Skip To Content

Programmatic Data Access Beta Program Agreement

By participating in the Programmatic Data Access Beta Program (“Beta Program”), you (“Client”) acknowledge that you have read, understand, and agree to the terms and conditions. This Beta Program is offered by Grasshopper Bank (“Bank”) via infrastructure licensed by Grasshopper Bank from Narmi Inc., its technology provider.

1. Nature of the Beta Program

This Beta Program enables you to access certain financial data from your Grasshopper Bank business account(s) programmatically, through one or both of the following access paths:

(a) AI Connector (MCP Server). You may grant your chosen Artificial Intelligence (AI) agent or Large Language Model (“Your AI Agent”) read-only access to certain financial data via our Model Context Protocol (MCP) Server. When you connect Your AI Agent, you authenticate through an OAuth authorization flow in which you sign in with your digital banking username and password (the “Authentication Credentials”) and authorize Your AI Agent to access your data. The MCP Server then issues an OAuth access token to Your AI Agent, which is used for subsequent data requests. Your Authentication Credentials themselves are never shared with Your AI Agent.

(b) Read-Only API Tokens. You, acting through an administrative user of your business account, may generate read-only access tokens (“API Tokens”) in the API Banking section of digital banking. An API Token authenticates requests to the Narmi Public API and allows your own software, internal tools, or authorized third parties to retrieve financial data scoped to your account(s).

The two access paths are independently enableable and may be used together or separately. Enabling one does not require enabling the other.

Both access paths expose data through Narmi’s APIs, but in different ways described in section 4. This Beta Program does not provide access to Narmi’s Admin API, Narmi’s Open Banking API, or any other Narmi interface. References in this Agreement to “the API,” “the Narmi API,” or comparable terms refer to the Narmi Public API only.

This is an experimental, beta feature. It is provided “AS IS” and “AS AVAILABLE” for testing and evaluation purposes only. It is not a fully tested or commercial product and may contain errors, bugs, or other deficiencies.

This Beta Program is currently limited to read-only access. Neither the AI Connector nor any API Token can initiate transactions, move funds, or make any changes to your account(s). Any future “write” capabilities would require a separate, explicit agreement with additional security controls.

You acknowledge that you may, at your discretion, use AI tools or AI-powered integrations in conjunction with either access path — for example, by feeding data retrieved through an API Token into an LLM or agent of your choosing. Any terms of this Agreement addressing AI use apply whenever you use AI, regardless of the access path through which data reaches the AI.

2. Your Assumption of Risk

2.1 AI Hallucinations and Incorrect Information

You understand and acknowledge that AI technologies, including LLMs, are prone to “hallucinations” or generating incorrect, misleading, or nonsensical information. If you use AI tools with data obtained through this Beta Program — whether via the AI Connector or by feeding data retrieved via an API Token into an AI system — the AI may misinterpret your financial data, provide inaccurate summaries, or offer flawed financial advice based on the data accessed. Grasshopper Bank is NOT responsible for any inaccuracies, errors, or omissions generated by any AI, nor for any decisions you make based on such information.

2.2 Bad Financial Advice

You understand that any AI tool or integration that consumes data obtained through this Beta Program is an automated tool and not a financial advisor. Any “advice,” analysis, or recommendations generated by any such tool should NOT be construed as financial, legal, tax, or investment advice from Grasshopper Bank. You are solely responsible for verifying the accuracy of any information and for all financial decisions made. Grasshopper Bank expressly disclaims any liability for financial loss or other damages resulting from reliance on information or advice generated by any AI, integration, or third-party tool.

2.3 Security Beyond Bank’s Control

Grasshopper Bank implements security measures to protect your data within its systems and during transmission to the AI Connector or to the recipient of an authorized API request. However, the security of any system that receives your data — including Your AI Agent, any LLM platform, your integration code, your servers, your vendors’ systems, and your devices — is solely your responsibility.

Bank’s Security Responsibility Ends once data is securely transmitted from Grasshopper Bank’s systems to the receiving party. This includes transmission from the MCP Server to Your AI Agent, and transmission from the Narmi Public API to any IP address authorized by an API Token.

