Research/Fintech

Composable Banking: How API-First Architecture Is Unbundling Financial Services

API-first banking infrastructure lets fintechs and platforms assemble custom financial products from modular, interchangeable components.

bcNeutronSep 18, 2026

For decades, launching a financial product meant partnering with a single bank that controlled everything: the charter, the ledger, the payment rails, and the compliance stack. Composable banking inverts that model. Instead of a monolithic relationship, fintechs assemble custom financial products from discrete, API-accessible primitives: accounts, payments, KYC, lending, cards, and compliance modules that plug together like building blocks.

The shift toward banking-as-a-service (BaaS) has accelerated since 2020, but so have its failures. The collapse of Synapse Financial Technologies in 2024 exposed critical vulnerabilities in the middleware model, triggering a regulatory reckoning that is reshaping how fintech-bank partnerships operate. Understanding the architecture patterns, their tradeoffs, and the regulatory landscape is now essential for any platform building financial products.

What Is Composable Banking?

Composable banking treats each financial capability as an independent, API-accessible service. Rather than licensing a monolithic core banking system and customizing it over years, a fintech selects best-of-breed providers for each layer of the stack and orchestrates them through APIs.

The concept borrows from microservices architecture in software engineering: each component handles one responsibility, communicates through well-defined interfaces, and can be swapped without rebuilding the entire system. A neobank might use Column for account infrastructure, Marqeta for card issuing, Alloy for KYC, and Plaid for account linking: all integrated through their respective APIs.

The Composable Banking Stack

A composable banking stack typically consists of six layers, each independently selectable:

  • Channel layer: customer-facing interfaces (mobile, web, third-party integrations)
  • API gateway: event-driven messaging, authentication, rate limiting, and request routing
  • Modular services: independently deployable capabilities (onboarding, KYC/AML, payments, lending, cards, compliance reporting)
  • Core ledger: account management, transaction processing, and balance tracking
  • Payment rails: connections to ACH, Fedwire, RTP, card networks, and increasingly, crypto settlement layers
  • Compliance infrastructure: BSA/AML screening, KYC verification, sanctions screening, and regulatory reporting

The power of this architecture is optionality. When a compliance vendor falls behind on regulatory changes, the fintech swaps it out. When a card issuer offers better interchange terms, the fintech migrates. Each decision is isolated rather than entangled with every other part of the system.

Three Architecture Patterns for Fintech-Bank Integration

Not all composable banking stacks are built the same way. The industry has converged on three distinct integration models, each with fundamentally different risk profiles.

Direct Bank Integration

In this model, the fintech either acquires a bank charter or partners directly with a chartered bank that provides both the regulatory wrapper and the technology APIs. There is no middleware layer between the fintech and the bank.

Column, founded in 2022 by Plaid co-founder William Hockey, exemplifies this approach. Column acquired a nationally chartered community bank and rebuilt it as a developer-first platform. The charter, payment rails, ledger, and compliance stack all live under one roof. Fintechs using Column get direct FDIC-insured accounts, real-time Fedwire access, and branded card programs without any intermediary. Brex migrated its business checking to Column, and Mercury moved users to Column after its previous partner, Evolve Bank, received a Federal Reserve consent order in June 2024.

In July 2026, Increase launched its own FDIC-member bank with direct connections to the Federal Reserve, The Clearing House, and Visa. Used by Gusto, Ramp, and Stripe, Increase represents another data point in the trend toward developer-first chartered institutions.

BaaS Middleware

The middleware model inserts a technology layer between the fintech and the sponsor bank. A BaaS platform like Unit or Treasury Prime provides APIs that abstract away banking operations, while the sponsor bank holds the charter, manages deposits, and maintains regulatory responsibility.

This pattern dominated the 2019 to 2023 era because it was the fastest path to market. A fintech could integrate a single BaaS API and gain access to FDIC-insured accounts, ACH transfers, and card issuing within weeks. Unit, the first BaaS provider to reach unicorn status in 2022 with its $100M Series C at a $1.2B valuation, serves over 140 customers with $2.6B in annual transaction volume.

The structural weakness is the ledger gap. The middleware provider maintains its own record of account balances, separate from the bank's core ledger. When those records diverge: whether through software bugs, fraud, or insolvency: the result can be catastrophic. This is precisely what happened with Synapse.

Embedded Finance Platforms

Embedded finance extends the composable model beyond standalone fintech apps. Non-financial platforms: marketplaces, SaaS tools, gig economy platforms: embed financial services directly into their workflows. Shopify Balance, Uber's driver payouts, and DoorDash's Dasher Direct cards are examples.

