3 ms·
A (UK) Open Banking API for Personal Use: Meet Endute Connect
- ggm 1mo agoNeeds to be a LOT more overt about where your keys to your specific financial institution live, and what permissions you overtly and covertly gave them in this. Sure, the front-end promise is "read only" but can you explain how the back-end API to the fintech side enforces that? Where is the contract over this being RO in that side, not on the front side? I don't think all the money machines hand out "this is a read only token" automatically. So I worry the surface promise is papering over a risk. holding a hash means that .. what? I have to manage the actual tokens in my edge device and your route to the event is through me?
- UniSpheryk 1mo ago[flagged]