Person reviewing a banking app on a smartphone next to a laptop
Photo by cottonbro studio on Pexels

In July 2025, JPMorgan Chase sent pricing sheets to the companies that carry data between banks and apps. Forbes reported that the fees could cost Plaid alone something like $300 million a year, more than 75% of what Plaid took in during all of 2024. That document is the most important thing to understand about how budgeting apps access your bank account, and it has nothing to do with the question everyone asks, which is whether the connection is safe. The connection is reasonably safe. What almost nobody has explained is that it has also been free, on purpose, by law, and that the law is being rewritten right now. The fee fight only makes sense once you can see the thing being billed for, so the plumbing comes first.

How budgeting apps access your bank account without ever seeing your password

At a large bank, the sequence goes like this. You tap “connect account” inside the app. The app hands you off to an aggregator, a middleman company whose entire business is speaking to thousands of banks at once. Plaid is the best known, but Yodlee, MX, Finicity and Akoya do the same job. The aggregator opens a window that loads your bank’s own login page, on your bank’s own domain. You authenticate there, with your own credentials and your own two-factor code, and you pick which accounts to share.

Your bank then issues a token. A token is a long random string that means “this specific app may read these specific accounts for this specific person.” It is not your password. It cannot be reused anywhere else, it is scoped to read-only in almost every budgeting use case, and both you and your bank can revoke it without changing your login. The practical test of a good credential is whether losing it forces you to change anything else. A stolen password means changing your password. A revoked token means clicking revoke.

What flows back through that token is more than most people picture: balances, cleared and pending transactions, account and routing numbers, sometimes your name and address. If you have ever wondered why your app’s number disagrees with your bank’s, it is usually because the app is reading one of two different figures, which is worth understanding on its own since available balance and current balance are not the same thing.

Screen scraping is the older method, and it has not retired

Before tokens, there was screen scraping. You gave the app your actual banking username and password. The aggregator stored them, logged in as you, and read whatever the online banking portal displayed. When the bank redesigned a page, the connection broke, and someone had to rewrite the scraper.

The CFPB called this out plainly when it finalized its data rule in 2024, describing screen scraping as a risky practice in which consumers hand account passwords to third parties who then access data indiscriminately. It persists mostly at smaller institutions that have not built a modern interface, and you can usually tell you are on the old plumbing when the app asks for your bank password inside its own screen instead of bouncing you to your bank’s site.

The migration has been real. The Financial Data Exchange, the industry standards body whose specification most of these interfaces follow, reported crossing 100 million consumer accounts on its API standard, with counts since running above 114 million. Those accounts are the ones on tokens rather than stored passwords.

The connection has been free because a regulation said so

Section 1033 of the Dodd-Frank Act, passed in 2010, said consumers have a right to their own financial data. It sat unused for fourteen years. Then in October 2024 the CFPB finalized the Personal Financial Data Rights rule, which required banks and card issuers to hand over your data to a provider you designate, and to do it without charging fees. It also built in privacy limits: an app can only use the data for the product you asked for, access ends immediately when you revoke it, and authorization expires after a year unless you renew it. Compliance was phased, with the largest institutions due April 1, 2026 and the smallest not until April 1, 2030.

The rule carries an assumption worth naming. Your transaction history belongs to you, and the bank is a custodian obliged to hand it over on request, which makes charging for it roughly like a coat check billing you to retrieve your own coat.

Banks describe a different object entirely. In their telling the asset is not your history, it is the interface: servers that answer automated requests around the clock, engineers who keep them from falling over, a security perimeter that has to survive whatever the aggregator’s own security does not catch. The Bank Policy Institute, which sued over the rule, has argued the whole way through that handing that infrastructure to commercial third parties for free is both a security problem and a subsidy. Call the pipe a product and the conclusion follows on its own. Someone buys it, and the buyer will not be the bank.

The rule is frozen, and the fee ban is exactly what is being reopened

The Bank Policy Institute, the Kentucky Bankers Association and Forcht Bank sued within days of the rule being finalized. In November 2025 a federal judge in the Eastern District of Kentucky enjoined the CFPB from enforcing it, pausing the compliance deadlines while the agency starts over. The CFPB, under new leadership, told the court it now considers its own rule unlawful.

The rewrite is underway. In August 2026 the Bureau sent a proposal called Personal Financial Data Rights Reconsideration to the White House regulatory office for review, one of the last steps before a proposed rule is published for comment. Among the four areas it reopened is whether data providers may charge for responding to data requests, with the reported approach allowing some number of free requests before the meter starts.

While the rule sat frozen, the market moved on its own. JPMorgan has now reached paid data-access agreements with Plaid, Yodlee, Morningstar and Akoya, aggregators that together handle more than 95% of the third-party data requests hitting Chase accounts. Consumer advocates note the obvious problem: the largest bank in the country setting a price during a regulatory vacuum establishes a floor everyone else can point to.

What a $300 million bill does to an app that charges you nothing

The scale is easier to feel with the arithmetic in front of you. If one bank’s fees would cost one aggregator roughly $300 million a year, and that figure represents more than three quarters of that aggregator’s 2024 revenue, then the aggregator’s entire revenue was somewhere under $400 million. A single vendor bill cannot exceed most of your revenue and leave the business intact.

Spread $300 million across the roughly 114 million consumer accounts now connected through FDX interfaces and you get about $2.63 per account per year. That sounds like nothing. But Chase does not hold 114 million of those accounts, so the true cost per Chase account is some multiple of $2.63, and it lands on companies whose customers frequently pay zero. Free budgeting apps, free credit-score dashboards, free savings round-up tools and pay-by-bank checkouts all sit downstream of that pipe. A per-request cost changes their economics directly: fewer refreshes a day, fewer supported institutions, a paid tier where there used to be a free one, or in some cases no app at all.

Your app will pass the cost to you before it explains why

Nothing breaks tomorrow. But once you know how budgeting apps access your bank account, the product changes stop looking random. An app that used to update on demand and now updates once overnight has not simplified its design. It has cut the number of billable requests it makes on your behalf. Same for an app that quietly drops your smaller bank, or opens a paid tier where the free one used to be enough.

Two habits are worth keeping either way. Prefer the apps that bounce you to your bank’s own login page rather than asking for your password inside their screen, because the second kind is still scraping. And clear out your connections once a year, which is the cadence the paused rule assumed anyway, revoking anything tied to an app you stopped opening. That is the same instinct that makes a credit freeze worth the twenty minutes: deciding in advance who gets to pull your financial data, rather than finding out afterward.

The honest answer to how budgeting apps access your bank account is that they use a connection nobody was allowed to bill for, under a rule that is being rewritten by the parties who wanted to bill for it. The plumbing is not changing. The invoice is.

By Olivia

Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted
0
Would love your thoughts, please comment.x
()
x