The integration depth is greater here. Rather than offering a separate banking experience, the financial product becomes invisible infrastructure. A seller on a marketplace platform receives payouts into an embedded account, spends with a branded card, and accesses working capital lending: all without leaving the platform.

Bain & Company projects U.S. embedded finance transactions to reach $7 trillion in 2026, with platform and infrastructure revenue on pace to hit $51 billion, up from $21 billion in 2021.

ModelTime to MarketRegulatory ControlLedger OwnershipRisk Profile
Direct bank integration6 to 18 monthsFull (charter holder)Single source of truthLow intermediary risk
BaaS middleware2 to 8 weeksDelegated to sponsor bankSplit across middleware and bankReconciliation and solvency risk
Embedded finance platform4 to 12 weeksVaries (depends on partner)Depends on architectureConcentration and vendor lock-in risk

The Sponsor Bank Model and Its Vulnerabilities

Most fintechs do not hold bank charters. Instead, they rely on sponsor banks: chartered institutions that provide the regulatory infrastructure allowing non-banks to offer financial products. The sponsor bank holds deposits, processes payments through Federal Reserve systems, and bears ultimate regulatory responsibility for the fintech's activities.

This model worked well during the low-interest-rate, growth-at-all-costs era. Sponsor banks earned fee revenue from fintech partnerships, while fintechs got to market without the multi-year charter application process. But 2024 exposed how fragile the arrangement had become.

Between January and June 2024, federal regulators issued consent orders against at least eight banks with significant fintech partnership programs:

BankDateRegulatorPrimary Issues
Blue Ridge BankJanuary 2024OCCBSA/AML failures, systemic internal controls breakdowns
Lineage BankJanuary 2024FDICInsufficient risk management of fintech partnerships
Sutton BankFebruary 2024FDICBSA violations, deficient third-party risk management
Piermont BankFebruary 2024FDICUnsafe practices, insufficient internal controls
Thread BankMay 2024FDICInadequate fintech partner risk assessment
Evolve Bank & TrustJune 2024Federal ReserveAML deficiencies, consumer compliance failures

The message from regulators was unambiguous: sponsor banks cannot outsource compliance. If a fintech partner's KYC is inadequate, the bank faces enforcement. If transaction monitoring fails to flag suspicious activity, the bank is liable. This shifted the economics of sponsor banking fundamentally, as the supervisory cost of running these programs now often exceeds the fee revenue they generate.

Concentration risk: Some sponsor banks now cap fintech partnerships at 20% of total deposits or 35% of revenue. As the number of willing sponsor banks shrinks, fintechs face increasing concentration risk: a single enforcement action against their sponsor can force an emergency migration, as Mercury experienced when it moved users from Evolve to Column.

The Synapse Collapse: A Case Study in Middleware Failure

The failure of Synapse Financial Technologies in 2024 became the defining cautionary tale for composable banking. Synapse operated as BaaS middleware connecting fintechs (Yotta, Juno, Copper, and others) to four partner banks: Evolve Bank & Trust, Lineage Bank, AMG National Trust, and American Bank.

On April 22, 2024, Synapse filed for Chapter 11 bankruptcy. A planned acquisition by TabaPay collapsed in May when Evolve Bank refused to cover a funds shortfall. More than 100,000 consumers lost access to approximately $265 million held across fintech platforms built on Synapse infrastructure.

The Ledger Problem

The core failure was architectural. Synapse maintained the only unified ledger mapping fintech app balances to bank-held funds across its four partner banks. When Synapse's systems went offline, no independent, reconciled record existed to verify who owned what. The bankruptcy trustee (former FDIC Chair Jelena McWilliams) reported $85 million of customer savings as missing. Synapse had inappropriately used $60 million of end-user funds to meet reserve obligations to Lineage Bank.

Partner banks returned over $187 million: approximately 85% of the $219 million in total reported end-user funds. But recovery was slow and incomplete. The CFPB filed a complaint against Synapse in August 2025 and ultimately allocated $46.2 million from its Civil Penalty Fund to reimburse affected consumers.

Critical lesson: FBO (For Benefit Of) accounts held at FDIC-insured banks are protected against bank failure, not middleware failure. When the middleman collapses, FDIC insurance provides no mechanism to intervene. This distinction caught consumers and fintechs alike off guard.

Regulatory Response: What Has Changed

The Synapse collapse and the 2024 consent order wave prompted immediate regulatory action. Three developments are reshaping the composable banking landscape.

