CONTROL TOWER FOR LINKING ACCOUNTS TO APPLICATIONS
Systems and methods for managing application access to account data via service provider computing systems are disclosed. A system can detect, via a graphical user interface (GUI), selection of an account comprising first account data and second account data. The system can present, in the GUI, an application listing of one or more client applications installed on a user device, including a first client application that communicates, when executed on the user device, with a first service provider computing system of a first entity. The system can generate a first access token corresponding to the account and transmit the first access token to the first service provider computing system for access to the first and second account data. The system can receive and verify an API call including the first access token and, upon verification, transmit requested account data.
1 . A system, comprising:
one or more processors coupled to non-transitory memory, the one or more processors configured to:
detect, via a graphical user interface (GUI), selection of an account comprising first account data and second account data;
present, in the GUI, an application listing of one or more client applications installed on a user device, the application listing comprising a first client application which communicates, when executed on the user device, with a first service provider computing system of a first entity;
detect, via the GUI, selection to link the first client application with the account;
generate a first access token corresponding to the account and transmit the first access token to the first service provider computing system for access to the first account data and the second account data of the account by the first client application via the first service provider computing system;
receive, from the first service provider computing system, a first application programming interface (API) call comprising the first access token and a first request for a first subset of the first account data and the second account data; and
verify the first access token to authenticate the first request, and in response to verifying the first access token, transmit the first subset to the first service provider computing system.
2 . The system of claim 1 , wherein the one or more processors are further configured to:
receive a login credential;
verify the login credential grants access to the GUI; and
present the application listing in the GUI in response to verifying the login credential.
3 . The system of claim 1 , wherein the one or more processors are further configured to:
present, in the GUI, the application listing comprising a second client application which communicates, when executed on the user device, with a second service provider computing system of a second entity;
generate a second access token corresponding to the account in response to a selection to link the second client application with the account.
4 . The system of claim 3 , wherein the one or more processors are further configured to:
transmit the second access token to the second service provider computing system for access to the first account data and the second account data by the second client application via the second service provider computing system.
5 . The system of claim 4 , wherein the one or more processors are further configured to:
receive, from the second service provider computing system, a second request comprising the second access token;
verify the second access token to authenticate the second request, and in response to verifying the second access token, transmit data to the second service provider computing system in response to the second request 6 . The system of claim 1 , wherein the one or more processors are further configured to:
present, in the GUI, based on the API call, information on access to the account by the first client application.
7 . The system of claim 1 , wherein the one or more processors are further configured to:
receive, via the GUI, access permissions limiting which functionality is available to the first client application.
8 . A method, comprising:
detecting, by one or more processors coupled to non-transitory memory, via a graphical user interface (GUI), selection of an account comprising first account data and second account data;
presenting, by the one or more processors, in the GUI, an application listing of one or more client applications installed on a user device, the application listing comprising a first client application which communicates, when executed on the user device, with a first service provider computing system of a first entity;
detecting, by the one or more processors, via the GUI, selection to link the first client application with the account;
generating, by the one or more processors, a first access token corresponding to the account and transmitting the first access token to the first service provider computing system for access to the first account data and the second account data of the account by the first client application via the first service provider computing system;
receiving, by the one or more processors, from the first service provider computing system, a first application programming interface (API) call comprising the first access token and a first request for a first subset of the first account data and the second account data; and
verifying, by the one or more processors, the first access token to authenticate the first request, and in response to verifying the first access token, transmitting, by the one or more processors, the first subset to the first service provider computing system.
9 . The method of claim 8 , further comprising:
receiving, by the one or more processors, a login credential;
verifying, by the one or more processors, the login credential grants access to the GUI; and
presenting, by the one or more processors, the application listing in the GUI in response to verifying the login credential.
10 . The method of claim 8 , further comprising:
presenting, by the one or more processors, in the GUI, the application listing comprising a second client application which communicates, when executed on the user device, with a second service provider computing system of a second entity; and
generating, by the one or more processors, a second access token corresponding to the account in response to a selection to link the second client application with the account.
11 . The method of claim 10 , further comprising:
transmitting, by the one or more processors, the second access token to the second service provider computing system for access to the first account data and the second account data by the second client application via the second service provider computing system.
12 . The method of claim 11 , further comprising:
receiving, by the one or more processors, from the second service provider computing system, a second request comprising the second access token;
verifying, by the one or more processors, the second access token to authenticate the second request; and
in response to verifying the second access token, transmitting, by the one or more processors, data to the second service provider computing system in response to the second request.
13 . The method of claim 8 , further comprising:
presenting, by the one or more processors, in the GUI, based on the API call, information on access to the account by the first client application.
14 . The method of claim 8 , further comprising:
receiving, by the one or more processors, via the GUI, access permissions limiting which functionality is available to the first client application.
15 . A non-transitory computer-readable medium storing instructions that, when executed by one or more processors, cause the one or more processors to perform operations comprising:
detecting, via a graphical user interface (GUI), selection of an account comprising first account data and second account data;
presenting, in the GUI, an application listing of one or more client applications installed on a user device, the application listing comprising a first client application which communicates, when executed on the user device, with a first service provider computing system of a first entity;
detecting, via the GUI, selection to link the first client application with the account;
generating a first access token corresponding to the account and transmitting the first access token to the first service provider computing system for access to the first account data and the second account data of the account by the first client application via the first service provider computing system;
receiving, from the first service provider computing system, a first application programming interface (API) call comprising the first access token and a first request for a first subset of the first account data and the second account data;
verifying the first access token to authenticate the first request; and
in response to verifying the first access token, transmitting the first subset to the first service provider computing system.
16 . The non-transitory computer-readable medium of claim 15 , wherein the instructions, when executed by the one or more processors, cause the one or more processors to perform further operations comprising:
receiving a login credential;
verifying the login credential grants access to the GUI; and
presenting the application listing in the GUI in response to verifying the login credential.
17 . The non-transitory computer-readable medium of claim 15 , wherein the instructions, when executed by the one or more processors, cause the one or more processors to perform further operations comprising:
presenting, in the GUI, the application listing comprising a second client application which communicates, when executed on the user device, with a second service provider computing system of a second entity; and
generating a second access token corresponding to the account in response to a selection to link the second client application with the account.
18 . The non-transitory computer-readable medium of claim 17 , wherein the instructions, when executed by the one or more processors, cause the one or more processors to perform further operations comprising:
Transmitting the second access token to the second service provider computing system for access to the first account data and the second account data by the second client application via the second service provider computing system.
19 . The non-transitory computer-readable medium of claim 18 , wherein the instructions, when executed by the one or more processors, cause the one or more processors to perform further operations comprising:
receiving, from the second service provider computing system, a second request comprising the second access token;
verifying the second access token to authenticate the second request; and
in response to verifying the second access token, transmitting data to the second service provider computing system in response to the second request.
20 . The non-transitory computer-readable medium of claim 15 , wherein the instructions, when executed by the one or more processors, cause the one or more processors to perform further operations comprising:
presenting, in the GUI, based on the API call, information on access to the account by the first client application.