Skip to main content
← frontier

JPMorgan Just Charged for 1.89 Billion API Requests. The Free Data Era Ends

By Elena Petrova•

The API Layer Becomes the Standard

In June 2025, JPMorgan Chase told its largest data aggregators it would start charging for the 1.89 billion API requests it received in a single month — the first major U.S. bank to monetize bulk access to open banking pipes. At fractions of a cent per pull, the annual cost for Plaid's volume runs into the low millions; if other major banks follow, the economics of free data access shift permanently.

That move crystallizes a shift: open banking APIs have become the standard financial infrastructure layer, powering thousands of fintech products across more than 12,000 institutions. But the generic design, built for consumer budgeting apps, is fracturing under the specialized pressure of frontier tech: space contractors managing classified billing milestones, robotics fleets paying suppliers across seventeen jurisdictions, biotech startups running regulated payroll for clinical-trial staff.

A decade ago, connecting a new app to a user's bank account meant screen-scraping, brittle, insecure, and barely tolerated by the institutions being scraped. Today that layer has hardened into a utility: a single API call reaches across twelve thousand banks and credit unions, moves seven hundred fifty thousand transactions a day, and powers payroll, lending, and treasury operations at companies building rockets, robots, and AI models. The question is no longer whether this plumbing exists. It is whether the standard design can survive the specialized pressure frontier tech puts on it.

Plaid wrote the de facto standard. Founded in 2013 by Zach Perret and William Hockey after they won the TechCrunch Disrupt hackathon in Manhattan with a prototype called Rambler, the company turned a personal connection at Venmo into its first enterprise customer. By 2020 Visa agreed to pay $5.3 billion, the Department of Justice reported, for it — a price Visa's own executives admitted did "not hunt on financial grounds" but served as an "insurance policy" against a competitor whose potential one executive diagrammed as a volcano, with current capabilities just "the tip showing above the water." The Department of Justice sued to block the merger, arguing Plaid planned to launch a lower-cost online debit product that would threaten Visa's monopoly. Visa and Plaid terminated the agreement in January 2021. Plaid stayed independent.

The numbers that followed suggest the DOJ saw the threat clearly. A joint press release with JPMorgan Chase in September 2025 confirmed connections to more than twelve thousand financial institutions and seven thousand customer companies. Independent directory tracking puts the institution count at 9,706 across twenty live markets, with 9,162 in the United States alone. Cumulative consumer account connections have passed five hundred million. Annual recurring revenue reached an estimated $546 million in 2025, up 40 percent year over year, marking the company's first full year of adjusted EBITDA profitability. A February 2026 employee tender offer valued the company at $8 billion, a 31 percent recovery from the $6.1 billion Series E price just ten months earlier. Preliminary IPO discussions are underway.

Regulatory tailwinds and headwinds arrive simultaneously. The CFPB finalized its Personal Financial Data Rights rule under Section 1033 in October 2024, effective January 2025, mandating that large institutions provide API-based data access. By May 2025 the Bureau moved to vacate its own rule; in August it reopened rulemaking on whether data providers can charge fees. In Europe the direction is opposite: the UK and EU provisional agreement on PSD3 and the Payment Services Regulation in November 2025 pushes variable recurring payments into commercial deployment, with sixteen percent of UK open banking payments already flowing through VRP rails.

Plaid's response has been to layer products on top of connectivity. New lines — Plaid Protect for fraud intelligence, Beacon for anti-fraud networking, Signal for ACH risk scoring, Check for cash-flow underwriting, Layer for instant onboarding, Transfer for ACH, RTP, and FedNow processing, surpassed twenty percent of ARR in 2024 and grew roughly ninety percent annually, per CFO Seun Sodipo. Anti-fraud services specifically grew approximately four hundred percent year over year in 2024; payments facilitation grew approximately two hundred fifty percent. The company also launched a Bank Intelligence suite selling retention analytics back to the institutions it once fought for data access, repositioning from a third party banks tolerate to a data vendor banks pay for.

Competitors have not stood still. MX Technologies and Finicity (acquired by Mastercard in 2020) contest the connectivity layer directly. Stripe Financial Connections uses Stripe's merchant network. The Financial Data Exchange, a voluntary standards body representing over 230 stakeholders, has built API specifications connecting ninety-four million consumer accounts, significant but well below Plaid's half-billion cumulative figure. Akoya, bank-owned and built on agreement-based access rather than scraping legacy, pitches contractual cleanliness for regulated fintechs. Tink, owned by Visa, publishes 3,400-plus institutions across eighteen markets with background refresh up to four times daily. Regional specialists — Belvo and Pluggy in Latin America, Basiq in Australia, Brankas in Southeast Asia, Fintoc in Chile and Mexico, cover markets Plaid does not.

