openapi: 3.2.0
info:
title: Account and Transactions Parties API
description: To retrieve account information for Barclays customers
termsOfService: https://www.openbanking.org.uk/terms
contact:
name: Service Desk
url: https://www.openbanking.org.uk
email: ServiceDesk@openbanking.org.uk
license:
name: open-licence
url: https://www.openbanking.org.uk/open-licence
version: v4.0
tags:
- name: Parties
description: Get Parties
paths:
/party:
summary: Get Parties
description: Get Parties
get:
tags:
- Parties
summary: Get Party
description: Retrieve details about the party that gave permission to the AISP to view an account(s).
operationId: GetParty
parameters:
- $ref: '#/components/parameters/x-fapi-auth-date'
- $ref: '#/components/parameters/x-fapi-customer-ip-address'
- $ref: '#/components/parameters/x-fapi-interaction-id'
- $ref: '#/components/parameters/Authorization'
- $ref: '#/components/parameters/x-customer-user-agent'
responses:
'500':
$ref: '#/components/responses/500Error'
'405':
$ref: '#/components/responses/405Error'
deprecated: false
/accounts/{accountId}/parties:
summary: Get Parties
description: Get Parties
get:
tags:
- Parties
summary: Get Parties for an AccountId
description: Enables an AISP to retrieve details about the PSU account-holder(s)/operator(s).
operationId: GetAccountsAccountIdParties
parameters:
- $ref: '#/components/parameters/AccountId'
- $ref: '#/components/parameters/x-fapi-auth-date'
- $ref: '#/components/parameters/x-fapi-customer-ip-address'
- $ref: '#/components/parameters/x-fapi-interaction-id'
- $ref: '#/components/parameters/Authorization'
- $ref: '#/components/parameters/x-customer-user-agent'
responses:
'200':
$ref: '#/components/responses/200AccountsAccountIdPartiesRead'
'400':
$ref: '#/components/responses/400Error'
'401':
$ref: '#/components/responses/401Error'
'500':
$ref: '#/components/responses/500Error'
'403':
$ref: '#/components/responses/403Error'
'404':
$ref: '#/components/responses/404Error'
'405':
$ref: '#/components/responses/405Error'
'406':
$ref: '#/components/responses/406Error'
'429':
$ref: '#/components/responses/429Error'
deprecated: false
/accounts/{accountId}/party:
summary: Get Parties
description: Get Parties
get:
tags:
- Parties
summary: Get Party for an AccountId
description: Enables an AISP to retrieve details about the party that gave permission to the AISP to view a specific PSU account.
operationId: GetAccountsAccountIdParty
parameters:
- $ref: '#/components/parameters/AccountId'
- $ref: '#/components/parameters/x-fapi-auth-date'
- $ref: '#/components/parameters/x-fapi-customer-ip-address'
- $ref: '#/components/parameters/x-fapi-interaction-id'
- $ref: '#/components/parameters/Authorization'
- $ref: '#/components/parameters/x-customer-user-agent'
responses:
'500':
$ref: '#/components/responses/500Error'
'405':
$ref: '#/components/responses/405Error'
deprecated: false
components:
schemas:
Meta:
type: object
additionalProperties: false
description: Meta Data relevant to the payload
properties:
TotalPages:
type: integer
format: int32
example: 42
maximum: 999999
minimum: 0
FirstAvailableDateTime:
$ref: '#/components/schemas/ISODateTime'
LastAvailableDateTime:
$ref: '#/components/schemas/ISODateTime'
title: MetaData
UnitNumber:
type: string
description: Number that identifies the unit of a specific address .
example: A88
maxLength: 16
minLength: 1
Links:
type: object
additionalProperties: false
description: Links relevant to the payload
properties:
Self:
type: string
format: uri
First:
type: string
format: uri
Prev:
type: string
format: uri
Next:
type: string
format: uri
Last:
type: string
format: uri
required:
- Self
OBErrorResponse1:
type: object
additionalProperties: false
deprecated: false
description: An array of detail error codes, and messages, and URLs to documentation to help remediation.
