Skip to content

Build1 publisher3 min readPublished

The free bank-data tier is gone, and your users have to re-authorize by hand

Nordigen's free account-information API has been sunset inside GoCardless Bank Account Data, which stopped onboarding new developers in 2025. PSD2 consents do not transfer.

The Engineer · Build desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • Nordigen was a Latvian open-banking startup that ran a genuinely free account-information API.
  • Nordigen was acquired by GoCardless in 2022 and is being folded into 'GoCardless Bank Account Data'.
  • Nordigen's free tier has been sunset.
  • GoCardless Bank Account Data stopped taking new onboarding in 2025.
  • As of the article's writing there is no indication that access is coming back for new independent developers.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

Nordigen, the Latvian open-banking startup that ran a genuinely free account-information API, was acquired by GoCardless in 2022, folded into GoCardless Bank Account Data, and its free tier has been sunset [1][2][3]. GoCardless Bank Account Data itself stopped taking new onboarding in 2025, and according to a migration field guide published on dev.to by John Frandsen there is no indication access is coming back for new independent developers [4][5].

The affected population is specific: nightly balance-and-transaction pulls for budgeting apps, card-spend categorizers, scripts pushing transactions into Google Sheets, and indie SaaS with a "connect your bank" button that a few hundred real people use [6]. All of it worked on a free tier, and none of it has a procurement department [6].

Frandsen sorts the exits into three, by pain. Going direct means registering as an account information service provider, surviving the paperwork, and buying QWAC and QSealC certificates from a qualified trust service provider before integrating bank by bank [7]. Certificates alone run EUR 2,000 to EUR 10,000 per year depending on the provider, which is roughly EUR 167 to EUR 833 a month before anyone writes code [8][9]. Add months of audit evidence, policy documents, insurance and registrations [10], per-bank onboarding that sometimes demands its own certificates [11], and permanent ownership of every bank's API quirks and breaking changes [12]. That is a reasonable trade if bank connectivity is the product, and not if you have 40 users [13].

The middle path, where Frandsen says most ex-Nordigen builders land, is an aggregator that holds the licence and certificates but lets you bring bank-issued client credentials you registered for yourself, usually through a web form with same-day approval, in exchange for one harmonized REST interface [14][15]. You keep the keys, so going direct later stays possible [15]. The enterprise option puts the licence, certificates and bank relationships entirely with the aggregator, and hands you sales calls, per-call pricing tiers and contract cycles [16].

The migration cost that no vendor choice removes is consent. A PSD2 consent is issued by the bank to one named provider for one user for a limited window, it does not export, and it stays behind when you switch [17]. Every end user re-authenticates once, so plan the messaging and expect connected accounts to dip [18]. Recurring-access consents last up to 90 days, 180 in some jurisdictions as rules evolve, and after migration day one is day one again [19] - about four re-authorization cycles a year to design around [20]. Nordigen requisitions and end-user agreements cannot be moved or converted; they die with the account [21].

History is the other thing you lose quietly. Most banks serve roughly 90 days of transactions per consent window, some more, few years [22]. If your old provider cached more than that, export raw accounts, balances, transactions and metadata into storage you control before deactivating, because the new provider cannot re-fetch what the bank will not serve [22].

Two ingestion details worth fixing during the move rather than after. Hash the bank's stable transaction ID together with the booking date as your dedupe key, because some banks re-issue the same ID for a corrected transaction on a different date and you want that as a new row [23]. And keep pending and booked in a state column, count only booked rows in financial reports, and expire old pendings instead of promoting them, since dropped card authorizations never become booked [24].

Watch whether GoCardless reopens onboarding at all [5], watch the 90-versus-180-day consent window as the rules move [19], and watch your connected-account count in the week after you flip providers [18].

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories