[{"data":1,"prerenderedAt":425},["ShallowReactive",2],{"post-\u002Fbank-account-api-integration":3},{"page":4,"translation":308,"nav":310,"related":417,"random":418},{"id":5,"title":6,"body":7,"categories":281,"category":284,"date":285,"description":286,"draft":287,"extension":288,"image":289,"imageAlt":290,"kind":291,"lang":292,"meta":293,"navigation":294,"path":295,"publishedAt":284,"readingTime":296,"seo":297,"seoTitle":298,"slug":299,"stem":299,"tags":300,"translationKey":299,"type":306,"updated":284,"__hash__":307},"posts\u002Fbank-account-api-integration.md","Integrating One Bank Is Easy. Keeping Forty Running Is Not.",{"type":8,"value":9,"toc":271},"minimark",[10,49,52,55,58,61,64,67,72,75,90,100,103,120,130,133,137,140,143,146,149,152,155,158,162,165,168,171,174,178,181,184,204,207,210,214,217,220,223,243,246,249,253,256,259,262,265,268],[11,12,13,21],"blockquote",{},[14,15,16,17],"p",{},"💡 ",[18,19,20],"strong",{},"TL;DR: Key Takeaways",[22,23,24,31,37,43],"ul",{},[25,26,27,30],"li",{},[18,28,29],{},"A single bank integration may be technically straightforward."," The difficult part is building thirty or forty different connections and keeping all of them working as banks change.",[25,32,33,36],{},[18,34,35],{},"Türkiye has regulated, standardised open-banking rails."," The fragmented interfaces we encountered were a different surface: proprietary services that banks offer directly to corporate customers for access to their own account data.",[25,38,39,42],{},[18,40,41],{},"An integration provider sells more than a common API."," It takes on much of the normalisation, monitoring, change management, and maintenance burden across banks.",[25,44,45,48],{},[18,46,47],{},"That convenience creates another trust boundary."," Credential handling, data location, access controls, incident management, and the exit path all belong in the decision.",[14,50,51],{},"We have an internal finance dashboard that brings together information from payment services and other financial systems.",[14,53,54],{},"At one point, we were asked whether it could also show transactions from the company's bank accounts. Our first reaction was optimistic. Open banking exists, so surely there would be a standard. We could integrate several banks in roughly the same way. If that proved inconvenient, we could use a ready-made service instead.",[14,56,57],{},"After reading the documentation from a few banks, we decided not to enter the direct-integration maze. We connected through a bank integration provider, took the data we needed, and displayed it inside the dashboard we already used.",[14,59,60],{},"The surprise came later, when I saw the settings screen used to configure each bank connection.",[14,62,63],{},"One bank expected a username and password. Another issued a token. Some used an OAuth-like flow; others required an IP address to be allowlisted. One required activation from the mobile-banking application. One bank's form had two fields, while another had ten.",[14,65,66],{},"The information we wanted from all of them was largely the same: accounts, balances, and transactions.",[68,69,71],"h2",{"id":70},"türkiye-does-have-an-open-banking-standard","Türkiye does have an open-banking standard",[14,73,74],{},"Before going further, an important distinction is necessary. It would be wrong to say that open banking in Türkiye has no standard.",[14,76,77,78,89],{},"Türkiye incorporated the PSD2 concepts of payment initiation and account information services into Law No. 6493 in 2019. The Central Bank of the Republic of Türkiye, usually abbreviated as CBRT in English and TCMB in Turkish, then established a national API standard for these services. Participating institutions connect through GEÇİT, an API gateway developed by the Interbank Card Center, known locally as BKM. The ",[79,80,88],"a",{"className":81,"href":83,"rel":84,"target":87},[82],"dofollow","https:\u002F\u002Fwww.tcmb.gov.tr\u002Fwps\u002Fwcm\u002Fconnect\u002FEN\u002FTCMB%2BEN\u002FMain%2BMenu\u002FAnnouncements\u002FPress%2BReleases\u002F2022\u002FANO2022-48",[85,86],"nofollow","noopener","_blank","CBRT's 2022 open-banking announcement"," describes the launch of that common