Open Banking Limited
Open Banking Read/Write API
The most prescriptive of the three, and the only one with a conformance certification programme. Everything is consent-then-resource, with FAPI-grade security and detached JWS signatures on write calls.
Security profile
- Client authentication
- FAPI 2.0: mTLS or private_key_jwt, with PAR and PKCE. Software statements come from the OB Directory.
- Message signing
- Detached JWS in x-jws-signature on all write endpoints, signed with the signing key from the Directory.
- Tokens
- OAuth2 / OIDC with intent-bound consent. The consent id travels in the openbanking_intent_id claim of a signed request object.
- Certificates
- OBWAC / OBSeal issued by the Open Banking Directory, not eIDAS.
SCA approaches
RedirectApp-to-app redirectDecoupled (CIBA)
What bites integrators
- The consent body and the payment body must match field for field. A single differing character yields a 400 with a rules-violation code.
- x-idempotency-key is mandatory on POST and scoped to 24 hours. Reusing it with a different body is a 400, not a replay.
- x-fapi-interaction-id is your trace id and must be echoed. Generate a UUID per call.
- Risk.PaymentContextCode drives fraud scoring and, for some banks, limits. EcommerceGoods and BillPayment behave differently.
APIs and endpoints
Account and Transaction API
AISPThe broadest data surface of any standard: statements, standing orders, direct debits, parties, offers.
- POST
/account-access-consentsCreate an account access consent - GET
/accountsList accounts - GET
/accounts/{AccountId}/transactionsRead transactions - GET
/accounts/{AccountId}/standing-ordersRead standing orders - GET
/accounts/{AccountId}/direct-debitsRead direct debits - GET
/accounts/{AccountId}/statementsRead statements
Payment Initiation API
PISPDomestic, international, scheduled and file payments. Consent and payment are separate resources with matching risk blocks.
- POST
/domestic-payment-consentsCreate a domestic payment consent - GET
/domestic-payment-consents/{ConsentId}/funds-confirmationConfirm funds before submission - POST
/domestic-paymentsSubmit the payment - GET
/domestic-payments/{DomesticPaymentId}Read payment status - POST
/international-paymentsSubmit an international payment - POST
/file-paymentsSubmit a file payment (pain.001 upload)
Variable Recurring Payments
PISPSweeping and commercial VRP. One SCA authorises a mandate with limits; subsequent payments need none.
- POST
/domestic-vrp-consentsCreate a VRP consent with control parameters - POST
/domestic-vrpsExecute a payment under the mandate - GET
/domestic-vrps/{DomesticVRPId}Read VRP payment status