Screen scraping relies on a third party handling customer credentials, which broadens credential exposure and weakens accountability. Consent-driven APIs use scoped authorisation and revocation so the bank can govern what is shared without handing out login secrets. The difference is not only technical, but also who controls access and how quickly it can be withdrawn.
Why screen scraping and consent-driven APIs are not the same control model
Screen scraping is a compatibility technique that imitates a user session after credentials have been shared with a third party. Consent-driven APIs are a governed integration model: access is granted to defined data and functions, under explicit scope, and the user or bank can revoke it without changing login secrets. That difference changes both trust boundaries and operational control.
With screen scraping, the third party often sees or handles the same credentials a customer would use directly, which creates a broader exposure surface and makes accountability harder to separate. With consent-driven APIs, the bank can keep authentication under its own control while exposing only the permitted data path. That is why the API model is usually easier to audit, restrict, and withdraw cleanly.
The practical distinction is less about transport and more about authority. A scrape-based flow depends on impersonation of the customer session, while a consent-based flow depends on authorisation that is narrowly defined and time-bounded. In a governed integration, the bank can usually see what was approved, what was accessed, and when that approval ended. For privacy and data-minimisation considerations, see the Identity Data Privacy and Consent Guide.
Why the difference matters for access control, privacy, and resilience
Consent-driven APIs reduce the need to expose primary login credentials to another party, which lowers the chance that a compromise of the aggregator becomes a compromise of the customer account itself. They also make revocation meaningful: access can be withdrawn at the authorisation layer instead of forcing a password reset or breaking unrelated services. In API terms, this is the difference between governed delegated access and hidden credential sharing.
Screen scraping is more brittle because it inherits the bank’s user interface and session behaviour. Small changes to the page, MFA step, challenge flow, or device checks can break integrations without warning. That creates resilience risk for the aggregator and indirect operational risk for customers who depend on it. A consent-based API is generally more stable because the contract is explicit and the access path is designed for machine-to-machine use.
For the API side of the comparison, the security issue is not just whether the endpoint exists, but whether authorisation is correctly scoped and enforced. The OWASP API Security Top 10 is useful here because it frames the common failure modes around broken authorisation and overexposure of data or actions.
How practitioners should evaluate the two models in the real world
In practice, the right question is not “does the integration work”, but “who controls consent, how is it limited, and how fast can it be revoked?” If the third party needs ongoing access to a live customer login, the model is carrying avoidable exposure. If the bank exposes a narrow API with customer-granted scope and clear auditability, the control posture is usually stronger even if the implementation is more formal.
Consent-driven APIs are also easier to align with data governance because the bank can define specific data elements, expiry, and purpose. Screen scraping tends to blur those boundaries: once a credential is shared, the third party may be able to see more than the intended dataset, and the bank has less practical control over how that access is exercised. That is why many teams treat credential sharing as a red flag even when it appears convenient.
What to verify: confirm whether the integration uses bank-controlled authorisation, whether scopes are granular, whether consent can be withdrawn independently of customer login credentials, and whether access logs show exactly what was shared and when. If those answers are unclear, the arrangement is behaving more like credential delegation than consent management.
Common mistake: treating a working screen-scrape connection as equivalent to an API simply because it returns the same data. The security model is different, and so are the failure and revocation paths.
Practitioner takeaway: prefer the model that preserves bank-controlled authentication and narrowly scoped authorisation, because that is what makes access governable, revocable, and auditable at scale.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP API Security Top 10 addresses the attack surface, NIST SP 800-53 Rev 5 sets the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP API Security Top 10 | API2 — Broken Authentication | Scraping often relies on shared credentials, while consent APIs avoid exposing login secrets. |
| Recommendation — Keep authentication under bank control and avoid credential sharing with third parties. | ||
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | Consent APIs should expose only the minimum data and actions required by the approved scope. |
| Recommendation — Limit delegated access to the minimum permissions needed for the approved consent scope. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | The question is about who controls access and how it is governed and revoked. |
| Recommendation — Define and enforce access rules that separate customer authentication from third-party authorisation. | ||
Related resources from NHI Mgmt Group
- What is the difference between screen scraping and API-based banking access?
- What is the difference between API access and screen scraping under PSD2 payment account rules?
- What is the difference between Section 1033 API access and screen scraping?
- What is the difference between RESTful APIs and event-driven APIs?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org