You download a budgeting app, tap “connect my bank,” and a familiar-looking login screen pops up asking for your bank username and password. It feels a little strange to type your bank credentials into an app that isn’t your bank. So what actually happens next, and is it safe? Here’s the plumbing behind it, explained without the jargon.
What Actually Happens When You Type Your Bank Login Into an App
When you connect your checking account to a budgeting app, you’re rarely handing your password straight to that app. Most U.S. fintech apps route the connection through a middle layer called a data aggregator. Names like Plaid, MX, and Finicity (owned by Mastercard) sit between your bank and the app you actually use. You type your bank login into a screen that the aggregator controls, not the budgeting app itself. The aggregator verifies you with your bank, then hands the app a token, a kind of access pass, instead of your real password.
That distinction matters. It’s the difference between an app storing your actual bank password (risky) and an app holding a limited, revocable token that only unlocks specific data like balances and transaction history (safer). Most major apps, including the ones covered in our roundup of the best budgeting apps, use this token model today. Older or smaller apps sometimes still rely on an older method entirely.

Screen Scraping vs. Tokenized API Access
There are really two ways an app can pull your financial data, and they’re not equally secure. Screen scraping is the older approach: the aggregator logs into your online banking portal using your actual credentials, then reads the page the same way a browser would. Tokenized API access is newer: your bank exposes a structured, permission-gated channel that shares only the data you approve, without ever passing your password along.
| Question | Screen scraping | Tokenized API access |
|---|---|---|
| Is your bank password stored? | Often yes, by the aggregator | No, a token replaces it |
| What can the app see? | Whatever’s on the page, sometimes more than needed | Only the specific data fields you approved |
| Can you revoke access easily? | Sometimes only by changing your password | Usually yes, from your bank’s connected-apps settings |
| Who controls the connection? | The aggregator, largely invisible to your bank | Your bank, with visibility into what’s shared |
| Where it’s headed | Being phased out by most major U.S. banks | The direction regulators and banks are pushing toward |
Most large U.S. banks have shifted the bulk of their fintech connections to tokenized API access as of mid-2026, though screen scraping hasn’t fully disappeared, especially with smaller institutions and older app integrations.
Where the CFPB’s Open Banking Rule Stands in 2026
The Consumer Financial Protection Bureau’s Section 1033 rule was supposed to be the thing that finally standardized this. It would have required banks to make consumer financial data available to third parties through secure, standardized interfaces, free of charge, on request. The original rule set an April 1, 2026 compliance deadline for the largest institutions.
That deadline came and went without effect. A federal court enjoined the original rule earlier in 2026 after industry groups challenged it, and the CFPB is now rewriting it rather than defending the original version in court. As of mid-2026, there’s no finalized, enforceable open banking rule in place. The agency has signaled a new proposal is coming, but the timeline keeps shifting, and what survives in the rewrite (including whether banks can charge for data access) is still an open question. Nothing here is settled, so treat any specific date you read elsewhere as provisional.
The Bank-Fintech Fee Fight, in Plain English
Here’s the part that actually affects your everyday app experience. In late 2025, JPMorgan Chase and Plaid announced a paid data-access agreement, a notable shift because banks had historically provided this data for free (or fought aggregators over access). That deal opened the door for other large banks to start charging aggregators for the pipes that budgeting, investing, and payment apps rely on.
If that cost gets passed down, it could eventually show up as new fees on some financial apps, slower rollout of bank connections, or fewer free-tier options. Nothing has forced a specific price change on consumers yet, and outcomes may vary by bank and by app. But it’s worth understanding that the “free” connection between your bank and your favorite app isn’t automatically guaranteed to stay free or unrestricted going forward.
Is Plaid Safe? What FDIC Coverage Does (and Doesn’t) Cover
Plaid itself doesn’t hold your money. It’s a data pipe, not a bank, so FDIC deposit insurance doesn’t apply to Plaid directly, and it wouldn’t need to. What FDIC coverage protects is money sitting in an FDIC-member bank account, up to the standard limits, if that bank fails. It says nothing about whether a data connection is secure or whether a third-party app might misuse the data it receives.
That’s a distinction worth sitting with if you use a neobank or fintech-based account. Some apps built on a bank’s rails advertise “FDIC insured” in a way that can be easy to misread. We break down exactly what that structure means, and doesn’t mean, in our piece on whether Chime is a real bank. Separately, once your data leaves your bank through an aggregator, it’s also worth knowing where that information can travel afterward, including to data brokers who buy and resell consumer financial profiles; we cover that in our explainer on data brokers and financial data.

A Safety Checklist: Review, Limit, and Disconnect App Access
You don’t have to guess which apps have access to your accounts. Most major U.S. banks now publish this somewhere in your online settings. Here’s how to check:
- Find your connected-apps list. Look under Settings, Security, or “Manage Data Sharing” in your bank’s app or website. Chase, Bank of America, Wells Fargo, and most large banks now have a dedicated screen for this.
- Review what each app can see. Some connections show only balances and transactions; others may include account and routing numbers. If an app you don’t recognize or no longer use shows up, that’s a flag.
- Revoke access you don’t need. One tap in most bank portals disconnects the token. The app will simply stop syncing until you reconnect, and your bank password never has to change as a result.
- Check the app’s side too. Inside the budgeting or payment app, look for “linked accounts” or “connections” and remove anything stale from your end as well.
- Watch for re-authorization requests. If an app suddenly asks you to log in again out of nowhere, verify it’s a legitimate prompt from the app itself before entering anything.
- If something looks wrong, report it. Unauthorized data sharing or a connection you never approved can be reported to your bank first, and if that doesn’t resolve it, you can file a complaint with the CFPB.
The Takeaway
Open banking isn’t inherently risky, and it isn’t inherently safe either. It depends on which method is doing the connecting, which company is passing your data through the pipe, and whether you actually check what’s connected once a year. The technology that makes budgeting and investing apps convenient is the same technology worth occasionally auditing. Fifteen minutes in your bank’s settings menu is a reasonable trade for that peace of mind.
This article is for general educational purposes and isn’t financial, legal, or investment advice. Rules, fees, and bank policies mentioned here may change and can vary by institution; confirm current terms directly with your bank or the CFPB before making decisions.
Frequently Asked Questions
What is open banking in simple terms?
Open banking is the system that lets your bank share your account data, like balances and transaction history, with apps you choose to connect, using secure digital channels instead of you manually typing that information everywhere yourself.
How do budgeting apps connect to my bank account?
Most connect through an aggregator like Plaid, MX, or Finicity. You log in through a screen the aggregator controls, and the aggregator passes a limited access token to the app rather than your actual password.
Is Plaid safe to use?
Plaid uses encryption and, for most major banks, tokenized access rather than storing your raw password. No connection is risk-free, but Plaid’s model is generally considered safer than older screen-scraping methods. Reviewing and limiting what any aggregator can access is still good practice.
What is the CFPB’s Section 1033 open banking rule?
It’s a federal rule meant to require banks to share consumer financial data with authorized third parties through standardized, secure channels. A court injunction in 2026 paused the original version, and the CFPB is currently rewriting it, so no finalized rule is in force as of mid-2026.
Can I revoke an app’s access to my bank account?
Yes. Most major banks let you view and disconnect linked apps from a security or data-sharing settings page. Disconnecting stops the data flow immediately; it doesn’t require changing your bank password.
What are the main risks of open banking?
The biggest ones are apps requesting more data than they need, older screen-scraping connections that store credentials, and data eventually being shared with or sold to parties beyond the original app. None of that means you should avoid connected apps entirely, just that occasional review matters.