properties:
Id:
type: string
description: A unique reference for the error instance, for audit purposes, in case of unknown/unclassified errors.
maxLength: 40
minLength: 1
Code:
type: string
description: Deprecated
High level textual error code, to help categorise the errors.
example: 400 BadRequest
maxLength: 40
minLength: 1
Message:
type: string
description: Deprecated
Brief Error message
example: There is something wrong with the request parameters provided
maxLength: 500
minLength: 1
Errors:
type: array
items:
$ref: '#/components/schemas/OBError1'
maxItems: 99999
minItems: 1
required:
- Errors
nullable: false
OBPostalAddress7:
type: object
description: Information that locates and identifies a specific address, as defined by postal services.
properties:
AddressType:
$ref: '#/components/schemas/OBAddressType2Code'
Department:
type: string
description: Identification of a division of a large organisation or building.
example: Finance
maxLength: 70
minLength: 1
SubDepartment:
type: string
description: Identification of a sub-division of a large organisation or building.
example: Payroll
maxLength: 70
minLength: 1
StreetName:
$ref: '#/components/schemas/StreetName'
BuildingNumber:
$ref: '#/components/schemas/BuildingNumber'
BuildingName:
$ref: '#/components/schemas/BuildingName'
Floor:
$ref: '#/components/schemas/Floor'
UnitNumber:
$ref: '#/components/schemas/UnitNumber'
Room:
$ref: '#/components/schemas/Room'
PostBox:
$ref: '#/components/schemas/PostBox'
TownLocationName:
$ref: '#/components/schemas/TownName'
DistrictName:
$ref: '#/components/schemas/DistrictName'
CareOf:
$ref: '#/components/schemas/CareOf'
PostCode:
$ref: '#/components/schemas/PostCode'
TownName:
$ref: '#/components/schemas/TownName'
CountrySubDivision:
type: string
description: Identifies a subdivision of a country such as state, region, county.
maxLength: 35
minLength: 1
Country:
type: string
description: Nation with its own government.
pattern: ^[A-Z]{2,2}$
AddressLine:
type: array
items:
type: string
description: Information that locates and identifies a specific address, as defined by postal services, presented in free format text.
maxLength: 70
minLength: 1
maxItems: 7
minItems: 0
BuildingName:
type: string
description: Name of a referenced building.
maxLength: 140
minLength: 1
ISODateTime:
type: string
format: date-time
description: "All dates in the JSON payloads are represented in ISO 8601 date-time format. \nAll date-time fields in responses must include the timezone. An example is below:\n2017-04-05T10:43:07+00:00"
OBAddressType2Code:
type: string
description: Identifies the nature of the postal address.
For a full set of codes see `OBAddressType2Code` in *OB_Internal_CodeSet* [here](https://github.com/OpenBankingUK/External_Internal_CodeSets).
enum:
- BIZZ
- DLVY
- MLTO
- PBOX
- ADDR
- HOME
- CORR
- STAT
example: BIZZ
PartyId:
type: string
description: A unique and immutable identifier used to identify the customer resource. This identifier has no meaning to the account owner.
example: PXSIF023
maxLength: 40
minLength: 1
PartyNumber:
type: string
description: Number assigned by an agent to identify its customer.
example: '20202002'
maxLength: 35
minLength: 1
BuildingNumber:
type: string
description: Number that identifies the position of a building on a street.
