openapi: 3.0.1 info: title: Flinks Authorize Enrich API description: Representative specification of the Flinks financial data API. Businesses connect to consumer and business bank accounts to aggregate account, transaction, and statement data, verify identity, and derive income, credit-risk, and fraud analytics. A session is opened with the multi-step /Authorize (MFA) endpoint using a LoginId returned by Flinks Connect; the resulting RequestId is passed to subsequent data, enrichment, and analytics endpoints. All calls are authenticated with a short-lived authorize token supplied in the flinks-auth-key header. termsOfService: https://flinks.com/terms-of-service/ contact: name: Flinks Support url: https://help.flinks.com/ version: '3.0' servers: - url: https://{instance}-api.private.fin.ag/v3/{customerId}/BankingServices description: Flinks per-customer instance host. variables: instance: default: toolbox description: Assigned instance / environment prefix (e.g. toolbox for sandbox). customerId: default: 00000000-0000-0000-0000-000000000000 description: Your Flinks customer identifier (GUID). security: - flinks_auth_key: [] tags: - name: Enrich paths: /GetCategorization: post: operationId: getCategorization tags: - Enrich summary: Return categorized transactional data. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/RequestIdBody' responses: '200': description: Categorized transactions returned. content: application/json: schema: $ref: '#/components/schemas/CategorizationResponse' components: schemas: Category: type: object properties: Name: type: string Amount: type: number Count: type: integer CategorizationResponse: type: object properties: RequestId: type: string format: uuid Categories: type: array items: $ref: '#/components/schemas/Category' RequestIdBody: type: object properties: RequestId: type: string format: uuid description: RequestId returned by /Authorize. required: - RequestId securitySchemes: flinks_auth_key: type: apiKey in: header name: flinks-auth-key description: Short-lived (30-minute) authorize token obtained from /GenerateAuthorizeToken.