How Open Collective is changing maintainer payment verification
Open Collective is replacing loose payment entry with account-based verification: maintainers now prove ownership through provider flows, KYC only where required, and host-side security checks for payout review.
If you want to ask a follow-up rather than read one: Join a community
How is Open Collective changing maintainer payment verification
Open Collective is moving maintainer payment verification away from simple self-reported payment details and toward proof of account ownership. The change is not one single rule, but a set of checks: identity verification when required, provider-backed payout verification, and host review signals that flag risky or mismatched payments.
The clearest change is for PayPal payouts. Maintainers and other payees who choose PayPal must now connect their PayPal account through PayPal’s authorization flow instead of just typing an email address. Open Collective then receives the verified name and email directly from PayPal, and old saved PayPal email entries are treated as unverified until they are reconnected.
That matters because the old flow had two weak points. A typed email did not prove ownership of the payout account, and a one-character typo could send money to the wrong place or fail the payment entirely. Open Collective says the new OAuth-based flow addresses both problems, which is why the platform now shows verified and unverified states for PayPal payout methods.
The part people get wrong is thinking this is a blanket KYC rollout for every maintainer payment. It is not. Open Collective says it began verifying identity only in specific cases, such as when it cannot verify that the requester owns the account, when a payment involves a sanctioned nation, or when a payment provider demands extra verification. It also says those checks applied to only a small fraction of payments.
That narrower scope is important for maintainers who are paid through different rails. Open Collective says PayPal has its own verification program, and it plans to use that for people who cannot be paid by bank transfer. In other words, verification is being pushed down into the payment path itself, instead of being handled as a single manual approval step for every person.
Open Collective is also changing what fiscal hosts see during payment review. Its security checks now surface payer and payee signals in the expense workflow, including whether a PayPal payout method is verified, unverified, or has a name mismatch. These checks are presented as guidance for hosts, not as hard blocks, so a red warning can still be processed if the host decides to continue.
That is the inconvenient part. Verification does not remove judgment from the process, it moves judgment earlier and makes it more visible. If a maintainer reconnects an old PayPal address, the account can become verified again. If they do not, the host sees an unverified badge and can ask for an updated payout method before paying.
Open Collective is also trying to reduce risk from data handling. In its March 2026 update on KYC checks, OSC said it did not store identity documents, stored only pass or fail results, and used Persona only for the specific verification cases it had identified. It then halted Persona use while it looked for alternative verification arrangements.
For maintainers, the practical effect is simple. If your payout method is still an old saved PayPal email, expect a reconnect step. If a host sees an identity mismatch or an unverified payout method, payment can pause while the maintainer updates the account. If the payout goes through bank transfer instead, the verification path may be different, because Open Collective’s check depends on the payment provider and the host’s process.
The part that is easy to miss is that Open Collective is not claiming every payment needs the same level of identity proof. It is building a layered system: provider verification where available, KYC where necessary, and security checks for hosts to review before approving payment. That is a different model from a one-time badge or a universal identity screen.
If you are managing a collective, the step you actually take is to review saved payout methods, reconnect legacy PayPal entries, and watch for unverified or name-mismatch warnings before approval. If you are a maintainer, the step is to use the provider’s own authorization flow instead of relying on an old email-only payout profile. That is where the verification now happens.
DevConnect is not the source of this change, but if you are trying to keep testing and payout work organized around real ownership, its model is similar in spirit: the work stays on accounts and projects you control, not on borrowed trust. The platform itself describes that approach in its own materials.
For readers who need the shortest version, the answer is this: Open Collective is making maintainer payment verification more account-based and provider-based, with stricter checks for PayPal payouts and selective KYC when the payment path requires it. It is not a universal identity lock on every maintainer payment, and unverified legacy payout methods are the main thing that can still trip people up.
FAQ
Does every maintainer need to complete KYC now No. Open Collective says it uses identity verification only in specific cases, such as account ownership uncertainty, sanctioned-country payments, or when a payment provider requires it.
What happens to old PayPal payout methods They are marked unverified until the payee reconnects the account through PayPal’s authorization flow. Hosts then see the verified or unverified status in the expense workflow.
Can a host still pay an expense with a red security check Yes. Open Collective says its security checks are guidance for fiscal hosts, not conclusive blocks. Hosts can still proceed after reviewing the warning.
Why did Open Collective stop using Persona OSC said it paused Persona while it looks for alternative identity verification arrangements, after using it for a limited set of KYC checks.
Does this change affect non-PayPal payouts too Open Collective says the new PayPal account verification specifically affects PayPal payout methods, while KYC and other checks apply only when the payment path or provider calls for them.
Frequently asked questions
Does every maintainer need to complete KYC now
No. Open Collective says it uses identity verification only in specific cases, such as account ownership uncertainty, sanctioned-country payments, or when a payment provider requires it.
What happens to old PayPal payout methods
They are marked unverified until the payee reconnects the account through PayPal’s authorization flow. Hosts then see the verified or unverified status in the expense workflow.
Can a host still pay an expense with a red security check
Yes. Open Collective says its security checks are guidance for fiscal hosts, not conclusive blocks. Hosts can still proceed after reviewing the warning.
Why did Open Collective stop using Persona
OSC said it paused Persona while it looks for alternative identity verification arrangements, after using it for a limited set of KYC checks.
Does this change affect non-PayPal payouts too
Open Collective says the new PayPal account verification specifically affects PayPal payout methods, while KYC and other checks apply only when the payment path or provider calls for them.
Know someone stuck on this? Send them the answer.
Sources
Every link here was fetched and confirmed to resolve before this page went live.
- On KYC checks and Persona - Open Collective
- PayPal Account Verification for Expense Payouts - Open Collective
- Verification | Open Collective Docs
- Understanding Security Checks | Open Collective Docs
- Open Source Collective - Open Collective updates
Related questions
- Are AI coding agents changing PR review?
- Do new personal Google Play accounts need device verification?
- Do new Google Play Console accounts still need device verification?
Not the question you had?
Ask it. Every source gets fetched and checked before anything goes up, so it takes a day or two, and questions that cannot be answered honestly do not get a page at all.
Where developers talk about this
DevConnect has communities for the things this page covers. Smaller than the big forums, and nobody is farming engagement.