infrastructure.",[14,91,92,93,99],{},"In the CBRT's English publications, the framework is called Data Sharing Services in the Field of Payments, or DSSP. Its Turkish abbreviation is ÖHVPS. The standard covers account information and payment initiation through authorised providers. It is not a dormant policy document: ",[79,94,98],{"className":95,"href":96,"rel":97,"target":87},[82],"https:\u002F\u002Fwww.tcmb.gov.tr\u002Fwps\u002Fwcm\u002Fconnect\u002F24dfd56f-2022-4198-8f79-6e226ae27438\u002FDUY2026-13.pdf?MOD=AJPERES",[85,86],"version 2.0.0 went live in March 2026",", expanding account and card information services and adding scheduled and recurring payment initiation.",[14,101,102],{},"The integrations we encountered were not those standard GEÇİT services. They were proprietary APIs and web services that banks offer to corporate customers so those customers can retrieve their own account transactions. The distinction resembles the difference between regulated third-party open-banking access and a bank's direct corporate data service.",[14,104,105,106,112,113,119],{},"These direct services do not all look alike. ",[79,107,111],{"className":108,"href":109,"rel":110,"target":87},[82],"https:\u002F\u002Fwww.ziraatbank.com.tr\u002Ftr\u002Fticari\u002Fnakit-yonetimi\u002Fhesap-hareketleri-entegrasyonu\u002Fweb-servis-online-hesap-hareketleri-entegrasyonu",[85,86],"Ziraat Bankası, for example, describes an XML web service"," for integrating corporate account transactions into a customer's own software. ",[79,114,118],{"className":115,"href":116,"rel":117,"target":87},[82],"https:\u002F\u002Fapiportal.denizbank.com\u002FapiDetail\u002FAccounts",[85,86],"DenizBank publishes separate account and corporate-transaction APIs"," through its API portal.",[14,121,122,123,129],{},"The legal classification also depends on more than the protocol. The ",[79,124,128],{"className":125,"href":126,"rel":127,"target":87},[82],"https:\u002F\u002Ftcmb.gov.tr\u002Fwps\u002Fwcm\u002Fconnect\u002Fd60cc679-ce04-4941-b310-b3788b6f3540\u002F%C3%96HVPS-Rehber-2023-04-30.pdf?MOD=AJPERES",[85,86],"CBRT's DSSP implementation guide"," distinguishes a customer contracting directly with its bank and receiving only technical support from a third party from a third party contracting with banks to provide account information to customers. The contractual counterparties and the path the data takes matter.",[14,131,132],{},"The rest of this article is therefore not a criticism of Türkiye's regulated open-banking standard. It is about the fragmented direct corporate banking services we had to use for our own accounts.",[68,134,136],{"id":135},"why-one-bank-integration-looks-easy","Why one bank integration looks easy",[14,138,139],{},"Taken alone, one bank is manageable.",[14,141,142],{},"You read the documentation, obtain test access, implement the authentication and network-access requirements, map accounts, balances, and transactions into your own data model, handle errors, test the flow, and release it.",[14,144,145],{},"The bank may use an old or unusual method. That does not automatically make the work a difficult engineering problem. A capable team can complete a well-scoped integration with one bank in a reasonable amount of time.",[14,147,148],{},"The economics change when the number of banks grows. You are not merely repeating the same task. You are importing each connection's small decisions and exceptions into your own system.",[14,150,151],{},"Credentials expire. An IP address changes and has to be registered again. Those are only the visible differences. Field meanings, error codes, pagination, maintenance windows, historical-data limits, date and amount formats, and duplicate detection must also be verified for each bank.",[14,153,154],{},"The initial implementation is only the beginning. Someone has to notice a service change, find out why a connection stopped, update the adapter, check whether a gap appeared in the transaction history, and release the fix without breaking other banks.",[14,156,157],{},"A small maintenance cost for one bank becomes an operating function across thirty or forty. Coordination, monitoring, and ownership grow faster than the