FDIC Custodial Account Recordkeeping Rule

In September 2024, the FDIC proposed new rules directly in response to the Synapse failure. The proposed rule requires FDIC-insured banks holding custodial deposit accounts with transactional features to maintain records identifying beneficial owners and their balances, reconcile accounts daily, and provide direct, continuous access to beneficial owner records. Bank CEOs or COOs must annually certify compliance. As of September 2026, the rule remains in proposed status.

Interagency Third-Party Risk Guidance

In June 2023, the Federal Reserve, FDIC, and OCC released final interagency guidance on third-party risk management, replacing prior individual agency guidance. In July 2024, the OCC issued a joint statement specifically addressing banks' arrangements with third parties to deliver deposit products, highlighting operational, compliance, strategic, liquidity, and concentration risks.

The Charter Renaissance

Regulatory pressure on sponsor banks has pushed fintechs toward seeking their own charters. 2025 saw an all-time high in U.S. bank charter filings, with 20 filings through October 2025 according to Oliver Wyman analysis. Column and Increase represent the template: technology-first companies that own their charters, eliminating the middleware dependency entirely.

Key Infrastructure Providers

The composable banking ecosystem has matured beyond a few early BaaS platforms. Today's landscape includes chartered banks with developer APIs, pure-play middleware providers, and specialized component vendors.

United States

ProviderModelKey CapabilityNotable Detail
ColumnChartered bank with APIsAccounts, payments, cards, lendingEst. $153M revenue in 2025 (Sacra)
IncreaseChartered bank with APIsAccounts, ACH, wires, cardsLaunched FDIC-member bank July 2026
UnitBaaS middlewareFull-stack BaaS (accounts, cards, payments, lending)$1.2B valuation, 140+ customers
Treasury PrimeBank-direct middlewareAPIs connecting fintechs directly to partner banksShifted to bank-direct model in February 2024
Galileo (SoFi)Processing platformCard issuing, digital banking, paymentsAcquired by SoFi for $1.2B in 2020
MarqetaCard issuing platformModern card issuing and processing$382.5B TPV in FY2025, certified in 40+ countries

International

ProviderRegionModelNotable Detail
GriffinUKFull-stack BaaS with banking licenceUK's first purpose-built BaaS bank, PRA/FCA authorized March 2024
Solaris SEEU (Germany)BaaS with German banking licenseEUR 140M Series G in February 2025, SBI Group majority shareholder
ClearBankUKClearing bank with APIsFirst new clearing bank in UK in 250 years
SwanEU (France)Embedded banking APIsFocuses on European B2B embedded finance

Global Open Banking Frameworks

Composable banking does not exist in a regulatory vacuum. Government-mandated open banking frameworks have created the legal foundation for API-driven financial services across major economies.

EU: From PSD2 to PSD3

The EU's PSD2 mandated that banks expose account and payment APIs to licensed third parties. Its successor: PSD3 and the accompanying Payment Services Regulation (PSR): reached political agreement in November 2025, with agreed texts published in April 2026. The PSR is a regulation rather than a directive, meaning it applies directly across all EU member states and eliminates the national interpretation inconsistencies that plagued PSD2. Key changes include higher API performance standards, customer permission dashboards, and the extension of open banking principles to savings, investments, insurance, and mortgages under a broader "Open Finance" umbrella.

UK: Post-Brexit Independence

The UK retained on-shored PSD2 after Brexit but is not bound by PSD3/PSR. Independent domestic reforms anticipated between 2026 and 2028 will address APP fraud, open banking evolution, and safeguarding requirements. Griffin represents the UK's first purpose-built BaaS bank with full regulatory authorization, demonstrating that the direct-charter model is gaining traction internationally.

Brazil: Open Finance and PIX

Brazil's PIX instant payment system and Open Finance Brasil framework together represent one of the most advanced composable payment ecosystems globally. The Open Finance API Standards v3.0 cover banking, insurance, investments, and PIX payments across 800+ institutions. PIX Automatico launched in June 2025, enabling pre-authorized recurring payments, while PIX by Proximity (tap-to-pay) and PIX-as-collateral are advancing through regulation in 2026.

How Crypto Settlement Fits Into the Composable Stack

The composable banking model's core promise is interchangeable modules. As stablecoin payment rails mature and gain regulatory clarity under frameworks like the GENIUS Act, crypto settlement is becoming another swappable component in the stack: one more payment rail alongside ACH, Fedwire, and card networks.

The API economy in payments already treats rails as abstracted services. A payment orchestration layer routes transactions to the optimal rail based on cost, speed, and destination. Adding a Bitcoin Layer 2 settlement option to that orchestration layer follows the same pattern.

