1:26-cv-00290
Mycard Inc v. Atomic Fi Inc
I. Executive Summary and Procedural Information
- Parties & Counsel:
- Plaintiff: MyCard, Inc. d/b/a Knot (Delaware)
- Defendant: Atomic Fi, Inc. (Delaware)
- Plaintiff's Counsel: Greenberg Traurig, LLP
- Case Identification: MyCard, Inc. v. Atomic Fi, Inc., 1:26-cv-00290, D. Del., 07/10/2026
- Venue Allegations: Venue is alleged to be proper in the District of Delaware because the Defendant, Atomic FI, Inc., is a Delaware corporation and therefore resides in the district.
- Core Dispute: Plaintiff seeks a declaratory judgment that its products do not infringe Defendant's patents related to secure authentication for third-party systems, and that those patents are invalid and unenforceable, alongside claims for trade secret misappropriation and copyright infringement against the Defendant.
- Technical Context: The technology involves financial technology (fintech) platforms that allow a user, within a primary application like a banking app, to securely connect to third-party services like payroll providers to automate tasks such as updating payment information.
- Key Procedural History: The complaint details a contentious history, including a Temporary Restraining Order (TRO) hearing where testimony from Defendant's founder is alleged to be contradicted by subsequently produced evidence. The complaint also references Defendant's prior litigation involving similar trade secret misappropriation allegations by another company, ClickSWITCH Holdings Inc. The current patent dispute arises from pre-suit cease-and-desist letters sent by Defendant to Plaintiff, which established the basis for this declaratory judgment action. Plaintiff alleges the asserted patents are unenforceable due to inequitable conduct, specifically the intentional withholding of Plaintiff's own prior art product from the patent office during prosecution.
Case Timeline
| Date | Event |
|---|---|
| 2022-08 | Plaintiff Knot launches CardSwitcher™ product |
| 2022-09-12 | Defendant Atomic contacts Plaintiff Knot to discuss partnership |
| 2022-12-22 | Defendant Atomic files Provisional Application No. 63/434,824 (priority date for ''118 and ''443 patents) |
| 2023-Late | Defendant Atomic launches TrueAuth product |
| 2023-10-03 | Plaintiff Knot files Provisional Application No. 63/587,667 |
| 2023-12-06 | Defendant Atomic files non-provisional application for '118 patent |
| 2024-10-15 | U.S. Patent No. 12,120,118 issues |
| 2024-11 | Plaintiff Knot launches AccountUpdater™ and MassSwitcher™ |
| 2024-11-04 | Defendant Atomic files non-provisional application for '443 patent |
| 2025-10-14 | U.S. Patent No. 12,445,443 issues |
| 2025-11-06 | Alleged start of source code misappropriation by Atomic |
| 2025-11-11 | Atomic allegedly reproduces Knot's Face ID feature |
| 2025-12-23 | Defendant Atomic sends cease-and-desist letter to Knot |
| 2026-01-13 | Plaintiff Knot responds to Atomic's letter |
| 2026-02-25 | Defendant Atomic sends second letter with claim charts |
| 2026-02-25 | Plaintiff Knot discovers "honeypot" code in Atomic's product |
| 2026-04-02 | TRO hearing held in the case |
| 2026-07-10 | First Amended Complaint filed |
II. Technology and Patent(s)-in-Suit Analysis
U.S. Patent No. 12,120,118 - "Securely Communicating Data Between an Application Associated With an Entity and a Third-Party System"
The '118 Patent issued on October 15, 2024.
The Invention Explained
- Problem Addressed: The patent's background describes the security risks and user friction in prior systems where an "intermediary service" handles a user's login credentials to connect to a third-party system (e.g., a payroll provider) '118 Patent, col. 1:30-51 This approach makes credentials vulnerable to compromise at the intermediary and can trigger repetitive, inconvenient security checks for the user '118 Patent, col. 3:36-44
- The Patented Solution: The invention proposes a method where a primary application (e.g., a bank's app) provides a "webview" that displays the native login page of the third-party system '118 Patent, abstract This allows the user to enter their credentials directly into the third-party system, removing the need for an intermediary to handle them '118 Patent, col. 4:29-39 The system then confirms successful authentication by "analyzing a response page" for "visual page elements" (such as "sign out" text) and, upon confirmation, automates tasks on the user's behalf '118 Patent, col. 6:4-8 '118 Patent, FIG. 7
- Technical Importance: This architecture aims to increase security by minimizing the exposure of sensitive user credentials and to improve the user experience by creating a more seamless, integrated authentication flow within a trusted application.
Key Claims at a Glance
- The complaint identifies independent method claim 14 as being asserted by Atomic Compl. ¶184
- Essential Elements of Claim 14:
- Providing, within an application, a "webview" that displays a "native login page" for a selected third-party system, which removes the need to provide credentials to an intermediary service.
- Determining that a user has been authenticated by "analyzing a response page" displayed in the webview.
