openapi: 3.0.0 info: title: Account and Transaction API Specification Account Access Consents Direct Debits API description: 'Swagger for Account and Transaction API Specification. **Please Note**: There are no optional fields, if a field is not marked as “Required” it is a Conditional field. ' termsOfService: https://www.openbanking.org.uk/terms contact: name: Service Desk email: ServiceDesk@openbanking.org.uk license: name: open-licence url: https://www.openbanking.org.uk/open-licence version: 4.0.1 servers: - url: /open-banking/v4.0/aisp tags: - name: Direct Debits paths: /accounts/{AccountId}/direct-debits: get: tags: - Direct Debits summary: Get Direct Debits for an AccountId description: Enables an AISP to retrieve Direct Debit information for a specific PSU account. operationId: GetAccountsAccountIdDirectDebits parameters: - $ref: '#/components/parameters/AccountId' - $ref: '#/components/parameters/x-fapi-auth-date' - $ref: '#/components/parameters/x-fapi-customer-ip-address' - $ref: '#/components/parameters/x-fapi-interaction-id' - $ref: '#/components/parameters/Authorization' - $ref: '#/components/parameters/x-customer-user-agent' - $ref: '#/components/parameters/x-client-id' responses: '200': $ref: '#/components/responses/200AccountsAccountIdDirectDebitsRead' '400': $ref: '#/components/responses/400Error' '401': $ref: '#/components/responses/401Error' '403': $ref: '#/components/responses/403Error' '404': $ref: '#/components/responses/404Error' '405': $ref: '#/components/responses/405Error' '406': $ref: '#/components/responses/406Error' '429': $ref: '#/components/responses/429Error' '500': $ref: '#/components/responses/500Error' security: - PSUOAuth2Security: - accounts /direct-debits: get: tags: - Direct Debits summary: Get Direct Debits description: Enables an AISP to retrieve Direct Debit information for account(s) that the PSU has consented to. operationId: GetDirectDebits parameters: - $ref: '#/components/parameters/x-fapi-auth-date' - $ref: '#/components/parameters/x-fapi-customer-ip-address' - $ref: '#/components/parameters/x-fapi-interaction-id' - $ref: '#/components/parameters/Authorization' - $ref: '#/components/parameters/x-customer-user-agent' - $ref: '#/components/parameters/x-client-id' responses: '200': $ref: '#/components/responses/200DirectDebitsRead' '400': $ref: '#/components/responses/400Error' '401': $ref: '#/components/responses/401Error' '403': $ref: '#/components/responses/403Error' '404': $ref: '#/components/responses/404Error' '405': $ref: '#/components/responses/405Error' '406': $ref: '#/components/responses/406Error' '429': $ref: '#/components/responses/429Error' '500': $ref: '#/components/responses/500Error' security: - PSUOAuth2Security: - accounts components: schemas: OBActiveCurrencyAndAmount_SimpleType: description: A number of monetary units specified in an active currency where the unit of currency is explicit and compliant with ISO 4217. type: string example: '1209.06' pattern: ^\d{1,13}$|^\d{1,13}\.\d{1,5}$ ExternalMandateStatus1Code: description: Specifies the status of the standing order in code form. For a full list of enumeration values refer to 'ExternalMandateStatus1Code' in *ISO_External_Codeset* [here](https://github.com/OpenBankingUK/External_Internal_CodeSets) type: string enum: - ACTV - CANC - EXPI - SUSP example: ACTV Meta: title: MetaData type: object description: Meta Data relevant to the payload properties: TotalPages: type: integer format: int32 FirstAvailableDateTime: $ref: '#/components/schemas/ISODateTime' LastAvailableDateTime: $ref: '#/components/schemas/ISODateTime' additionalProperties: false OBMandateRelatedInformation1: type: object description: Provides further details of the mandate signed between the creditor and the debtor. required: - Frequency properties: MandateIdentification: description: Unique identification, as assigned by the creditor, to unambiguously identify the mandate. type: string example: Golfers minLength: 1 maxLength: 35 Classification: $ref: '#/components/schemas/OBExternalMandateClassification1Code' CategoryPurposeCode: $ref: '#/components/schemas/ExternalCategoryPurpose1Code' FirstPaymentDateTime: description: The date on which the first payment for a recurrent credit transfer will be made. example: '2024-04-25T12:46:49.425Z' type: string format: date-time RecurringPaymentDateTime: description: "The date on which the first recurring payment for a Standing Order schedule will be made. \nUsage: This must be populated only if the first recurring date is different to the first payment date. All dates in the JSON payloads are represented in ISO 8601 date-time format. \nAll date-time fields in responses must include the timezone. An example is below:\n2017-04-05T10:43:07+00:00" type: string example: '2024-04-25T12:46:49.425Z' format: date-time FinalPaymentDateTime: description: The date on which the final payment for a recurrent credit transfer will be made. type: string example: '2024-04-25T12:46:49.425Z' format: date-time Frequency: $ref: '#/components/schemas/OBFrequency6' Reason: description: Reason for the setup of the credit transfer mandate. type: string example: To pay monthly membership maxLength: 256 minLength: 1 OBFrequency6: description: Regularity with which credit transfer instructions are to be created and processed type: object required: - Type properties: Type: oneOf: - $ref: '#/components/schemas/OBFrequency6Code' - $ref: '#/components/schemas/Frequency_1' CountPerPeriod: description: 'Number of instructions to be created and processed during the specified period. Specifies a frequency in terms of a count per period within a specified frequency type. Note: should not be used alongside `PointInTime`' type: integer example: 1 format: int32 PointInTime: $ref: '#/components/schemas/PointInTime' AccountId: description: A unique and immutable identifier used to identify the account resource. This identifier has no meaning to the account owner. type: string example: '22289' minLength: 1 maxLength: 40 ActiveOrHistoricCurrencyCode_1: description: A code allocated to a currency by a Maintenance Agency under an international identification scheme, as described in the latest edition of the international standard ISO 4217 "Codes for the representation of currencies and funds". type: string example: GBP pattern: ^[A-Z]{3,3}$ Frequency_1: description: 'Individual Definitions: NotKnown - Not Known EvryDay - Every day EvryWorkgDay - Every working day IntrvlDay - An interval specified in number of calendar days (02 to 31) IntrvlWkDay - An interval specified in weeks (01 to 09), and the day within the week (01 to 07) WkInMnthDay - A monthly interval, specifying the week of the month (01 to 05) and day within the week (01 to 07) IntrvlMnthDay - An interval specified in months (between 01 to 06, 12, 24), specifying the day within the month (-05 to -01, 01 to 31) QtrDay - Quarterly (either ENGLISH, SCOTTISH, or RECEIVED) ENGLISH = Paid on the 25th March, 24th June, 29th September and 25th December. SCOTTISH = Paid on the 2nd February, 15th May, 1st August and 11th November. RECEIVED = Paid on the 20th March, 19th June, 24th September and 20th December. Individual Patterns: NotKnown (ScheduleCode) EvryDay (ScheduleCode) EvryWorkgDay (ScheduleCode) IntrvlDay:NoOfDay (ScheduleCode + NoOfDay) IntrvlWkDay:IntervalInWeeks:DayInWeek (ScheduleCode + IntervalInWeeks + DayInWeek) WkInMnthDay:WeekInMonth:DayInWeek (ScheduleCode + WeekInMonth + DayInWeek) IntrvlMnthDay:IntervalInMonths:DayInMonth (ScheduleCode + IntervalInMonths + DayInMonth) QtrDay: + either (ENGLISH, SCOTTISH or RECEIVED) ScheduleCode + QuarterDay The regular expression for this element combines five smaller versions for each permitted pattern. To aid legibility - the components are presented individually here: NotKnown EvryDay EvryWorkgDay IntrvlDay:((0[2-9])|([1-2][0-9])|3[0-1]) IntrvlWkDay:0[1-9]:0[1-7] WkInMnthDay:0[1-5]:0[1-7] IntrvlMnthDay:(0[1-6]|12|24):(-0[1-5]|0[1-9]|[12][0-9]|3[01]) QtrDay:(ENGLISH|SCOTTISH|RECEIVED) Full Regular Expression: ^(NotKnown)$|^(EvryDay)$|^(EvryWorkgDay)$|^(IntrvlDay:((0[2-9])|([1-2][0-9])|3[0-1]))$|^(IntrvlWkDay:0[1-9]:0[1-7])$|^(WkInMnthDay:0[1-5]:0[1-7])$|^(IntrvlMnthDay:(0[1-6]|12|24):(-0[1-5]|0[1-9]|[12][0-9]|3[01]))$|^(QtrDay:(ENGLISH|SCOTTISH|RECEIVED))$' type: string pattern: ^(NotKnown)$|^(EvryDay)$|^(EvryWorkgDay)$|^(IntrvlDay:((0[2-9])|([1-2][0-9])|3[0-1]))$|^(IntrvlWkDay:0[1-9]:0[1-7])$|^(WkInMnthDay:0[1-5]:0[1-7])$|^(IntrvlMnthDay:(0[1-6]|12|24):(-0[1-5]|0[1-9]|[12][0-9]|3[01]))$|^(QtrDay:(ENGLISH|SCOTTISH|RECEIVED))$ OBExternalStatusReason1Code: description: Low level textual error code, for all enum values see `OBExternalStatusReason1Code` in *OB_Internal_CodeSet* [here](https://github.com/OpenBankingUK/External_Internal_CodeSets) type: string minLength: 4 maxLength: 4 example: U001 ExternalCategoryPurpose1Code: description: Enumeration of codes that outlines the type of purpose behind a transaction, payment or risk. For all enum values see `ExternalCategoryPurpose1Code` in *ISO_External_CodeSet* [here](https://github.com/OpenBankingUK/External_Internal_CodeSets) type: string enum: - BONU - CASH - CBLK - CCRD - CGWV - CIPC - CONC - CORT - DCRD - DIVI - DVPM - EPAY - FCDT - FCIN - FCOL - GOVT - GP2P - HEDG - ICCP - IDCP - INTC - INTE - LBOX - LOAN - MP2B - MP2P - OTHR - PENS - RPRE - RRCT - RVPM - SALA - SECU - SSBE - SUPP - SWEP - TAXS - TOPG - TRAD - TREA - VATX - VOST - WHLD - ZABA PointInTime: description: 'Exact2NumericText - Further information on the exact point in time the event should take place. Specifies a frequency in terms of an exact point in time or moment within a specified frequency type. Note: should not be used alongside `CountPerPeriod`.' type: string example: '00' maxLength: 2 OBReadDirectDebit2: type: object required: - Data properties: Data: type: object properties: DirectDebit: type: array items: type: object description: Account to or from which a cash entry is made. required: - AccountId - Name properties: AccountId: $ref: '#/components/schemas/AccountId' DirectDebitId: $ref: '#/components/schemas/DirectDebitId' DirectDebitStatusCode: $ref: '#/components/schemas/ExternalMandateStatus1Code' MandateRelatedInformation: $ref: '#/components/schemas/OBMandateRelatedInformation1' Name: $ref: '#/components/schemas/Name_2' PreviousPaymentDateTime: $ref: '#/components/schemas/PreviousPaymentDateTime' PreviousPaymentAmount: $ref: '#/components/schemas/OBActiveOrHistoricCurrencyAndAmount_0' Links: $ref: '#/components/schemas/Links' Meta: $ref: '#/components/schemas/Meta' additionalProperties: false OBFrequency6Code: description: For a full list of values see `OBFrequency6Code` in *OB_Internal_CodeSet* [here](https://github.com/OpenBankingUK/External_Internal_CodeSets) type: string example: MNTH enum: - ADHO - YEAR - DAIL - FRTN - INDA - MNTH - QURT - MIAN - WEEK - WODL - FOWK - TWMH - FOMH - FIMH - ALMH - NONE - LWMH - LXMH - TWYR Links: type: object description: Links relevant to the payload properties: Self: type: string format: uri First: type: string format: uri Prev: type: string format: uri Next: type: string format: uri Last: type: string format: uri additionalProperties: false required: - Self OBExternalMandateClassification1Code: description: Type of mandate instruction. For a full list of values see `OBExternalClassification1Code` in *OB_Internal_CodeSet* [here](https://github.com/OpenBankingUK/External_Internal_CodeSets) type: string example: FIXE enum: - FIXE - USGB - VARI Name_2: description: Name of Service User. type: string minLength: 1 maxLength: 70 ISODateTime: description: "All dates in the JSON payloads are represented in ISO 8601 date-time format. \nAll date-time fields in responses must include the timezone. An example is below:\n2017-04-05T10:43:07+00:00" type: string format: date-time DirectDebitId: description: A unique and immutable identifier used to identify the direct debit resource. This identifier has no meaning to the account owner. type: string minLength: 1 maxLength: 40 OBErrorResponse1: description: An array of detail error codes, and messages, and URLs to documentation to help remediation. type: object properties: Id: description: A unique reference for the error instance, for audit purposes, in case of unknown/unclassified errors. type: string minLength: 1 maxLength: 40 Code: description: Deprecated
