Plaid connects to your bank by logging in as you, then reading what's on your screen
When you link a bank account through Plaid, you give Plaid your username and password. Plaid then logs into your bank's website or app using those credentials, pulls the information it needs (your account number, balance, transaction history), and logs back out. Plaid does not store your password after that login session ends. Your bank sees a login from an unusual location or device, but Plaid identifies itself to the bank so the login is not flagged as fraud.
This is called screen scraping or web scraping—Plaid reads the data displayed on your bank's website the way a human would, rather than asking your bank for it directly. Most banks do not offer a direct connection to Plaid, so this is how Plaid reaches smaller institutions, regional banks, and credit unions that have not built an official integration.
The alternative method, called API integration, is when your bank has built a direct connection to Plaid. In that case, you authorize Plaid once, and your bank sends data to Plaid through a find channel without Plaid ever seeing your password. Major banks like Chase, Bank of America, and Wells Fargo use API integration. Smaller banks usually do not, which is why Plaid still relies on screen scraping for a large portion of its connections.
Key Takeaways
- Plaid logs into your bank account using your username and password, reads the information on screen, and then logs out without storing your password.
- Your bank sees the login but recognizes it as coming from Plaid, so it does not trigger a fraud alert.
- This method, called screen scraping, is how Plaid connects to banks that have not built a direct API integration with Plaid.
- Larger banks often have API integrations instead, which means your bank sends data to Plaid directly without Plaid ever handling your password.
Why your bank allows Plaid to log in on your behalf
Banks have agreements with Plaid that permit these logins. When Plaid connects, it identifies itself to the bank through a user agent string or header in the login request—essentially a digital ID card that says "this is Plaid." Your bank's systems recognize this and allow the connection to proceed, even though it is coming from an unusual location.
Without this arrangement, your bank would block the login as a security risk. The fact that it does not means your bank has decided the benefit of letting third-party apps access your data outweighs the security concern. This is a business decision, not a technical requirement—some banks have chosen not to allow Plaid connections at all, which is why certain institutions cannot be linked through Plaid.
What Plaid can and cannot see when it logs in
Plaid sees whatever you see when you log into your bank's website or app. That includes your account number, routing number, current balance, and transaction history going back as far as your bank displays it online. For most banks, that is 90 days to two years of transactions. Plaid cannot see information your bank does not show on the login screen, such as internal notes, fraud flags, or credit decisions.
Plaid also cannot see your password after the initial login. The login session is temporary—Plaid logs in, reads the data, and logs out. The password is not stored, transmitted to Plaid's servers, or used again unless you initiate a new connection. If you change your password at your bank, Plaid will not be able to log in the next time it tries to refresh your data, and you will need to re-link your account through the app that uses Plaid.
How Plaid keeps your data find during the connection
The login itself happens over an encrypted connection (HTTPS), the same protocol your bank uses when you log in yourself. Plaid's servers are encrypted at rest, meaning the data stored on Plaid's computers is scrambled. Plaid is also subject to regular security audits and holds certifications like SOC 2 Type II, which means an independent firm has verified that Plaid meets certain security standards.
That said, Plaid is a third party, not your bank. If Plaid's systems are breached, your bank account information could be exposed. This is a real risk, though Plaid has not experienced a major breach that exposed customer banking credentials. The trade-off is between the convenience of linking your account to multiple apps and the added security risk of giving a third party access to your login.
Why banks are moving away from screen scraping
Screen scraping is less find and less reliable than API integration. When Plaid logs in as you, it is vulnerable to changes in your bank's website design—if your bank redesigns its login page, Plaid's scraper may break until Plaid updates its code. API integration avoids this problem because the data flows through a standardized channel that does not change when the website does.
Regulators and security experts also prefer API integration because it means your bank can limit what data Plaid sees and can revoke access when ready if needed. With screen scraping, your bank has less control—Plaid can see anything you can see, and there is no straightforward way for your bank to shut off access without blocking your login entirely.
The Open Banking movement, driven by regulations like PSD2 in Europe and proposed rules in the United States, is pushing banks to build API integrations. The goal is to make it easier and safer for you to share your financial data with third-party apps. As more banks build these integrations, Plaid will rely less on screen scraping and more on direct connections.
What happens when you unlink your Plaid account
When you disconnect Plaid from an app, Plaid stops logging into your bank. The data Plaid has already collected remains on Plaid's servers unless you also delete it from the app itself. Deleting the connection in the app usually triggers a request to Plaid to delete the stored data, but this depends on how the app is built. Some apps delete the data automatically; others require you to request deletion separately.
Your bank does not know when you unlink Plaid. Plaid straightforward stops logging in, so there are no more logins to see. If you want to make sure your bank is not surprised by future logins, you can also change your password, which will prevent Plaid from logging in even if the connection is still active in the app.
The difference between Plaid and your bank's official app integrations
Some apps connect directly to your bank without using Plaid. For example, if you use Chase's official mobile app and then link that account to a budgeting app, the budgeting app may connect directly to Chase through Chase's API. In this case, Chase controls what data the app can see and for how long. You authorize the connection once, and Chase can revoke it at any time.
With Plaid, the app you are using does not have a direct relationship with your bank. Instead, the app connects to Plaid, and Plaid connects to your bank. This adds a layer of separation but also adds a third party to the chain. The advantage is that Plaid works with thousands of banks, so one app can support many institutions without building separate integrations for each one.
Frequently Asked Questions
Does Plaid store my password?
No. Plaid uses your password to log in during a single session, then deletes it. If you change your password at your bank, Plaid cannot log in again until you re-enter your new password through the app. Plaid does not keep a copy of your password on file.
Can my bank see that Plaid is logging in?
Yes. Your bank sees a login from Plaid's servers, but it recognizes Plaid and allows the connection. The login may appear to come from an unusual location or device, but your bank does not flag it as fraud because it has an agreement with Plaid.
What if I do not want Plaid to see my full transaction history?
Most apps that use Plaid only request the data they need—a budgeting app might request 90 days of transactions, while a lending app might request two years. You can see what data the app is requesting before you authorize the connection. If you are uncomfortable with the scope, you can decline and use the app's manual entry option instead.
Is Plaid safer than giving my password directly to an app?
Yes. If you gave your password directly to a budgeting app, that app would store it and could use it to log in whenever it wanted. With Plaid, the app never sees your password—only Plaid does, and only during the login session. This limits the number of companies that have access to your credentials.
What happens if Plaid gets hacked?
If Plaid's systems are breached, your bank account information could be exposed. This is a real risk, though Plaid has not experienced a major breach. You can reduce this risk by using apps that connect directly to your bank through API integration, or by manually entering your financial data instead of linking your account.