- This determination involves finding that the response page includes "one or more visual page elements" indicating authentication.
- In response to this determination, "automating one or more tasks" with the third-party system.
- The complaint does not mention the assertion of any dependent claims.
U.S. Patent No. 12,445,443 - "Securely Communicating Data Between an Application Associated With an Entity and a Third-Party System"
The '443 Patent issued on October 14, 2025.
The Invention Explained
- Problem Addressed: The '443 Patent addresses the same problem as the '118 Patent: the security and usability drawbacks of using an intermediary service to manage credentials for third-party system access '443 Patent, col. 1:26-50
- The Patented Solution: The solution is architecturally similar, using a "webview" for direct authentication '443 Patent, abstract However, the claims of the '443 Patent add a layer of implementation detail. The method is performed by "code associated with a second entity" (the technology provider) that is embedded within the primary application '443 Patent, claim 16 After authentication is determined, this code communicates with a "backend server" which, in turn, determines the correct "parameter" and "request structure" needed to generate and send an API request to automate the desired task '443 Patent, col. 7:4-22 '443 Patent, claim 16
- Technical Importance: This patent describes a more robust and scalable architecture where the logic for post-authentication task automation is managed by a backend server, allowing for more complex and dynamically updatable interactions with third-party systems.
Key Claims at a Glance
- The complaint identifies independent method claim 16 as being asserted by Atomic Compl. ¶191
- Essential Elements of Claim 16:
- Providing, via "code associated with a second entity" in an application, a "webview" displaying a "native login page" for a third-party system.
- "Determining by executing the code" that the user has been authenticated, using "data comprising a response page".
- In response, "automating one or more tasks" by executing code to "communicate with a backend server".
- The backend server "determines a parameter and a request structure" used to generate and send an "application programming interface request" to the third-party system.
- The complaint does not mention the assertion of any dependent claims.
III. The Accused Instrumentality
Product Identification
The accused products are Plaintiff Knot's "CardSwitcher™" product and other products "incorporating relevant authentication technology" Compl. ¶184
Functionality and Market Context
Knot's CardSwitcher™ is a feature, delivered via a Software Development Kit (SDK) integrated into banking applications, that allows an end-user to automatically update their card-on-file payment information across various merchant and subscription service websites Compl. ¶21 Compl. ¶27 The complaint describes Knot as a "clear leader in the market" for these "merchant connectivity" services, which help financial institutions reduce customer churn and increase user spending Compl. ¶20 Compl. ¶25 The complaint includes a screenshot of an Atomic marketing page for a "SKU-Level Data" product, which Knot presents as evidence of Atomic copying its product features Compl. p. 26
IV. Analysis of Infringement Allegations
The complaint seeks a declaratory judgment of non-infringement, and its analysis is based on refuting infringement allegations made by Atomic in pre-suit correspondence Compl. ¶146 The following tables summarize Knot's arguments against those allegations.
'118 Patent Infringement Allegations
| Claim Element (from Independent Claim 14) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| determining that a user has been authenticated by a third-party system using data comprising a page displayed via the provided webview associated with the selected third-party system at least in part by analyzing a response page displayed via the provided webview associated with the selected third-party system and determining that the response page includes one or more visual page elements indicative of the user being authenticated... | Knot's products allegedly determine user authentication by analyzing a response page for visual elements. | ¶186 | col. 6:4-8 |
| in response to a determination that the response page includes the one or more visual page elements indicative of the user being authenticated, automating one or more tasks... | Knot's products allegedly automate tasks after determining authentication. | ¶186 | col. 6:11-16 |
'443 Patent Infringement Allegations
| Claim Element (from Independent Claim 16) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| determining by executing the code associated with the second entity, that the user has been authenticated by the selected third-party system, using data comprising a response page displayed via the provided webview... | Knot's products allegedly determine user authentication by executing code that uses data from a response page. | ¶193 | col. 5:16-24 |
| in response to determining that the data comprising the response page includes data indicative of the user being authenticated, automating one or more tasks... by executing code associated with the second entity to communicate with a backend server that determines a parameter and a request structure... | Knot's products allegedly automate tasks by communicating with a backend server to determine parameters for an API request. | ¶193 | col. 7:4-22 |
- Identified Points of Contention:
- Scope Questions: The central infringement dispute appears to hinge on the scope of the "determining" limitations. The complaint alleges that Atomic's infringement theory relies on Knot's use of "cookie data" to confirm authentication Compl. ¶187 Compl. ¶194 Knot contends that this theory is baseless because Atomic, during the prosecution of the patents, allegedly disclaimed the use of cookie data and distinguished its invention by its reliance on "visual elements" or "a response page displayed" Compl. ¶187 Compl. ¶194 This raises the question of whether the claim terms "analyzing a response page ... [for] visual page elements" ('118 Patent) or "using data comprising a response page" ('443 Patent) can be interpreted to cover non-visual information like cookies in light of this alleged disclaimer.