High level textual error code, to help categorise the errors. type: string minLength: 1 example: 400 BadRequest maxLength: 40 Message: description: Deprecated
Brief Error message type: string minLength: 1 example: There is something wrong with the request parameters provided maxLength: 500 Errors: items: $ref: '#/components/schemas/OBError1' type: array minItems: 1 required: - Errors additionalProperties: false PreviousPaymentDateTime: description: "Date of most recent direct debit collection. All dates in the JSON payloads are represented in ISO 8601 date-time format. \nAll date-time fields in responses must include the timezone. An example is below:\n2017-04-05T10:43:07+00:00" type: string format: date-time OBError1: type: object properties: ErrorCode: $ref: '#/components/schemas/OBExternalStatusReason1Code' Message: description: 'A description of the error that occurred. e.g., ''A mandatory field isn''t supplied'' or ''RequestedExecutionDateTime must be in future'' OBL doesn''t standardise this field' type: string minLength: 1 maxLength: 500 Path: description: Recommended but optional reference to the JSON Path of the field with error, e.g., Data.Initiation.InstructedAmount.Currency type: string minLength: 1 maxLength: 500 Url: description: URL to help remediate the problem, or provide more information, or to API Reference, or help etc type: string required: - ErrorCode additionalProperties: false minProperties: 1 OBActiveOrHistoricCurrencyAndAmount_0: type: object required: - Amount - Currency description: The amount of the most recent direct debit collection. properties: Amount: $ref: '#/components/schemas/OBActiveCurrencyAndAmount_SimpleType' Currency: $ref: '#/components/schemas/ActiveOrHistoricCurrencyCode_1' parameters: x-client-id: in: header name: x-client-id required: false description: "Only used if an ASPSP requires the client ID in order to return rate limit headers. \n\nTPPs __must__ refer to ASPSP developer portals for further information on any rate limit policies, if the headers are supported and any additional requirements.\n\nThis header __must not__ be used for client authentication\n" schema: type: string x-fapi-auth-date: in: header name: x-fapi-auth-date required: false description: "The time when the PSU last logged in with the TPP. \nAll dates in the HTTP headers are represented as RFC 7231 Full Dates. An example is below: \nSun, 10 Sep 2017 19:43:31 UTC" schema: type: string pattern: ^(Mon|Tue|Wed|Thu|Fri|Sat|Sun), \d{2} (Jan|Feb|Mar|Apr|May|Jun|Jul|Aug|Sep|Oct|Nov|Dec) \d{4} \d{2}:\d{2}:\d{2} (GMT|UTC)$ AccountId: name: AccountId in: path description: AccountId required: true schema: type: string Authorization: in: header name: Authorization required: true description: An Authorisation Token as per https://tools.ietf.org/html/rfc6750 schema: type: string x-fapi-interaction-id: in: header name: x-fapi-interaction-id required: false description: An RFC4122 UID used as a correlation id. schema: type: string x-fapi-customer-ip-address: in: header name: x-fapi-customer-ip-address required: false description: The PSU's IP address if the PSU is currently logged in with the TPP. schema: type: string x-customer-user-agent: in: header name: x-customer-user-agent description: Indicates the user-agent that the PSU is using. required: false schema: type: string responses: 400Error: description: Bad request headers: x-fapi-interaction-id: description: An RFC4122 UID used as a correlation id. required: true schema: type: string content: application/json; charset=utf-8: schema: $ref: '#/components/schemas/OBErrorResponse1' application/json: schema: $ref: '#/components/schemas/OBErrorResponse1' application/jose+jwe: schema: $ref: '#/components/schemas/OBErrorResponse1' 401Error: description: Unauthorized headers: x-fapi-interaction-id: description: An RFC4122 UID used as a correlation id. required: true schema: type: string 404Error: description: Not found headers: x-fapi-interaction-id: description: An RFC4122 UID used as a correlation id. required: true schema: type: string 405Error: description: Method Not Allowed headers: x-fapi-interaction-id: description: An RFC4122 UID used as a correlation id. required: true schema: type: string 429Error: description: Too Many Requests headers: Retry-After: description: Number in seconds to wait schema: type: integer x-fapi-interaction-id: description: An RFC4122 UID used as a correlation id. schema: type: string 200DirectDebitsRead: description: Direct Debits Read headers: x-fapi-interaction-id: description: An RFC4122 UID used as a correlation id. required: true schema: type: string RateLimit-Policy: $ref: '#/components/headers/RateLimit-Policy' RateLimit: $ref: '#/components/headers/RateLimit' content: application/json; charset=utf-8: schema: $ref: '#/components/schemas/OBReadDirectDebit2' application/json: schema: $ref: '#/components/schemas/OBReadDirectDebit2' application/jose+jwe: schema: $ref: '#/components/schemas/OBReadDirectDebit2' 403Error: description: Forbidden headers: x-fapi-interaction-id: description: An RFC4122 UID used as a correlation id. required: true schema: type: string content: application/json; charset=utf-8: schema: $ref: '#/components/schemas/OBErrorResponse1' application/json: schema: $ref: '#/components/schemas/OBErrorResponse1' application/jose+jwe: schema: $ref: '#/components/schemas/OBErrorResponse1' 200AccountsAccountIdDirectDebitsRead: description: Direct Debits Read headers: x-fapi-interaction-id: description: An RFC4122 UID used as a correlation id. required: true schema: type: string RateLimit-Policy: $ref: '#/components/headers/RateLimit-Policy' RateLimit: $ref: '#/components/headers/RateLimit' content: application/json; charset=utf-8: schema: $ref: '#/components/schemas/OBReadDirectDebit2' application/json: schema: $ref: '#/components/schemas/OBReadDirectDebit2' application/jose+jwe: schema: $ref: '#/components/schemas/OBReadDirectDebit2' 500Error: description: Internal Server Error headers: x-fapi-interaction-id: description: An RFC4122 UID used as a correlation id. required: true schema: type: string content: application/json; charset=utf-8: schema: $ref: '#/components/schemas/OBErrorResponse1' application/json: schema: $ref: '#/components/schemas/OBErrorResponse1' application/jose+jwe: schema: $ref: '#/components/schemas/OBErrorResponse1' 406Error: description: Not Acceptable headers: x-fapi-interaction-id: description: An RFC4122 UID used as a correlation id. required: true schema: type: string headers: RateLimit-Policy: required: false description: 'TPPs __must__ refer to ASPSP developer portals for further information on any rate limit policies, if the headers are supported and any additional requirements. A non-empty list of Quota Policy Items. The Item value __MUST__ be a String. Example: `RateLimit-Policy: "default";q=100;w=10` The **REQUIRED** "q" parameter indicates the quota allocated by this policy measured in quota units. The **OPTIONAL** "w" parameter value conveys a time window. ' schema: type: string RateLimit: required: false description: 'TPPs __must__ refer to ASPSP developer portals for further information on any rate limit policies, if the headers are supported and any additional requirements. A server uses the "RateLimit" response header field to communicate the current service limit for a quota policy for a particular partition key. Example: `RateLimit: "default";r=50;t=30` The **REQUIRED** "r" parameter value conveys the remaining quota units for the identified policy. The **OPTIONAL** "t" parameter value conveys the time window reset time for the identified policy. ' schema: type: string securitySchemes: TPPOAuth2Security: type: oauth2 description: TPP client credential authorisation flow with the ASPSP flows: clientCredentials: tokenUrl: https://authserver.example/token scopes: accounts: Ability to read Accounts information PSUOAuth2Security: type: oauth2 description: OAuth flow, it is required when the PSU needs to perform SCA with the ASPSP when a TPP wants to access an ASPSP resource owned by the PSU flows: authorizationCode: authorizationUrl: https://authserver.example/authorization tokenUrl: https://authserver.example/token scopes: accounts: Ability to read Accounts information