STET (French banking industry)

STET PSD2 API

France, Belgiumv1.6.3currentPublisher docs ↗

The French profile. Structurally closer to ISO 20022 than Berlin Group: payment requests carry creditTransferTransaction arrays that map almost one-to-one onto pain.001. HAL-style _links throughout.

Security profile

Client authentication
mTLS with a QWAC, plus OAuth2 client_credentials for AISP/PISP registration-level auth.
Message signing
HTTP Signature is mandatory, not optional. Sign (request-target), date, digest and x-request-id with a QSealC; the keyId is the certificate URL.
Tokens
OAuth2. client_credentials for PISP payment requests, authorization_code with the AISP scope for account access. Tokens are short-lived and refresh tokens are the norm.
Certificates
QWAC + QSealC. France also expects the certificate to be reachable at the keyId URL.

SCA approaches

RedirectDecoupled

What bites integrators

  • The confirmation POST is a distinct call. A 201 on /payment-requests means "accepted for authorisation", not "sent".
  • HTTP Signature covers the digest of the body. Any middleware that re-serialises JSON — a pretty-printer, a proxy — breaks the signature.
  • psuAuthenticationFactor is only present in the decoupled/embedded variants; in redirect mode it must be absent.
  • Amounts are strings with a dot separator. Sending a JSON number is a spec violation that some ASPSPs silently round.

APIs and endpoints

Account Information

AISP

Trusted-beneficiary and account-identification endpoints alongside the usual balances and transactions.

  • GET/v1/accountsList accounts covered by the consent
  • GET/v1/accounts/{resourceId}/balancesRead balances
  • GET/v1/accounts/{resourceId}/transactionsRead transactions
  • POST/v1/consentsPush the PSU consent record to the ASPSP
  • GET/v1/trusted-beneficiariesRead whitelisted beneficiaries
  • GET/v1/end-user-identityRead PSU identity

Payment Request

PISP

A payment request is a single resource containing the whole instruction set. Confirmation is a separate POST after SCA — forget it and the payment never leaves.

  • POST/v1/payment-requestsCreate a payment request
  • GET/v1/payment-requests/{paymentRequestResourceId}Read a payment request
  • POST/v1/payment-requests/{paymentRequestResourceId}/confirmationConfirm after SCA — the step everyone forgets

Funds Coverage

CBPII

Funds coverage check for card-based instruments.

  • POST/v1/funds-confirmationsCheck funds coverage

Flows using this standard

Sample payloads