The standard is set. The pipes are laid. The volume is real. But the generic design that serves a consumer budgeting app does not automatically serve a space contractor managing classified billing milestones, a robotics fleet paying suppliers across seventeen jurisdictions, or a biotech startup running regulated payroll for clinical-trial staff. The next fracture lines appear where the standard meets the specific.

Market Size: Three Layers, One Stack

The fintech API infrastructure market is not a niche, it is a $15 billion industry on track to hit $45 billion by 2033, a 12% compound annual growth rate that outpaces most enterprise software categories. A parallel track, API management platforms for fintech, sits at $2.5 billion in 2024 and projects to $8.7 billion by 2033 on a 16.2% CAGR. The broader API marketplace — covering payments, identity, investment, and insurance APIs across marketplaces, cloud providers, and SaaS gateways, was valued at $21.3 billion in 2025 and climbs to $82.1 billion by 2033 at 18.4% CAGR, per Grand View Research. These are not overlapping estimates; they measure different layers of the same stack.

Market Segment 2024 Value 2033 Projection CAGR (2026–2033)
Fintech API Platforms $15B $45B 12%
API Management for Fintech $2.5B $8.7B 16.2%
Global API Marketplace $21.3B (2025) $82.1B 18.4%

APIs captured 39.1% of fintech technology market share in 2026, driven by interoperability and ecosystem connectivity, said Coherent Market Insights. Payment and fund transfer APIs hold the largest solution share at 33.9%. Commercial cards dominate the fintech card segment at 73.7%. Enterprise fintech leads end-user adoption. North America commands 33.7% of the regional market, with Grand View Research showing a 34.6% revenue share in 2025. Asia-Pacific leads funding share at 25%, Europe at 24%, North America at 21%, Middle East and Africa at 20%, and Latin America at 15%, a reversal from LatAm's previous leadership, per BCG data cited in a September 2026 industry review.

Plaid's own hiring signals the layer's momentum. The company posted 12 roles in the past seven days, Zero G Talent's board data shows, spanning sales, product marketing, AI applications, and machine learning research. Its board salary band runs $119k–$330k, Zero G Talent's data shows, with a $250k median, Zero G Talent found, across 119 salaried roles, Zero G Talent reported. That hiring pace, combined with a staff-level AI research role, suggests Plaid is investing in intelligence atop the connectivity layer, not just more pipes.

Public fintechs confirm the infrastructure thesis. Among the 85 largest, average EBITDA margin rose four points to 20% in 2026, and 74% are now profitable, up from 68% a year earlier. Equity funding rebounded 53% to $58 billion, with Q1 2026 alone hitting $14.8 billion. The recovery is funded by operating performance, not cheap money. Investors are paying for rails that move revenue, not vision decks.

The market's next move is vertical. Horizontal APIs solve connectivity; they do not solve underwriting for a satellite manufacturer, payroll for a biotech running clinical trials, or fund movement for a robotics fleet operating in three jurisdictions. The $45 billion projection assumes the layer thickens, compliance, identity, credit, and movement logic stacked on top of the raw pipe. Companies that treat the API as a finished product will hit the ceiling first.

Why Capital-Intensive Industries Are Building on This Layer

Frontier-tech companies operate with a distinct financial rhythm: multi-year contracts, globally distributed workforces, capital-intensive equipment, and regulatory regimes that treat money movement as a compliance surface. The standard open banking layer was built for consumer fintech. But the same plumbing now powers the back-office operations of space launch providers, defense primes, robotics fleets, AI labs, energy developers, and biotech manufacturers. They are not using it for consumer-facing apps. They are using it to run payroll across 30 countries, pay contractors in local rails before the weekend, finance a $300,000 cobot on a 48-hour credit decision, and satisfy a Pentagon memo that demands machine-readable access to their financial systems.

The contractor-payment problem is the sharpest edge. A robotics integrator deploying AGVs in Germany, Brazil, and India cannot wait three business days for a SWIFT transfer to clear. Grid, built on Lightspark, connects to local instant schemes in 65 countries — SEPA Instant in Europe, PIX in Brazil, UPI in India, RTP and FedNow in the U.S., and settles in seconds, not days. Remote advertises one-click global contractor payouts in 178 to 200 countries with fee-free local-currency delivery. Deel covers 150-plus countries. Gusto handles international contractor payments in 90-plus. The pattern is consistent: the API layer abstracts the rail, the FX margin, and the compliance check into a single call. "Country count is a vanity metric. Rail quality is what matters," Lightspark's evaluation guide notes. For a frontier-tech firm paying 500 contractors across 30 jurisdictions, the settlement gap — days of capital sitting idle, is the real cost.