technical novelty of the work.",[68,159,161],{"id":160},"what-an-integration-provider-is-really-selling","What an integration provider is really selling",[14,163,164],{},"If you look at one connector in isolation, it is easy to say, “We could build this ourselves.” We probably could.",[14,166,167],{},"But the product is not merely an endpoint that returns bank transactions. The provider also takes on much of the work of connecting to banks individually, translating different data models into a common structure, tracking access requirements, and restoring a connection when a bank changes something.",[14,169,170],{},"The providers we reviewed had their own reporting interfaces. We chose not to use those interfaces. We only consumed the data and presented it in our own dashboard, because the value for us was not another finance screen. It was adding bank data to the operational view we already had.",[14,172,173],{},"That choice makes the provider's value clearer. It is not concentrated in the code for one adapter. It is in the operating capacity required to keep the whole portfolio of adapters alive.",[68,175,177],{"id":176},"what-a-common-corporate-access-profile-would-change","What a common corporate-access profile would change",[14,179,180],{},"It would be unrealistic to expect every bank to design all its products and internal systems in the same way. A common baseline for direct corporate-access services could still remove a substantial amount of unnecessary work.",[14,182,183],{},"At minimum, a shared industry profile could cover:",[22,185,186,189,192,195,198,201],{},[25,187,188],{},"Customer and application registration",[25,190,191],{},"Authorisation for read-only account access",[25,193,194],{},"Account, balance, and transaction data models",[25,196,197],{},"Error codes and retry behaviour",[25,199,200],{},"Versioning, change notices, and deprecation policy",[25,202,203],{},"Test environments and connection-health checks",[14,205,206],{},"Such a standard would not force banks to use the same technology internally. It would create a common external contract for the information that corporate customers repeatedly need. Banks could still differentiate where their products are genuinely different; every transaction feed would no longer require a new access model and vocabulary.",[14,208,209],{},"Türkiye's regulated DSSP infrastructure already shows that a common API profile across banks is possible. Applying a similar baseline to direct corporate services would not only make development easier. It would lower integration costs, reduce forced dependence on aggregators, and make it easier for smaller providers and internal teams to participate.",[68,211,213],{"id":212},"the-provider-removes-work-and-adds-a-trust-boundary","The provider removes work and adds a trust boundary",[14,215,216],{},"Choosing not to integrate directly does not remove the security responsibility. It adds another party between the bank and our system.",[14,218,219],{},"That does not mean an integration provider is inherently less secure. It means we now depend on the provider's access controls, data handling, and operational continuity as well as those of the bank and our own systems. “How many banks do you support?” and “What does it cost per month?” are not enough to make the decision.",[14,221,222],{},"At minimum, the following questions need clear answers:",[22,224,225,228,231,234,237,240],{},[25,226,227],{},"Who stores the bank credentials, where, and for how long?",[25,229,230],{},"Can permissions be limited to read-only account access?",[25,232,233],{},"In which country is the financial data stored, when is it deleted, and who can access it?",[25,235,236],{},"Are access and data transfers covered by auditable logs?",[25,238,239],{},"How are security incidents and connection failures reported?",[25,241,242],{},"How do we export our data and move the connections if we leave the provider?",[14,244,245],{},"Closed-source software does not answer those questions automatically. Nor is an open-source collection of bank adapters inherently insecure.",[14,247,248],{},"Open source may let us inspect and change the integration code. It does not decide