Plaid logo
Core Exchange
Getting started
  • Welcome
  • Onboarding guide
  • Implementation checklist
Setup & configuration
  • Dashboard overview
  • Testing & validation
  • Production access
Building your integration
  • Authentication
  • User experience
  • Security best practices
  • Mock server
Post-launch
  • Post-launch operations
  • Dashboard monitoring
  • Consent management
  • App Directory
  • Troubleshooting
Reference
  • API reference
  • Changelog
  • Migrating from earlier Core Exchange versions
  • Data mapping guide
  • Migrating from Plaid Exchange
Core Exchange
Close search modal
Ask Bill!
Ask Bill!
Hi! I'm Bill! You can ask me all about Core Exchange. Try asking questions like:
    Note: Bill isn't perfect. He's just a robot platypus that reads our docs for fun. You should treat his answers with the same healthy skepticism you might treat any other answer on the internet. This chat may be logged for quality and training purposes. Please don't send Bill any PII -- he's scared of intimacy. All chats with Bill are subject to Plaid's Privacy Policy.
    Plaid.comGet Started
    Open nav

    Welcome

    Build an FDX-aligned API with Plaid's free open finance solution

    What this guide contains

    This documentation contains everything you need to build and launch your FDX-aligned API. It includes:

    • An onboarding guide covering the end-to-end integration journey, from setup through post-launch
    • A checklist of all the steps that must be completed during each stage of development
    • A visual walkthrough of the experience your customers will have once Plaid is fully integrated to your FDX-aligned API
    • An in-depth explanation of the OAuth-compliant authentication process, including FDX Explorer, which provides an interactive demo of the full OAuth flow and Core Exchange API calls
    • Example requests you can send to the mock server to get familiar with FDX data payloads
    • An API reference with sample requests, responses, and required fields for all FDX-aligned spec endpoints
    • A data mapping guide including a FAQ and how to avoid common mistakes

    Core Exchange

    Core Exchange is Plaid's free, FDX-aligned API specification scoped to the data models and endpoints that power Plaid downstream products. It includes developer documentation, tooling in the Data Partner Dashboard, and dedicated support from the Plaid team.

    For more details, see the onboarding guide.

    Consent management

    Consent management gives data providers the tools to gain visibility into the authorization details for connections their customers have made via Plaid, build a consent portal that enables customers to manage their connections, and receive real-time alerts.

    Dashboard search interface for looking up customer connections
    Search by customer to view authorization details

    For more details, see Consent management.

    App Directory

    App Directory gives data providers insights about the thousands of apps on Plaid's network that their customers have connected to, including categories and number of connections. App Directory is FDX-aligned and available via both the no-code Dashboard and APIs.

    App Directory showing connected applications with categories and connection counts
    View connected applications and their details

    For more details, see App Directory.

    Building with Plaid

    When you build your API with Plaid, your institution becomes available to Plaid-powered applications. If your institution is not already supported in Plaid Link, it will appear once your API is validated and launched. If your institution is already supported, API connectivity generally leads to better conversion and longer-lasting connections for your end users.

    Building your FDX-aligned API with Plaid helps your organization align with industry standards for consumer-authorized data sharing.

    Security and privacy

    Plaid has established security and privacy processes to help keep your customers' data secure, including TLS 1.2+ enforcement, mTLS support, IP allowlisting, and OAuth with PKCE for public clients. For more details, see Security best practices and the Plaid Security Portal.