STET (French banking industry)
STET PSD2 API
The French profile. Structurally closer to ISO 20022 than Berlin Group: payment requests carry creditTransferTransaction arrays that map almost one-to-one onto pain.001. HAL-style _links throughout.
Security profile
- Client authentication
- mTLS with a QWAC, plus OAuth2 client_credentials for AISP/PISP registration-level auth.
- Message signing
- HTTP Signature is mandatory, not optional. Sign (request-target), date, digest and x-request-id with a QSealC; the keyId is the certificate URL.
- Tokens
- OAuth2. client_credentials for PISP payment requests, authorization_code with the AISP scope for account access. Tokens are short-lived and refresh tokens are the norm.
- Certificates
- QWAC + QSealC. France also expects the certificate to be reachable at the keyId URL.
SCA approaches
RedirectDecoupled
What bites integrators
- The confirmation POST is a distinct call. A 201 on /payment-requests means "accepted for authorisation", not "sent".
- HTTP Signature covers the digest of the body. Any middleware that re-serialises JSON — a pretty-printer, a proxy — breaks the signature.
- psuAuthenticationFactor is only present in the decoupled/embedded variants; in redirect mode it must be absent.
- Amounts are strings with a dot separator. Sending a JSON number is a spec violation that some ASPSPs silently round.
APIs and endpoints
Account Information
AISPTrusted-beneficiary and account-identification endpoints alongside the usual balances and transactions.
- GET
/v1/accountsList accounts covered by the consent - GET
/v1/accounts/{resourceId}/balancesRead balances - GET
/v1/accounts/{resourceId}/transactionsRead transactions - POST
/v1/consentsPush the PSU consent record to the ASPSP - GET
/v1/trusted-beneficiariesRead whitelisted beneficiaries - GET
/v1/end-user-identityRead PSU identity
Payment Request
PISPA payment request is a single resource containing the whole instruction set. Confirmation is a separate POST after SCA — forget it and the payment never leaves.
- POST
/v1/payment-requestsCreate a payment request - GET
/v1/payment-requests/{paymentRequestResourceId}Read a payment request - POST
/v1/payment-requests/{paymentRequestResourceId}/confirmationConfirm after SCA — the step everyone forgets
Funds Coverage
CBPIIFunds coverage check for card-based instruments.
- POST
/v1/funds-confirmationsCheck funds coverage