You acknowledge that vulnerabilities or breaches in Your AI Agent’s platform, an LLM provider’s systems, your integration environment, your code repositories, your vendors’ environments, or your own devices could expose your data. Grasshopper Bank is not responsible for security failures or data breaches that occur outside of its direct control.

2.4 Prompt Injection and Adversarial Attacks

If you use AI tools with data obtained through this Beta Program, you acknowledge that AI systems may be vulnerable to “prompt injection” attacks. These attacks occur when malicious instructions are embedded in data (such as in an email, a calendar invite, a transaction description, or a merchant name) that manipulate or trick the AI into performing unintended actions, including potentially exposing your personal or financial information in unintended ways.

Examples of prompt injection risks:

  • Hidden instructions in an email an AI reads
  • An unsolicited event description with a nefarious prompt in a calendar invite reviewed by an AI
  • Transaction descriptions containing hidden commands
  • Merchant names with embedded instructions
  • Sophisticated social engineering attacks that exploit how AI systems process instructions
  • Data being exposed in formats or ways you did not intend due to manipulated AI responses

You are responsible for:

  • Understanding the risk of prompt injection attacks when using any AI tool with your financial data
  • Reviewing AI-generated outputs for accuracy and unexpected information disclosure
  • Not blindly trusting AI responses about your financial data
  • Being cautious about sharing AI conversation outputs with untrusted parties
  • Using privacy features when available (see Section 3.4)
  • Assuming that any data accessible to an AI could potentially be exposed through conversation manipulation

2.5 Data Usage by Third-Party LLMs

If you use any third-party LLM (e.g., Anthropic’s Claude, Google Gemini, OpenAI, or others) with data obtained through this Beta Program, you acknowledge that the terms of service and privacy policies of those third-party LLM providers govern their use of your data. Grasshopper Bank has no control over the data handling practices of third-party LLM providers. You are solely responsible for understanding and agreeing to those practices before you connect any AI to data from your Grasshopper Bank account(s).

2.6 API Token Security

You acknowledge that an API Token is a bearer credential. Any party in possession of an API Token can retrieve the financial data described in Section 4.2 from any IP address on the token’s whitelist. You understand that:

  • API Tokens must be treated as secrets equivalent to passwords. Any exposure — accidental or otherwise — of an API Token may allow unauthorized parties to retrieve your financial data from whitelisted IP addresses until the token is revoked.
  • IP whitelisting is a security control, not a guarantee. If a server on your whitelist is itself compromised, a leaked token could be used from that server.
  • Grasshopper Bank cannot recover a lost token. Tokens are displayed only once at creation. If you lose either, you must revoke the token and generate a new one.
  • Grasshopper Bank monitors API Token usage for anomalies and reserves the right to investigate, throttle, or revoke tokens that exhibit suspicious patterns (see Section 6).

You are responsible for:

  • Storing API Tokens securely (for example, in an encrypted secrets manager, and not in source code, environment files committed to version control, email, or chat systems)
  • Rotating tokens on a regular cadence and immediately upon any employee turnover, vendor change, or suspected compromise
  • Maintaining the IP whitelist associated with each token and promptly removing IP addresses that are no longer authorized
  • Revoking any token that is no longer in active use
  • Reviewing the list of your active tokens in the API Banking section of digital banking no less than quarterly

2.7 Third-Party Data Redistribution

You understand that both access paths enable you to retrieve your financial data from Grasshopper Bank and redistribute it to third parties of your choosing — including, for example, accounting platforms, ERP systems, analytics vendors, auditors, AI agents, and internal tools.

When you redistribute financial data obtained through this Beta Program, you act as the data controller for that onward sharing. Grasshopper Bank has no direct relationship with, and exercises no control over, the third parties you choose to share your data with. You are solely responsible for:

  • Selecting third parties that have adequate security and privacy practices
  • Entering into appropriate contractual arrangements with those third parties (including data processing agreements where applicable)
  • Ensuring that your onward sharing complies with all applicable laws and regulations
  • Understanding and accepting the third parties’ data retention, data usage, and data deletion practices
  • Responding to any data-subject or regulatory inquiry arising from that onward sharing

Grasshopper Bank is not a party to your relationships with third parties that consume data obtained through this Beta Program. Grasshopper Bank is not responsible for the security, accuracy, or lawfulness of any onward data processing that occurs after data leaves the Bank’s systems.