example: '11'
maxLength: 16
minLength: 1
OBParty2:
type: object
additionalProperties: false
properties:
PartyId:
$ref: '#/components/schemas/PartyId'
PartyNumber:
$ref: '#/components/schemas/PartyNumber'
PartyType:
$ref: '#/components/schemas/OBInternalPartyType1Code'
Name:
$ref: '#/components/schemas/Name_3'
FullLegalName:
$ref: '#/components/schemas/FullLegalName'
LegalStructure:
$ref: '#/components/schemas/OBInternalLegalStructureType1Code'
LEI:
$ref: '#/components/schemas/LEI'
BeneficialOwnership:
type: boolean
description: A flag to indicate a party's beneficial ownership of the related account
AccountRole:
$ref: '#/components/schemas/OBInternalAccountRole1Code'
EmailAddress:
$ref: '#/components/schemas/EmailAddress'
Phone:
$ref: '#/components/schemas/PhoneNumber_0'
Mobile:
$ref: '#/components/schemas/PhoneNumber_1'
Relationships:
$ref: '#/components/schemas/OBPartyRelationships1'
Address:
type: array
items:
$ref: '#/components/schemas/OBPostalAddress7'
maxItems: 99999
minItems: 0
required:
- PartyId
Room:
type: string
description: Information that locates and identifies a room to form part of an address
example: Basement 03
maxLength: 70
minLength: 1
StreetName:
type: string
description: Name of a street or thoroughfare.
example: Bank Street
maxLength: 140
minLength: 1
LEI:
type: string
description: Legal entity identification as an alternate identification for a party. Legal Entity Identifier is a code allocated to a party as described in ISO 17442 "Financial Services - Legal Entity Identifier (LEI)".
example: IZ9Q00LZEVUKWCQY6X15
maxLength: 20
minLength: 1
pattern: ^[A-Z0-9]{18,18}[0-9]{2,2}$
OBPartyRelationships1:
type: object
description: The Party's relationships with other resources.
properties:
Account:
type: object
description: Relationship to the Account resource.
properties:
Related:
type: string
format: uri
description: Absolute URI to the related resource.
example: https://api.alphabank.com/open-banking/v4.0/aisp/accounts/89019
Id:
type: string
description: Unique identification as assigned by the ASPSP to uniquely identify the related resource.
example: '89019'
maxLength: 40
minLength: 1
required:
- Id
- Related
OBInternalPartyType1Code:
type: string
description: Party type, in a coded form. For a full list see `OBInternalPartyType1Code` in *OB_Internal_CodeSet* [here](https://github.com/OpenBankingUK/External_Internal_CodeSets)
enum:
- Delegate
- Joint
- Sole
example: Joint
OBInternalLegalStructureType1Code:
type: string
description: Legal standing of the party. For a full list refer to `OBInternalLegalStructureType1Code` in *OB_Internal_CodeSet* [here](https://github.com/OpenBankingUK/External_Internal_CodeSets)
example: UK.OBIE.Individual
x-namespaced-enum:
- UK.OBIE.CIC
- UK.OBIE.CIO
- UK.OBIE.Charity
- UK.OBIE.CoOp
- UK.OBIE.GeneralPartnership
- UK.OBIE.Individual
- UK.OBIE.LimitedLiabilityPartnership
- UK.OBIE.LimitedPartnership
- UK.OBIE.PrivateLimitedCompany
- UK.OBIE.PublicLimitedCompany
- UK.OBIE.ScottishLimitedPartnership
- UK.OBIE.Sole
PhoneNumber_1:
type: string
description: Collection of information that identifies a mobile phone number, as defined by telecom services.
example: +44-7700900000
pattern: \+[0-9]{1,3}-[0-9()+\-]{1,30}
EmailAddress:
type: string
description: Address for electronic mail (e-mail).
example: d.user@semiotec.co.jp
maxLength: 256
minLength: 1
OBExternalStatusReason1Code:
type: string
description: Low level textual error code, for all enum values see `OBExternalStatusReason1Code` in *OB_Internal_CodeSet* [here](https://github.com/OpenBankingUK/External_Internal_CodeSets)
example: U001
maxLength: 4
minLength: 4
TownName:
type: string
description: Name of a built-up area, with defined boundaries, and a local government.
example: London
maxLength: 140
minLength: 1
PostCode:
type: string
description: Identifier consisting of a group of letters and/or numbers that is added to a postal address to assist the sorting of mail.
