Why AgenticBooks reads European bank accounts through a regulated open-banking provider, how a connection works, and what we built on top so the books stay right.
AgenticBooks connects to more than 1,400 banks in 29 European countries through Enable Banking, a Finnish open-banking provider. Every connection is read-only by construction. It refreshes once a day, books settled transactions only, and puts each bank account in the ledger under its own name.
This post explains why we picked Enable Banking, how a connection works, and what we built on top of it. It also covers the limits we can’t engineer away, because a bank feed is only as good as what the bank sends.
Direct bank APIs are for account holders
Banks like Revolut offer business APIs so that account holders can connect their own tools. We used Revolut’s API for our own company while we built the ledger. It gave us live data from real accounts from the first day, which is how we tested the bookkeeping engine.
That route only covers an account holder’s own accounts. When a software company reads a customer’s bank account in Europe, PSD2 EU regulation sets the route: the customer gives consent to their bank, and access runs through a regulated account information service provider (AISP). So opening AgenticBooks to customers means choosing an AISP.
What we looked at
| Option | Outcome | Why |
|---|---|---|
| GoCardless Bank Account Data (formerly Nordigen) | Not available | Closed to new sign-ups |
| Salt Edge | Fallback | The runner-up, kept in reserve in case Enable Banking’s coverage or licence fell through |
| CSV uploads | Rejected | A stopgap that contradicts books that build themselves |
| Enable Banking | Chosen | Business accounts across the EEA, a hosted consent flow, a simple session model, clear pricing, and a sandbox with a mock bank |
Enable Banking is based in Espoo, Finland, and is a registered account information service provider supervised by the Finnish Financial Supervisory Authority (FIN-FSA). Its API sits in front of the account-information interfaces of more than 2,700 banks across 30 countries.
We are Enable Banking’s client. The customer gives consent to their own bank through Enable Banking’s hosted flow, and the regulated role sits with Enable Banking.
Before opening it to customers, we ran it side by side with the direct connection on our own Revolut account, compared 30 days of data from both, and reconciled every balance. The first production import, on a test organisation set up like a customer’s, brought in all transactions, and a disconnect-and-reconnect rehearsal ended with zero duplicates.
Read-only by construction
Before we chose Enable Banking, we set a rule for anything that touches a customer’s bank: prefer a structural guarantee over a behavioural promise. “The credential can’t move money” beats “we could, but we won’t”.
With Enable Banking, an account information session has no payment capability at all. As a comment in our code puts it: “Structurally read-only: AIS sessions cannot move money.”
The stored credential can read balances and settled transactions for the accounts the customer chose, until the consent expires. It can’t start a payment, change a beneficiary, read accounts the customer didn’t select, or outlive 180 days.
Two custody details go beyond the minimum. The whole deployment uses a single application key that we hold, so no customer ever uploads a certificate or key to anyone. And when a customer removes a bank, we drop its session data straight away. We keep one copy only long enough for a final history pull and the call that revokes the consent at Enable Banking, then delete that too.
How a connection works
The integration is small, and that’s mostly down to Enable Banking’s design. There’s one application credential for the whole deployment: a token we sign with our own key, valid for at most 24 hours. Per customer, we store a session ID and its expiry date. Sessions never refresh. They expire or get revoked, and the customer consents again. There’s no token manager and no refresh logic to get wrong.
A connection runs in five steps:
- Pick the bank. The picker searches the whole catalogue by name and only asks for a country when a bank operates in several. It lists only banks that support business accounts and are out of beta.
- Consent at the bank. The customer is sent to their bank, approves in their banking app with strong customer authentication, and comes back to AgenticBooks. We ask for 180 days, and some banks set a shorter limit. A signed token checks that the bank coming back is the one that was chosen.
- First import, while the customer is there. The first pull runs within 15 minutes of consent, carrying the customer’s IP address and browser details, so it counts as customer-present and doesn’t use the daily allowance.
- A daily sweep after that. Each connection is read again once a day.
- Settled transactions only. Pending transactions are never stored. Balances are saved as dated snapshots, using the bank’s own reference date.
Three rules that shaped the product
Four reads a day. PSD2 lets an account information provider read an account at most four times in 24 hours when the customer isn’t actively asking, unless the bank agrees to more. That rules out fetching live balances whenever a dashboard loads or an AI agent asks. Instead, every balance a person or an agent sees comes from a snapshot the daily sweep wrote, stamped with the bank’s reference date. The sweep waits 23.5 hours between pulls and backs off for six hours after a failure.
