Paysera clients can self-issue a free API token to connect AI accounting or bookkeeping tools, with no separate agreement needed. All payments still require manual two-factor confirmation.
This article is for informational purposes only and does not constitute financial, tax, or legal advice. Consult a qualified professional for guidance specific to your situation.
Editorial note: Reviewed for accuracy by the Startup Finance Guide editorial team. Our editors cross-reference all claims against platform documentation, regulatory publications, and vendor disclosures. Last reviewed: 2026-09-11.
Paysera, a Lithuania-based payment institution operating under the EU's Payment Services Directive 2 (PSD2), has begun letting any client self-generate a personal access token, free of charge and without a separate API agreement, to connect AI accounting assistants and bookkeeping software directly to their Paysera account. The announcement was reported by Finextra and confirmed by Paysera's own documentation at bank.paysera.com.
PSD2 is the European Union's revised Payment Services Directive, which has governed open banking access across EU member states since January 2018. Under PSD2, payment initiation services are normally restricted to licensed third-party providers holding a specific regulatory certificate. Paysera's personal access token sidesteps that bottleneck for its own clients by giving them direct, self-scoped API access to their own accounts, without routing through a licensed intermediary. That distinction matters: the client is authorizing access to their own data, not delegating payment initiation to a regulated third party.
The token is created in a browser at bank.paysera.com under Security settings. It is not yet available inside the Paysera mobile app. Setup takes a few minutes. The client sets the scope: which accounts the software can see, what actions it can take, spending limits, and an expiry date. The token can be revoked at any time from the same settings panel.
Payment drafts are prepared by the connected software, but money moves only after the account holder logs in and confirms the transfer with two-factor authentication inside the Paysera Super App. Paysera CEO Justina Sidlauskiene described the design logic in the Finextra release: "The software prepares, the human confirms. The token draws that line technically, not by a promise."
What this means for founders
If your startup already uses Paysera for cross-border payments and you run a separate bookkeeping or reconciliation workflow, this token removes one integration barrier. You no longer need to negotiate an API agreement or wait for Paysera to approve a developer application before connecting a tool.
The practical workflow Paysera describes: an invoice arrives by email, you forward it to an AI assistant connected via the token, the assistant reads the document and populates the payee, amount, and payment reference in a draft inside your Paysera account, and you confirm the transfer in the app. For founders or finance leads processing dozens of supplier invoices monthly, that eliminates manual data entry without removing the human approval step.
Paysera has published an official open-source skill for Claude and Codex called "Paysera Payments." If your team uses either of those AI assistants, the integration path is documented and free. For teams running their own accounting software or internal finance tools, the token works directly with the public Paysera Transfer API.
Before connecting any tool, check three things. First, confirm that your accounting software or AI assistant actually supports Paysera's token-based API. Tools like Xero and QuickBooks have their own bank-feed architectures and may not yet have a Paysera connector that uses personal access tokens. Inkle, a US-incorporated cross-border accounting platform serving Indian founders, is another option in this space, though its Paysera compatibility is not publicly documented. Second, review the token scope you set: granting read-plus-draft access is materially different from granting read-only access, and the risk profile differs accordingly. Third, confirm your internal controls still satisfy any audit or compliance requirements your startup operates under, since a payment draft prepared by software and confirmed by one person may or may not meet your approval-chain policy.
For compliance officers at cross-border startups, the token's scoping controls are the relevant mechanism. The client defines which accounts are visible and sets transaction limits. That is a reasonable control surface, but it is self-administered. There is no third-party audit of how the token is configured, and Paysera has not published a formal security certification for this feature as of this writing.
What changed
Before this feature, a Paysera client who wanted to connect accounting software to their account programmatically had two options: use Paysera's existing business API (which required a formal agreement) or export statements manually and import them into their bookkeeping tool. Neither path was frictionless for a small team.
The personal access token changes the entry point. It is self-service, free, and scoped by the client rather than by Paysera's onboarding team. That is a meaningful shift in how payment account access gets distributed, particularly for the small and medium-sized businesses Paysera explicitly names as the primary target.
The broader context is that self-service open banking access of this kind is still uncommon inside the EU. PSD2 opened bank interfaces to licensed third parties, but it did not create a simple mechanism for individual clients to grant scoped API access to their own tools without going through a regulated intermediary. Paysera's approach is one of a small number of EU-market implementations that give clients direct token-based access, according to the Finextra report.
For AI accounting tools competing in this space, including platforms like Vic.ai and Docyt, Paysera's open-source skill lowers the integration cost on the payment-data side. Whether those platforms build connectors is a separate question.
Limitations and open questions
Several things are not settled yet. Paysera has stated it plans to introduce exceptions to the mandatory two-factor confirmation requirement, specifically for payments to trusted payees and for business clients, but no timeline has been published. Until those exceptions exist, every payment requires a manual confirmation step, which limits how much routine payment processing can actually be automated.
The token feature is browser-only for now. Paysera has said app-based token creation is not yet available, which adds friction for founders who manage their accounts primarily from mobile.
Paysera has not published a formal security audit or independent certification for the personal access token system. The scoping controls are client-administered, which means the security of any given integration depends on how carefully the client configures the token. The European Banking Authority (EBA), which oversees PSD2 implementation standards, has not issued specific guidance on self-issued client tokens of this type, and it is not clear whether this feature has been reviewed against EBA's Regulatory Technical Standards on strong customer authentication.
Finally, compatibility with specific AI accounting tools is not guaranteed. Paysera's official skill targets Claude and Codex. Founders using other AI assistants or accounting platforms will need to verify whether a working connector exists before assuming the workflow described above is available to them.
This article is for informational purposes only and does not constitute financial, tax, or legal advice. Consult a qualified professional for guidance specific to your situation.