example: EC2N 4AG
maxLength: 16
minLength: 1
PhoneNumber_0:
type: string
description: Collection of information that identifies a phone number, as defined by telecom services.
example: +44-2079460000
pattern: \+[0-9]{1,3}-[0-9()+\-]{1,30}
Floor:
type: string
description: Number that identifies the level within a building
example: '11'
maxLength: 70
minLength: 1
OBInternalAccountRole1Code:
type: string
description: A party’s role with respect to the related account. For a full list refer to `OBInternalAccountRole1Code` in *OB_Internal_CodeSet* [here](https://github.com/OpenBankingUK/External_Internal_CodeSets)
x-namespaced-enum:
- UK.OBIE.Administrator
- UK.OBIE.Beneficiary
- UK.OBIE.CustodianForMinor
- UK.OBIE.Granter
- UK.OBIE.LegalGuardian
- UK.OBIE.OtherParty
- UK.OBIE.PowerOfAttorney
- UK.OBIE.Principal
- UK.OBIE.Protector
- UK.OBIE.RegisteredShareholderName
- UK.OBIE.SecondaryOwner
- UK.OBIE.SeniorManagingOfficial
- UK.OBIE.Settlor
- UK.OBIE.SuccessorOnDeath
Name_3:
type: string
description: Name by which a party is known and which is usually used to identify that party.
example: Mx Jane Smith
maxLength: 350
minLength: 1
OBError1:
type: object
additionalProperties: false
minProperties: 1
properties:
ErrorCode:
$ref: '#/components/schemas/OBExternalStatusReason1Code'
Message:
type: string
description: 'A description of the error that occurred. e.g., ''A mandatory field isn''t supplied'' or ''RequestedExecutionDateTime must be in future''
OBL doesn''t standardise this field'
maxLength: 500
minLength: 1
Path:
type: string
description: Recommended but optional reference to the JSON Path of the field with error, e.g., Data.Initiation.InstructedAmount.Currency
maxLength: 500
minLength: 1
Url:
type: string
description: URL to help remediate the problem, or provide more information, or to API Reference, or help etc
required:
- ErrorCode
CareOf:
type: string
description: The 'care of' address is used whenever sending mail to a person or organisation who does not actually live or work at the address. They will receive the mail for the individual.
example: Jane Smith
maxLength: 140
minLength: 1
OBReadParty3:
type: object
additionalProperties: false
deprecated: false
properties:
Data:
type: object
properties:
Party:
type: array
items:
$ref: '#/components/schemas/OBParty2'
maxItems: 99999
minItems: 0
Links:
$ref: '#/components/schemas/Links'
Meta:
$ref: '#/components/schemas/Meta'
required:
- Data
nullable: false
PostBox:
type: string
description: Information that locates and identifies a box in a post office assigned to a person or organization, where letters for them are kept until called for.
example: PO Box 123456
maxLength: 16
minLength: 1
FullLegalName:
type: string
description: The full legal name of the party.
example: Jane Smith
maxLength: 350
minLength: 1
DistrictName:
type: string
description: Number that of the regional area, known as a district, which forms part of an address
example: Greater London
maxLength: 140
minLength: 1
parameters:
x-fapi-interaction-id:
name: x-fapi-interaction-id
in: header
description: An RFC4122 UID used as a correlation id.
required: false
schema:
type: string
deprecated: false
maxLength: 36
minLength: 32
pattern: ^[A-Za-f0-9]{8}-?[A-Za-f0-9]{4}-?[1-5][A-Za-f0-9]{3}-?[89ab][A-Za-f0-9]{3}-?[A-Za-f0-9]{12}$
nullable: false
example: 93bac548-d2de-4546-b106-880a5018460d
x-fapi-customer-ip-address:
name: x-fapi-customer-ip-address
in: header
description: The PSU's IP address if the PSU is currently logged in with the TPP.