The constraint has an upside. The dashboard, the reconciliation view and the MCP tools an agent calls all read the same number. An agent asking for a balance gets a dated snapshot, never a throttled bank.
Consents last 180 days. EU rules require the account holder to authenticate with their bank again at least every 180 days, and there’s no refresh token to get around it. We treat this as a planned renewal rather than an outage. Our team is alerted 14 days before a consent runs out, the integrations page shows each connection’s expiry date, and reconnecting carries on in the same books. We also only switch a connection off on positive evidence that the consent is dead. In the words of another comment in our code: “Disable demands positive evidence; unknown errors retry, they never disable.”
A bank is a country and a name. Enable Banking lists each bank once for every country it serves. Danske Bank appears as six banks in six countries. Revolut, bunq, N26, PayPal and Wise each appear 29 times. So AgenticBooks applies an identity rule: a handful of cross-border neobanks count as one bank by name, whichever country a customer connects them through, and every other bank keeps its country-and-name pair.
Data integrity is our skill
Moving data out of the bank is easy, but keeping the books stable while connections come and go is harder.
Every time a customer re-consents, each account comes back with a new session ID. Books keyed on those IDs would duplicate at every renewal, so every transaction, cash account and balance snapshot in AgenticBooks is keyed on a stable account fingerprint from Enable Banking, with the IBAN as a fallback. If a bank provides neither for an account, we refuse that account at connection time rather than let it split the books months later.
A few more safeguards sit on top:
- Duplicates collapse. Daily re-pulls and overlapping consents see the same transactions again, and a dedupe key with an occurrence count absorbs them.
- Balances only move forward. An older snapshot never overwrites a newer one, so two consents on the same account can’t roll a balance backwards.
- Each bank account is its own cash account. It sits under Cash & Bank in the chart of accounts, named after the bank and currency, so the balance sheet, the reconciliation view and the MCP tools all use the customer’s own bank names.
- Several banks at once. A business can connect more than one bank, or hold more than one consent at the same bank. Removing one never touches accounts another connection still serves, and a transfer from Revolut to N26 is paired from its two legs into a single movement.
Connects versus books-verified
There’s no bookkeeper between the bank feed and the ledger in AgenticBooks, so the feed has to be right before it reaches the books. That’s why we make two separate claims about banks.
Connects means a bank is in the picker. Enable Banking’s catalogue has about 2,700 entries. We offer only the ones that are out of beta and support business accounts: 1,661 entries in 29 countries, which comes to just over 1,400 distinct banks once a bank listed in several countries is counted once.
Books-verified means a person has reviewed that bank’s first real import. The first import from any new bank sends our team a quality report: how many transactions came through, how far back the history goes, and what share of rows carry a counterparty name and a bank reference. We compare it against Revolut, whose first import had a counterparty name and a bank reference on every row, and 90 days of history. Today the verified list has one bank on it: Revolut. It grows one review at a time.
We also log every bank search that comes back empty, so the list of banks people want and can’t find yet is data rather than guesswork. One of our design notes put it well: “The real deliverable of opening the catalog is measurement — which banks people search for and don’t find.”
FAQ
Is AgenticBooks a regulated account information provider?
No. Enable Banking Oy is the registered account information service provider, supervised by FIN-FSA. AgenticBooks is its client and holds no banking licence.
Can AgenticBooks move money from a connected bank?
No. Connections use account information access only, which has no payment capability. The credential can read balances and settled transactions, and nothing else.
How fresh are bank balances in AgenticBooks?
Up to a day old. PSD2 allows four unattended reads per account per day, so balances come from a daily snapshot that carries the bank’s reference date.
Why does a bank need reconnecting every 180 days?
EU rules require the account holder to authenticate with their bank again at least every 180 days. AgenticBooks shows each connection’s expiry date, our team is alerted 14 days before it runs out, and reconnecting continues in the same books.
Which banks work with AgenticBooks?
More than 1,400 banks across 29 European countries connect through Enable Banking. Revolut is books-verified today. Other banks join the verified list once a person has reviewed their first import.
What happened to GoCardless Bank Account Data (Nordigen)?
It closed to new sign-ups, so it wasn’t an option when we chose a provider.
AgenticBooks is the accounting layer for AI-native businesses — a ledger AI agents can operate over MCP, with unified multi-bank balances, automatic transfer matching, and one-command month-end close.