Payroll APIs have followed the same trajectory. Finch, founded in 2020 by Jeremy Zhang and Ansel Parikh to untangle Paycheck Protection Program loans, now connects more than 200 HR and payroll systems through a unified API and serves 1.5 million employees. It powers Vanta, Lendio, Middesk, and OpenComp. Check provides a payroll API that handles tax calculation, money movement, and form filing so product teams can embed payroll without becoming a payroll company. CloudPay's API-led integrations ingest HCM, time-and-attendance, and benefits data globally, validating continuously rather than once per pay period. Gusto's embedded payroll API, backed by 15 years of operational data, adds another on-ramp. The common thread: specialized HR teams need to onboard engineers in Texas, analysts in France, and firmware leads in Singapore, this month, without filing three separate entity registrations.

Equipment financing is the next layer up. Axiant Partners offers an equipment leasing API that plugs automated lease origination, approval, and management directly into a manufacturer's procurement workflow. Industrial robots, cobots, and AGVs from $25,000 to $500,000-plus receive 24- to 48-hour approvals at a 600-plus FICO threshold. For a space-systems integrator ordering a custom vibration table or a biotech lab commissioning a high-throughput sequencer, the API turns a six-week capital-expenditure committee into a software flag. The lease API is a software bridge; the underwriting still leans on credit scores and tax returns, but the data now flows through the same open banking pipes that verify the account and move the funds.

Defense and space add a regulatory overlay that consumer fintech never sees. On August 18, 2026, Deputy Secretary of War Stephen Feinberg signed a memo titled "Supplier Cost and Pricing Transparency" that points the Pentagon toward direct, machine-to-machine access to defense contractors' financial systems. The Defense Department is already testing modern financial software to replace PDF-based budget transfers worth billions. The systems, controls, and processes a contractor uses to manage financial data must also satisfy cybersecurity requirements; a modernization that addresses only one dimension introduces control gaps in the other. Open banking APIs, designed for consumer consent flows, are being repurposed to feed the DoD's emerging audit trail. The same infrastructure that lets a Venmo user link a Chase account now lets a prime contractor expose general-ledger segments to a government API endpoint.

Energy and biotech follow parallel paths. A solar-developer EPC firm pays subcontractors across Latin America via PIX and SPEI; a cell-therapy manufacturer finances a $400,000 bioreactor through an embedded lease API while running global payroll through CloudPay. The API layer is generic. The use cases are not. Specialized sectors adopt it because building the connectivity, compliance, and rail logic in-house represents 12 to 18 months of engineering work that rarely justifies itself unless global payments is the core product. The plumbing is invisible until it backs up. Then it is the only thing that matters.

Where the Generic Plumbing Breaks

Standard open banking APIs were built for consumer fintech, linking a checking account to a budgeting app, verifying income for a loan, moving money between retail accounts. They assume a world of known counterparties, reversible transactions, and regulatory frameworks that map neatly to domestic banking licenses. Capital-intensive industries operate in none of those worlds.

Classified Contracts and the FIPS Wall

Defense and intelligence programs don't run on commercial ACH rails. Payment system architecture for classified environments must satisfy NIST 800-53 security controls and DFARS compliance requirements before a single transaction processes. Implementation costs for FIPS-compliant payment systems range from $1.2 million to $4.8 million depending on transaction volume and integration complexity with existing federal financial systems, and integration costs typically exceed core development expenses by 30-40%. Microservices-based architectures deliver 37% greater scalability and 42% improved fault tolerance compared to monolithic systems when deployed in classified environments, but they also demand 99.999% availability even when 30% of component services experience failures. Plaid's consumer-grade connectivity layer was never architected for this threat model. Defense payment systems face sophisticated threats beyond those encountered in commercial environments, including advanced persistent threats that standard fraud detection — built for card-not-present fraud, not nation-state adversaries, simply doesn't cover.

