Skip to main content

Open Banking

Overview​

A European framework that lets users grant regulated third parties access to their payment accounts. Swan's Open Banking service lets licensed providers retrieve account information and initiate payments on behalf of Swan account holders, under PSD2.

Swan uses Salt Edge as the PSD2 compliance platform that connects Third-Party Providers (TPPs) to Swan's accounts.

Swan supports three Open Banking services.

ServiceAbbreviationDescription
Account Information ServiceAISTPPs can access account balances and transaction history.
Payment Initiation ServicePISTPPs can initiate SEPA Credit Transfers directly from accounts.
Bulk Payment Initiation ServiceBulk PISTPPs can initiate batched SEPA Credit Transfers directly from accounts.
Open Banking vs Swan GraphQL API

Swan's GraphQL API allows partners to embed banking services into their products. The Open Banking API enables regulated TPPs to offer aggregation and payment services to users who already hold Swan accounts. These are two distinct access models.

How it works​

An Open Banking flow involves three parties: a software application (such as accounting or financial management software), a TPP (a regulated aggregator the software works with), and a Swan user.

The connection is established as follows.

  1. The user works with a software application and wants to connect their Swan account to it.
  2. The software relies on a TPP to establish the bank connection.
  3. The TPP sends an authorization request to Salt Edge, Swan's PSD2 compliance platform.
  4. Salt Edge redirects the user to Swan's consent application.
  5. The user authenticates with Strong Customer Authentication (SCA).
  6. The user grants explicit consent to the TPP on behalf of the software.
  7. Salt Edge receives an access token and enables data access or payment initiation.
  8. The software application can now access account data (AIS) or initiate payments (PIS) on behalf of the user.
TPPs don't connect to Swan directly

All requests go through Salt Edge, which acts as the compliance layer between TPPs and Swan.

Architecture​

ComponentRole
Software applicationThe application the end user interacts with, such as accounting, finance, or ERP tools.
TPPRegulated aggregator the software works with to access bank data or initiate payments.
Salt EdgePSD2 compliance platform that manages TPP registration, authentication flows, and data formatting to the Berlin Group standard.
PSD2 ConnectorIntegration layer between Salt Edge and Swan's core systems.
Swan GraphQL APISource of account data and payment execution.

Ecosystem​

Open Banking relies on a network of regulated TPPs that connect banking data to software applications.

Connected TPPs​

List maintained by Salt Edge

This list reflects TPPs registered with Swan's Open Banking infrastructure as of May 2026. The list is maintained by Salt Edge and may change.

Legal entityCommercial nameTypeCountryDescription
BridgeBridgeAIS and PISπŸ‡«πŸ‡· FranceOpen Banking API for payment initiation and financial data aggregation.
LinxoLinxo ConnectAIS and PISπŸ‡«πŸ‡· FranceOpen Banking solutions by Linxo Group, a CrΓ©dit Agricole subsidiary.
FintectureFintectureAIS and PISπŸ‡«πŸ‡· FrancePayment initiation and bank data platform for B2B payments.
PowensPowens (formerly Budget Insight)AISπŸ‡«πŸ‡· FranceEuropean Open Finance platform for account aggregation and financial data.
SI-ExpertiseSI-ExpertiseAISπŸ‡«πŸ‡· FranceFrench regulated TPP.
WildmeeWildmeeAISπŸ‡«πŸ‡· FranceFrench regulated TPP.
finAPI GmbHfinAPIAIS and PISπŸ‡©πŸ‡ͺ GermanyGerman Open Banking platform, used for accounting and ERP integrations.
fino run GmbHfino.digitalAISπŸ‡©πŸ‡ͺ GermanyAI-based account analysis and Open Banking solutions for businesses.
MRH applications GmbHMRH applicationsAISπŸ‡©πŸ‡ͺ GermanyGerman regulated TPP.
GoCardlessGoCardlessAISπŸ‡¬πŸ‡§ UKGlobal payment and bank debit platform.
Unlimit EU LtdUnlimitPISπŸ‡¨πŸ‡Ύ CyprusGlobal fintech offering payment processing, BaaS, and Open Banking payment initiation services.
iban-XS B.V.ibanXSAIS and PISπŸ‡³πŸ‡± NetherlandsPSD2-regulated payment and Open Banking services across Europe.
Isabel NV/SAPontoAISπŸ‡§πŸ‡ͺ BelgiumB2B Open Banking platform for accounting and ERP integrations.
Digiteal SADigitealAIS and PISπŸ‡§πŸ‡ͺ BelgiumE-invoice presentment, electronic payments, and Open Banking.
BudgetBakers s.r.o.Wallet by BudgetBakersAISπŸ‡¨πŸ‡Ώ Czech RepublicPersonal finance management app with over 10 million users.
SPENDEE a.s.SpendeeAISπŸ‡¨πŸ‡Ώ Czech RepublicMoney manager and budget planner app.

Accounting and financial software​

The following table lists some of the accounting and financial software in Swan's markets and the TPP each one uses to access bank data, as of July 2026. This list isn't exhaustive.

SoftwareCountryTPPService
PennylaneπŸ‡«πŸ‡· FranceBridgeAIS
MyUnisoftπŸ‡«πŸ‡· FrancePowensAIS
HoldedπŸ‡ͺπŸ‡Έ SpainGoCardlessAIS
SageπŸ‡«πŸ‡· France and EuropeBridgeAIS
InqomπŸ‡«πŸ‡· FranceBridgeAIS
EBPπŸ‡«πŸ‡· FrancePowensAIS
XeroπŸ‡¬πŸ‡§ UK and EuropeYodleeAIS
DATEVπŸ‡©πŸ‡ͺ GermanyfinAPIAIS
Cegid QuadraπŸ‡«πŸ‡· FranceProprietaryAIS
Open Banking or direct API access

If a user's accounting software is different from their Swan partner, they connect their Swan account through the Open Banking consent flow, using the TPP chosen by that software.

If the accounting software is the Swan partner, Open Banking isn't involved: the partner already has real-time access to the user's transactions through the Swan API.

Strong Customer Authentication​

A PSD2 requirement that protects sensitive banking actions with two independent authentication factors. Strong Customer Authentication (SCA) combines something the user has (such as their phone) with something they know or are (such as a passcode or biometric). PSD2 requires SCA for Open Banking consent and payment confirmation.

Every Open Banking connection requires SCA. This works the same way as when a Swan user logs into Web Banking or initiates a payment: two authentication factors are required.

  1. Possession factor: the user receives a 6-digit OTP code by SMS, tied to their phone or SIM card.
  2. Knowledge or inherence factor: the user enters their 6-digit passcode, or uses Face ID or Touch ID.

Token architecture​

Two separate tokens govern the Open Banking connection.

TokenLifecycleManaged byDescription
User consent token180 daysTPP and Salt EdgeGrants the TPP access to account data. Requires user SCA to renew.
Technical refresh token24 hoursSwan and Salt EdgeMaintains the data refresh connection. Renewed automatically.
User token renewal

Every 180 days, the user must re-authenticate with SCA to renew the consent token. PSD2 requires this. Renewal is initiated by the TPP through Salt Edge. Swan cannot trigger this renewal directly.

Technical token refresh

Most TPPs can perform up to 4 refreshes per day. For details, refer to the PSD2 EBA Q&A on refresh frequency.

  • AIS: one consent grants data access for up to 180 days, then requires re-authentication.
  • PIS: each payment requires its own consent.
Transactions since account creation

The 180-day limit applies to how long the consent grants data access, not to the time range of transactions you can view. By default, Swan returns all transactions since the account was created.

Users can ask their TPP to revoke the consent token. Swan can't revoke it directly.

Under PSD3

With PSD3 (the third Payment Services Directive), allowing end users to revoke their consent directly from their online banking interface will become mandatory.

Registration and testing​

To get access, TPPs first apply to Salt Edge at compliance-hub@saltedge.com. Salt Edge reviews the application and, if approved, grants access to their platform and Swan's PSD2 API. Testing happens in Salt Edge's own sandbox, not in Swan's Sandbox environment.

Key concepts​

All Open Banking terms are defined in the glossary.