required: false
schema:
type: string
maxLength: 40
minLength: 7
pattern: ^((?:(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.){3}(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)|(([0-9a-fA-F]{1,4}:){7,7}[0-9a-fA-F]{1,4}|([0-9a-fA-F]{1,4}:){1,7}:|([0-9a-fA-F]{1,4}:){1,6}:[0-9a-fA-F]{1,4}|([0-9a-fA-F]{1,4}:){1,5}(:[0-9a-fA-F]{1,4}){1,2}|([0-9a-fA-F]{1,4}:){1,4}(:[0-9a-fA-F]{1,4}){1,3}|([0-9a-fA-F]{1,4}:){1,3}(:[0-9a-fA-F]{1,4}){1,4}|([0-9a-fA-F]{1,4}:){1,2}(:[0-9a-fA-F]{1,4}){1,5}|[0-9a-fA-F]{1,4}:((:[0-9a-fA-F]{1,4}){1,6})|:((:[0-9a-fA-F]{1,4}){1,7}|:)|fe80:(:[0-9a-fA-F]{0,4}){0,4}%[0-9a-zA-Z]{1,}|::(ffff(:0{1,4}){0,1}:){0,1}((25[0-5]|(2[0-4]|1{0,1}[0-9]){0,1}[0-9])\.){3,3}(25[0-5]|(2[0-4]|1{0,1}[0-9]){0,1}[0-9])|([0-9a-fA-F]{1,4}:){1,4}:((25[0-5]|(2[0-4]|1{0,1}[0-9]){0,1}[0-9])\.){3,3}(25[0-5]|(2[0-4]|1{0,1}[0-9]){0,1}[0-9])))$
nullable: false
example: 104.25.212.99
Authorization:
name: Authorization
in: header
description: An Authorisation Token as per https://tools.ietf.org/html/rfc6750
required: true
schema:
type: string
maxLength: 4871
minLength: 1
pattern: ^Bearer [A-Za-z0-9-_=]{1,256}\.\.[A-Za-z0-9-_=]{1,100}\.[A-Za-z0-9-_=]{1,4096}\.[A-Za-z0-9-_=]{1,100}$
nullable: false
example: Bearer eyJhbGciOiJIUzI1NiJ9.eyJleHAiOjE0OTk4NTA5NjUsInN1YiI6IkJhcmNsYXlzX1BheW1lbnRfU2VydmljZSIsInNjb3BlIjpbImlkcy5tYW5hZ2Vfa2V5IiwiaWRzLm1hbmFnZV9jbGllbnQiXSwiaXNzIjoiaHR0cDovL2lkZW50aXR5LXNlcnZpY2UvIiwiaWF0IjoxNDk5ODUwMDY1fQ.OX-u14YLs7iksl6gnZ9ZqMBu-ekFi4pSva5mzhuf2xU
AccountId:
name: accountId
in: path
description: AccountId
required: true
schema:
type: string
deprecated: false
maxLength: 20
minLength: 1
pattern: ^\d{1,20}$
nullable: false
example: '12345678901234567890'
x-fapi-auth-date:
name: x-fapi-auth-date
in: header
description: "The time when the PSU last logged in with the TPP. \nAll dates in the HTTP headers are represented as RFC 7231 Full Dates. An example is below: \nSun, 10 Sep 2017 19:43:31 UTC"
required: false
schema:
type: string
deprecated: false
maxLength: 29
minLength: 29
pattern: ^(Mon|Tue|Wed|Thu|Fri|Sat|Sun), \d{2} (Jan|Feb|Mar|Apr|May|Jun|Jul|Aug|Sep|Oct|Nov|Dec) \d{4} \d{2}:\d{2}:\d{2} (GMT|UTC)$
nullable: false
example: Sun, 10 Sep 2017 19:43:31 UTC
x-customer-user-agent:
name: x-customer-user-agent
in: header
description: Indicates the user-agent that the PSU is using.