2.8 Unforeseen Risks

The technologies underlying AI agents, MCP, and programmatic banking APIs are rapidly evolving and largely untested in widespread commercial banking contexts. You understand that there may be risks not yet identified or contemplated by Grasshopper Bank. Your participation in this Beta Program is an acceptance of these inherent uncertainties and risks.

3. Your Responsibilities

3.1 Authentication and Token Security

You are solely responsible for the selection, configuration, and use of any AI agent, software, integration, or third-party service that consumes data obtained through this Beta Program.

You must keep your Authentication Credentials, and API Tokens confidential and secure. You must not share them with any party that has not agreed to safeguard them with controls at least as protective as those described in this Agreement, and you must never share them publicly.

You must immediately revoke access — by disconnecting the AI Connector, deleting an API Token, or both — if your Authentication Credentials, or an API Token is compromised or if you suspect unauthorized access. Only users with administrative privileges on your business account may create or delete API Tokens.

You must not share AI conversation transcripts, API responses, or other outputs containing your financial data in public forums, on social media, or with untrusted parties.

3.2 Monitoring and Verification

  • You must monitor your account activity regularly through standard Grasshopper Bank digital banking channels, independent of any AI or any API integration, to detect any discrepancies or unauthorized access.
  • You should periodically verify that AI-generated summaries or API-delivered data match your actual account data by cross-referencing with Grasshopper Bank’s official digital banking platform.
  • You agree to immediately notify Grasshopper Bank if you suspect any unauthorized access to your account, or any compromise of your Authentication Credentials, API Tokens, or bank data.
  • You agree to immediately notify Grasshopper Bank if any AI tool or integration consuming your data produces unexpected outputs that appear to expose more information than intended or to bypass security measures.

3.3 API Integration

Building and maintaining an API integration, including debugging, is explicitly Client’s responsibility. You understand that this API is made available as a Beta Program and may change at any time. You understand that Grasshopper Bank may not offer integration support services. You understand that Grasshopper Bank can revoke API access at any time for any reason including but not limited to excessive API requests, suspicious activity, or activity outside the scope of this Agreement, Grasshopper Bank’s Master Services Agreement, or as required by banking regulation or law. 

Given the experimental nature of this Beta Program, we strongly recommend the following:

When using AI tools with data obtained through this Beta Program (regardless of access path):

  • Using “Incognito Mode” or equivalent privacy features in the AI tool when available to prevent retention of financial data across sessions
  • Limiting sharing of AI conversation transcripts containing your financial data
  • Being skeptical of unusual or unexpected AI responses about your financial data, especially those that reveal information in unexpected formats or detail levels
  • Treating AI conversations as potentially less secure than direct access to your Grasshopper Bank online banking portal

When using API Tokens:

  • Storing API Tokens in a dedicated secrets manager (e.g., AWS Secrets Manager, HashiCorp Vault, 1Password, or equivalent) — not in source code, version control systems, environment files committed to repositories, email, or chat systems
  • Restricting the IP whitelist associated with each token to the minimum set of addresses required
  • Rotating tokens on a regular cadence (at least annually) and immediately upon employee turnover or vendor change
  • Using separate tokens for separate integrations so that revocation of one does not disrupt others
  • Reviewing token usage and the list of active tokens in the API Banking section of digital banking periodically

3.5 Data Controller Responsibilities

As described in Section 2.7, when you redistribute financial data obtained through this Beta Program to any third party, you are the data controller for that onward sharing. This includes, without limitation:

  • AI agents and LLM platforms you connect to your Grasshopper Bank data
  • Software-as-a-service platforms you connect to your Grasshopper Bank data (accounting systems, ERPs, dashboards, analytics vendors)
  • Individual contractors, auditors, board members, or advisors to whom you provide data or reports derived from data
  • Internal tools that you or your employees build using data retrieved through this Beta Program

