# Clearstream > Clearstream Banking S.A. is the Deutsche Börse Group post-trade infrastructure business: > settlement, custody, collateral management and fund order routing for international > securities. Its programmable surface has two layers. The layer almost everyone means by > "the Clearstream API" is regulated post-trade messaging — ISO 15022 MT and ISO 20022 MX over > SWIFTNet FIN and FileAct, plus MQ host-to-host into the German CSD — published as message > specifications to SWIFT MyStandards. The newer layer is a genuine REST platform at > api.clearstream.com, running OAuth 2.0 over mandatory mutual TLS, whose first published API > is SCIM 2.0 user management for the Xact Web Portal. generated: 2026-09-05 method: generated source: Generated by the API Evangelist enrichment pipeline from this repository's apis.yml and artifacts, all of which are sourced from Clearstream's own published pages and live probes. ## What an integrator needs to know first - There is no self-service. API access is granted to an existing Clearstream client's Xact Organisation Unit by sending a SWIFT MT599 message to CEDELULLXXX (attn. PRGConnect) naming the API resources to link. Prospects contact connect@clearstream.com. - Every call — including the token request — requires a mutual-TLS client certificate issued to a named Xact "API Consumer" technical user. The certificate Common Name must match the Xact user id carried in the OAuth token subject. - Certificate pinning is unsupported and Clearstream may rotate server certificates without notice. Trust the DigiCert Global Root G2 chain instead. - The OpenAPI/Swagger definitions exist but are published inside the Deutsche Börse Digital Business Platform catalogue, which requires registration. An anonymous read returns 401. ## API platform - Production base URL: https://api.clearstream.com - Pre-production (UAT / OCCT) base URL: https://api-t2s-test.clearstream.com - OAuth 2.0 token endpoint: /authmanager/oauth2/access_token (grant_type=password, over mutual TLS) - Access tokens are JWTs with expires_in 3599; a refresh token is issued alongside. - Scope string format: the mandatory scope `allow` plus at least one API scope. ### Known scopes and prefixes (disclosed by the platform's own 403 responses) - `allow` — mandatory on every token request. - `ocapi-playground-v1` — /playground — free synthetic Playground API (/playground/v1/info, /playground/v1/echo?value=...). The recommended first integration. - `scim2-ext-v1` — /scim2 — Xact Web Portal User Management, SCIM 2.0. Most calls additionally require the Xact SCIM Admin or SCIM Read-Only role. - `cmax-api` — /cmax — CmaX triparty collateral management. ### Error shape Not RFC 9457. Errors are `application/json` of the form `{ "status": 403, "error": "Forbidden", "required_scopes": { "mandatory": "allow", "at_least_one_of": ["ocapi-playground-v1"] }, "message": "..." }`. Scope denials name exactly what to request, which makes a 403 self-remediating. During maintenance the whole host returns a 503 HTML page on every path, including JSON endpoints. ### Not published No rate-limit numbers or headers, no idempotency mechanism, no pagination convention, no request-id header, no deprecation or sunset policy, no SLA, no status dashboard, no SDKs, no MCP server, no A2A agent card, no llms.txt of Clearstream's own, no security.txt on clearstream.com. Verified 2026-09-05 by probing the full named well-known path list (security.txt, openid-configuration, oauth-authorization-server, oauth-protected-resource, api-catalog, ai-plugin, ucp, acp, aauth-resource, apis.json, /apis.json, /apis.yml, agent-card.json, agent.json) across nine hosts: 144 probes, zero documents. The pre-production host answers 200 with the same HTML landing page for every path including a negative-control path that cannot exist, so none of its 200s is a document. ## Connectivity channels (the message layer) - Xact via SWIFT — settlement, custody, asset servicing and reporting over SWIFTNet FIN; ISO 15022 MT today, migrating to ISO 20022 MX under SWIFT CBPR+. https://www.clearstream.com/clearstream-en/res-library/connectivity/xact-via-swift--1276378 - Xact File Transfer — bulk exchange over SWIFTNet FileAct in ISO 15022, ISO 20022, PDF, XML or XLS. https://www.clearstream.com/clearstream-en/res-library/connectivity/xact-file-transfer-1276390 - Xact Web Portal — browser interface to ClearstreamXact, and the place API consumers and their credentials are created. https://www.clearstream.com/clearstream-en/res-library/connectivity/xact-web-portal-1275688 - CASCADE — German CSD settlement platform, reachable via SWIFT and MQ. https://www.clearstream.com/clearstream-en/res-library/connectivity/cascade-via-swift-1277130 - Vestima — investment fund order routing (subscriptions, redemptions, switches, transfers). https://www.clearstream.com/clearstream-en/res-library/connectivity/vestima-1277090 - CmaX — triparty collateral allocation, optimisation, margining and substitution. https://www.clearstream.com/clearstream-en/securities-services/collateral-lending-and-liquidity-solutions - SWIFT MyStandards — where Clearstream publishes its message specifications. https://www.clearstream.com/clearstream-en/res-library/connectivity/swift-mystandards-1277070 ## Key links - Clearstream API services: https://www.clearstream.com/clearstream-en/res-library/connectivity/clearstream-api-services-2916788 - Clearstream API Developer Guide (PDF, August 2025): https://www.clearstream.com/caas/v1/media/2934048/data/3fa3fec668d8dd198e9bed4df879b26b/api-developer-guide.pdf - Clearstream API Platform landing page: https://api.clearstream.com/ - Deutsche Börse Group API Platform catalogue: https://console.developer.deutsche-boerse.com - Deutsche Börse Group API Platform docs: https://docs.developer.deutsche-boerse.com - Connectivity resource library: https://www.clearstream.com/clearstream-en/res-library/connectivity - Operational news (change and incident channel): https://www.clearstream.com/clearstream-en/res-library/operational-news - Releases, Initiatives and Testing (forward change calendar): https://www.clearstream.com/clearstream-en/res-library/releases-and-initiatives - Clearstream Fee Schedule (the company's published price list — for post-trade services, not API calls): https://www.clearstream.com/clearstream-en/res-library/key-documents/clearstream-fee-schedule-1274812 ## Disambiguation This record is Clearstream Banking S.A., clearstream.com, part of Deutsche Börse Group. It is NOT the US church text-messaging company also called Clearstream (clearstream.io), which owns the GitHub organisation github.com/clearstream. Do not attribute that organisation's repositories, packages or APIs to this company.