Spark, for example, provides an SDK that fintechs can integrate as one module alongside traditional banking primitives. A composable banking stack using Column for fiat accounts, Marqeta for card issuing, and Spark for Bitcoin and stablecoin settlement can offer users both traditional and crypto rails through a unified interface. The settlement layer becomes a configuration choice rather than an architectural commitment.

This is particularly relevant for cross-border payments, where traditional correspondent banking involves multiple intermediaries, multi-day settlement, and significant fees. A composable stack can route cross-border transactions through stablecoin rails when the cost and speed advantages outweigh the complexity, while falling back to SWIFT or local rails for jurisdictions where crypto settlement is impractical.

The modular principle: In a composable architecture, the settlement rail is just another API endpoint. Whether a transaction settles via ACH in two days, RTP in seconds, or a Bitcoin L2 like Spark in milliseconds, the fintech's application logic remains the same. Only the routing configuration changes.

Risks and Tradeoffs of Composable Banking

Composable architecture introduces its own failure modes. Understanding these tradeoffs is critical for any platform evaluating the approach.

Vendor Dependency and Integration Complexity

Assembling five or six vendors into a coherent banking product creates integration surface area. Each API has its own versioning cadence, uptime SLA, and data format. When Provider A's webhooks change shape, the downstream effects on Providers B and C must be managed. The operational overhead of maintaining a multi-vendor stack is non-trivial, and a single vendor outage can cascade.

Regulatory Accountability Gaps

When a fintech, a BaaS middleware provider, and a sponsor bank all participate in a customer relationship, determining who is accountable for a compliance failure becomes ambiguous. The 2024 enforcement actions made clear that regulators view the bank as ultimately responsible, but the operational reality is that banks often lack visibility into the fintech's customer-facing processes.

Data Sovereignty and Portability

Switching providers in a composable stack is theoretically easy but practically challenging. Customer data, transaction history, and compliance records must migrate cleanly. Account numbers may change. Direct deposit instructions must update. Idempotency during migration is difficult to guarantee. Mercury's migration from Evolve to Column, while successful, required significant engineering effort and careful customer communication.

What Composable Banking Looks Like in Practice

Consider a vertical SaaS platform serving freelancers that wants to offer banking features: a deposit account for receiving payments, instant payouts, a branded debit card, and eventually, stablecoin settlement for international clients.

  1. The platform selects Column or Increase for FDIC-insured deposit accounts and ACH/wire connectivity.
  2. It integrates Marqeta for card issuing and transaction authorization.
  3. It adds Alloy or Persona for identity verification and KYC.
  4. For international freelancers who prefer dollar-denominated stablecoin payments, the platform integrates a crypto settlement module using an SDK like Spark's, enabling instant Bitcoin and stablecoin transfers alongside traditional rails.
  5. A payment orchestration layer routes each transaction to the optimal rail based on the destination country, amount, and the recipient's preferences.

Each provider handles one capability. The platform owns the user experience. When regulation changes or a better vendor emerges, the platform swaps the affected module without rebuilding from scratch.

Where the Industry Is Heading

Several trends are shaping the next phase of composable banking.

The direct-charter model is gaining ground. As sponsor bank partnerships grow more expensive and operationally complex, the economics of owning a charter improve. Column and Increase demonstrate that a technology company can operate a regulated bank while maintaining developer-grade APIs. The 20 new charter filings in 2025 suggest more fintechs are reaching the same conclusion.

Banking API call volumes are projected to grow from 137 billion in 2025 to 722 billion by 2029, according to Juniper Research: a 427% increase. This growth reflects not just more fintechs building on banking APIs, but more embedded finance use cases where non-financial platforms consume banking primitives programmatically.

The regulatory environment, while more demanding, is also becoming more predictable. The FDIC's proposed custodial account rules, the OCC's third-party risk guidance, and the EU's PSD3/PSR framework all push toward the same outcome: clearer accountability, better recordkeeping, and more direct relationships between the entities that hold deposits and the entities that serve customers.

For developers building on composable banking infrastructure, the key resources include the API economy in payments infrastructure for understanding how modern payment APIs work, and the embedded finance and BaaS overview for a deeper look at how these models converge. Platforms exploring how crypto settlement modules fit into this stack can start with the Spark developer documentation to evaluate integration patterns.

This article is for educational purposes only. It does not constitute financial or investment advice. Bitcoin and Layer 2 protocols involve technical and financial risk. Always do your own research and understand the tradeoffs before using any protocol.