Complete UK Banking Guide 2026 — Current Accounts, Switching & Getting the Best Deal

Open Banking UK 2026 — How It Works, What It Shares, and How to Stay Safe

Open banking lets regulated apps access your bank data securely with your consent. Find out how it works, which apps use it, and how to revoke access.

Open banking is the technology behind many of the UK’s most useful money apps — from budgeting tools to mortgage eligibility checkers. Introduced by the FCA and CMA in 2018, it lets regulated apps securely access your bank account data with your explicit consent, using secure APIs rather than your password.


How Open Banking Works

Open banking operates under the Payment Services Regulations 2017. UK banks are required by the Competition and Markets Authority (CMA) to give authorised third-party providers (TPPs) access to customer data via standardised APIs — but only when the customer consents.

The process works like this:

StepWhat happens
1. You choose an appSelect a budgeting tool, mortgage checker, or other open-banking-powered service
2. App requests accessThe app specifies exactly what data it wants: read-only account data or payment initiation
3. You authenticate via your bankYou are redirected to your bank’s own login — your credentials never go to the third-party app
4. Access is grantedA secure, time-limited API token allows the app to access the specified data
5. You can revoke any timeThrough your bank’s app or online banking under connected apps / open banking permissions

Your bank password is never shared with the third-party app. The secure token is what grants access, and it expires or can be revoked at any time.


Two Types of Open Banking Access

Not all open banking access is the same. There are two distinct permission types:

Access typeWhat it allowsCommon use cases
Account Information (read-only)View balances, transactions, account detailsBudgeting apps (Emma, Plum), mortgage affordability checkers, credit score tools
Payment InitiationInitiate a payment from your accountPay-by-bank at checkout, instant bank transfers via apps

Payment initiation is a much stronger permission. When an app requests it, your bank will prompt you to authorise the specific payment amount before it proceeds — the app cannot silently move money.


How to Check an App Is Authorised

Before granting any open banking access, verify the provider is FCA-authorised:

  1. Go to the FCA register
  2. Search for the app or company name
  3. Confirm it has Account Information Service Provider (AISP) or Payment Initiation Service Provider (PISP) permissions

If the provider is not on the FCA register, do not grant access. This is the single most important safety check with open banking.


Open Banking vs Traditional Screen Scraping

Before open banking, some apps used “screen scraping” — asking for your full bank login credentials to log in as you and harvest data. This is insecure and most banks now prohibit it. Open banking replaced screen scraping with a secure, consent-based API system where your credentials stay with your bank.


The Digital Pound (UK CBDC)

The Bank of England and HM Treasury are exploring a central bank digital currency (CBDC) — a digital form of pound sterling issued directly by the Bank of England. Key facts as of 2026:

FactDetail
Official nameThe digital pound (informally: “Britcoin”)
StatusDesign and consultation phase — no launch date confirmed
Who issues itBank of England (not a private company or crypto project)
Relationship to cashWould complement, not replace, physical cash
Privacy concernsHM Treasury has confirmed the digital pound would not give the government real-time visibility of individual spending

The digital pound is entirely separate from Bitcoin and other cryptocurrencies. It would be a state-issued, stable-value digital currency.


E-Money vs Bank Accounts

Open banking connections can be made to both bank accounts and e-money accounts. Understanding the difference matters for how your money is protected:

Provider typeExamplesFSCS-protected?
Fully licensed UK bankMonzo, Starling, Chase, BarclaysYes — up to £85,000
E-money institutionRevolut (UK), Wise (UK), PayPalNo — safeguarding only

For open banking read-only connections, the distinction is less critical — you are only sharing data, not deposits. For payment initiation and stored balances, the protection difference is significant.


Articles in This Hub


Sources

  1. Open Banking Implementation Entity (OBIE)
  2. FCA — Open banking and payment services
  3. Bank of England — Digital pound
  4. FCA — Check if a firm is authorised