Post #3956511
2026-07-14 09:31 UTC
@mrc@mastodon.berlin This is typical EU PSDA2 guideline. Third-parties that require bank account get logged out after N days and require new authentication.
Some banks and some authentication providers don't "work well together", and then you don't have a seamless experience.
Replies (1)
-
@mrc@mastodon.berlin 2026-07-14 11:22
@yvg@indieweb.social I mean, *I* get logged out after a few minutes, and I have 2fa active, so it's not a huge deal in practice, but imagine there was a *way* to delegate fine grained, temporary API access to third parties without handing over half of the two authentication factors... (And I don't think PDS2 compliant third party would need to access my password for that matter.)