generated: '2026-07-20' method: derived source: openapi/gateway-bank-cds-banking-products-openapi.yml (x-scopes extensions) docs: https://consumerdatastandardsaustralia.github.io/standards/#authorisation-scopes note: Scopes are the standard CDR banking authorisation scopes carried on the CDS operations via the x-scopes extension (the DSB spec does not declare OpenAPI securitySchemes; it expresses authorisation via x-scopes). They apply only to the authenticated consumer-data surface; the public PRD endpoints require no scope. schemes: - name: CDR-security-profile type: openIdConnect profile: FAPI 2.0 (CDR) flows: - flow: authorizationCode scopes: - scope: bank:accounts.basic:read description: Read basic account information (account list and basic detail). operations: [listBankingAccounts, listBankingBalancesBulk, listBankingBalancesSpecificAccounts, getBankingBalance] - scope: bank:accounts.detail:read description: Read detailed account information. operations: [getBankingAccountDetail] - scope: bank:transactions:read description: Read account transactions. operations: [listBankingTransactions, getBankingTransactionDetail] - scope: bank:payees:read description: Read saved payees. operations: [listBankingPayees, getBankingPayeeDetail] - scope: bank:regular_payments:read description: Read direct debits and scheduled/regular payments. operations: [listDirectDebits, listDirectDebitsBulk, listDirectDebitsSpecificAccounts, listScheduledPayments, listScheduledPaymentsBulk, listScheduledPaymentsSpecificAccounts]