


The standard is to redirect the user to a login page on the website of the service providing the login.

Never give credentials to a third party.In addition to, plenty of other popular services use Plaid, including Venmo, Robinhood, and Coinbase.ĭespite the popularity, this service appears to break two "fundamental" Internet security rules: Plaid provides an API for websites and apps to easily access this banking information. Then, Plaid accesses the user’s bank account with those credentials on the user’s behalf to get information. To do this, it requires the user to provide their banking username and password to a webpage from Plaid, not their bank. I recently signed up for, which uses a service called Plaid to link a bank account.
