generated: '2026-07-20' method: derived source: openapi/bendigo-and-adelaide-bank-cds-banking-products-openapi.yml docs: https://consumerdatastandardsaustralia.github.io/standards/#http-headers notes: >- Cross-cutting request/response semantics for the CDR Banking API surface, derived from the OpenAPI and the Australian Consumer Data Standards. Standardised by the DSB, so these apply uniformly across all CDR data holders (Bendigo/Adelaide/Up), not just this provider. authentication: public_prd: none (unauthenticated Product Reference Data) data_sharing: FAPI 1.0 Advanced (OIDC + OAuth2 authorization_code, PAR, MTLS-bound tokens) see: authentication/bendigo-and-adelaide-bank-authentication.yml versioning: scheme: header-negotiated request_headers: [x-v, x-min-v] response_header: x-v detail: >- Clients send x-v (required, positive integer) and optional x-min-v; the server responds with the highest supported version in [x-min-v, x-v] and echoes it in the x-v response header. Unsupported versions return 406 (urn:au-cds:error:cds:header:unsupported-version). see: lifecycle/bendigo-and-adelaide-bank-lifecycle.yml request_tracing: header: x-fapi-interaction-id detail: RFC 4122 UUID correlation id; echoed in the response, or generated by the holder if absent. pagination: style: offset request_params: [page, page-size] defaults: {page: 1, page-size: 25, max_page_size: 1000} response_fields: meta: [totalRecords, totalPages] links: [self, first, prev, next, last] errors: [400 invalid-page-size, 422 invalid-page] filtering: list_products: [effective, updated-since, brand, product-category] idempotency: supported: false detail: >- The public PRD surface is read-only (GET only), so no idempotency-key contract applies. Write operations exist only on the authenticated CDR data-sharing surface and are governed by the Consumer Data Standards. error_envelope: media_type: application/json schema: ResponseErrorListV2 (errors[] with URN code/title/detail/meta) see: errors/bendigo-and-adelaide-bank-problem-types.yml rate_limiting: detail: >- CDR traffic-thresholds are defined by the Consumer Data Standards (non-functional requirements) rather than per-holder headers; no custom rate-limit headers declared in the spec.