Open Banking Limited

Open Banking Read/Write API

United Kingdomv4.0 (3.1.11 widely deployed)currentPublisher docs ↗

The most prescriptive of the three, and the only one with a conformance certification programme. Everything is consent-then-resource, with FAPI-grade security and detached JWS signatures on write calls.

Security profile

Client authentication
FAPI 2.0: mTLS or private_key_jwt, with PAR and PKCE. Software statements come from the OB Directory.
Message signing
Detached JWS in x-jws-signature on all write endpoints, signed with the signing key from the Directory.
Tokens
OAuth2 / OIDC with intent-bound consent. The consent id travels in the openbanking_intent_id claim of a signed request object.
Certificates
OBWAC / OBSeal issued by the Open Banking Directory, not eIDAS.

SCA approaches

RedirectApp-to-app redirectDecoupled (CIBA)

What bites integrators

  • The consent body and the payment body must match field for field. A single differing character yields a 400 with a rules-violation code.
  • x-idempotency-key is mandatory on POST and scoped to 24 hours. Reusing it with a different body is a 400, not a replay.
  • x-fapi-interaction-id is your trace id and must be echoed. Generate a UUID per call.
  • Risk.PaymentContextCode drives fraud scoring and, for some banks, limits. EcommerceGoods and BillPayment behave differently.

APIs and endpoints

Account and Transaction API

AISP

The broadest data surface of any standard: statements, standing orders, direct debits, parties, offers.

  • POST/account-access-consentsCreate an account access consent
  • GET/accountsList accounts
  • GET/accounts/{AccountId}/transactionsRead transactions
  • GET/accounts/{AccountId}/standing-ordersRead standing orders
  • GET/accounts/{AccountId}/direct-debitsRead direct debits
  • GET/accounts/{AccountId}/statementsRead statements

Payment Initiation API

PISP

Domestic, international, scheduled and file payments. Consent and payment are separate resources with matching risk blocks.

  • POST/domestic-payment-consentsCreate a domestic payment consent
  • GET/domestic-payment-consents/{ConsentId}/funds-confirmationConfirm funds before submission
  • POST/domestic-paymentsSubmit the payment
  • GET/domestic-payments/{DomesticPaymentId}Read payment status
  • POST/international-paymentsSubmit an international payment
  • POST/file-paymentsSubmit a file payment (pain.001 upload)

Variable Recurring Payments

PISP

Sweeping and commercial VRP. One SCA authorises a mandate with limits; subsequent payments need none.

  • POST/domestic-vrp-consentsCreate a VRP consent with control parameters
  • POST/domestic-vrpsExecute a payment under the mandate
  • GET/domestic-vrps/{DomesticVRPId}Read VRP payment status

Flows using this standard

Sample payloads