UK Open Banking hits 100 B API calls

UK Open Banking reported that its network processed more than 100 billion API calls and surpassed one billion account-to-account payments by June 2026, according to data from Open Banking Limited. The milestone shows the rapid adoption of digital transaction interfaces across banks and third-party providers, highlighting how open-banking standards have become a core part of everyday financial activity.
Scaling of Transaction Volumes
The CMA-mandated nine largest current-account providers, known as the CMA9, handled a 4.4 percent month-on-month increase in total API requests during June 2026. This growth reflects heightened consumer and business reliance on real-time data feeds, prompting the participating institutions to fine-tune capacity planning.
Network latency improved by 50 milliseconds compared with the previous period, while weighted system uptime reached 99.35 percent, reflecting steady resilience across the core infrastructure.
Growth in Variable Recurring Payments
Single domestic payments fell 1.2 percent to 32.43 million transactions in June, yet overall payment volume remained robust thanks to Variable Recurring Payments. Enterprises have turned to these mechanisms to automate liquidity management and subscription processing, reducing manual reconciliation effort.
Sweeping Variable Recurring Payments (sVRPs) grew 6.7 percent month-on-month, reaching 7.73 million transactions, as firms use them for continuous consent-based account-to-account transfers. These services let users set continuous consent for A2A transfers within defined limits, eliminating traditional credit-card scheme fees for many merchants.
Read Also: UK’s Open Finance Roadmap Nears Deadline
Security and Performance Challenges
Open Banking Limited recorded 2.81 billion API calls each month, demanding strict gateway rate-limiting, edge caching, and automated load balancing to keep average response time at 349 milliseconds. The firm’s engineering teams have introduced adaptive throttling rules that dynamically adjust thresholds based on traffic patterns.
Consent management now relies on OAuth 2.0 and Financial-grade API (FAPI) token frameworks, which must resist credential stuffing and token hijacking attempts.
Regulatory Contrast and Future Steps
Security teams are advised to upgrade FAPI implementations to support long-lived, multi-use consent tokens, isolate token endpoints with mutual TLS, and monitor abnormal refresh rates. IT architects should deploy inline, machine-learning-driven threat detection at the API gateway to meet sub-350 ms response benchmarks without sacrificing fraud controls.
DevSecOps groups must audit third-party consent lifecycles, ensuring stale permissions are automatically revoked as the UK framework expands to commercial non-sweeping VRPs and broader open-finance integrations.
