Paysera's new free personal access token lets founders connect AI bookkeeping tools to live payment accounts, with every transfer still requiring human two-factor confirmation.
This article is for informational purposes only and does not constitute financial, tax, or legal advice. Consult a qualified professional for guidance specific to your situation.
Editorial note: Reviewed for accuracy by the Startup Finance Guide editorial team. Our editors cross-reference all claims against platform documentation, regulatory publications, and vendor disclosures. Published 2026-09-12.
Paysera, a Lithuania-based licensed payment institution regulated under the European Union's Payment Services Directive 2 (PSD2), announced on 11 September 2026 that clients can now generate a personal access token at no cost and without a separate contract, and hand that token to an AI assistant or accounting software to prepare payment drafts on their behalf.
The announcement, reported by Finextra, is notable because PSD2 normally restricts payment initiation access to licensed third-party providers holding a specific certificate issued by a national competent authority. Paysera is threading that needle by keeping the token inside its own infrastructure: the software can read account statements and prepare transfer drafts, but money moves only after the account holder logs in and confirms with two-factor authentication. No payment is ever authorised automatically.
For cross-border startups juggling supplier invoices across the US, India, and Canada, the practical implication is direct: a founder can forward an invoice to an AI assistant, ask it in plain language to prepare the payment, and then approve a pre-filled draft in the Paysera app. The assistant fills in the payee, amount, and payment purpose. The human checks and confirms.
What this means for founders
If you are already using AI-assisted bookkeeping tools such as QuickBooks (Intuit, US), Xero (Xero Limited, New Zealand), or a custom in-house accounting stack, the question worth asking your payment processor is whether it supports token-based API access of this kind. Most do not, at least not for individual accounts or small businesses without a separate enterprise agreement.
Paysera's token is created in a browser at bank.paysera.com under Security settings. The option is not yet available in the mobile app. Setup takes a few minutes. The client sets the scope: which accounts the software can see, what actions it can take, transaction limits, and how long the token stays valid. The token can be revoked at any time from the same settings panel.
For accounting workflows, the token also unlocks read access to account statements if the client grants that permission. That means an AI assistant can categorise expenses, pull payment history, and generate spending overviews without the founder exporting CSV files or copy-pasting transaction data. That is the part that removes manual data entry from the reconciliation loop.
Paysera has published an official open-source skill for AI assistants, called Paysera Payments, compatible with Claude and Codex. Founders building on their own stack can connect directly via the public Paysera Transfer API. Both routes use the same personal access token.
For founders not on Paysera, the comparison point matters. Competitors in the AI-connected payments and accounting space include platforms such as Airwallex (Airwallex Pty Ltd, Australia), which offers API-based payment initiation for businesses but requires a formal API agreement, and Wise Business (Wise PLC, UK), which provides a public API for balance reads and transfers but similarly gates initiation access behind an application process. Neither currently offers a self-service token model equivalent to what Paysera has described here. That gap is worth tracking if your stack depends on real-time reconciliation.
What changed
Before this release, connecting third-party software to a Paysera account for payment initiation required either a licensed integration partner or a bespoke arrangement. The new token model removes that barrier for individual clients and small businesses.
The broader regulatory context is that PSD2, the EU's second Payment Services Directive, created a framework for open banking by requiring banks to open APIs to licensed third-party providers. What it did not do is give individual account holders a direct, self-service mechanism to grant structured API access to software of their choosing. Paysera's token works within PSD2 because it does not initiate payments autonomously: the human confirmation step keeps the transaction inside the account holder's own authentication flow, not inside a third-party payment initiation service provider (PISP) flow that would require a separate licence.
Justina Sidlauskiene, CEO of Paysera, described the design principle in the announcement: the software prepares, the human confirms. The token draws that line technically, not by a promise.
For founders in India operating under Foreign Exchange Management Act (FEMA) rules, or in Canada subject to Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) reporting requirements, the key compliance point is that Paysera is an EU-regulated entity. Cross-border use of the token for payments involving non-EU accounts will still be subject to the correspondent banking rules and currency controls that apply in those jurisdictions. The token does not change what Paysera can send or receive; it changes how instructions reach Paysera.
Limitations and open questions
Several things about this feature are still moving. The token is browser-only at launch; Paysera says app-based token creation is not yet available, with no published timeline. The company has indicated it plans to introduce exceptions to the mandatory confirmation step for payments to trusted payees and for business clients, but no date or regulatory approval path for that has been disclosed.
The Finextra article notes this is an external press release, not independently reported editorial content. Finextra did not verify the technical claims. Startup Finance Guide has not independently tested the token or the Paysera Payments skill, and the feature's behaviour at scale, or under edge cases like failed two-factor authentication or API rate limits, is not documented in publicly available materials as of this writing.
For US-incorporated startups, the Consumer Financial Protection Bureau (CFPB) has not issued formal guidance on AI-assisted payment initiation tools, and the Federal Reserve's Regulation E (Electronic Fund Transfer Act) protections apply to consumer accounts rather than business accounts, so the liability framework for an AI-prepared transfer that a founder confirms in error is not clearly settled under US law.
Finally, the open-source Paysera Payments skill is compatible with Claude and Codex as named examples. Whether it works with other AI assistant platforms, and what data those platforms retain when processing invoice content, depends on the terms of those platforms, not Paysera's. Founders handling sensitive supplier or client data through an AI assistant should review the data retention and processing terms of whichever model they connect before granting statement-read access.
This article is for informational purposes only and does not constitute financial, tax, or legal advice. Consult a qualified professional for guidance specific to your situation.
Sources
- Paysera lets clients connect AI assistants to payments — Finextra
- Payment Services Directive 2 (PSD2) — EUR-Lex, European Commission
- Regulation E (Electronic Fund Transfer Act) — Consumer Financial Protection Bureau (CFPB)
- Foreign Exchange Management Act (FEMA) notifications — Reserve Bank of India (RBI)
- FINTRAC — Financial Transactions and Reports Analysis Centre of Canada
- Paysera personal access token documentation
