关于Garden FI与真实金融机构环境插件窗口打开能力的一致性问询
关于Garden FI与真实金融机构环境插件窗口打开能力的一致性问询
Hey Josh, great question—this is exactly the kind of detail that makes or breaks plugin deployments with clients, so let’s unpack this clearly.
First, let’s get the core distinction straight: Garden FI is a sandbox/test environment, not a 1:1 replica of a real financial institution’s production setup. Its primary job is to let developers build and test plugins without hitting all the strict security and compliance walls that production FIs enforce.
关于窗口跳转的行为差异
- The reason you could open a window to a URI not in your redirect list using
<a target="_blank" href="http://my_url"></a>is that Garden FI intentionally relaxes security rules like redirect URI validation. This is by design—so you can test different navigation flows without getting blocked during development. - The documentation note that you "shouldn’t be able to open other windows" refers to production FI environments, not the sandbox. Real FIs enforce redirect URI whitelisting rigorously to prevent phishing attacks, unauthorized navigation, and compliance violations. In production, any attempt to jump to a URI not on your approved list would almost certainly be blocked.
针对你的插件场景的建议
- If your plugin needs to link to the FI’s FAQ or external FAQ pages, you’ll need to add those specific URIs to your developer portal’s redirect_uri whitelist before deploying to production. Some FIs also have a process for approving trusted external domains (like their own official FAQ sites) even if they weren’t in your initial list—reach out to their dev support to confirm this.
- While Garden FI lets you bypass this check for testing, don’t rely on this behavior in production. Make sure to validate your redirect flow with the real FI’s staging environment (if available) before going live, to avoid unexpected failures.
核心差异总结
Garden FI and real FI environments differ most in their security posture:
- Security restrictions: Production FIs have strict compliance and security controls (including redirect URI checks) to protect user data and meet regulatory requirements. Garden FI skips many of these to streamline development.
- Rule enforcement: Garden FI doesn’t always mirror production-level rule execution—this includes redirect validation, rate limiting, and other security checks.
- Purpose: Garden FI is for building and debugging; real FI environments are for live user traffic, so every action must adhere to strict standards.
Hope this clarifies things and helps you set the right expectations with your client!
备注:内容来源于stack exchange,提问作者Josh
相关产品推荐
相关产品推荐