- Technical Questions: A key factual question will be the specific technical mechanism that Knot's CardSwitcher™ product actually employs to confirm that a user has successfully authenticated with a third-party system. The complaint denies that the accused products perform the claimed steps but does not provide a detailed alternative explanation of its own technology's operation Compl. ¶186 Compl. ¶193
V. Key Claim Terms for Construction
The Term: "analyzing a response page ... and determining that the response page includes one or more visual page elements indicative of the user being authenticated" (from '118 Patent, claim 14).
Context and Importance: The construction of this term is critical. The complaint frames the dispute around whether this language is limited to literal, on-screen visual analysis or if it can be interpreted more broadly to cover other forms of data returned from the server. Practitioners may focus on this term because Knot's non-infringement defense and its prosecution history estoppel argument are directly tied to it Compl. ¶187
Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The specification states that the SDK is configured to "inspect a document object model (DOM) associated with the native login page or other page" and use "visual elements associated with a page and a uniform resource locator (URL)" to determine the state '118 Patent, col. 5:5-12 An argument could be made that analyzing the DOM or URL goes beyond what is strictly "visual" to an end-user.
- Evidence for a Narrower Interpretation: The claim language itself specifies "visual page elements." The specification provides explicit examples of such elements, including "a 'sign out' or other visual text on the page (e.g. 'paycheck linked' in FIG. 7)" '118 Patent, col. 6:5-8 Knot's argument will likely center on this explicit language and the alleged disclaimer of non-visual methods like analyzing cookie data during prosecution Compl. ¶187
The Term: "data comprising a response page" (from '443 Patent, claim 16).
Context and Importance: This term in the continuation patent is arguably broader than the "visual page elements" language in the parent patent. Its construction will determine whether the '443 Patent covers a wider range of authentication-detection methods. Knot's defense hinges on confining this term's scope, again pointing to alleged prosecution history disclaimers Compl. ¶194
Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The phrase itself, "data comprising a response page," does not contain an explicit "visual" limitation. It could plausibly be argued to encompass all data returned by the server to render the page, including the HTML, headers, and associated metadata or cookies.
- Evidence for a Narrower Interpretation: Knot will argue that this term must be interpreted in the context of the entire patent family and its prosecution history. If Atomic distinguished its invention from prior art by focusing on analyzing the displayed page rather than other data channels (like cookies), Knot will argue this limitation must be read narrowly to exclude those disclaimed methods Compl. ¶194 The specification's consistent examples focus on analyzing the displayed page and its contents '443 Patent, col. 5:16-24 '443 Patent, FIG. 7
VI. Other Allegations
The complaint is for declaratory judgment of non-infringement, invalidity, and unenforceability, and also includes affirmative claims for trade secret misappropriation and copyright infringement.
- Trade Secret & Copyright Infringement: The complaint's primary narrative alleges that Atomic engaged in "brazen theft" of Knot's source code Compl. ¶1 The central piece of evidence cited is a 37-character "honeypot" string, a meaningless piece of code Knot inserted into its software that was later found in Atomic's source code Compl. ¶1 Compl. ¶104 Compl. ¶109 A side-by-side comparison of the code from both companies is provided as visual evidence Compl. p. 1 The complaint also alleges Atomic's deceptive use of the "KnotAPI" keyword in sponsored search results to divert customers Compl. ¶99, providing a screenshot of the search results page Compl. p. 23
- Inequitable Conduct: Knot seeks a declaratory judgment that the '118 and '443 patents are unenforceable due to inequitable conduct Compl. Counts VII-VIII The complaint alleges that Atomic and its inventors were aware of Knot's CardSwitcher™ product, which launched in August 2022, well before they filed their provisional application in December 2022 Compl. ¶215 It is alleged that CardSwitcher™ is material prior art and that Atomic intentionally withheld it from the U.S. Patent and Trademark Office with an intent to deceive the examiner Compl. ¶217 Compl. ¶219
VII. Analyst's Conclusion: Key Questions for the Case
- A core issue will be one of claim scope defined by prosecution history: The court must determine whether Atomic, during patent prosecution, disclaimed reliance on non-visual data (such as cookies) to distinguish its invention from the prior art. If such a disclaimer occurred, it may prevent Atomic from asserting that its patent claims now cover Knot's products based on a similar, non-visual technical mechanism.
- A second key question centers on patent enforceability and allegations of bad faith: Knot has put forth detailed allegations, supported by a "honeypot" code discovery, that Atomic misappropriated its trade secrets and engaged in a pattern of copying. The court will have to decide if these broader allegations of misconduct support Knot's claim that Atomic's inventors also acted with an intent to deceive the patent office by withholding material prior art, which could render the patents unenforceable for inequitable conduct.
- Finally, a central evidentiary question will be one of technical operation versus claim scope: Assuming the patents survive validity and enforceability challenges, the infringement analysis will depend on discovery into the precise technical method Knot's CardSwitcher™ product uses to confirm user authentication. The outcome will depend on whether that method falls within the court's final construction of the patent claims.