THE GUIDE · BEYOND CARDS · 10 MIN

Pay from your bank. No card required.

Every fintech card is a stack of rented parts — but open banking skips the card entirely. Your data and your bank's payment rail, opened by your permission: near-free, instant, and the structural threat to interchange.

SCROLL ↓
IN PLAIN WORDS — READ THIS FIRST

A card isn't the only way to pay a shop. Open banking lets you pay straight from your bank account — no card, no card network. You give a licensed app permission (through your own bank) to either read your account or push a payment, and that's it. You never hand over your bank password, and you can revoke the permission whenever you like.

Two things make it a big deal. It's almost free for the merchant, because there's no interchange — which is why shops love it and the card networks are nervous. And you hold the permission: you grant it, you scope it, you cancel it. The catch: a bank push has no card-style chargeback, so buyer protection works differently.

PART 01

Money that moves with no card in the middle.

Step through consent, reading your accounts, pushing a payment, and the standing permission that makes recurring pay-by-bank work.

PART 02

The moving parts.

Data and payments, opened by permission — and the pieces that turn it into a real card alternative.

OPEN BANKING

"Your data, opened by you."

Banks expose APIs that let you share account data and initiate payments through licensed third parties. It reframes the bank as a platform — and hands the customer, not the bank, control over who can see and move their money.

AISP vs PISP

"Read vs move."

Two licences. An AISP reads account information (balances, transactions). A PISP initiates payments (pushes money). Many fintechs hold both — one to understand you, one to charge you.

PAY-BY-BANK / A2A

"The card-free checkout."

Account-to-account payment pushes funds straight from buyer's bank to seller's, usually on an instant rail. Near-zero cost, instant settlement, no chargeback — which is exactly why merchants love it and card networks are buying in.

VRP

"Subscriptions without a card."

Variable Recurring Payments let a payee pull repeatedly within a consented rulebook. Sweeping VRP (moving money between your own accounts) is live; commercial VRP — paying third parties — is the piece that unlocks A2A subscriptions and bill pay.

AGGREGATION

"One pipe to every account."

Aggregators (Plaid, Yodlee, Tink, TrueLayer) sit between apps and thousands of banks, normalising connections. They began by screen-scraping with your login; the industry is now being pushed onto permissioned APIs and tokenised access.

OPEN FINANCE

"Beyond the checking account."

The next step extends the same consent model to investments, pensions, insurance and mortgages — your whole financial life, portable by permission. The EU's FIDA proposal is the flagship: 'open banking' becomes 'open everything.'

PART 03

Why merchants are pushing this.

Pay-by-bank rides the instant rail with no interchange. Here is roughly what the same $100 sale costs the merchant, by rail.

Pay-by-bank / A2A push on the instant rail
~0.1-0.3%
Regulated debit Durbin-capped
~0.5%
Consumer credit
~1.8%
Rewards credit the points come from here
~2.3%
Illustrative merchant cost. A2A's marginal cost is near zero because it carries no interchange — the structural reason merchants push it and card incumbents are nervous. The catch: no chargeback also means no built-in buyer protection.
PART 04

Same idea. Opposite politics.

Whether open banking happens is decided by regulators, not technology.

// OPEN BANKING, TWO WAYS

EU / UK   MANDATE   banks must open APIs; regulators drive adoption (PSD2 → PSD3 + PSR)
INDIA / BRAZIL   PUBLIC RAIL   UPI + account aggregator; Pix + open finance — state-led, fast
USA   MARKET   CFPB 1033 rule finalised, then reopened — direction uncertain

// Same technology, opposite posture. Adoption follows the mandate.
WHEN IT BREAKS

The catch nobody mentions.

A bank push is cheap and instant, and it drops the one thing a card quietly gives you: a built-in undo. Three ways pay-by-bank goes wrong, then a tree for when a payment does.