You agree to:

  • Disclose to your employees, contractors, and third-party recipients that data retrieved through this Beta Program originated from Grasshopper Bank and is subject to the applicable bank privacy notice
  • Maintain records sufficient to identify which parties have received data obtained through this Beta Program, in the event of a data-subject request or a security incident
  • Promptly notify Grasshopper Bank of any suspected or confirmed data incident involving data obtained through this Beta Program, even when the incident occurred at a downstream recipient’s environment (see Section 9)

3.6 Compliance

You are responsible for ensuring your use of the AI Connector and any API Token complies with all applicable laws and regulations, including but not limited to data privacy laws, financial regulations, and export control laws. You are further responsible for ensuring that any third party to whom you redistribute data obtained through this Beta Program complies with all applicable laws and regulations in its handling of that data.

4. Data Access and Scope

The two access paths expose different sets of financial data. This section describes the data surface for each. You explicitly authorize Grasshopper Bank to make this data available through the access paths you enable.

4.1 Data Available via the AI Connector (MCP Server)

The AI Connector is designed for consumption by AI agents and intentionally omits certain sensitive fields (such as full account numbers) that an AI does not need for analytical and conversational use cases. The following types of data are available via the AI Connector:

Account Information:

  • Account identifiers (UUIDs) — permanent unique identifiers for your accounts
  • Account balances — exact dollar amounts
  • Account types (checking, savings, loan) and purpose (personal/business)
  • Account status (active, inactive, pending, verified, removed)
  • Loan details (when applicable):
    • Interest rates
    • Minimum payment amounts
    • Next payment due dates
  • Account creation and update timestamps

Transaction Information:

  • Full transaction amounts — exact dollar amounts for all transactions
  • Complete transaction descriptions — including full merchant names, memo fields, and any text entered
  • Transaction dates and times (creation timestamps and settlement timestamps)
  • Transaction types (credit/debit)
  • Transaction states (pending, settled, hidden)
  • Transaction-level geographic location data where available
  • Check numbers for check-based transactions
  • Transaction categories and internal identifiers
  • Scheduled transfers (state, schedule, frequency, amount, description, next transfer date and time, etc.)

Data Not Accessible via the AI Connector:

  • Full (unmasked) Primary Account Numbers (PAN)
  • Account Holder Personal Information — first name, last name, date of birth, address, and social security numbers are NOT available, unless you or a counterparty include personally identifiable information in another available field, such as a transaction description or memo
  • Other Grasshopper client account data (the AI Connector can only access accounts associated with your Authentication Credentials)
  • Your Authentication Credentials (username/password)
  • Cardholder security data (CVV codes, PINs, 16-digit card numbers, and expiration dates)
  • Internal bank system data

4.2 Data Available via a Read-Only API Token

An API Token authenticates requests directly to the Narmi Public API, which is the data source that powers your digital banking experience. Because an API Token is intended for use by your own software and business integrations (rather than consumption by an AI), the data surface is broader than that of the AI Connector and includes information necessary for operational integrations such as accounting system reconciliation and inbound payment setup.

The following types of data are available via a read-only API Token:

Account Information:

  • All information described in Section 4.1 under “Account Information”
  • Full (unmasked) account numbers for each of your accounts
  • Account-specific payment network and routing information (ACH and wire instructions)
  • Hold information on your accounts
  • Linked external accounts you have verified

Transaction Information:

  • All information described in Section 4.1 under “Transaction Information”
  • Transaction counterparty details where available
  • Transaction images (for example, check images associated with mobile or remote deposits)

Transfers and Payees:

  • Internal and external transfer history and status
  • Scheduled and recurring transfer details
  • Saved ACH payees and wire recipients associated with your account

Documents:

  • Account statements (typically in PDF format)
  • Tax documents (for example, 1099s) where available
  • Other account documents made available through digital banking

Data Not Accessible via a Read-Only API Token:

