API Strategy for Open Banking
API Strategy for Open Banking
Insights and case studies from leading open banking experts and API strategists.
About the Book
Within API Strategy for Open Banking, we present a holistic API perspective on open banking. We cover PSD2, open banking benefits, developer experience tips, frameworks for high-grade security and access management, and more. We've featured best practices and case studies from some of the world's largest open banking initiatives.
PSD2 EU regulation unlocked consumer data, spurring an open banking global response. Making the bank programmable is a win-win-win for banks, developers, and end consumers, but simply being an API provider doesn't guarantee an open banking advantage. It requires "API thinking" to take a holistic outside perspective that considers developer consumer needs. As banks treat their assets more like products, monolithic infrastructure is decomposing into an amalgamation of reusable components.
The financial industry has opened up, to much excitement. However, not all open banking initiatives are successful. In fact, 92% of consumers haven't heard of open banking. So how do we make them care? Banks can encourage adoption by improving the developer onboarding process and evangelizing an internal API mindset. Within API Strategy for Open Banking, we cover business reasons to adopt API-first open banking and see how open banking is being adopted in the EU, US, and UK markets.
API Strategy for Open Banking also describes how to adopt an API specification like OpenAPI to organize and standardize API design practices. It also considers how API security open standards like OAuth and the OpenID Connect FAPI profile can be used to track identity and keep open banking architecture secure.
- Foreword: Embracing Open Banking
- Preface: APIs Support the Open Banking Movement
The Premise of PSD2 And Open Banking
- Open Banking: The Premise and Promise
- What PSD2 Means For Banks
6 Reasons to Embrace an API Strategy for Open Banking
- 1. Compliance
- 2. Improved Digital Agility
- 3. Premium API Products
- 4. Increased Customer Satisfaction
- 5. Potential for Collaboration
- 6. Wider Client Base
Bring on the Players: Who Wins in Open Banking?
- What Open Banking Really Means
- Comply-first Providers
- Open-first Providers
- Plotting the Opportunity
- Final Thoughts
Case Study: Nordea’s Journey to PSD2 Compliance, 300 Signups in 72 Hours
- A World Beyond PSD2 Compliance
- Final Thoughts
FinTech and APIs: Making the Bank Programmable
- What is FinTech?
- Advantages of Exposing a Bank with an API
- Banks and FinTech Can Play Nice
- Use of APIs: In-Account App Marketplace Concept
- Data Transparency and the Rise of Open Banking
- New Platforms Lead to Unexpected Innovation
- More Advances in the Financial Sector
How Can Consumers Relate To Open Banking?
- Building Context for Consumers
- Open Banking Must Foster Trust With End Users
- Control Matters
- The Open Banking Marketplace
- Final Thoughts: How to Establish Consumer Faith in Open Banking
How Banks Are Becoming Uberized
- APIs are Nothing New
- Smartphones: Kindling a Change
- Time to API Up
- Building with Purpose
How Does Open Banking Apply to US Banks?
- Regulation in Europe
- Regulation in the US
- The Role of the Market
- Final Thoughts
Case Study: From API Doing to API Thinking at ING Bank
- APIs versus Web Services: What’s the Difference?
- API Doing vs API Thinking
- APIs and Customer Journeys
- Why API Doing is Equally Important
- From API Doing to API Thinking
Open Banking Amplifies the Need For Definition Driven APIs
- Adjusting Practices With The Shifting API Landscape
- How OpenAPI Specification (OAS) Accelerates API Development
- Supporting OAS Throughout the API Lifecycle
- Final Thought: Drive Open Banking API Strategies with OAS
High-Grade API Security For Banks
- Regulatory Compliance Considerations
- Identifying Vital Data
- Potential Vulnerabilities
- API Security Methodologies
- Security is The API Provider’s Responsibility
- Recent Exploits and Breaches
Is OAuth Enough for Financial-Grade API Security?
- Can OAuth Make The Grade?
- Some Tokens Are Unbearer-able
- Away With The PKCEs
- Signed, Sealed, Delivered
- What’s Next For Financial Grade API Security?
OpenID Connect: Overview of Financial-grade API (FAPI) Profile
- What is FAPI?
- Adding Resilience: The Read-Only Profile
- Bullet-Proofing: The Read-Write Profile
- Improving OAuth 2.0: JWT-Secured Authorization Codes
- Decoupling Authentication: Client-Initiated Backchannel Authentication
- Final Thoughts
Case Study: Growing Internal API Consumption in Danske Bank
- The Path Towards APIs
- Set-and-Forget Performance
- Identifying Setbacks… and Addressing Them!
- The Results
It Started With PSD2 and Personal Data
- The Status Quo
- Regulatory Impact
- The Open Banking (and Data) Landscape
- Final Thoughts
- Nordic APIs Resources
The Leanpub 45-day 100% Happiness Guarantee
Within 45 days of purchase you can get a 100% refund on any Leanpub purchase, in two clicks.
