Why LedgerSync Requires Full Account Owner Access to Fetch Bank Statements

Why LedgerSync Requires Full Account Owner Access to Fetch Bank Statements

What Is Bank Restricted Access?

Many financial institutions offer a feature called restricted access (sometimes called "read-only access," "accountant access," or "third-party access"). This is a limited login credential that a bank account owner can create and share with a third party — such as their accountant or bookkeeper — granting them the ability to view certain account information without having full control over the account.

Restricted access credentials are intentionally limited. Depending on the bank, they may allow a third party to view balances, review recent transactions, or download basic reports. They are designed to give visibility without granting the ability to move money, change account settings, or perform other sensitive actions.

Why Bank APIs Require Full Account Owner Credentials

When LedgerSync connects to a financial institution to retrieve bank statements, it does so through the bank's data aggregation API — the same secure infrastructure used by platforms like QuickBooks, Mint, and other financial tools.

These APIs are built with a fundamental security requirement: only the account owner's credentials can authorize data access.

The reason is straightforward. Banks are regulated institutions with strict obligations around account access and data privacy. Their systems are designed to verify that the person (or authorized application) requesting data is the legitimate account owner. When a user authenticates through LedgerSync, the bank's API validates that the credentials belong to someone with full account ownership rights before releasing any data.

Restricted access credentials — even legitimate ones issued by the bank — do not satisfy this ownership verification. They are not recognized by the API as having authorization to grant data-sharing consent on behalf of the account. The API interprets them as insufficient for the level of access required to export statement-level data.

This is not a LedgerSync limitation. It is a universal requirement enforced by the financial institutions themselves.

Why LedgerSync Cannot Use Restricted Access Credentials

Even if a client shares their restricted access login with the accounting firm, LedgerSync cannot use those credentials to fetch bank statements. Here is why:

  1. API rejection. The bank's aggregation API will simply reject the connection attempt or return no data when restricted credentials are used. The API expects account owner-level authentication to authorize the data request.
  2. Incomplete data access. Restricted credentials are often scoped to a limited view of the account — they may not expose the full transaction history, statement documents, or account identifiers that LedgerSync needs to perform accurate reconciliation.
  3. No consent authority. Data aggregation APIs require the account owner to grant consent for a third-party application to access their data. Restricted users do not have the authority to grant that consent — only the account owner can.

Why It Is Better Security for the Client to Enter Their Own Credentials

We understand that asking a client to enter their bank login may feel like an added step. However, this model is actually the most secure approach for everyone involved — and here is why.

The accounting firm never sees or stores the client's credentials. When the client enters their username and password directly into LedgerSync's secure credential flow, those credentials are passed directly to the bank's authentication system. LedgerSync does not log, store, or have access to the client's login information. The accounting firm is completely removed from the credential chain.

It limits liability for the accounting firm. If the firm were to collect, store, or handle client banking credentials directly, it would expose itself to significant legal and regulatory risk. Under the current model, the firm has no access to credentials and therefore no liability if those credentials were ever compromised through an unrelated breach.

It keeps the client in control. The client retains full ownership of their banking credentials at all times. They are not surrendering control to a third party — they are simply authorizing LedgerSync, on a session or persistent basis, to retrieve their data on their behalf. This is the same model used by QuickBooks, Xero, and every major financial platform in the industry.

Credentials are encrypted and handled by bank-grade infrastructure. LedgerSync's credential flow uses the same tokenization and encryption standards required by financial data aggregators like MX and Mastercard/Finicity. Once authenticated, LedgerSync stores only a secure token — not the password itself — to perform ongoing data refreshes.

Summary

Restricted AccessFull Account Owner Access
Accepted by bank APINoYes
Can authorize data-sharing consentNoYes
Exposes full statement historyOften noYes
Firm handles client credentialsYes (risky)No (client enters directly)
Best security practiceNoYes

Having the client enter their own credentials directly is not just a technical requirement — it is the safest, most compliant, and most professionally sound way to connect bank accounts for statement retrieval.

    • Related Articles

    • I have full access to the bank and don't want to invite the client

      What if you have full access to the client's banking and you do not want to invite them to Ledgersync? See the below article and suggestion. In the event that you have full account owner access to the bank and that the token code will come to you ...
    • LedgerSync Close — Overview and How It Works

      Overview LedgerSync Close is a month-end reconciliation tool that compares your bank statements directly against the transactions recorded in QuickBooks Online (QBO). It automatically identifies missing transactions, duplicate entries, and category ...
    • How to Convert Bank PDF Statements to Excel, QBO, or CSV

      Overview The LedgerSync PDF Converter extracts transactions from bank statement PDFs and converts them into Excel, CSV, QBO, or OFX format — without any manual data entry. This is especially useful when a client can only provide PDF statements and ...
    • MX Bank Connection — Overview, Setup, and FAQ

      Overview MX is LedgerSync's second full bank data aggregator, available alongside the Mastercard API. MX is fully deployed and actively used across the platform — it is not a beta feature. If your bank is not supported by the Mastercard API, or if ...
    • How do I Access Chase Bank Statements?

      To Fetch Chase Bank Statements do the following: 1- Click on the client on the left side menu bar 2- Click on "Add Bank Connection 3- Click on "Statements" (using Finicity) 4- Select it and follow the steps to add Chase! You must see Chase Statements ...