by regulatory authorities. In Europe, that regulation is the revised Payment Services Directive (PSD2).

PSD2 and Strong Customer Authentication

PSD2 mandates that banks in the European Union must allow third-party applications and service providers with a license to access customer data in their bank accounts and initiate payments on their behalf.

Strong Customer Authentication (SCA) was also mandated for electronic payments under PSD2. For the payment industry, this means that 3D Secure 2.0 (3DS2) was implemented as the protocol to meet SCA compliance for online electronic payments. 3DS2 allows the customer to authenticate to the website performing the transaction and also authorize the transaction using their bank's authentication methods, while also ensuring that the checkout and purchasing process for customers does not get abandoned due to too many authentication steps.

Comparison of AISP and PISP open banking licenses and what each permits a PSP to do.

AISP and PISP licensing

There are two types of licenses that a third-party application must hold to have open banking connectivity to a customer's bank account under PSD2. Depending on what type of license a PSP holds, they will be able to offer different services to their customers.

  • Account Information Service Provider (AISP): license allows a third party to retrieve and view information from a customer's bank accounts, but does not permit any transfers of funds from those accounts.
  • Payment Initiation Service Provider (PISP): license allows a third party to initiate payments from a customer's bank accounts on their behalf.

A PSP that creates a budgeting application will require an AISP license. A PSP that builds a pay-by-bank application will require a PISP license. Some companies offer both services and licenses.

Who uses open banking?

  • Banks and PSPs use open banking to provide their customers with better banking experiences without having to rebuild their existing banking or payment infrastructure.
  • Fintech companies build applications on top of bank accounts without having to hold those bank accounts themselves. These companies use the data and account information to build products for customers, such as budgeting applications and lending platforms.
  • Many e-commerce websites and merchants use pay-by-bank services offered by the PSPs that serve these merchants and provide them with customer service and support.
  • The individual bank customer whose data is shared is at the center of open banking. All data sharing between the bank and the third-party application occurs with the customer's consent.

Benefits of open banking

  • No card transaction costs: open banking allows third parties to initiate payments from bank accounts directly, so there is no need for the customer to use their bank or credit card for payments. By avoiding the use of credit card transactions, there is no card network cost associated with those transactions for the third party, usually an e-commerce business.
  • Better decisioning: open banking provides better decision-making for third-party companies by allowing them to have real-time access to customer account information. Instead of decisions being made based on static data from bank accounts, decisions for things like underwriting or lending can be based on real-time data from a customer's bank account.
  • Faster onboarding without documentation: with open banking, third-party companies are no longer required to ask customers for bank and financial documentation to establish an account with them. Open banking allows companies and banks to pull that information directly from the customer's bank account.

Open banking use cases in the payments industry

Pay by bank applications allow customers to complete the checkout process on e-commerce websites by authorizing a payment from their bank account.

Open banking allows account-to-account payments to be initiated without the use of a credit card. The process of initiating these payments is faster than the process of using credit cards.

Open banking allows third parties to pull real-time account and customer information during the onboarding process of a customer for a third-party company. This can be used to verify the customer's bank account and their financial standing.

PSPs can use open banking to verify the income of a customer who is applying for a loan product. Instead of depending upon the information from the customer's credit report, a PSP can verify the income from the customer's bank account transaction history directly.

How DECTA supports PSPs and banks with open banking-ready infrastructure

Open banking was made possible thanks to the development of infrastructure that can support it. For instance, DECTA offers acquirer and issuer processing services that include 3D Secure 2.0 implementations. These implementations support the PSD2 regulation of strong customer authentication.

Additionally, DECTA's digital banking platform combines account data, payment initiation, and card issuing into a single customer-facing experience, allowing customers to access their banking information and perform banking transactions directly through third-party applications.

Finally, if a PSP wants to offer customers a digital card and account without acquiring a banking license themselves, DECTA can provide them with BIN sponsorship and white-label card-issuing services to help them get to market.

Ready to talk open banking infrastructure?

Our team can walk you through how DECTA fits your PSD2 and SCA compliance needs.

Get in touch