FAILURE 01 · NO CHARGEBACK
The goods never come, and there's no undo
WHAT YOU SEEYou paid by bank, the merchant vanished or never shipped, and there's no "dispute this charge" button to get your money back.
WHYA card payment carries a chargeback right — the network can claw the money back from the merchant. An account-to-account push has none of that machinery; it's a completed bank transfer. Cheap and final cuts both ways.
THE FIXFor anything risky, a card's buyer protection is worth its fee. Some pay-by-bank schemes are bolting on protection layers, but it isn't the automatic safety net a chargeback is.
FAILURE 02 · THE SCAM YOU AUTHORIZE
You push the money yourself
WHAT YOU SEEA convincing "your account is at risk" message, and you approve a payment straight from your bank to a fraudster.
WHYBecause the payment is a push you approved with your own bank login, every fraud check passes — the money moves instantly and there's no card network to reverse it. This is authorized push payment (APP) fraud, and instant A2A rails are its favourite home.
THE FIXName-check tools (Verification of Payee, Confirmation of Payee), payment delays on new payees, and — in the UK — mandatory bank reimbursement for most APP-scam victims. See the fraud chapter.
FAILURE 03 · THE FLAKY BANK API
The connection just stops working
WHAT YOU SEEAn app that reads your accounts suddenly can't — a blank balance, a failed payment, a "please reconnect your bank" loop.
WHYOpen banking runs on banks' own APIs, and their uptime, data quality and coverage vary widely. A token expires, a bank changes its interface, or an outage hits — and the connection silently breaks. The messy shift off screen-scraping onto real APIs made this worse before it got better.
THE FIXRe-consent to refresh the token; expect gaps at smaller banks. For builders, this is why aggregators (Plaid, Tink, TrueLayer) exist — they absorb thousands of flaky connections so you don't.
A PAY-BY-BANK PAYMENT WENT WRONG. WHAT NOW?
1 · Did the money leave, but the goods never arrived?
NO CHARGEBACK — IT'S A DISPUTEThere's no card-network reversal on an A2A push. Chase the merchant directly, and if it was a scam, use your bank's fraud process (and any local APP-reimbursement scheme). Prevention beats recovery here.
PAYMENT ITSELF LOOKS WRONG — KEEP GOINGToo much pulled, or it keeps pulling? Go to step 2.
2 · Is a recurring payment (VRP) pulling too much or too often?
REVOKE THE CONSENT AT YOUR BANKA VRP runs on a standing permission you hold. Unlike a card-on-file, you can cancel it directly in your banking app — no need to ask the merchant. Anything outside the agreed cap shouldn't have been approved at all.
NOT RECURRING — KEEP GOINGGo to step 3.
3 · Did the connection stop working (the app can't see your bank)?
A BROKEN TOKEN OR BANK OUTAGERe-consent to refresh the permission. If it still fails, it's a bank-side outage or an API coverage gap — the app's aggregator, not your account, is the thing that's stuck.
THE GENERAL RULEThe push is strongly authenticated, so "wrong" usually means a delivery dispute, a consent to revoke, or a flaky connection — rarely a stolen-card-style theft.
COMMON QUESTIONS — ASKED PLAINLY

The things everyone wonders.

Five honest questions about paying straight from your bank.

IS PAY-BY-BANK SAFE IF THERE'S NO CHARGEBACK?
The payment itself is strongly protected: it's a push from your own bank, approved by you with your bank's own login, so a stranger can't just run it off a stolen card number. What you give up is the card's built-in dispute right. If a merchant takes your money and doesn't deliver, you can't file a chargeback to claw it back — you're negotiating with the merchant or going through slower fraud channels. So it's very safe against card theft, and weaker if you're tricked into paying a scammer or a shop that vanishes. That trade — cheaper and final, versus a little pricier with an undo button — is the whole story of A2A versus cards.
HOW IS THIS DIFFERENT FROM JUST A BANK TRANSFER?
Under the hood it often is a bank transfer — but you never leave the merchant's checkout, never type in sort codes and account numbers, and never share your banking password. A licensed provider initiates the transfer for you with a scoped, usually one-time permission, and your bank confirms it with the same login you always use. Think of it as a normal bank transfer with a smooth checkout wrapped around it, and the error-prone manual bits removed. The payment rail underneath is usually the country's instant rail (UPI, Pix, Faster Payments, SEPA Instant).
DO I HAVE TO GIVE AN APP MY BANK PASSWORD?
No, and that's the entire point of the modern model. You authenticate at your own bank and hand the app a scoped, revocable token — the app never sees your credentials and can only do what you allowed (read balances, or make one payment, or a capped recurring pull). The old way, screen-scraping, really did take your login and log in as you, which was fragile and risky. Regulation (PSD2, the new PSR, the US 1033 rule) is precisely about killing that and forcing the token-based API model. If an app ever asks for your actual bank password, that's the old, worse way.
WHY DON'T I SEE PAY-BY-BANK EVERYWHERE YET?
Because adoption follows the mandate, and the mandate is uneven. Where a regulator forced the issue — the EU and UK with PSD2, India and Brazil by building public rails — pay-by-bank is common and growing fast. Where the rules keep wavering — the US, whose 1033 open-banking rule was finalised and then reopened — cards still dominate and there's no single "pay by bank" button. The technology has been ready for years; what varies country to country is whether the banks were made to open up and whether there's a rail underneath worth pushing on.
CAN A MERCHANT KEEP PULLING MONEY FROM MY ACCOUNT?
Only within the rulebook you agreed to. A Variable Recurring Payment (VRP) carries explicit limits — a maximum amount, a frequency, an end date — and the bank won't approve a pull outside them. And unlike a card-on-file, where cancelling can mean fighting the merchant, a VRP is a permission you hold: you can revoke it directly in your banking app at any time, and the pulls stop. That customer-held, switch-off-able control is exactly what makes VRP the credible A2A answer to card subscriptions.
FIELD NOTES — THE PRO LAYER

