What Is Open Banking, and How Does It Work in the UK?
By Rendict Staff · Updated August 14, 2026 · 5 min read
Open Banking is an FCA-regulated framework that requires UK banks to give authorised third-party apps read-only access to your bank transaction data — with your explicit permission — through a secure API connection. It's the technology that allows budgeting apps like Emma, Plum, and Snoop to connect to your bank account and show your transactions without you needing to share your password.
This article is for information only and does not constitute financial advice.
The Short Answer: What It Actually Does
When you connect a budgeting app to your bank account, you're using Open Banking. Instead of giving the app your online banking username and password (which older "screen scraping" methods used to require, and which is now prohibited), you're redirected to your bank's own secure login page, where you authorise a specific, limited permission: "allow this app to read my transaction history for X days." That authorisation generates a time-limited token the app uses to fetch your data — a token that expires, that you can revoke at any time, and that only allows reading, not writing or initiating payments.
The Legal Foundation
Open Banking connections are governed by the FCA under PSD2, the Payment Services Directive 2. When you link an account, you grant the app a time-limited, read-only access token that typically expires every 90 days and must be renewed — at which point you re-authorise via your bank's own authentication flow. Your bank can revoke access at any time without notice to the third party.
This regulatory framework is why reputable UK budgeting apps using Open Banking are safer to connect to your bank than apps asking for your password directly. The permission is explicit, limited, and reversible.
What Third-Party Apps Can and Cannot Do via Open Banking
Can do: Read your transaction history, balances, and account details within the authorised permission scope.
Cannot do: Initiate payments, move money between accounts, change account settings, or take any action within your bank account. Open Banking access is strictly read-only for consumer-facing budgeting and tracking apps.
Cannot do: See your full banking password or login credentials. The app never receives these — you authenticate directly with your bank.
How the Connection Actually Works Step by Step
- You tap "connect your bank" in an app like Emma or Plum
- You're redirected to your actual bank's secure login page (not a page controlled by the app)
- You log in as normal and approve the specific permission being requested
- Your bank generates a time-limited access token and passes it to the app
- The app uses this token to fetch your transaction data
- The token expires (typically after 90 days) and you'll need to re-authorise to continue the connection
Why Some UK Banks Are Better Than Others to Connect
Not all UK banks implement their Open Banking APIs with equal reliability. The major digital banks (Monzo, Starling, Revolut) have built their entire infrastructure with API-first design, making connections to apps like Emma and Snoop consistently reliable. Some older high street banks implemented their Open Banking APIs more reluctantly and with less investment, resulting in connections that can drop, lag, or miss recent transactions. This is a meaningful real-world factor — UK bank connections to YNAB can be less reliable than in the US, with some users ending up manually importing transactions — and it's worth checking how well your specific bank connects to any app before committing to a paid tier.
Open Banking vs Screen Scraping: Why the Difference Matters
Before Open Banking was mandated, some financial apps accessed bank accounts by logging in as you — storing your password and periodically fetching your transaction data as if they were you. This "screen scraping" approach was legally ambiguous and a meaningful security risk: the app had your actual credentials, meaning if the app was breached, so was your banking password. Open Banking eliminated this by creating a regulated, token-based alternative that doesn't require apps to ever hold your credentials.
Is Open Banking Safe to Use?
Yes, provided you stick to FCA-registered apps and providers. The practical safety checklist: verify any app is listed on the FCA register before connecting it to your bank; never authorise an app that asks for your banking password directly; check how frequently the connection token expires and make sure you're comfortable with the re-authorisation process; and remember you can revoke any app's access at any time through your bank's own app or online banking settings.
Transparency Mode: What Happens If You Say No
If you decline an Open Banking permission request or later revoke it, the app simply loses the ability to fetch new transaction data — your bank account itself is entirely unaffected, and nothing about declining or revoking access changes how your bank account functions day to day. This asymmetry is part of what makes Open Banking meaningfully safer than the old screen-scraping approach: revoking access is a clean, one-sided action that can't be blocked or delayed by the app on the other end.
Frequently Asked Questions
See the FAQ section above for the most common questions on whether Open Banking shares your password, how to revoke access, what happens to your data after disconnecting, and why connections periodically expire.
For specific app recommendations that use Open Banking, see our Best Budgeting Apps UK 2026 and Best Personal Finance Apps for Beginners UK 2026 guides.
| Product | |||
|---|---|---|---|
| 4.4 | GBP 4.99 | Check price | |
| 4.3 | GBP 85.00 | Check price |
Frequently asked questions
No — reputable apps use Open Banking, which is regulated by the FCA. They can read your transaction data but can't move your money without explicit authorisation. They never receive your actual banking password.