Heads up: not what I mean by data silos
When companies entrust customers with control over their own data, they earn actual customer loyalty.
Why Companies Won’t Share Data#
There are tons of reasons that companies do not want to allow applications to have access to our accounts’ data. An airline wants you to visit their website to see your mileage balance, so they can market airfare and credit cards to you. A bank assumes more liability by allowing other applications to read your balance and account number. A boutique loyalty program might not have the budget to engineer a custom data-sharing solution. Security issues, development costs, and marketing strategies turn companies into data silos, forcing inefficient consumer behaviors and generally keeping life harder for everyone. Businesses’ choice to silo squanders their potential to build an advanced world where businesses and consumers willingly contribute to a healthy data-sharing ecosystem.
Fortunately, some companies have built sophisticated little peep-holes into these silos– the wallet applications of Google, Apple, and AwardWallet deserve some mention– but none of these wallets can do what I want out of a digital wallet. If third-party loyalty services want to have their place in the wallet of my dreams, they need to come to the table with a solution that can work for them, so I’d like to suggest one.
First, let’s talk about how these three wallets work and what that tells us about (1) the companies that store our data and (2) the people who (like me) want it all tidily in one place.
What are Wallet Applications and How Do They Work#
Wallet applications offer users the ability to aggregate and pay with their digital assets. Digital assets include points, cryptocurrencies, gift cards, credit cards, and even boarding passes. There are a million and one wallet applications that offer these (or some subset of these) services, so I’ll cover three preeminent wallet developers: Google, Apple, and AwardWallet.
Users can manually copy their data from third parties, like from hotels, airlines, and even restaurants into almost any wallet application, but these “smart” wallets use clever ways to automatically populate and update your wallet. Google Pay and Apple Wallet built “Pass” APIs that allow businesses to integrate with their native wallet applications, while AwardWallet takes a hackier approach.
Apple Wallet#
Apple Wallet offers the most straightforward way to integrate third-party digital assets. A user can either add a “Pass” to their wallet either directly from the Apple Wallet app, or they can click a special link on their phone to add a Pass into their wallet. With Apple Wallet, you can see your Starbucks gift card balance and pay with your phone, but you won’t be able to see how many United Airlines MileagePlus Rewards points you have. Apple’s PassKit for developers certainly enables airlines to integrate this information, but these companies don’t want to share this information outside of controlled channels. Apple Wallet is also limited to a mobile interface, so maybe loyalty program companies figure that their Pass users don’t want to deal with the clutter.

What Apple Wallet looks like
Google Pay#
Google Pay is like Apple Wallet because it allows users to personally add Passes to their wallet, but it also automatically adds accounts. Google has all of the information that arrives in Gmail, so in other words, Google knows your soul. Google can populate your wallet with your United Airlines MileagePlus Rewards points and Marriott Bonvoy points because your account balances arrive every month into your inbox.

Google Pay grabs your loyalty account updates from your inbox.

Both Google and Apple built new wallet data sharing standards (Pass APIs) and enticed companies to feed data into their wallets by touting a huge user pool for third parties to tap into. These frameworks are undeniably sophisticated, but they are opinionated; that is, they’re limited to use on mobile devices and add extra complexity for businesses to integrate with those devices.
AwardWallet#
AwardWallet is where things get really interesting. Challenging all of the reasons why companies won’t share digital asset data, AwardWallet’s popularity attests to consumer demand for more control over their own data. The company provides tracking services to its more than 713,378 users despite severe pushback from third-party companies complaining about its unconventional approaches to pulling data into users’ wallets.

The AwardWallet dashboard showing credit card, airline, rental, and other loyalty account information
AwardWallet is like Google since it reads your emails to populate your account balances and to track your travel itineraries, but AwardWallet requires users to opt-in to this feature. If sharing your emails outside of your email service seems sketchy to you, you might be surprised to know that 36% of new AwardWallet users opt-in. The other 64% of those users are just fine providing their various accounts’ usernames and passwords to the wallet service so that it can retrieve information on your behalf. Operating for over 17 years, AwardWallet’s user base has entrusted the online wallet with tracking 4,031,992 (and counting) loyalty accounts.¹