who will monitor changes across thirty or forty banks, publish security updates, or take responsibility when a connection fails. Code can be available while sustainable ownership remains missing.",[68,250,252],{"id":251},"build-or-buy","Build or buy?",[14,254,255],{},"Direct integration can be entirely sensible for a system that uses one or two banks, needs only read access, and faces little change. If the team can own both the engineering and the operation, another layer may add more complexity than it removes.",[14,257,258],{},"As the bank portfolio grows, the decision changes. If monitoring many connections is not a capability that differentiates the company, delegating it to a specialist provider becomes more rational. The fee is better understood as the price of continuous maintenance and normalisation than as the price of an API call.",[14,260,261],{},"After reading the documentation from several banks, we chose not to turn this into an internal product. The work was possible. At the number of banks we needed, it would have created a maintenance product that had little to do with where we wanted to invest our engineering attention.",[14,263,264],{},"I still wish a common baseline were more widespread across direct corporate banking services. Companies would then have a more balanced choice between building their own integrations and using an intermediary. The fragmented surface makes the intermediary the default for many organisations, adding a third party to the relationship as well as an engineering cost.",[14,266,267],{},"Integrating one bank may be easy. The real product is keeping forty of them working today and after the next change.",[14,269,270],{},"If you work with corporate banking APIs in Türkiye and there is a common route or a materially different practice that I have missed, I would be glad to hear the correction.",{"title":272,"searchDepth":273,"depth":273,"links":274},"",2,[275,276,277,278,279,280],{"id":70,"depth":273,"text":71},{"id":135,"depth":273,"text":136},{"id":160,"depth":273,"text":161},{"id":176,"depth":273,"text":177},{"id":212,"depth":273,"text":213},{"id":251,"depth":273,"text":252},[282,283],"business","engineering",null,"2026-08-27","A single bank integration may be straightforward. The real cost is normalising different access models and keeping dozens of connections working as banks change.",false,"md","\u002Fimages\u002Fhero\u002Fbank-api-integration.avif","Bank connections with different authentication methods converge on a shared integration line.","Field Notes","en",{},true,"\u002Fbank-account-api-integration",8,{"title":6,"description":286},"Bank Account API Integration: Why Scale Gets Expensive","bank-account-api-integration",[301,302,303,304,305],"open-banking","bank-api","account-transactions","integration","build-vs-buy","post","ieUYk8CX0X3W1XdH-sAh3vPzLr4Uu3jZGGqNzHvCkvI",{"path":309},"\u002Ftr\u002Fbanka-hesap-hareketleri-entegrasyonu",{"prev":311,"next":314,"others":317,"lucky":416,"readingTime":296},{"path":312,"title":313},"\u002Fhow-to-do-content-pruning-a-real-world-case-study","How to Do Content Pruning: A Real-World Case Study",{"path":315,"title":316},"\u002Fai-assisted-rest-api-development","Preserving API Quality in AI-Assisted Development",[318,321,324,325,326,329,332,335,338,341,344,347,350,353,356,359,362,365,368,371,374,377,380,383,386,389,392,395,398,401,404,407,410,413],{"path":319,"title":320},"\u002Fwhen-process-automation-actually-needs-ai","When Does Process Automation Actually Need AI?",{"path":322,"title":323},"\u002Fstart-with-the-business-problem-not-the-ai-model","Start With the Business Problem, Not the AI Model",{"path":312,"title":313},{"path":315,"title":316},{"path":327,"title":328},"\u002Ftesting-a-button-treating-an-entire-website-redesign-as-a-sure-thing","Testing a Button, Treating an Entire Website Redesign as a Sure Thing",{"path":330,"title":331},"\u002Fmanaging-technology-and-transforming-the-business-are-not-the-same","Managing Technology and Transforming the Business Are Not the Same Thing",{"path":333,"title":334},"\u002Fturkeys-first-real-time-mystery-shopping-reporting","Turkey's First Real-Time Mystery Shopping Reporting