About this tool
Checklist of which phone permissions a banking app genuinely needs, which are optional, and which are red flags to revoke.
The Banking App Permission Audit checks a bank, wallet or lending app against the permissions it genuinely needs: transaction notifications, biometric unlock, camera for QR or KYC, microphone for a one-off video call, and foreground location for branch or ATM search. It flags high-risk requests such as SMS, call logs, accessibility service, display-over-other-apps, notification access and installed-app inventory because those grants expose OTPs, contacts, screen contents or device fingerprints that a banking app should not need for day-to-day use.
Open Banking App Permission Audit on AltFTool — it loads instantly in your browser.
Add your input to the workspace.
Adjust the options until the result looks right.
Copy or download the output and put it to work.
Transaction alerts and biometric unlock are treated differently from one-off KYC camera or microphone access.
Accessibility, overlays, notification access and SMS are elevated because they are common in banking trojan playbooks.
Each permission explains the feature you lose if you revoke it and the safer alternative where one exists.
No. Android's SMS Retriever and SMS User Consent APIs can pass one matching OTP to an app without giving it READ_SMS access to every message. Manual copy-paste is also safer than full inbox access.
Treat it as a red flag. Accessibility services can read screen contents and tap on your behalf, which is why device-takeover malware asks for it. A normal bank login or payment flow should not need it.
Keep camera only if you regularly scan QR codes or cheques. If it was granted for a one-time video KYC flow, revoke it afterwards and grant again only when needed.