India’s consent-based financial data sharing framework — what it is, who the licensed players are, what data you receive and how Roopya’s ready-to-use AA API works .
The RBI’s framework for secure, consent-based financial data sharing in India.
An Account Aggregator (AA) is a category of entity licensed and regulated by the Reserve Bank of India under the Financial Data Sharing and Monitoring Framework. The AA acts as a secure intermediary that retrieves a customer’s financial data from one or more Financial Information Providers (FIPs) — such as banks, NBFCs, mutual fund houses, and insurance companies — and delivers it to a Financial Information User (FIU), such as a lender, strictly based on the customer’s explicit, time-bound, purpose-specific consent.
The customer is always in control. They decide what data is shared, with whom, for what purpose, and for how long. No data flows without an active, digitally signed consent artefact that the customer has approved. The customer can revoke consent at any time.
Before the AA framework, lenders had to rely on physical bank statements or bureau data alone. The AA framework gives lenders real-time, machine-readable, verified bank transaction data directly from the source — enabling faster, more accurate credit decisions, especially for thin-file borrowers and small businesses.
Every participant has a specific, RBI-defined role in the data flow.
The individual or business whose financial data is being shared. Initiates and approves all consent requests, and can revoke access at any time.
The RBI-licensed entity that manages consents and routes data requests between FIPs and FIUs. Never stores financial data — a secure conduit only.
The bank, NBFC, mutual fund, or insurance company that holds the data and releases it upon a valid consent-linked request.
The lender or fintech that requests data for a specific purpose and receives it in a standardized format for processing.
As of 2026, all are interoperable through the Sahamati alliance — a consent created on one AA can fetch data from FIPs connected to any other AA in the network.
Sahamati is not an AA itself. It’s the non-profit industry alliance that sets interoperability standards, manages the shared registry of AAs/FIPs/FIUs, and ensures consents and data flow seamlessly across all licensed AAs.
One unified API that handles multi-AA routing, consent management, data fetching, and normalization.
Integrating directly with multiple Account Aggregators is complex — each has its own API spec, authentication flow, consent lifecycle, and response format. A lender reaching all bank FIPs typically needs to integrate with 3–6 AAs separately, taking 4–8 weeks of engineering effort.
Roopya solves this with a single, unified REST API. You call one set of endpoints, and Roopya handles routing, consent approval, data fetching, and normalization — so you go live in 1–2 days instead of weeks.
The end-to-end flow from consent creation to receiving structured financial data.
Your app calls Roopya’s API specifying the customer’s identifiers, data types, purpose, and consent validity duration.
The customer gets a notification with a link to the AA’s consent approval page, authenticates via OTP, and approves or rejects.
Roopya sends a webhook once the customer approves. The consent is now active.
Your app calls the data fetch endpoint with the active consent ID; Roopya triggers the AA to request data from the FIP.
Roopya normalizes the raw ReBIT response into clean JSON, delivered via API response or webhook.
Your app processes the data; the customer can revoke consent anytime, and Roopya notifies you of expiry or revocation.
The AA framework the ReBIT standard — a structured XML/JSON schema. Roopya normalizes it into clean, consistent JSON regardless of source AA or FIP.
A transparent breakdown of what it costs to access AA data directly versus through Roopya’s unified API.
| Cost Component | Direct AA Integration | Roopya Unified AA API |
|---|---|---|
| One-time Setup Fee | Rs. 50,000 – Rs. 2,00,000 per AA | Zero |
| Integration Time | 4–8 weeks per AA | 1–2 days |
| Per Consent Request | Rs. 10 – Rs. 25 | Included |
| Per Data Fetch | Rs. 2 – Rs. 5 | Rs. 15 per successful fetch |
| Multi-AA Routing | Separate integration per AA | Built-in, automatic |
| Data Normalization | Build your own parser | Included |
| Consent UI | Build your own | Hosted, included |
| Engineering Team Required | 2–4 developers, 4–8 weeks | None — API-first |
Pull verified bank transaction data into your underwriting engine — assess cashflow, detect EMIs, estimate income.
Share bank statement data securely in minutes — no printing statements or emailing PDFs.
A consolidated view of a client’s accounts, funds, deposits, and insurance with a single consent.
Offer a unified view of user finances across all linked accounts, powered by verified data.
An RBI-regulated entity that securely shares your financial data from your bank to a lender or app — only with your explicit, time-bound consent. Think of it as UPI for financial data.
Yes. The AA never stores your data — it’s a conduit that passes data only when a valid, signed consent is active. You control what’s shared, with whom, and for how long, and can revoke access anytime.
Direct integration means separate onboarding with 3–6 AAs, each with its own spec — 4–8 weeks of work. Roopya gives you one unified API: we route requests, manage consent, fetch data, and normalize it. Live in 1–2 days.
Bank account profiles, transaction histories, fixed/recurring deposits, mutual fund holdings, insurance policy summaries, and SIP details — coverage depends on which FIPs the customer’s institutions connect to.
Typically 30 seconds to 2 minutes if their bank is already linked to the AA. New users need 1–2 minutes per bank to link first.
Rs. 15 per successful data fetch, zero setup fee, no minimum commitment. No charge for consent creation, status checks, or failed fetches.
Yes, at any time through the AA’s app or website. Roopya sends a webhook when consent is revoked or expires so you can handle data deletion.
Over 1,100 institutions as of 2026, including all major public and private banks, NBFCs, cooperative banks, mutual fund houses, and insurers. Coverage keeps expanding.
Go live with Roopya’s unified Account Aggregator API in 1–2 days.
© 2025 Roopya (Geoalgo Technologies Private Limited). All rights reserved.
In case you have any grievances with respect to in accordance with applicable law on Information Technology and rules made there under, the name and contact details of the Grievance Officer are provided below:
| Level 1 | contact@roopya.com |
| Level 2 | tech@roopya.com |
| Level 3 | bhavika@roopya.com |