Payment initiation

NextGenPSD2 XS2A Framework

SEPA credit transfer with decoupled SCA

A single SEPA payment initiated by a PISP, authorised in the bank app rather than a browser redirect. The status endpoint is the only source of truth.

Why read this

Decoupled SCA is growing because it survives mobile browsers. The cost is polling and a much longer worst-case wait.

Try in live showcase

Technical view of SEPA Credit Transfer, PISP A2A

Messages · pacs.008

pissepadecoupledberlin group

Transaction flow

PSUUserTPPProviderASPSPBankSCAAuthCSMClearing01 Initiate the payment01 POST02 Start the authorisation02 POST03 Select the SCA method03 PUT04 Push challenge to the bank app0405 Poll the transaction status05 GET06 pacs.008 into clearing06 pacs.008
PSU: UserTPP: ProviderASPSP: BankSCA: AuthCSM: Clearing
API hop Clearing hopClick a tag on an arrow (pacs.008, …) for info, usage and sample
Messages
01

Initiate the payment

API layer

POST/v1/payments/sepa-credit-transfers→ 201

TPP-Explicit-Authorisation-Preferred=true asks for a separate authorisation sub-resource, which you want if you plan to offer SCA method selection.

Headers that matter

X-Request-IDPSU-IDTPP-Explicit-Authorisation-Preferred

Codes you can see here

tppaspsp

API payload· XML

SEPA credit transfer initiation

The sepa-credit-transfers product. instructedAmount.amount is a string — sending a JSON number is a spec violation even though many sandboxes accept it.

<payload>
<instructedAmount>
<currency>EUR</currency>
<amount>1250.00</amount>
</instructedAmount>
<debtorAccount>
<iban>FR7630006000011234567890189</iban>
</debtorAccount>
<creditorName>Atelier Rousseau SARL</creditorName>
<creditorAccount>
<iban>DE89370400440532013000</iban>
</creditorAccount>
<creditorAgent>COBADEFFXXX</creditorAgent>
<remittanceInformationUnstructured>Facture 2026-0842</remittanceInformationUnstructured>
<requestedExecutionDate>2026-08-13</requestedExecutionDate>
</payload>
12 elementsdepth 2574 charsxml

Try it

Mock ASPSP

Substitute your own ids in the path — the mock resolves any UUID-shaped consentId and advances the SCA state machine on each call, so polling behaves the way a real ASPSP does.