  • Tax identification numbers (EIN, SSN) and dates of birth for account holders or authorized users
  • Other Grasshopper client account data (an API Token can only access the accounts associated with the issuing Client’s business)
  • Your Authentication Credentials (username/password)
  • Cardholder security data (CVV codes, PINs)
  • Internal bank system data
  • The ability to initiate any transaction, modify any account, or change any setting on your account(s)

4.3 Data Transmission and Control Boundaries

You understand that data is transmitted from Grasshopper Bank’s systems to Your AI Agent or to the IP address authorized by an API Token via secure encrypted connection (TLS 1.2 or higher). Grasshopper Bank’s direct control over your data ceases once it is securely transmitted from the MCP Server to Your AI Agent’s platform, or from the Narmi Public API to the IP address authorized by your API Token.

4.4 Data Retention by Third Parties

Any third party that receives data obtained through this Beta Program — including AI platforms, LLM providers, software-as-a-service integrations, and your own systems and vendors — may retain that data according to its own retention policies and your configuration. This retention persists even after you disconnect the AI Connector or delete an API Token. You are responsible for:

  • Understanding the data retention, backup, and deletion policies of each downstream recipient of your data
  • Ensuring that those policies are acceptable to you and consistent with applicable law
  • Using available privacy controls (such as conversation deletion, incognito modes, or vendor-specific data deletion features) to manage retention
  • Requesting deletion of data from downstream recipients when appropriate (for example, when terminating a vendor relationship or deactivating an AI integration)
  • Recognizing that revocation of an AI Connector session or an API Token prevents future data transmission but does not cause downstream systems to delete data they have already received, and that backups may persist beyond your deletion requests

5. Prohibited Uses

This Beta Program is intended to support your use of your own Grasshopper Bank financial data in operating your own business. It is not intended to support, and you agree that you will not, and will not permit any third party acting on your behalf or any recipient of data obtained through this Beta Program to:

  • Access, attempt to access, or retrieve data belonging to any party other than your own business account(s)
  • Attempt to circumvent, disable, or otherwise interfere with security-related features of the AI Connector, the Narmi Public API, or the API Banking section of digital banking
  • Resell, sublicense, or otherwise commercialize data obtained through this Beta Program to any party other than your own employees, contractors, and service providers acting on your behalf in the ordinary course of your own business
  • Operate, or facilitate the operation of, financial services on behalf of others — including, without limitation, deposit-taking, payment initiation or processing, money transmission, lending, custody, or any other activity that would require a state or federal financial services license, charter, or registration. Clients seeking to offer financial services to their own customers should contact Grasshopper Bank about our Banking-as-a-Service and Embedded Finance offerings, which are governed by separate agreements with controls appropriate for those activities.
  • Use data obtained through this Beta Program to provide data aggregation, account aggregation, or account information services to any party other than your own business
  • Share an API Token with any party that has not agreed to safeguard it with controls at least as protective as those described in this Agreement
  • Use the AI Connector or any API Token in a manner that materially degrades the performance or availability of Grasshopper Bank’s or Narmi’s services (including, without limitation, by polling at frequencies in excess of published rate limits or by retrieving excessive historical data beyond your legitimate operational need)
  • Use the AI Connector or any API Token in connection with any unlawful activity or in violation of applicable law

Violation of this Section 5 constitutes a material breach of this Agreement and entitles Grasshopper Bank to disconnect your AI Connector access, delete any or all of your API Tokens, terminate your participation in this Beta Program, and pursue any other remedies available under law.

6. Program Termination and Changes

Grasshopper Bank reserves the right to modify, suspend, or terminate this Beta Program, or your access to it (including any individual API Token), at any time, with or without notice, and for any reason, including but not limited to security concerns, regulatory changes, anomalous usage patterns, violation of Section 5, or technical issues. Grasshopper Bank may update these terms and conditions at any time.

