# Connexis Cash > Connexis Cash is BNP Paribas's corporate digital banking and cash management platform for > multinational corporates — payment initiation, real-time payment tracking, account reporting, > reconciliation and liquidity management across the BNP Paribas network. Its public API surface is a > PSD2 Account Information Service (AISP) exposed by BNP Paribas Corporate and Institutional Banking > and aligned to the French STET standard, so that authorised third-party providers can read a > Connexis Cash user's accounts, balances, transactions and trusted beneficiaries on that user's behalf. Generated by API Evangelist (https://apievangelist.com) on 2026-09-05 from the artifacts in https://github.com/api-evangelist/connexis-cash. This is an independent third-party profile. BNP Paribas does not publish an llms.txt — /llms.txt on developers.cib.bnpparibas.com returns 403. ## What you can actually call The published contract has FOUR operations, all read-only GETs, all requiring the `aisp` OAuth2 scope: - accountsGet — GET /v2/accounts — list the PSU accounts made available to the AISP - accountsBalancesGet — GET /v2/accounts/{accountResourceId}/balances — balance report for one account - accountsTransactionsGet — GET /v2/accounts/{accountResourceId}/transactions — booked and pending entries - trustedBeneficiariesGet — GET /v2/trusted-beneficiaries — the PSU's whitelisted beneficiaries There is no write operation. There is no payment initiation on this contract. The STET payment schemas shipped inside the file (PaymentRequestResource and friends) are unreachable components — do not build against them. ## Two environments, and they are not interchangeable - Sandbox: https://api.sandbox.cib.bnpparibas.com/gb-account-information-psd2-stet-mock OAuth2 client_credentials only, token at https://api.sandbox.cib.bnpparibas.com/oauth2/v1/token, simulated data, no client certificate, no PSD2 fallback. - Production: https://psd2.api.cib.bnpparibas.com/gb-account-information-psd2-stet OAuth2 authorization_code, authorize at https://api.cib.bnpparibas.com/oauth2/v1/authorize, token at https://api.cib.bnpparibas.com/oauth2/v1/token, and mutual TLS with an eIDAS QWAC issued by a QTSP. An anonymous request to the production host returns HTTP 400 "No required SSL certificate was sent". client_id must be the organizationIdentifier from the certificate's distinguished name (ETSI TS 119 495 §5.2.1). The sandbox cannot rehearse the production journey: it offers no authorization_code flow, so the consent and Strong Customer Authentication steps are untestable there. ## Specification - OpenAPI 3.0.0, published by the provider: https://developers.cib.bnpparibas.com/index.php/system/files/api-ref-files/2022-02/BNP_CIB_CNX_PSD2_VSTET1.4_OAS3_v.1.4.0.47A3_SANDBOX%20%281%29_0.yaml - API version 2.0.0; standard version STET 1.4.0.47 (info.x-stet-version); consent model Full-AISP ("A1") - Local copy: openapi/connexis-cash-account-information-psd2-stet-mock-openapi.yml ## Documentation - Developer portal: https://developers.cib.bnpparibas.com/ - API reference: https://developers.cib.bnpparibas.com/index.php/api-docs/account-information-psd2-stet-mock - Getting started: https://developers.cib.bnpparibas.com/index.php/docs/get-started - How to consume PSD2 APIs: https://developers.cib.bnpparibas.com/index.php/docs/psd2 - OAuth2 Authorization Code (PSD2): https://developers.cib.bnpparibas.com/index.php/docs/auth2-ac-psd2 - Strong Customer Authentication through Connexis Cash: https://developers.cib.bnpparibas.com/index.php/docs/sca - Calling the APIs programmatically: https://developers.cib.bnpparibas.com/index.php/docs/try-api-prg - PSD2 availability KPI (quarterly PDFs, Q3 2019 – Q1 2024): https://developers.cib.bnpparibas.com/index.php/docs/psd2-kpi - Terms of use: https://developers.cib.bnpparibas.com/index.php/terms-of-use - Sign up: https://developers.cib.bnpparibas.com/index.php/user/register - Product site: https://cashmanagement.bnpparibas.com/solutions/digital-channels ## Conventions you will trip on - X-Request-ID is a REQUIRED request header (max 70 chars). It is echoed back on most responses — but the 401/404/429 branch echoes `x-correlation-id` instead. Read both when tracing a failure. - A `Signature` header (HTTP signature keyed to your qualified certificate) is required on every call; `Digest` is optional. - Responses are HAL. Follow `_links.next` rather than incrementing pageNumber. Note that the example hrefs inside the published spec still say `v1/` while the real paths are `/v2/`. - Transaction filtering is asymmetric: entryDateFrom is INCLUSIVE, entryDateTo is EXCLUSIVE. - accountResourceId is the ASPSP-assigned resourceId, not the IBAN. - Errors are a bespoke envelope (status, message, error, path, timestamp), not RFC 9457 problem+json, and seven of the ten declared error statuses carry no schema at all. - A 429 is declared on every operation, but no rate limit is published and no Retry-After or RateLimit-* header is returned. Back off on your own judgement. ## What does not exist No MCP server. No A2A agent card. No AsyncAPI, webhooks or any event surface. No SDK in any public registry. No CLI. No public Postman collection. No changelog. No live status page. No published rate limits. No published pricing — access is granted through PSD2 TPP onboarding, not a plan. ## Derived artifacts in this profile - authentication/connexis-cash-authentication.yml — OAuth2 schemes and flows - scopes/connexis-cash-scopes.yml — aisp, pisp, piisp - conventions/connexis-cash-conventions.yml — pagination, signing, tracing, idempotency (na — read-only) - errors/connexis-cash-problem-types.yml — the error catalog and its gaps - conformance/connexis-cash-conformance.yml — STET, PSD2, eIDAS, ETSI, ISO 20022, HAL - data-model/connexis-cash-data-model.yml — the entity graph - lifecycle/connexis-cash-lifecycle.yml — versioning, availability reporting, environments - sandbox/connexis-cash-sandbox.yml — how to get in without a certificate - mcp/connexis-cash-mcp.yml — a CANDIDATE tool surface; nobody ships a server - skills/ — packaged agent skills grounded in the four real operationIds