Skip to content

A (UK) Open Banking API for Personal Use: Meet Endute Connect

endute.com
1 pointwillx861 comment
On HN

Comments

Needs to be a LOT more overt about where your keys to your specific financial institution live, and what permissions you overtly and covertly gave them in this.

Sure, the front-end promise is "read only" but can you explain how the back-end API to the fintech side enforces that? Where is the contract over this being RO in that side, not on the front side?

I don't think all the money machines hand out "this is a read only token" automatically. So I worry the surface promise is papering over a risk.

holding a hash means that .. what? I have to manage the actual tokens in my edge device and your route to the event is through me?

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.