required: false
schema:
type: string
deprecated: false
maxLength: 500
minLength: 1
nullable: false
example: Mozilla/5.0 (iPad; U; CPU OS 3_2_1 like Mac OS X; en-us) AppleWebKit/531.21.10 (KHTML, like Gecko) Mobile/7B405
responses:
406Error:
description: Not Acceptable
headers:
x-fapi-interaction-id:
description: An RFC4122 UID used as a correlation id.
required: true
schema:
type: string
deprecated: false
maxLength: 36
minLength: 32
pattern: ^[A-Za-f0-9]{8}-?[A-Za-f0-9]{4}-?[1-5][A-Za-f0-9]{3}-?[89ab][A-Za-f0-9]{3}-?[A-Za-f0-9]{12}$
nullable: false
example: 93bac548-d2de-4546-b106-880a5018460d
Cache-Control:
description: GIS mandatory response header. This is added by the Cognac sidecar.
schema:
type: string
default: no-cache, no-store, must-revalidate
deprecated: false
maxLength: 35
minLength: 35
pattern: ^no-cache, no-store, must-revalidate$
nullable: false
example: no-cache, no-store, must-revalidate
200AccountsAccountIdPartiesRead:
description: Parties Read
headers:
x-fapi-interaction-id:
description: An RFC4122 UID used as a correlation id.
required: true
schema:
type: string
deprecated: false
maxLength: 36
minLength: 32
pattern: ^[A-Za-f0-9]{8}-?[A-Za-f0-9]{4}-?[1-5][A-Za-f0-9]{3}-?[89ab][A-Za-f0-9]{3}-?[A-Za-f0-9]{12}$
nullable: false
example: 93bac548-d2de-4546-b106-880a5018460d
Cache-Control:
description: GIS mandatory response header. This is added by the Cognac sidecar.
schema:
type: string
default: no-cache, no-store, must-revalidate
deprecated: false
maxLength: 35
minLength: 35
pattern: ^no-cache, no-store, must-revalidate$
nullable: false
example: no-cache, no-store, must-revalidate
content:
application/json:
schema:
$ref: '#/components/schemas/OBReadParty3'
examples:
get-account-parties-response:
value:
Data:
Party:
- PartyId: PABC123
PartyType: Sole
Name: Semiotec
FullLegalName: Semiotec Limited
LegalStructure: UK.OBIE.PrivateLimitedCompany
BeneficialOwnership: true
AccountRole: UK.OBIE.Principal
EmailAddress: contact@semiotec.co.jp
LEI: 068700IA8DVYPS77MD05
Relationships:
Account:
Related: https://api.alphabank.com/open-banking/v4.0/aisp/accounts/22289
Id: '22289'
Phone: +44-2079460000
Mobile: +44-7700900000
Address:
- AddressType: BIZZ
StreetName: Street
BuildingNumber: '15'
PostCode: NW1 1AB
TownName: London
Country: GB
- PartyId: PXSIF023
PartyNumber: '0000007456'
PartyType: Delegate
Name: Kevin Atkinson
FullLegalName: Mr Kevin Bartholmew Atkinson
LegalStructure: UK.OBIE.Individual
BeneficialOwnership: false
LEI: 068700IA8DVHGY77MD85
AccountRole: UK.OBIE.Administrator
EmailAddress: kev@semiotec.co.jp
Relationships:
Account:
Related: https://api.alphabank.com/open-banking/v4.0/aisp/accounts/22289
Id: '22289'
Links:
Self: https://api.alphabank.com/open-banking/v4.0/aisp/accounts/22289/parties
Meta:
TotalPages: 1
403Error:
description: Forbidden
headers:
x-fapi-interaction-id:
description: An RFC4122 UID used as a correlation id.
required: true
schema:
type: string
deprecated: false
maxLength: 36
minLength: 32
pattern: ^[A-Za-f0-9]{8}-?[A-Za-f0-9]{4}-?[1-5][A-Za-f0-9]{3}-?[89ab][A-Za-f0-9]{3}-?[A-Za-f0-9]{12}$
nullable: false
example: 93bac548-d2de-4546-b106-880a5018460d
Cache-Control:
description: GIS mandatory response header. This is added by the Cognac sidecar.