7. Limitation of Liability

To the fullest extent permitted by law, Grasshopper Bank and its affiliates, directors, officers, employees, and agents shall not be liable for any direct, indirect, incidental, special, consequential, or punitive damages, including but not limited to loss of profits, data, use, goodwill, or other intangible losses, resulting from:

  • (i) your access to or use of, or inability to access or use, the Beta Program;
  • (ii) any conduct or content of any third party, including LLM providers and any third party to whom you redistribute data obtained through this Beta Program;
  • (iii) any content, analysis, or advice obtained from the Beta Program, any AI tool, or any integration consuming an API Token;
  • (iv) unauthorized access, use, or alteration of your transmissions or content;
  • (v) prompt injection attacks or adversarial manipulation of any AI tool that results in unintended disclosure of your financial data;
  • (vi) AI hallucinations, errors, or inaccuracies in financial analysis or advice;
  • (vii) failure of AI security instructions or behavioral controls to prevent data exposure;
  • (viii) exposure of your financial data due to limitations in any AI tool to detect a prompt injection attack or other security vulnerability;
  • (ix) compromise, loss, theft, or unauthorized disclosure of any Authentication Credential, or API Token, whether caused by you, your employees, your contractors, your vendors, or any other party;
  • (x) the security, accuracy, or lawfulness of any onward data processing by any third party to whom you redistribute data obtained through this Beta Program;

whether based on warranty, contract, tort (including negligence), or any other legal theory, whether or not we have been informed of the possibility of such damage.

8. Indemnification

You agree to defend, indemnify, and hold harmless Grasshopper Bank and its affiliates, directors, officers, employees, and agents from and against any and all claims, damages, obligations, losses, liabilities, costs or debt, and expenses (including but not limited to attorney’s fees) arising from or in connection with:

  • (i) your use of and access to the Beta Program, including any data accessed or decisions made based on information obtained through the Beta Program;
  • (ii) your breach of these Terms, including without limitation Section 5;
  • (iii) your violation of any third-party right, including without limitation any intellectual property, property, or privacy right;
  • (iv) any claim that any AI tool, integration, or third party to whom you redistributed data caused damage to another party;
  • (v) your failure to maintain the security of your Authentication Credentials, any API Token, or any AI platform or integration you use;
  • (vi) your sharing of financial data, API Tokens, or AI conversation transcripts obtained through the Beta Program with unauthorized third parties or in public forums;
  • (vii) any exposure of your financial data resulting from prompt injection attacks or AI security instruction failures that occur due to your usage patterns or queries;
  • (viii) any act or omission of any third party to whom you have redistributed data obtained through this Beta Program, to the extent such act or omission gives rise to a claim relating to that data.

9. Incident Reporting

Client agrees to fully cooperate with Grasshopper Bank’s fraud, security, and internal audit teams, including providing relevant access logs and incident reports upon request. 

  • Suspected unauthorized access to your account via the AI Connector or any API Token
  • Evidence of prompt injection or adversarial attacks against any AI tool consuming your data
  • AI-generated outputs that expose more financial information than expected or bypass apparent security measures
  • AI behavior that appears to contradict stated security instructions (e.g., displaying full account numbers when instructed not to)
  • AI responses that include your financial data in unexpected formats (CSV, JSON, structured tables) without your explicit request
  • Compromise of your Authentication Credentials, or any API Token
  • Accidental public exposure of an API Token (for example, commit to a public version-control repository, email to an unintended recipient, or posting in a public forum)
  • Suspected or confirmed security incident at any third party to whom you have redistributed data obtained through this Beta Program, where that incident involves or may involve the data redistributed
  • Security vulnerabilities in the Beta Program
  • Unexpected behavior by any AI tool or integration consuming data obtained through this Beta Program

Contact for security incidents: [email protected] or 888.895.9685.

10. Your Right to Revoke Access

AI Connector. You may revoke an AI Agent’s access to your financial data at any time by:

  1. Disconnecting the AI Connector in your AI Agent’s connector settings
  2. Toggling the Grasshopper AI Connector tool off

Access tokens for the AI Connector only last for 7 days.

API Tokens. You may delete any API Token at any time by:

  1. Navigating to Settings → API Banking in your Grasshopper Bank digital banking portal
  2. Selecting the token you wish to revoke and choosing “Delete”

Deletion of an API Token takes effect immediately. Any attempt to use the deleted token thereafter will fail.

