openapi: 3.0.1 info: title: Flinks Authorize API description: Representative specification of the Flinks financial data API. Businesses connect to consumer and business bank accounts to aggregate account, transaction, and statement data, verify identity, and derive income, credit-risk, and fraud analytics. A session is opened with the multi-step /Authorize (MFA) endpoint using a LoginId returned by Flinks Connect; the resulting RequestId is passed to subsequent data, enrichment, and analytics endpoints. All calls are authenticated with a short-lived authorize token supplied in the flinks-auth-key header. termsOfService: https://flinks.com/terms-of-service/ contact: name: Flinks Support url: https://help.flinks.com/ version: '3.0' servers: - url: https://{instance}-api.private.fin.ag/v3/{customerId}/BankingServices description: Flinks per-customer instance host. variables: instance: default: toolbox description: Assigned instance / environment prefix (e.g. toolbox for sandbox). customerId: default: 00000000-0000-0000-0000-000000000000 description: Your Flinks customer identifier (GUID). security: - flinks_auth_key: [] tags: - name: Authorize paths: /GenerateAuthorizeToken: post: operationId: generateAuthorizeToken tags: - Authorize summary: Generate a short-lived authorize token. description: Exchanges your API secret for a 30-minute authorize token that must be supplied in the flinks-auth-key header on all other endpoints. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/GenerateAuthorizeTokenRequest' responses: '200': description: Authorize token generated. content: application/json: schema: $ref: '#/components/schemas/AuthorizeTokenResponse' components: schemas: AuthorizeTokenResponse: type: object properties: AuthorizeToken: type: string ExpiresIn: type: integer description: Token lifetime in seconds (1800). GenerateAuthorizeTokenRequest: type: object properties: secret: type: string description: Your Flinks API secret. required: - secret securitySchemes: flinks_auth_key: type: apiKey in: header name: flinks-auth-key description: Short-lived (30-minute) authorize token obtained from /GenerateAuthorizeToken.