See full terms
Free Updates. DRM Free.
If you buy a Leanpub book, you get free updates for as long as the author updates the book! Many authors use Leanpub to publish their books in-progress, while they are writing them. All readers get free updates, regardless of when they bought the book or how much they paid (including free).
Most Leanpub books are available in PDF (for computers), EPUB (for phones and tablets) and MOBI (for Kindle). The formats that a book includes are shown at the top right corner of this page.
Finally, Leanpub books don't have any DRM copy-protection nonsense, so you can easily read them on any supported device.
C++ Best PracticesJason Turner
Level up your C++, get the tools working for you, eliminate common problems, and move on to more exciting things!
Digital-First EventsJoep Piscaer and Jana Boruta
The only resource you will ever need to launch your digital events program.
C++20 is the next big C++ standard after C++11. As C++11 did it, C++20 changes the way we program modern C++. This change is, in particular, due to the big four of C++20: ranges, coroutines, concepts, and modules.
The book is almost daily updated. These incremental updates ease my interaction with the proofreaders.
Sockets and PipesType Classes
Sockets and Pipes is not an introduction to Haskell; it is an introduction to writing software in Haskell. Using a handful of everyday Haskell libraries, this book walks through reading the HTTP specification and implementing it to create a web server.
Atomic KotlinBruce Eckel and Svetlana Isakova
For both beginning and experienced programmers! From the author of the multi-award-winning Thinking in C++ and Thinking in Java together with a member of the Kotlin language team comes a book that breaks the concepts into small, easy-to-digest "atoms," along with exercises supported by hints and solutions directly inside IntelliJ IDEA!
Algebra-Driven DesignSandy Maguire
A how-to field guide on building leak-free abstractions and algebraically designing real-world applications.
Introducing EventStormingAlberto Brandolini
The deepest tutorial and explanation about EventStorming, straight from the inventor.
node-opcua by exampleEtienne Rossignon
Get the best out of node-opcua through a set of documented examples by the author himself that will allow you to create stunning OPCUA Servers or Clients.
Ansible for DevOpsJeff Geerling
Ansible is a simple, but powerful, server and configuration management tool. Learn to use Ansible effectively, whether you manage one server—or thousands.
Cloud StrategyGregor Hohpe
“Strategy is the difference between making a wish and making it come true.” A successful migration to the cloud can transform your organization, but it shouldn’t be driven by wishes. This book tells you how to develop a sound strategy guided by frameworks and decision models without being overly abstract nor getting lost in product details.
Software Architecture for Developers: Volumes 1 & 2 - Technical leadership and communication
2 Books"Software Architecture for Developers" is a practical and pragmatic guide to modern, lightweight software architecture, specifically aimed at developers. You'll learn:The essence of software architecture.Why the software architecture role should include coding, coaching and collaboration.The things that you really need to think about before...
Django for Beginners/APIs/Professionals
CCIE Service Provider Ultimate Study Bundle
2 BooksPiotr Jablonski, Lukasz Bromirski, and Nick Russo have joined forces to deliver the only CCIE Service Provider training resource you'll ever need. This bundle contains a detailed and challenging collection of workbook labs, plus an extensively detailed technical reference guide. All of us have earned the CCIE Service Provider certification...
Cisco CCNA 200-301 Complet
4 BooksCe lot comprend les quatre volumes du guide préparation à l'examen de certification Cisco CCNA 200-301.
Linux Administration Complet
4 BooksCe lot comprend les quatre volumes du Guide Linux Administration :Linux Administration, Volume 1, Administration fondamentale : Guide pratique de préparation aux examens de certification LPIC 1, Linux Essentials, RHCSA et LFCS. Administration fondamentale. Introduction à Linux. Le Shell. Traitement du texte. Arborescence de fichiers. Sécurité...
Modern Management Made Easy
3 BooksRead all three Modern Management Made Easy books. Learn to manage yourself, lead and serve others, and lead the organization.
3 BooksBuy every PowerShell book from Adam Bertram at a 20% discount!
2 BooksDocker and Kubernetes are taking the world by storm! These books will get you up-to-speed fast! Docker Deep Dive is over 400 pages long, and covers all objectives on the Docker Certified Associate exam.The Kubernetes Book includes everything you need to get up and running with Kubernetes!
CCDE Practical Studies (All labs)
3 BooksCCDE lab
All the Books of The Medical Futurist
6 BooksWe put together the most popular books from The Medical Futurist to provide a clear picture about the major trends shaping the future of medicine and healthcare. Digital health technologies, artificial intelligence, the future of 20 medical specialties, big pharma, data privacy, digital health investments and how technology giants such as Amazon...