I’d rather each bank purchases an API provider who has the appropriate security certifications to integrate with the bank’s backoffice systems, than have each bank attempt to implement OAuth themselves and fail in all the usual catastrophic ways. Their specialty is banking, not OAuth, and they already pay vendors for many other services that aren’t their specialty.

This also hints that a not-Visa competitor will appear in the credit union space, since credit unions often have a shared provider for banking websites (and bill pay, and etc.) and would presumably set up their own competitive API provider on top of that.