Acceptance of this Agreement. Only users with administrative privileges on your business account may create an API Token. Before creating a Client’s first API Token, an administrative user must accept this Agreement through the click-through acknowledgment presented in the API Banking section of digital banking. Grasshopper Bank records the identity of the accepting user and the date and time of acceptance.

IMPORTANT: Revocation of either the AI Connector or an API Token prevents future data transmission but does not:

  • Delete data already obtained by any AI agent or integration
  • Remove conversation history from any AI provider’s systems
  • Delete any copies of your financial data that may have been made by any downstream recipient
  • Cause third parties to whom you have redistributed data to delete that data

You must separately manage data deletion according to each provider’s or recipient’s policies.

11. Client Acknowledgment and Agreement

I have read and understand the Grasshopper Bank Programmatic Data Access Beta Program Agreement, including the data exposure information in Sections 4.1 and 4.2.

I understand the experimental nature of this Beta Program and the risks involved, including those related to:

  • AI hallucinations and incorrect information, whenever I use AI tools with data obtained through this Beta Program
  • Inappropriate or flawed financial advice generated by AI tools or integrations
  • Prompt injection and adversarial attacks on AI systems that could expose my financial data
  • Data usage and retention by third-party LLM providers, AI platforms, and other integration partners
  • Compromise, theft, or accidental public exposure of my Authentication Credentials, or any API Token
  • My role as data controller when I redistribute data obtained through this Beta Program to any third party, including AI agents and software-as-a-service integrations
  • Data security vulnerabilities outside the Bank’s control
  • Access by the AI Connector or an API Token to my account information and financial activity, with the different data surfaces for each access path described in Sections 4.1 and 4.2
  • Unforeseen risks in emerging technology

I agree to:

  • Use these features at my own risk
  • Accept all responsibilities outlined above, including monitoring my accounts, protecting my conversation data, and safeguarding any API Tokens I issue
  • Monitor my accounts independently through official Grasshopper Bank channels
  • Immediately report security concerns, unexpected AI behavior, or any suspected compromise of my Authentication Credentials, or API Tokens
  • Exercise caution in how I leverage AI tools and other third-party connectors or integrations that could expose me to prompt injection attacks or data breach
  • Accept my responsibilities as data controller when I redistribute data obtained through this Beta Program to any third party, and comply with all applicable laws and regulations in doing so
  • Refrain from the prohibited uses described in Section 5, including use of this Beta Program to operate financial services on behalf of others

Change Log

August 13, 2026

This revision replaces the prior AI Connector Beta Program Agreement (last revised February 13, 2026) and renames the program to the Programmatic Data Access Beta Program to reflect that it now covers both the AI Connector (MCP Server) and read-only Narmi Public API tokens issued through the API Banking section of digital banking. Sections addressing AI risk apply whenever a Client uses AI with data obtained through the Beta Program, regardless of access path. Sections addressing redistribution of data to third parties apply to both access paths. Section 4 describes the distinct data surfaces exposed by the AI Connector and by read-only API Tokens. Section 5 establishes explicit prohibited uses, including operation of financial services on behalf of others. Sections 7 through 10 extend liability, indemnification, incident reporting, and revocation terms to cover both access paths. Section 1 clarifies that the AI Connector authenticates Your AI Agent through an OAuth authorization flow and that the Beta Program provides access to the Narmi Public API only, not to Narmi’s Admin API, Open Banking API, or any other Narmi interface.

February 13, 2026

The updated agreement formalizes the transition from API token-based authentication to a Single Sign-On (SSO) framework, while introducing a comprehensive section on adversarial AI risks such as prompt injection and social engineering. It further replaces general data descriptions with a granular, exhaustive list of accessible financial data fields, including account UUIDs, transaction metadata, and geographic identifiers, to ensure full transparency regarding the scope of information shared with third-party LLMs. Additionally, the revised terms establish stringent incident reporting protocols and explicit user responsibilities regarding the management of AI-generated conversation transcripts and data retention.

We don't support Internet Explorer

Please use Chrome, Safari, Firefox, or Edge to view this site.

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.