Multi-Year Space Programs and the Duration Mismatch

The space economy will require more than connectivity. It will require financial infrastructure. Satellite services, orbital logistics, remote communications, Earth-observation platforms, commercial space stations, lunar programs, autonomous systems, and off-world resource initiatives will create new forms of economic participation. But open banking APIs operate on settlement cycles measured in days; space programs operate on cycles measured in years. A multi-year launch services contract with milestone payments tied to orbital insertion events, regulatory clearances, and international frequency coordination doesn't map to an ACH credit or a real-time payment rail. The plumbing assumes instantaneous finality. Space programs deal with force majeure clauses, launch window delays, and regulatory regimes that span ITU, FCC, and foreign sovereign authorities. No standard API exposes the metadata fields to carry that context, and no consumer-permissioned data flow captures the counterparty risk of a foreign launch provider whose bank may be sanctioned mid-contract.

International Robotics Fleets and Hard Constraints

Robotics fleets operating across borders (warehouse automation in Germany, last-mile delivery in Singapore, agricultural units in Brazil) need payroll, vendor payments, and equipment financing that respect local labor law, tax treaties, and capital controls. Standard APIs offer account connectivity and fund movement as related but distinct layers, but they don't encode the regulatory logic that determines whether a payment to a Romanian subcontractor triggers withholding tax, or whether a Brazilian central bank reporting threshold has been crossed. Worse, the control systems governing those fleets increasingly rely on generative AI for path planning and obstacle avoidance. MIT researchers demonstrated that in safety-critical applications like robot path planning on a crowded factory floor, an answer that is "nearly correct" may not be good enough. Their HardFlow algorithm achieves perfect constraint satisfaction by enforcing hard constraints on the final output rather than at every intermediate step, a pattern that financial infrastructure for robotics will need to mirror. An API that moves funds correctly 99.9% of the time but fails on the 0.1% that triggers a sanctions violation isn't a reliability problem; it's a compliance catastrophe.

Regulated Biotech Payroll and the Rate-Limiting Layer

Biotech companies running clinical trials across multiple jurisdictions face payroll and contractor payments that intersect with HIPAA, GDPR, FDA 21 CFR Part 11, and local clinical trial regulations. API rate limiting in regulated environments is simultaneously a security control, an availability mechanism, and a fair-use policy enforcement tool, and each of those objectives requires different limiting strategies implemented at different architectural layers. Standard open banking APIs expose a single rate limit, if they expose one at all. They don't distinguish between a payroll batch that must clear before a regulatory filing deadline and a routine vendor payment that can wait. Mobile application development for defense-grade implementations ranges from $180,000 to $650,000; biotech-grade implementations carry similar cost structures because the penetration testing must verify controls against OWASP Mobile Top 10 vulnerabilities plus domain-specific requirements. The generic plumbing doesn't know what a clinical trial milestone payment looks like, so it can't prioritize it, audit it, or prove to an auditor that it happened on the required timeline.

The pattern across all four domains is the same: standard APIs provide connectivity without context. They move money but don't carry the operational metadata that specialized operations require to remain legal, safe, and funded. The next section examines how companies are building vertical-specific financial layers on top of this generic infrastructure to close those gaps.

The Vertical Integration Response

The standard API layer solved connectivity. It did not solve context. Companies operating in specialized verticals — rent payments, equipment financing, government contracting, found that generic account linking and ACH initiation left the hard problems untouched: compliance workflows, data enrichment for underwriting, reward structures aligned to industry economics. The response has been a wave of vertical-specific financial layers that sit on top of the open banking plumbing, translating generic rails into domain-specific products.

This build-on-top strategy reflects a broader shift. Fintechs increasingly choose API-driven infrastructure over building in-house, comparing cost, speed to market, and compliance burden before committing to a build. Decision frameworks now circulate: per-layer scoring models that weigh vendor lock-in, hidden costs, and regulatory complexity guide teams on when to buy connectivity, when to partner for money movement, and when to compose a vertical application layer. Enterprise integration patterns, long used in banking modernization, are being reapplied: event-driven architectures for real-time ledger updates, API gateways for partner onboarding, pub/sub for reconciliation across processors.

For specialized operators, the lesson is direct. The generic plumbing — the ACH and RTP rails, is necessary but not sufficient. A robotics fleet operator paying contractors in three currencies needs tax-form automation and FX hedging, not just account verification. A biotech startup running clinical-trial stipends needs IRB-compliant disbursement schedules. The companies winning in those niches are not replacing the API layer; they are verticalizing it, turning plumbing into product.

What Engineers and Operators Need to Know

Specialized teams treat financial infrastructure the way they treat launch vehicles: it must work under stress, survive provider failures, and let you swap components without rewriting the mission code. Research shows that 78% of high-growth enterprises have already moved to event-driven APIs, and fintech leads at 82% adoption for real-time fraud detection. If your payroll, contractor payments, or equipment financing still run on batch-oriented ACH files, you are operating a stage-one rocket in a stage-two world.

