API Strategy for Open Banking
API Strategy for Open Banking
Insights and case studies from leading open banking experts and API strategists.
About the Book
Within API Strategy for Open Banking, we present a holistic API perspective on open banking. We cover PSD2, open banking benefits, developer experience tips, frameworks for high-grade security and access management, and more. We've featured best practices and case studies from some of the world's largest open banking initiatives.
PSD2 EU regulation unlocked consumer data, spurring an open banking global response. Making the bank programmable is a win-win-win for banks, developers, and end consumers, but simply being an API provider doesn't guarantee an open banking advantage. It requires "API thinking" to take a holistic outside perspective that considers developer consumer needs. As banks treat their assets more like products, monolithic infrastructure is decomposing into an amalgamation of reusable components.
The financial industry has opened up, to much excitement. However, not all open banking initiatives are successful. In fact, 92% of consumers haven't heard of open banking. So how do we make them care? Banks can encourage adoption by improving the developer onboarding process and evangelizing an internal API mindset. Within API Strategy for Open Banking, we cover business reasons to adopt API-first open banking and see how open banking is being adopted in the EU, US, and UK markets.
API Strategy for Open Banking also describes how to adopt an API specification like OpenAPI to organize and standardize API design practices. It also considers how API security open standards like OAuth and the OpenID Connect FAPI profile can be used to track identity and keep open banking architecture secure.
Table of Contents
- Foreword: Embracing Open Banking
- Preface: APIs Support the Open Banking Movement
-
The Premise of PSD2 And Open Banking
- Open Banking: The Premise and Promise
- What PSD2 Means For Banks
-
6 Reasons to Embrace an API Strategy for Open Banking
- 1. Compliance
- 2. Improved Digital Agility
- 3. Premium API Products
- 4. Increased Customer Satisfaction
- 5. Potential for Collaboration
- 6. Wider Client Base
- Conclusion
-
Bring on the Players: Who Wins in Open Banking?
- What Open Banking Really Means
- Comply-first Providers
- Protectionists
- Open-first Providers
- Plotting the Opportunity
- Final Thoughts
-
Case Study: Nordea’s Journey to PSD2 Compliance, 300 Signups in 72 Hours
- A World Beyond PSD2 Compliance
- Final Thoughts
-
FinTech and APIs: Making the Bank Programmable
- What is FinTech?
- Advantages of Exposing a Bank with an API
- Banks and FinTech Can Play Nice
- Use of APIs: In-Account App Marketplace Concept
- Data Transparency and the Rise of Open Banking
- New Platforms Lead to Unexpected Innovation
- More Advances in the Financial Sector
- Conclusion
-
How Can Consumers Relate To Open Banking?
- Building Context for Consumers
- Open Banking Must Foster Trust With End Users
- Control Matters
- The Open Banking Marketplace
- Final Thoughts: How to Establish Consumer Faith in Open Banking
-
How Banks Are Becoming Uberized
- APIs are Nothing New
- Smartphones: Kindling a Change
- Time to API Up
- Building with Purpose
-
How Does Open Banking Apply to US Banks?
- Regulation in Europe
- Regulation in the US
- The Role of the Market
- Final Thoughts
-
Case Study: From API Doing to API Thinking at ING Bank
- APIs versus Web Services: What’s the Difference?
- API Doing vs API Thinking
- APIs and Customer Journeys
- Why API Doing is Equally Important
- From API Doing to API Thinking
-
Open Banking Amplifies the Need For Definition Driven APIs
- Adjusting Practices With The Shifting API Landscape
- How OpenAPI Specification (OAS) Accelerates API Development
- Supporting OAS Throughout the API Lifecycle
- Final Thought: Drive Open Banking API Strategies with OAS
-
High-Grade API Security For Banks
- Regulatory Compliance Considerations
- Identifying Vital Data
- Potential Vulnerabilities
- API Security Methodologies
- Security is The API Provider’s Responsibility
- Recent Exploits and Breaches
- Conclusion
-
Is OAuth Enough for Financial-Grade API Security?
- Can OAuth Make The Grade?
- Some Tokens Are Unbearer-able
- Away With The PKCEs
- Signed, Sealed, Delivered
- What’s Next For Financial Grade API Security?
-
OpenID Connect: Overview of Financial-grade API (FAPI) Profile
- What is FAPI?
- Adding Resilience: The Read-Only Profile
- Bullet-Proofing: The Read-Write Profile
- Improving OAuth 2.0: JWT-Secured Authorization Codes
- Decoupling Authentication: Client-Initiated Backchannel Authentication
- Final Thoughts
-
Case Study: Growing Internal API Consumption in Danske Bank
- The Path Towards APIs
- Set-and-Forget Performance
- Identifying Setbacks… and Addressing Them!
- The Results
- Summary
-
It Started With PSD2 and Personal Data
- The Status Quo
- Regulatory Impact
- The Open Banking (and Data) Landscape
- Final Thoughts
- Nordic APIs Resources
The Leanpub 60-day 100% Happiness Guarantee
Within 60 days of purchase you can get a 100% refund on any Leanpub purchase, in two clicks.
See full terms
Do Well. Do Good.
Authors have earned$11,574,417writing, publishing and selling on Leanpub, earning 80% royalties while saving up to 25 million pounds of CO2 and up to 46,000 trees.
Learn more about writing on Leanpub
Free Updates. DRM Free.
If you buy a Leanpub book, you get free updates for as long as the author updates the book! Many authors use Leanpub to publish their books in-progress, while they are writing them. All readers get free updates, regardless of when they bought the book or how much they paid (including free).
Most Leanpub books are available in PDF (for computers), EPUB (for phones and tablets) and MOBI (for Kindle). The formats that a book includes are shown at the top right corner of this page.
Finally, Leanpub books don't have any DRM copy-protection nonsense, so you can easily read them on any supported device.
Learn more about Leanpub's ebook formats and where to read them
Top Books
Recipes for Decoupling
Matthias NobackThe BDD Books - Discovery (Japanese Edition)
Gáspár Nagy, Seb Rose, and Yuya Kazamaウクライナ難民を支援 - 2022年5月末まで延長!
この本の売り上げの50%は、 https://unicef.hu/veszhelyzet-ukrajnaban と https://int.depaulcharity.org/fundraising-for-depaul-ukraine/ に寄付されます。
本書籍は、振る舞い駆動開発(Behavior Driven Development, BDD)や受け入れテスト駆動開発(Acceptance Test-Driven Development, ATDD)の発見フェーズを最大限に活用する方法を提供します。
SignalR on .NET 6 - the Complete Guide
Fiodar SazanavetsLearn everything there is to learn about SignalR and how to integrate it with the latest .NET 6 and C# 10 features. Learn how to connect any type of client to SignalR, including plain WebSocket client. Learn how to build interactive applications that can communicate with each other in real time without making excessive calls.
Agile Testing Condensed Japanese Edition
Yuya Kazama, Janet Gregory, and Lisa CrispinJanet GregoryとLisa Crispinによる2019年9月発行の書籍『Agile Testing Condensed』の日本語翻訳版です。アジャイルにおいてどのような考えでテストを行うべきなのか簡潔に書かれています!
OpenIntro Statistics
David Diez, Christopher Barr, Mine Cetinkaya-Rundel, and OpenIntroA complete foundation for Statistics, also serving as a foundation for Data Science.
Leanpub revenue supports OpenIntro (US-based nonprofit) so we can provide free desk copies to teachers interested in using OpenIntro Statistics in the classroom and expand the project to support free textbooks in other subjects.
More resources: openintro.org.
The easiest way to learn design patterns
Fiodar SazanavetsLearn design patterns in the easiest way possible. You will no longer have to brute-force your way through each one of them while trying to figure out how it works. The book provides a unique methodology that will make your understanding of design patterns stick. It can also be used as a reference book where you can find design patterns in seconds.
Functional event-driven architecture: Powered by Scala 3
Gabriel VolpeExplore the event-driven architecture (EDA) in a purely functional way, mainly powered by Fs2 streams in Scala 3!
Leverage your functional programming skills by designing and writing stateless microservices that scale, powered by stateful message brokers.
Tech Giants in Healthcare
Dr. Bertalan MeskoThis comprehensive guide, Tech Giants in Healthcare, clarifies how and why big tech companies step into healthcare, and breaks it down from one market player to the other in what direction they are going, what tools they are using and what horizons they have in front of them.
CCIE Service Provider Version 4 Written and Lab Exam Comprehensive Guide
Nicholas RussoThe service provider landscape has changed rapidly over the past several years. Networking vendors are continuing to propose new standards, techniques, and procedures for overcoming new challenges while concurrently reducing costs and delivering new services. Cisco has recently updated the CCIE Service Provider track to reflect these changes; this book represents the author's personal journey in achieving that certification.
Mastering STM32 - Second Edition
Carmine NovielloWith more than 1200 microcontrollers, STM32 is probably the most complete ARM Cortex-M platform on the market. This book aims to be the first guide around that introduces the reader to this exciting MCU portfolio from ST Microelectronics and its official CubeHAL and STM32CubeIDE development environment.
Top Bundles
- #1
Practical FP in Scala + Functional event-driven architecture
2 Books
Practical FP in Scala (A hands-on approach) & Functional event-driven architecture, aka FEDA, (Powered by Scala 3), together as a bundle! The content of PFP in Scala is a requirement to understand FEDA so why not take advantage of this bundle!? - #2
All the Books of The Medical Futurist
6 Books
We put together the most popular books from The Medical Futurist to provide a clear picture about the major trends shaping the future of medicine and healthcare. Digital health technologies, artificial intelligence, the future of 20 medical specialties, big pharma, data privacy, digital health investments and how technology giants such as Amazon... - #3
Software Architecture for Developers: Volumes 1 & 2 - Technical leadership and communication
2 Books
"Software Architecture for Developers" is a practical and pragmatic guide to modern, lightweight software architecture, specifically aimed at developers. You'll learn:The essence of software architecture.Why the software architecture role should include coding, coaching and collaboration.The things that you really need to think about before... - #4
CCIE Service Provider Ultimate Study Bundle
2 Books
Piotr Jablonski, Lukasz Bromirski, and Nick Russo have joined forces to deliver the only CCIE Service Provider training resource you'll ever need. This bundle contains a detailed and challenging collection of workbook labs, plus an extensively detailed technical reference guide. All of us have earned the CCIE Service Provider certification... - #6
Pattern-Oriented Memory Forensics and Malware Detection
2 Books
This training bundle for security engineers and researchers, malware and memory forensics analysts includes two accelerated training courses for Windows memory dump analysis using WinDbg. It is also useful for technical support and escalation engineers who analyze memory dumps from complex software environments and need to check for possible...