How do you prevent end users for getting access to a plain text auth token?
My plan is to have an app that communicates directly with Nordigen. But this means end users need access to secret keys, I knoe this is a bad practice and I think in the end I will put Nordigen behind a proxy that authenticates end users.
Democratising PSD2 Data @ Nordigen | Fintech | Open Banking
0
0
Hi George,
It would be more optimal to put Nordigen behind a proxy that authenticates end users (as you write yourself).
In the more medium term, Nordigen also has user level permissions on our roadmap, that would be another way how such situations could be solved.
GoCardless Bank Account Data (Ex-Nordigen) enables businesses to securely access your user’s bank account information for better lending, accounting, KYC, and financial management.
Why chose us?
1)
With over 2.5 million reviews, we can provide the specific details that help you make an informed software buying decision for your business. Finding the right product is important, let us help.
or continue with
LinkedIn
Google
Google (Business)
Gmail.com addresses not permitted. A business domain using Google is allowed.