schema:
type: string
default: no-cache, no-store, must-revalidate
deprecated: false
maxLength: 35
minLength: 35
pattern: ^no-cache, no-store, must-revalidate$
nullable: false
example: no-cache, no-store, must-revalidate
content:
application/json:
schema:
$ref: '#/components/schemas/OBErrorResponse1'
examples:
403ErrorResponse:
value:
Code: OB.BadRequest
Id: 2b5f0fb2-730b-11e8-adc0-fa7ae01bbebc
Message: Invalid request parameters
Errors:
- ErrorCode: AC17
Message: Version must be supplied
Path: Data.Initiation
Url:
- ErrorCode: AC17
Message: Version supplied is not valid
Path: Data.Initiation.CreditorAccount
Url:
429Error:
description: Too Many Requests
headers:
Retry-After:
description: Number in seconds to wait
schema:
type: integer
deprecated: false
maximum: 9999999
minimum: 1
nullable: false
example: 120
x-fapi-interaction-id:
description: An RFC4122 UID used as a correlation id.
schema:
type: string
deprecated: false
maxLength: 36
minLength: 32
pattern: ^[A-Za-f0-9]{8}-?[A-Za-f0-9]{4}-?[1-5][A-Za-f0-9]{3}-?[89ab][A-Za-f0-9]{3}-?[A-Za-f0-9]{12}$
nullable: false
example: 93bac548-d2de-4546-b106-880a5018460d
Cache-Control:
description: GIS mandatory response header. This is added by the Cognac sidecar.
schema:
type: string
default: no-cache, no-store, must-revalidate
deprecated: false
maxLength: 35
minLength: 35
pattern: ^no-cache, no-store, must-revalidate$
nullable: false
example: no-cache, no-store, must-revalidate
500Error:
description: Internal Server Error
headers:
x-fapi-interaction-id:
description: An RFC4122 UID used as a correlation id.
required: true
schema:
type: string
deprecated: false
maxLength: 36
minLength: 32
pattern: ^[A-Za-f0-9]{8}-?[A-Za-f0-9]{4}-?[1-5][A-Za-f0-9]{3}-?[89ab][A-Za-f0-9]{3}-?[A-Za-f0-9]{12}$
nullable: false
example: 93bac548-d2de-4546-b106-880a5018460d
Cache-Control:
description: GIS mandatory response header. This is added by the Cognac sidecar.
schema:
type: string
default: no-cache, no-store, must-revalidate
deprecated: false
maxLength: 35
minLength: 35
pattern: ^no-cache, no-store, must-revalidate$
nullable: false
example: no-cache, no-store, must-revalidate
content:
application/json:
schema:
$ref: '#/components/schemas/OBErrorResponse1'
examples:
500ErrorResponse:
value:
Code: OB.BadRequest
Id: 2b5f0fb2-730b-11e8-adc0-fa7ae01bbebc
Message: Invalid request parameters
Errors:
- ErrorCode: AC17
Message: Version must be supplied
Path: Data.Initiation
Url:
- ErrorCode: AC17
Message: Version supplied is not valid
Path: Data.Initiation.CreditorAccount
Url:
400Error:
description: Bad request
headers:
x-fapi-interaction-id:
description: An RFC4122 UID used as a correlation id.
required: true
schema:
type: string
deprecated: false
maxLength: 36
minLength: 32
pattern: ^[A-Za-f0-9]{8}-?[A-Za-f0-9]{4}-?[1-5][A-Za-f0-9]{3}-?[89ab][A-Za-f0-9]{3}-?[A-Za-f0-9]{12}$
nullable: false
example: 93bac548-d2de-4546-b106-880a5018460d
Cache-Control:
description: GIS mandatory response header. This is added by the Cognac sidecar.
