generated: '2026-10-09' method: searched source: openapi/groupe-bpce-natixis-psd2-accounts-openapi.yml, openapi/groupe-bpce-natixis-wealth-management-psd2-accounts-openapi.yml, openapi/groupe-bpce-open-finance-transfer-openapi.yml, openapi/groupe-bpce-psd2-accounts-openapi.yml, openapi/groupe-bpce-psd2-funds-availability-openapi.yml, openapi/groupe-bpce-psd2-payments-openapi.yml, https://apistore.groupebpce.com/api/psd2-registration, https://apistore.groupebpce.com/api/account-information-services-3 summary: types: - mutualTLS - oauth2 oauth2_flows: - authorizationCode - clientCredentials schemes: - name: accessCode type: oauth2 flows: - flow: authorizationCode authorizationUrl: /stet/psd2/oauth/authorize tokenUrl: /stet/psd2/oauth/token scopes: 2 description: 'In order to access the PSU''s account information, the AISP needs to get either an authorization code grant or a Client Initiated Backchannel Authentication token. In order to post a funds confirmation request, the CBPII needs to get either an authorization code grant or a Client Initiated Backchannel Authentication token when registration of the account has not been previously processed. In order ' sources: - openapi/groupe-bpce-natixis-psd2-accounts-openapi.yml - openapi/groupe-bpce-natixis-wealth-management-psd2-accounts-openapi.yml - openapi/groupe-bpce-open-finance-transfer-openapi.yml - openapi/groupe-bpce-psd2-accounts-openapi.yml - openapi/groupe-bpce-psd2-funds-availability-openapi.yml - openapi/groupe-bpce-psd2-payments-openapi.yml - name: clientCredentials type: oauth2 flows: - flow: clientCredentials tokenUrl: /stet/psd2/oauth/token scopes: 1 description: 'In order to post, get or cancel a Payment or Transfer Request, the PISP needs to get a client credential OAUTH2 token. In order to confirm a Payment or Transfer Request, the PISP needs to get either an authorization code grant or a client credential OAUTH2 token. In order to post a funds confirmation request, the CBPII needs to get a client credential OAUTH2 token when registration of the account ' sources: - openapi/groupe-bpce-psd2-funds-availability-openapi.yml - openapi/groupe-bpce-psd2-payments-openapi.yml - name: eidas-mtls type: mutualTLS description: '"Use of same TPP eIDAS certificate (QWAC) to be presented for mutual TLS authentication"; "TPP needs to use a TLS mutual authentication based on QWAC certificate with this POST /token method." Not declared as a securityScheme in the specs.' sources: - https://apistore.groupebpce.com/api/account-information-services-3 - https://apistore.groupebpce.com/api/psd2-registration - name: http-signature-qsealc type: signature description: PSD2 requests carry Signature and Digest headers (STET); the registration jwks must contain the QSEALC public key ("kty" RSA, "alg" RS256, "use" sig). sources: - openapi/groupe-bpce-psd2-payments-openapi.yml - https://apistore.groupebpce.com/api/psd2-registration - name: registration-client-credentials type: oauth2 flows: - flow: clientCredentials tokenUrl: https://www..live.api.89C3.com/stet/psd2/oauth/token description: 'Registration API: generic client_id “PSD2_TPPRegister”, grant_type client_credentials, scope manageRegistration; returns a temporary access token; POST /register returns the client_id used in all PSD2 methods.' sources: - https://apistore.groupebpce.com/api/psd2-registration docs: https://apistore.groupebpce.com/api/psd2-registration client_id_rule: client_id must equal the organization identifier from the eIDAS certificate distinguished name (ETSI TS 119 495 §5.2.1), e.g. PSDFR-ACPR-12345.