4 ms·
If anyone's looking for API access to UK high street banks: https://teller.io https://teller.io
by djm_ 9y ago
If anyone's looking for API access to UK high street banks: https://teller.io https://teller.io
- sjtgraham 9y agoThanks! Founder here. Currently in private beta, but if you're with Santander, Nationwide, RBS, Natwest, Ulster Bank NI, or IOM Bank I can give you access - sg@teller.io.
- bjackman 9y agoHave you integrated this directly with the banks or do you take user's login details and scrape the online banking sites (like MoneyDashboard does)? I would be more than willing to switch banks just to get a read-only API for this kind of thing, if only it was properly integrated (read: I don't have to give my login details to a third party)
- sjtgraham 9y agoTeller uses the APIs used by the bank's own mobile app, i.e. they have been reverse-engineered. Whether Teller requires personal credentials is dependent on the bank's implementation. Barclays (integration temporarily unavailable), and Nationwide use EMV CAP (the card reader) for registration. If we can figure out a way to not take user credentials, we will always take that route. I recommend Starling and Monzo if you want a read-only API for your own account, but if you want to build apps for 65 million customers they're not yet much use to you.
- bjackman 9y agoCool, thanks for the info. It's such a shame we have to resort to (slightly) compromising on security & reliability to make banking work for consumers. Do you think there's a future where there's a standard API that banks expose for authorised apps to get at customer data?
- jsudhams 9y agoI think you can use yodlee and it good for read only purpose.
- sjtgraham 9y agoYodlee isn't read-only. They only expose a read-only API. Ordinarily you're giving them the credentials you use to login to online banking, therefore they notionally have the same access you do. Yodlee is also beyond broken and is made available on very unfriendly terms, e.g. Pricing covered by NDAs complete with very significant setup fees, and minimum commitments.
- fastball 9y agoIs support for Barclays in the pipeline?
- sjtgraham 9y agoBarclays has already been integrated. We temporarily took the integration offline in good faith, pending commercial negotiations with them. Sadly, this seems like it was a ruse to buy themselves time to make changes to the app that break the integration. Their app is the most hardened app I've ever seen and it's challenging to reverse, but it's in progress. Don't worry, it will be back soon. :)
- deadbunny 9y agoUsing undocumented APIs that are able to be changed on a whim doesn't seem like something I would want to trust my finances too. This is not meant in a bad way it just seems a bit too risky for me to trust moving my money about with. I am glad you are doing something though, the state of banking access is atrocious.
- deleted 9y ago[deleted]
- Tharkun 9y agoHow will teller be impacted by PSD2? Will it make your life easier?
- sjtgraham 9y agoPSD2 will raise awareness of APIs, but I expect what is delivered by banks to be disappointing. There are many reasons to suspect this all flowing from the reality that opening up access to the customer is in the exact opposite of their own best interests. Even if they act in good faith, which in my opinion they are generally speaking not, the design is by committee, with no users (account owners or developers) involved and their needs taking a back seat. This is the opposite to Teller's approach.
- lol768 9y agoForgive me for the naive question, but how does this stack up in terms of the legality of what you're doing? I'm aware of some limited exceptions that would allow you to do this sort of reverse engineering for interoperability reasons in the EU. Also, isn't it going to be reasonably fragile? There's nothing stopping the banks (other than [in my experience] their general inability to make technical changes at a reasonable pace) pushing an update and breaking old API clients, right?
- sjtgraham 9y agoThanks for the questions: The legal one was looked at by lawyers earlier this year. There were two points to consider: - copyright infringement via reverse engineering - "hacking" statutes, e.g. Computer Misuse Act 1990 They concluded that there are no concerns in terms of copyright infringement, we have devised many non-infringing techniques for reverse-engineering and use them wherever possible, not least because they are easier to work with. When it is not possible to use such a technique this is where the exemption kicks in for creating inter-operable systems. FYI "infringement" occurs when transforming a low level language, e.g. machine code, into a high level representation. Computer programs are considered literary works, and their authors enjoy the full protection afforded as such. The hacking statutes are very broad and technically if you used my laptop to access your own email while I was away in the bathroom you would fall foul of computer hacking laws in the UK. They said action via this angle said is a low risk (despite lawyers being conservative by nature). Teller isn't actually liable anyway, as it does not "cause" the access, the user does. Can a user accessing their own bank account ever be considered unauthorized? Would a bank prosecute their own customers for doing so? Unlikely, given Yodlee has been able to operate without legal challenge for decades now. In terms of breakage, bank APIs rarely change. Most do not ever. The most aggressively defensive and technically competent bank IMO is Barclays and it takes them months to ship something to mess with me. They also can't just simply break something there is a window where both versions are supported where they advise users to upgrade before forcing the matter some releases down the line.
- lol768 9y agoThanks for taking the time to answer all that in so much detail, the legal aspect in particular is really interesting. Users staying on old versions is also a good point, and something I didn't consider. Best of luck with the future of Teller, you're doing something that I personally think consumer banks should've been offering for years and it's great to see someone filling that gap. I'm hoping Monzo and others end up pushing "legacy" banks into opening up API access but I guess the realist in me finds this unlikely.