Start evaluation by mapping every external financial dependency — Plaid for account connectivity, Stripe or a processor for fund movement, a KYC/AML vendor for onboarding, a card issuer for corporate spend, and ask whether each integration lives behind a canonical internal interface or leaks vendor-specific fields into your core systems. The DashDevs analysis is blunt: when "a little provider logic" leaks into core services, swapping a card processor becomes a core migration. Companies running multi-year space programs or classified defense contracts cannot afford that coupling. Build a partner integration layer that owns ingress, egress, authentication, secret rotation, retry policies, idempotency keys, correlation IDs, and structured audit logging. Keep your canonical API model stable; let adapters absorb each vendor's quirks, error codes, and webhook shapes.

Resilience is a product requirement, not an ops afterthought. Model at least three states per critical domain: primary provider, warm standby, and controlled offload. Maintain a simple catalog: partner name, domains covered, regions, supported rails, rate limits, contract owner, technical owner, last disaster test date, known gaps. Run a tabletop exercise once per major domain. Before launching a critical adapter, document who pages whom, how you failover, what customer messaging is allowed, and how you preserve audit trails during recovery. If your team cannot answer "which partner call failed for this user's onboarding in under five minutes," you have archaeology, not observability.

Integration speed compounds. RapidPay cut average integration time 30% to 8.4 weeks within 18 months; LoanFlow shaved 40% off new data-source integrations. The levers are standard: mandate OpenAPI Specification, publish SDKs for your stack, expose a centralized developer portal with interactive docs (Swagger UI or Postman collections), and enforce boring versioning. Adopt an API gateway — Kong, Apigee, or a cloud-agnostic equivalent, as the single entry point. Use service meshes (Istio, Linkerd) for consistent traffic policies across clouds; 68% of enterprises already run APIs in multi-cloud environments. Implement cross-cloud monitoring with Datadog or New Relic. Treat APIs as product features: clear SLAs, versioning, developer docs, and a Definition of Done that includes runbooks, dashboards, and alert thresholds, not just "works in sandbox."

Security and compliance cannot be bolted on. The minimum bar leadership should expect: short-lived credentials where partners support them, rotation runbooks where they don't, strict separation between sandbox and production secrets, mutual TLS or equivalent with an inventory of expiring certificates, scoped API keys per environment and per adapter, no god-keys. Integrate third-party KYC and AML services early; retrofitting them across regions is costly rework. Automate compliance reporting for GDPR, SOC 2, and industry-specific mandates. Contract tests between your canonical layer and adapters should fail CI before a provider shape change reaches production. Record fixtures for edge cases — timeouts, ambiguous AML hits, duplicate webhooks, and run chaos or fault injection on retries to prove idempotency keys actually work under stress.

AI is changing the integration calculus. In 2026, autonomous agents dynamically compose, call, and optimize API workflows based on real-time context, cutting manual integration effort by up to 60%. LLM-powered tools generate connectors from natural-language specs. AI-driven gateways auto-route requests by load and latency. Centralized policy engines with anomaly detection replace static rule sets. Forty-five percent of new API integrations are now created by business analysts using visual drag-and-drop tools; your engineers should be building the platform those analysts consume, not hand-wiring every endpoint.

Advocacy inside the organization means speaking the language of runway and risk. Frame the partner integration layer as the system that lets you change a strategic provider in under a quarter without freezing product work. If the answer is no, the layer is underfunded relative to business ambition. Ask for a small scorecard — SLOs, error budgets, vendor scorecards, not fifty vanity graphs. Someone must own the financial services integration platform as a product: roadmap, migrations, vendor scorecards, developer experience for internal consumers. Talent market signals show this layer is now a core competency, not a vendor management footnote.

Buy versus build is rarely binary. Many organizations buy specialized connectivity for niche rails or regional compliance but still own the partner integration layer that defines how those purchases plug into the business. The durable pattern: keep your canonical model stable while adapters encode regional differences — payout cutoffs, strong customer authentication for open banking, local identity document types, region-specific AML screening lists. That is the plumbing that lets a robotics fleet in Germany, a biotech payroll in Boston, and a satellite program in Colorado share the same financial control plane without each team reinventing the wheel — and without the next JPMorgan invoice catching them off guard.


Working in frontier tech? Zero G Talent tracks the openings: see every open Plaid role, browse frontier tech jobs, the companies hiring, and the people building the field.

Ready to Start Your Space Career?

Browse frontier jobs and find your next opportunity.

View frontier Jobs