schema:
type: string
default: no-cache, no-store, must-revalidate
deprecated: false
maxLength: 35
minLength: 35
pattern: ^no-cache, no-store, must-revalidate$
nullable: false
example: no-cache, no-store, must-revalidate
content:
application/json:
schema:
$ref: '#/components/schemas/OBErrorResponse1'
examples:
400ErrorResponse:
value:
Code: OB.BadRequest
Id: 2b5f0fb2-730b-11e8-adc0-fa7ae01bbebc
Message: Invalid request parameters
Errors:
- ErrorCode: AC17
Message: Version must be supplied
Path: Data.Initiation
Url:
- ErrorCode: AC17
Message: Version supplied is not valid
Path: Data.Initiation.CreditorAccount
Url:
401Error:
description: Unauthorized
headers:
x-fapi-interaction-id:
description: An RFC4122 UID used as a correlation id.
required: true
schema:
type: string
deprecated: false
maxLength: 36
minLength: 32
pattern: ^[A-Za-f0-9]{8}-?[A-Za-f0-9]{4}-?[1-5][A-Za-f0-9]{3}-?[89ab][A-Za-f0-9]{3}-?[A-Za-f0-9]{12}$
nullable: false
example: 93bac548-d2de-4546-b106-880a5018460d
Cache-Control:
description: GIS mandatory response header. This is added by the Cognac sidecar.
schema:
type: string
default: no-cache, no-store, must-revalidate
deprecated: false
maxLength: 35
minLength: 35
pattern: ^no-cache, no-store, must-revalidate$
nullable: false
example: no-cache, no-store, must-revalidate
404Error:
description: Not found
headers:
x-fapi-interaction-id:
description: An RFC4122 UID used as a correlation id.
required: true
schema:
type: string
deprecated: false
maxLength: 36
minLength: 32
pattern: ^[A-Za-f0-9]{8}-?[A-Za-f0-9]{4}-?[1-5][A-Za-f0-9]{3}-?[89ab][A-Za-f0-9]{3}-?[A-Za-f0-9]{12}$
nullable: false
example: 93bac548-d2de-4546-b106-880a5018460d
Cache-Control:
description: GIS mandatory response header. This is added by the Cognac sidecar.
schema:
type: string
default: no-cache, no-store, must-revalidate
deprecated: false
maxLength: 35
minLength: 35
pattern: ^no-cache, no-store, must-revalidate$
nullable: false
example: no-cache, no-store, must-revalidate
405Error:
description: Method Not Allowed
headers:
x-fapi-interaction-id:
description: An RFC4122 UID used as a correlation id.
required: true
schema:
type: string
deprecated: false
maxLength: 36
minLength: 32
pattern: ^[A-Za-f0-9]{8}-?[A-Za-f0-9]{4}-?[1-5][A-Za-f0-9]{3}-?[89ab][A-Za-f0-9]{3}-?[A-Za-f0-9]{12}$
nullable: false
example: 93bac548-d2de-4546-b106-880a5018460d
Cache-Control:
description: GIS mandatory response header. This is added by the Cognac sidecar.
schema:
type: string
default: no-cache, no-store, must-revalidate
deprecated: false
maxLength: 35
minLength: 35
pattern: ^no-cache, no-store, must-revalidate$
nullable: false
example: no-cache, no-store, must-revalidate
securitySchemes:
TPPOAuth2Security:
type: oauth2
description: TPP client credential authorisation flow with the ASPSP
flows:
clientCredentials:
tokenUrl: https://authserver.example/token
scopes:
accounts: Ability to read Accounts information
PSUOAuth2Security:
type: oauth2
description: OAuth flow, it is required when the PSU needs to perform SCA with the ASPSP when a TPP wants to access an ASPSP resource owned by the PSU
flows:
authorizationCode:
authorizationUrl: https://authserver.example/authorization
tokenUrl: https://authserver.example/token
scopes:
accounts: Ability to read Accounts information