# BANCOMAT S.p.A. (incl. FlowPay, a BANCOMAT company) > Italy's domestic payment scheme operator (PagoBancomat debit, ATM network, BANCOMAT Pay) and, since the 2025-07-22 acquisition of FlowPay S.r.l., the publisher of a public open-banking REST API (AIS/PIS, invoicing, pagoPA, webhooks). This file was GENERATED by API Evangelist from the provider's public surface on 2026-09-17; neither bancomat.it nor flowpay.it serves an llms.txt (bancomat.it/llms.txt 404; flowpay.it/llms.txt returns the homepage; docs.flowpay.it/llms.txt 404). The BANCOMAT scheme itself exposes NO public API: issuer, acquirer and certified-operator documentation is distributed only through BANCOMAT Insight (https://insight.bancomat.it, OTP login for scheme members); api.bancomat.it answers every unauthenticated path with a JSON 404. Merchants accept BANCOMAT Pay through PSPs (Nexi, Axerve, PPRO, HiPay, Viva.com, Braintree, Nuvei, Mollie). ## FlowPay API (v1) — production - [API reference (ReDoc)](https://docs.flowpay.it/): 59 operations, OpenAPI 3.0.3, Italian; base https://app.flowpay.it/api; every resource path is prefixed by /{tenantID} - [Developer portal](https://developer.flowpay.it/): register a company account, create an application, get client_id / client_secret (sandbox enabled immediately) - [OpenID Provider metadata](https://core.flowpay.it/api/openid/.well-known/openid-configuration): issuer https://core.flowpay.it/api, authorization_code + client_credentials + refresh_token, PKCE, PAR (/api/oauth/par), ES256/PS256 request objects - Surfaces: AIS consents and accounts (/ais, /{tenantID}/consents, /accounts, /balances, /transactions), banks (/banks), invoices, salaries, transfers, bulk and chain payments, hosted checkout sessions (/{tenantID}/checkout), pagoPA notices (/pagopa), webhooks (/webhooks, /{tenantID}/webhooks) - Webhooks: 14 documented events (invoice/bill/checkout payment authorised and status changes, consent_expiring / consent_expired, checkout_opened/closed/sca_opened/ok/ko, token_revoked), ECDSA P-256 signatures in X-FlowPay-Raw-Signature / X-FlowPay-Der-Signature over ".", 10 s delivery timeout, subscriptions expire after at most 1 month unless renewed ## FlowPay API (v2) — 2.0.0-alpha.4 - [OpenAPI 3.1.0 source](https://github.com/FlowPay/client-openapi) (openapi.json + docs/*.md): base https://api.flowpay.it/v2 (answers; GET /v2/banks is public), mock https://mock.flowpay.it/v2 (502 on 2026-09-17), customer sandbox https://sandbox.{customerID}.flowpay.it/v2 - [General guide](https://github.com/FlowPay/client-openapi/blob/main/docs/general.md): onboarding, sandbox limits, OAuth flows, rate limits (100 requests/minute per source IP, burst 10/s, HTTP 429) - Lifecycle guides: [invoices, proforma, credit notes](https://github.com/FlowPay/client-openapi/blob/main/docs/invoice_lifecycle.md), [bulk payments](https://github.com/FlowPay/client-openapi/blob/main/docs/bulk_lifecycle.md), [payment chains](https://github.com/FlowPay/client-openapi/blob/main/docs/chain_lifecycle.md), [pagoPA](https://github.com/FlowPay/client-openapi/blob/main/docs/pagopa_lifecycle.md), [fees](https://github.com/FlowPay/client-openapi/blob/main/docs/fee_description.md) - operationIds: getBanks, getAccounts, createAisConsentSession, createInvoice, getInvoices, createProformaInvoice, createCreditNote, createCheckout, getCheckout, deleteCheckout, createTransfer, deleteTransfer, createBulkPayment, createChainPayment, pagopaPayment, getPagopaList, getPayments, getTransactions, getFees, getFeeRules, startKyc, createConstructionSite, registerWorkProgress, ... (59 total) - Pagination: page + size (or pageSize/limit) plus from/to date windows on list endpoints; no cursor or totals - Errors: JSON envelope {statusCode, requestID, message, additionalInfo} in the contract; the live host returns {error, correlationId, statusCode, message, additionalData}; no RFC 9457 ## Semantics an agent must know - Idempotency: NONE — no Idempotency-Key header on any write; documents are de-duplicated by content fingerprint (v1 code 2012), payments and checkouts are not - Reversibility: DELETE exists for checkouts (unpaid only), transfers (not yet executed), proforma invoices (unpaid), credit notes, bulk aggregates (linked documents survive) and v1 invoices/salaries; executed SEPA transfers and pagoPA activations cannot be reversed through the API — issue a credit note instead - Dry run: none; use the shared sandbox (issuer https://core.sandbox-new.flowpay.it/api/openid) — payment-status webhooks, bulk and chain payments and onboarding are NOT available there - Regulatory: FlowPay is a Bank of Italy-authorised payment institution (ref. 36925) acting as AISP/PISP under PSD2; AIS consents recur for 90 days - Support: https://youtrack.flowpay.it/ (ticket form), api-support@flowpay.it ## Company - [BANCOMAT S.p.A.](https://bancomat.it/en) — [the company](https://bancomat.it/en/the-company), [how to join the circuits](https://bancomat.it/en/adhere-to-the-circuits), [payment security](https://bancomat.it/en/payment-security), [privacy](https://bancomat.it/en/privacy-policy), [terms](https://bancomat.it/en/terms-and-conditions), [press releases](https://bancomat.it/en/press-releases) - [FlowPay](https://flowpay.it/) — [blog](https://blog.flowpay.it/), [GitHub](https://github.com/FlowPay) (client-openapi, checkout-generator, checkout-generator-cli, FatturaElettronica-Swift) ## Machine-readable artifacts in this profile - openapi/bancomat-flowpay-api-v1-openapi.yml, openapi/bancomat-flowpay-api-v2-openapi.yml (verbatim originals under openapi/_original/) - well-known/bancomat-flowpay-openid-configuration.json, scopes/bancomat-scopes.yml, authentication/bancomat-authentication.yml - conventions/bancomat-conventions.yml, errors/bancomat-problem-types.yml, asyncapi/bancomat-flowpay-webhooks.yml, sandbox/bancomat-sandbox.yml, rate-limits/bancomat-rate-limits.yml, lifecycle/bancomat-lifecycle.yml, conformance/bancomat-conformance.yml, data-model/bancomat-data-model.yml, packages/bancomat-packages.yml, cli/bancomat-cli.yml, mcp/bancomat-mcp.yml (candidate, no server exists), skills/_index.yml