I’ve signed up for a couple retail investment aggregation and analysis products recently. They’re a set of services that look at your online brokerage accounts and analyze how you are performing relative to index benchmarks and then make suggestions to improve your performance. My interest in the space is both professional (possible investment) and personal (could be useful to me).
I cannot understand why the financial services industry will not embrace an OAuth-like solution. Companies like Yodlee and CashEdge that take users credentials and store them for persistent access into the future are scary.
However, Yodlee and CashEdge are not to blame (IMHO). It’s the online brokerages and online banking software that have failed to embrace an OAuth-like permission system that deserve the blame. Why not allow users to create a revokable token that they can pass to authorized aggregators, and permission that token with read-only access or other limitations that will give consumers comfort? This would be so much safer (and a better user experience) an asking users to hand over their username and password.
The answer is simple, brokerages and banks know that their relationship with the end customer is paramount, and they want to own both the interface that the customer uses and the data that the customer creates. It’s a walled-garden-type of approach, and that approach rarely ever wins in the long run.
Are you creating a new bank or brokerage (What’s up Simple…)? If so, embrace OAuth! Cut Yodlee and CashEdge out of the equation. Let a thousand flowers of front-end experiences bloom on top of your banking back end. You’ll still see all the data, and you’ll still charge all the same fees. This approach would allow you to be so much more than just another commodity brokerage/bank app. Instead, you could build a financial operating system… a platform where thousands of app developers will build the best possible banking experience for you, for free.
This is a real investment opportunity, but because starting a new brokerage or bank is such a capital intensive exercise, I’m publishing it here in hopes that some of the existing players in this space read it and build it into their existing products. Do you all know of any brokerages or banks that support OAuth already?
