Read-only access
A connection type that can see account data but structurally cannot move money, initiate trades, or log in as you.
Read-only access is a category of connection between a financial app and your account: the app can see balances, transactions, and account details, but has no capability to move money, initiate transfers or trades, or change account settings. It is a structural limitation of the credential type, not a setting the app has turned off.
With modern connections, sign-in happens on the bank's own page, and the bank hands the aggregator a limited-scope token. The app receives data, not credentials. The bank password is never in the app's systems, so it cannot leak from them.
Connecting one account reveals that account, not everything at that institution and not anything elsewhere. Access can be ended from either side — by disconnecting inside the app or by revoking the connection from the bank's security settings. The tradeoff of read-only is that the app can never act for you; every actual move happens at the bank, by your own hand. Plumb uses read-only connections through a bank-grade aggregator.
Plumb is financial education, not financial, investment, tax, or legal advice.