AwardWallet can track over 680 loyalty accounts.
Third party digital asset companies hate this one trick to keep track of all your important digital assets in one place. AwardWallet has received several Cease and Desists from major airlines, including American Airlines, Delta, United Airlines, and Southwest Airlines, urging AwardWallet to stop tracking their loyalty programs. In response, the AwardWallet community has rallied against these airlines’ decisions with petitions to allow integrations to resume.
In the meantime, loyalty customers are forced to visit several individual websites, juggling passwords and scrolling past advertisements every time they want to check up on their vouchers and points. This friction often means that users lose out on rewards that expire quietly in the night.
While a select few airlines have taken to sending Cease and Desist letters, hundreds of airlines, banks, and credit card issuers are still allowing AwardWallet to fetch information on behalf of their users.
In 2016, when I got into credit card churning, this service turned out to be an invaluable tool to keep track of my travel rewards.
¹ Data courtesy of Alexi Vereschaga, AwardWallet
What Companies Should Do#
Companies that provide digital assets should go headless and loosen their control over how their customers interact with their own assets. Just as I trust Mint and Personal Capital integrate with Chase through their secure API to give me my full financial picture, I want AwardWallet to be able to manage all of my rewards and Delta to provide a similar secure API.
As part of their data sharing strategy, businesses like Delta could limit which wallets services qualify for integration, and if certain wallet providers manage to prove themselves as responsible custodians of customer data, Delta could graduate them to have elevated access to information.
A Concrete Example#
Here’s what an ideal use case would look like for AwardWallet and Delta:
- AwardWallet applies to Delta as a wallet and flight tracking application.
- Delta approves AwardWallet’s app registration. Now AwardWallet users can track their Delta rewards and trips.
As an AwardWallet user,
- I log into AwardWallet and add my Delta account.
- Instead of an AwardWallet form prompting me for my sensitive SkyMiles member ID and password credentials (like it does for my credit card account), AwardWallet can redirect me to Delta’s website.
- I log into Delta, then Delta asks if I would like to share my SkyMiles member ID, mileage balance and expiration date, and (optionally) upcoming trips with AwardWallet.
- I authorize AwardWallet to have access to my mileage information, but not to my upcoming trips (maybe I’m just paranoid about sharing that).
- Whenever I log into AwardWallet, my dashboard shows my SkyMiles balance and expiration date, but it has no idea that I’m flying to Cincinnati next Tuesday.
How OAuth2.0 Fits In#
OAuth 2.0 can be used to implement this formulaic use case by providing a standard way to administer data rights to third-party applications. With OAuth 2.0, businesses can let their customers decide what account and asset information is shared with their wallets.
An OAuth 2.0 protected API would be platform agnostic; that is, businesses would not have to build custom solutions to accomodate the likes of Google’s and Apple’s opinionated “Pass” frameworks. Businesses could build their API once and it could work everywhere.
But OAuth 2.0 is not the full story. It is a broad characterization of APIs that use the OAuth2.0 framework to restrict which information is shared with individual users. If we really want to foster an ecosystem of responsible data sharing, the most invested businesses should define standard data types, similar to how the Internet Engineering Task Force created GeoJSON to help people convey geospatial information. The models and schemas that airlines, restaurants, and hotels could use might resemble these types defined by Google’s Pass API:
- Boarding passes
- Event tickets
- Gift cards
- Loyalty Offers
- Transit passes

A Google developer guide walks you through some use cases for implementing a Pass.
There are a lot of different types of businesses that would need to be involved as stakeholders in this design. The data fields that should be included in a “boarding pass” are pretty consistent among airlines, yet there might be variations in how loyalty programs treat points and vouchers. For example, mileage programs points typically have expiration dates, while credit card points typically do not. Unless there is an inclusive effort towards standardization, a wallet application would have to write custom business logic to handle every unique API’s interpretation of a user’s “rewards balance.”
The applications that would consume loyalty rewards data would hardly be limited to wallets. Businesses might find that by providing controlled access to customer assets, they’ll open up new, unexpected revenue streams.
Reality Check#
When I reached out to Alexi Vereschaga (who started AwardWallet back in 2004) about AwardWallet building a direct integration with loyalty program providers, he explained,
You lost me at “integrating with airlines” ;) This is next to impossible.
Good APIs are hard to make, and industries such as airlines are laggardly when it comes to building IT. If a community of businesses with loyalty programs did manage to define a new standard API specification, it could easily become “just another standard” that gets outdated quickly.

I only hope that the businesses running loyalty programs are considering the millions of reasons for and against publishing standard APIs. In any event, I’ll leave this suggestion out there in hopes that one day my rewards can integrate with my trackers in a more modern way.

