How to see and revoke which apps are connected to your bank

by Lee Schmidt

Published September 20, 2026

Every app that reads your bank is listed somewhere you can see it, and revoking one takes a click. The bank's own security or privacy settings list the apps it has granted access to, the connection service's portal lists the connections it holds on your behalf, and either place can end one. Review the list twice a year, revoke anything you no longer use or do not recognize, and if an app you still want stops working because you revoked it, reconnect from inside that app. A first review usually finds connections nobody remembers making: a lender's application from two years ago, a trading app tried once, a service that closed. Six connections reviewed, two removed, in ten minutes.

Where the list lives

PlaceWhat it showsWhat it can do
The bank's website or app, under security, privacy, or linked appsEach app or service with access, often the date and the accountsRevoke the access from the bank's side
The connection service's consumer portalEach app connected through that service, the accounts, and the data sharedRevoke the connection, and see what was shared
The app's own settingsThe connection from the app's sideDisconnect, which also asks the service to end it

The three lists overlap and are not identical. A bank that connects through a service may show the service's name rather than the app's, which is why a bank's list can read "Plaid" for an app you know by a different name; see What Plaid is, and why your bank shows it. The service's portal shows the apps by their own names.

Review the list

  1. Open the bank's security or privacy settings and find the section for linked apps, third-party access, or data sharing. Every bank names it differently; the words to look for are apps, access, and sharing.
  2. Read each entry: the name, the date, and the accounts. Mark each as keep, remove, or unknown.
  3. Open the connection service's consumer portal, sign in with the email you use for the apps, and read its list the same way. It shows the app's real name and what was shared.
  4. Revoke the removes and the unknowns. An unknown that turns out to be wanted is reconnected in a minute from inside the app; an unknown left in place is access with no owner.
  5. Note the date, and repeat in six months.

A worked review, six connections

ConnectionLast usedWhat it wasDecision
A budgeting appTodayDaily balances and transactionsKeep
A lender's applicationTwo years agoIncome verification for a loan applicationRemove; the loan closed
A payment appLast weekFunding transfersKeep
A trading appFourteen months agoFunded once, never usedRemove; then close the trading account
A tax preparation serviceLast springImporting interest statementsKeep; it is used every year
A name nobody recognizedEight months agoA service that closedRemove

Two removals and one reminder to close an account. The lender's connection is the common one: an application authorizes a service to read balances for a decision made in an afternoon, and the access outlives the decision by years unless someone revokes it.

What revoking does, and what it doesn't

Revoking ends the app's ability to read anything new. The session is gone, the daily sync stops, and the app shows the connection as broken. It does not delete what the app already synced: the transactions from before the revocation stay in the app until you ask the app to delete them, which most allow from their settings or by request. It also does not cancel a subscription to the app, which is a separate thing billed separately, and it does not change the bank account itself.

An app you still want that you revoked by mistake, or that you revoked while cleaning up, is reconnected from inside the app: the connection window opens, you sign in on the bank's page, and syncing resumes on the same accounts, with the missed days filling in. Reconnect only from inside the app, never from a link in an email, since a reconnect prompt by email is the shape of the phishing that targets bank connections.

Common mistakes

  • Checking only the bank's list. The service's portal shows the apps by name and what was shared; the bank's list can show only the service.
  • Leaving unknowns in place. Access with no owner is the one to remove first.
  • Assuming revoking deletes the data. It stops new data; the old data is the app's until you ask.
  • Revoking instead of cancelling. The app's subscription bills on; cancel it with the app.
  • Reconnecting from an email. Reconnect from inside the app, so the window you type into is the one the app opened.
  • Reviewing once and never again. Applications and trials add connections all year.

Common questions

How do I see what apps have access to my bank account? In the bank's security or privacy settings, under linked apps, third-party access, or data sharing, and in the connection service's consumer portal, which lists each connected app with what it shares. Check both, because the bank's list may show the service's name rather than the app's.

How do I revoke an app's access? From the bank's list, from the service's portal, or from the app's own settings; any of the three ends the session. Revoking stops new data from flowing and leaves the data already synced with the app until you ask the app to delete it.

Will revoking break the app? Yes, for that connection: the app shows it as broken and stops updating those accounts. If you still use the app, reconnect from inside it; if you do not, that is the point.

What if I see a connection I don't recognize? Revoke it. If it was something you use, the app will tell you the connection is broken and you reconnect in a minute from inside the app. Then change the bank password, since a connection nobody made is a question about who did.

How often should I review the list? Twice a year, and after any application, trial, or new app that asked to connect. Each of those adds a connection that outlives its purpose unless removed.

How Zypper handles this

Zypper shows its own side of the list and lets you end a connection in one place. The connections settings list each institution with its status, the accounts it provides, and when it last updated; removing a connection there disconnects the entire institution, so every account it provides stops syncing, while removing a single account deletes that account and its data and leaves the rest of the bank connected. Your bank may list Zypper's access under Plaid, since connections run through the secure Plaid window where you sign in on your bank's own screen, and a connection revoked from the bank's side shows in Zypper as expired, with a reconnect action that opens the Plaid window again. See Editing and removing accounts, Checking connection status and refreshing, and Fixing an expired or broken connection for the details, or get started with Zypper to see your connections in one list.