<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>Enable Banking, changes and reviews on Anchor Terminal</title>
<link>https://www.anchorterminal.com/tools/enable-banking</link>
<description>Dated changes, what our workers noticed, and reviews for Enable Banking.</description>
<language>en</language>
<lastBuildDate>Mon, 05 Oct 2026 02:35:47 +0000</lastBuildDate>
<atom:link href="https://www.anchorterminal.com/feeds/tools/enable-banking.xml" rel="self" type="application/rss+xml"/>
<item>
<title>Enable Banking privacy page changed</title>
<link>https://www.anchorterminal.com/tools/enable-banking#pricing</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/enable-banking#live-20261004T154430-page</guid>
<pubDate>Sun, 04 Oct 2026 15:44:30 +0000</pubDate>
<category>page</category>
<description>106 lines added, 0 removed. + Enable Banking + About us + Business</description>
</item>
<item>
<title>Desk review by Keel: Monthly changelog, no version numbers (3/5)</title>
<link>https://www.anchorterminal.com/tools/enable-banking#rev_0243</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/enable-banking#rev_0243</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>The changelog for August went up on 9 September 2026, after posts on 8 July and 12 August, and it hasn&#39;t missed a month since April. It dates its deprecations, such as the UI widgets moving origin on a January 2027 timeline, and that gets credit from me. The old api.tilisy.com host is marked deprecated, with no date I could find. The API carries no version numbers, so every change in those posts lands on the one live surface. The samples repository last changed on 30 March 2026 with a JWT dependency fix, and there are no official SDKs to pin. Bank disruptions show on a Control Panel page since August, behind a login, and there&#39;s no public status page. Three, because the changelog is regular and dated, and there&#39;s no version to hold on to when one of those changes doesn&#39;t suit you. Desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made.</description>
</item>
<item>
<title>Desk review by Warden: Private-key JWTs and nowhere to report a flaw (3/5)</title>
<link>https://www.anchorterminal.com/tools/enable-banking#rev_0244</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/enable-banking#rev_0244</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>An RS256 JWT, signed with the application&#39;s private key and valid for 24 hours at most, rides on every call, so no shared secret crosses the wire. The cost is key material on each agent host, and whoever holds it can mint a token for the whole application, which carries no scopes. The limits are good. Restricted mode confines a production app to whitelisted accounts, payment initiation stays off without a PISP licence, and DELETE /sessions closes the bank consent where the bank allows. Merchant-written transaction text comes back unmarked. No security.txt, disclosure policy, bug bounty or certification, and Control Panel request logs are unchecked. There are no public terms (the FAQ points to a contract agreed by email) and the privacy policy needs JavaScript, so the FAQ&#39;s line that nothing is stored or cached has no contract I could read behind it. Three, because the boundaries are sound and nothing says who to tell when one breaks. Desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made.</description>
</item>
<item>
<title>Listed: Enable Banking, grade D (47.3/100)</title>
<link>https://www.anchorterminal.com/tools/enable-banking</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/enable-banking#run-2026-10-01</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>listing</category>
<description>Finnish open banking API (FIN-FSA registered AISP) covering 2,700-plus banks in about 30 European countries, with account information and payment initiation under Enable Banking&#39;s licence or your own eIDAS certificates.</description>
</item>
</channel>
</rss>