Platform",{"path":336,"title":337},"\u002Fkeeping-customers-happy-isnt-enough","Keeping Customers Happy Isn’t Enough. You Have to Follow Up.",{"path":339,"title":340},"\u002Fdo-ai-visibility-tools-really-work","Do AI Visibility Tools Really Work? What They Actually Measure",{"path":342,"title":343},"\u002Fllms-txt-was-never-the-point","llms.txt Was Never the Point",{"path":345,"title":346},"\u002Fdo-you-know-how-dependent-your-company-is-on-ai","Do You Know How Dependent Your Company Is on AI?",{"path":348,"title":349},"\u002Fthe-ai-productivity-baseline-is-moving-faster-than-we-remember","AI Wasn’t Always This Good. We Just Got Used to It.",{"path":351,"title":352},"\u002Fai-made-code-cheap-verification-is-still-expensive","AI Made Code Cheap. Verification Is Still Expensive.",{"path":354,"title":355},"\u002Faccessing-know-how-is-not-the-same-as-creating-it","Accessing Know-How Is Not the Same as Creating It",{"path":357,"title":358},"\u002Fthe-threshold-collapsed-to-zero","The Threshold Collapsed: What ProductLog Taught Me About Building in Public",{"path":360,"title":361},"\u002Fbuild-in-public-2-0","Build in Public in the AI Era: What to Share and What to Keep Private",{"path":363,"title":364},"\u002Fgoogle-generative-ai-data-ai-citation-timing","AI Visibility Dropped Before Search: The Google Data That Changed My Theory",{"path":366,"title":367},"\u002Fthe-era-of-the-previous-vibe-coder-begins","The Era of the \"Previous Vibe Coder\" Begins: The Invisibility of Clean Code and the Technical Debt Bill of AI",{"path":369,"title":370},"\u002Fone-victory-several-defeats","One Victory, Several Defeats",{"path":372,"title":373},"\u002Fthe-job-ai-wont-take-and-the-five-it-prevents","The Hiring AI Makes Invisible",{"path":375,"title":376},"\u002Fproductlog-the-platform-i-built-for-myself-first","ProductLog: The Platform I Built for Myself First",{"path":378,"title":379},"\u002Fcomprehension-debt-the-bill-comes-due-alone","Comprehension Debt: The Bill Comes Due Alone",{"path":381,"title":382},"\u002Fwordpress-to-nuxt-ai-powered-content-pipeline","From WordPress to Nuxt: Building an AI-Powered Content Pipeline",{"path":384,"title":385},"\u002Fai-visibility-illusion-bing-citation-share","The AI Visibility Illusion: What Bing's Citation Share Data Actually Reveals",{"path":387,"title":388},"\u002F1m-impressions-per-month-0-revenue-a-programmatic-seo-post-mortem","1M Impressions per Month, $0 Revenue: A Programmatic SEO Post-Mortem",{"path":390,"title":391},"\u002Fthe-end-of-coding-or-a-new-renaissance-the-invisible-crisis-of-ai","The End of Coding or a New Renaissance? The Invisible Crisis of AI",{"path":393,"title":394},"\u002Fraising-children-in-the-age-of-artificial-intelligence","Raising Children in the Age of Artificial Intelligence",{"path":396,"title":397},"\u002Fredar-ai-powered-summaries-for-kap-disclosures-and-open-sources","Redar: AI-Powered Summaries for KAP Disclosures and Open Sources",{"path":399,"title":400},"\u002Fpesintaksit-cash-vs-installments-a-turkish-inflation-aware-payment-comparison-tool","Cash or Installments? – The Story Behind PeşinTaksit",{"path":402,"title":403},"\u002Fbeyond-the-bot-lessons-from-building-a-chat-system-for-global-patients","What We Learned Building a Healthcare Chatbot for International Patients",{"path":405,"title":406},"\u002Fhow-i-built-a-modern-infrastructure-using-open-source-tools-and-the-power-of-cloudflare","Why I Run camiler.org on a Single VPS",{"path":408,"title":409},"\u002Ffrom-rules-to-decisions-the-real-time-sales-intelligence-platform-we-built-at-vanity","Medical Tourism Lead Management: How We Moved from Manual Routing to a Real-Time Sales System",{"path":411,"title":412},"\u002Fwhy-im-building-rankextension-making-google-search-console-actually-make-sense","What Happened to RankExtension?",{"path":414,"title":415},"\u002Fan-seo-experiment-in-a-low-competition-serp-with-google-maps-and-openai","Building camiler.org: A Programmatic SEO Experiment with Google Maps and OpenAI",{"path":336,"title":337},[],[419,421,423],{"path":375,"title":376,"date":420},"2026-06-23",{"path":348,"title":349,"date":422},"2026-08-20",{"path":396,"title":397,"date":424},"2025-10-30",1787875354828]