For the professionals.

The pieces up close — Europe's mandate, America's wobble, VRP, the death of screen-scraping, and open finance.

PSD2 → PSD3 + PSR — EUROPE MANDATES IT
The EU created open banking by fiat: PSD2 (2018) forced banks to open APIs. Its successor reached provisional political agreement on 27 Nov 2025: a PSR (a directly-applicable Regulation rather than a directive) plus PSD3. The PSR kills screen-scraping, mandates permission dashboards and a Verification of Payee name check, and tightens fraud liability. Because it's a Regulation, it lands uniformly across the bloc — the opposite of the US approach.
THE US 1033 SAGA — A MANDATE THAT WOBBLED
The CFPB finalised its Section 1033 'personal financial data rights' rule in Oct 2024 — America's first real open-banking mandate. Then through 2025 the CFPB moved to reconsider and partly vacate its own rule, reopening data-access fees and third-party-liability questions. As of Jul 2026 the US direction is genuinely uncertain. It's the cleanest case study in the academy of how regulatory posture, not technology, decides whether open banking actually happens.
VRP — SWEEPING TODAY, COMMERCIAL NEXT
Sweeping VRP (automatically moving money between a customer's own accounts) is live and safe by design. The prize is commercial VRP — paying third parties on a standing mandate, the true card-on-file killer. The UK launched an industry cVRP scheme with a first cohort of firms, targeting first live commercial payments in early 2026. If cVRP works, subscriptions and bill-pay start leaking off the card rails.
AGGREGATION & THE DEATH OF SCREEN-SCRAPING
Before APIs, aggregators logged in as you and scraped the page — fragile and risky. Regulation (PSD2, the PSR, the CFPB rule) is forcing a shift to permissioned APIs and tokenised access, where the third party never holds your credentials. Plaid, Tink and TrueLayer are re-platforming onto this model. The transition is messy — coverage gaps, flaky bank APIs — but it's the plumbing nearly every lending and PFM fintech quietly depends on.
OPEN FINANCE & DATA RECIPROCITY
'Open banking' covers payment accounts; open finance extends the consent model to investments, pensions, insurance and more. The unresolved fights are reciprocity — if fintechs read bank data, must they share their own back? — and who pays for the APIs. The EU's FIDA proposal, the UK's 'smart data' agenda, and Brazil's open-finance rollout are the ones to watch; Brazil and India show how fast adoption moves when a regulator leads.
PART 05

Remember three things.

1
Open banking is your bank data plus your bank's payment rail, opened by your permission — not sold by the bank and not routed through a card network.
2
A2A is the structural threat to interchange: pay-by-bank is instant, near-free and chargeback-free, and VRP is the piece that lets it handle subscriptions — the card's last stronghold.
3
The technology is settled; the politics are not. The EU is mandating it, the US keeps wavering, and everywhere adoption follows the mandate. Whoever controls the consent layer controls the customer.