openapi: 3.2.0 info: title: 'Open Banking: TPP API v2 Account API' description: Endpoints for interacting with ASPSPs accounts. version: 2.0.0 servers: - url: '%tpp_api_url%/tpp/v2' security: - tokenAuth: [] - clientId: [] tags: - name: Account description: Endpoints for confirming funds in the account. paths: /accounts: get: tags: - Account summary: Returns a list of accounts. description: '**Scope:** `accounts`' parameters: - name: Digest in: header description: A hash (SHA256, SHA512) of the request content encoded in base64. required: false schema: type: string example: SHA-256=LsUn8L4rScYKhYKf8eNr5QIbiB+1n9wFioBJ0C3XSU8= - name: X-Request-Id in: header description: A randomly generated request ID - must be a valid UUID. required: true schema: type: string example: 39c97edf-7469-42af-96ca-169a902fd8a6 - name: Signature in: header description: A calculated HTTP Signature for the request. required: false schema: type: string example: keyId="SN=3595A71FCB74E837959C3F0CF5F73A03B31F1952,CA=TribePayments CA",algorithm="rsa-sha256",headers="digest x-request-id x-client-id",signature="fNQmDCpFT5K8qAx0bNvNQsRfCm9mGKN/Srv7pufS07s8VuEGGk7HTVGVfwkYFrhpnXxtWimu77/3o+U+v61ZYsLdfOyKpv3v8u3jwee3warI6u+FyZbBvMFDnzWND68lecWB5OTdh6GlNQp8fQKp/ef/mJOVGhZ1wMVVTMH9kbH6/hVV6OoYpMs0kpIpfglnWXDJSiu8glTAGi7iC5n9eWCDunoH0a2QT2vr/gI6acEvPIin2Cqm8rIGCYk43G8K1fhdVaMDvhkyG76ld/IM7wVWzBkxiwrDYf1h3nDpzxPhJKHUv4d/BMcUd2JuVW+y5yYMd8RUnf6Ti5mmSEC90w==" - name: Tpp-Signature-Certificate in: header description: A certificate that was used to sign the request. Provided as a base64 encoded value. required: false schema: type: string example: MIIFLjCCBBagAwIBAgIBEzANBgkqhkiG9w0BAQsFADCBszElMCMGCSqGSIb3DQEJARYWaW5mb0B0cmliZXBheW1lbnRzLmNvbTElMCMGA1UEAwwcVHBwU2FuZGJveCBRc2VhbCBDZXJ0aWZpY2F0ZTEZMBcGA1UECwwQT3BlbmJhbmtpbmcgVGVhbTEZMBcGA1UECgwQVHJpYmVQYXltZW50cyBDQTEPMA0GA1UEBwwGTG9uZG9uMQ8wDQYDVQQIDAZMb25kb24xCzAJBgNVBAYTAkdCMB4XDTIxMDkyODE1MTA0NVoXDTMxMDkyNjE1MTA0NVowgcsxCzAJBgNVBAYTAkdCMQ8wDQYDVQQIDAZMb25kb24xDzANBgNVBAcMBkxvbmRvbjEWMBQGA1UECgwNVHJpYmVQYXltZW50czEZMBcGA1UECwwQT3BlbmJhbmtpbmcgVGVhbTElMCMGA1UEAwwcVHBwU2FuZGJveCBRc2VhbCBDZXJ0aWZpY2F0ZTElMCMGCSqGSIb3DQEJARYWaW5mb0B0cmliZXBheW1lbnRzLmNvbTEZMBcGA1UEYQwQR0ItVFNULTAwMDAwMDAwMDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANxZeuMSN1RyuMj/xNfwPzfW3ffepWQ4PYSE6kdja75EALosifw6n5RhDte9De57xxXnQAzyJcCGC/4GCpMfzecN/hcmSxHZhe8zbITqRmyLPXbcaEswDnGYRxIGNqGG2RWKZ6I0wSGK89t1Fw1Kz8ob8Lzh6k0UQNfujYOItTaVM4JCgKp5yjTb0HWcqp7X2Jb0eamMWfY5cxKolbJYSIlclt4loAhpEdCiqVJi5hc05+GrsSjchjNQzUpwot/GZFfm2faBPSR5sfxV0B+pXLehmzXdF7nA6Q2hAqXb8jjpbIXgDzcSRdaP7kNBLzXzNuUUUNf2LL4rFkTn5k2XgrcCAwEAAaOCATEwggEtMB0GA1UdDgQWBBSmFBRxrHvtWHkjDHg6Do6GrW5evDAfBgNVHSMEGDAWgBSmFBRxrHvtWHkjDHg6Do6GrW5evDAJBgNVHRMEAjAAMAsGA1UdDwQEAwIFoDBKBgNVHREEQzBBggtleGFtcGxlLmNvbYIPd3d3LmV4YW1wbGUuY29tghBtYWlsLmV4YW1wbGUuY29tgg9mdHAuZXhhbXBsZS5jb20wLAYJYIZIAYb4QgENBB8WHU9wZW5TU0wgR2VuZXJhdGVkIENlcnRpZmljYXRlMEQGCCsGAQUFBwEBBDgwNjA0BggrBgEFBQcwAYYoaHR0cDovL3RwcC12YWxpZGF0b3Iub3BlbmJhbmsubG9jYWwvb2NzcDATBgNVHSUEDDAKBggrBgEFBQcDCTANBgkqhkiG9w0BAQsFAAOCAQEAXgIfFYqAv/KKh/7l8XfnsQC6QXhQ6h+0Cm9lO03XxoUcZDGlPLYrjhaiTs7gfGcQjktBRnY+mSLMVfea+bSHI3tj+e8fkRNKryU2wLQpFfmTN2e7lF5tIc1KxHusxU5nSqRxVq/tmGx4Jt2G2lVmdjdrBGnpzbce8+YjPJGAHB+lxC7rX2qp8yNvFXWAEn8T6FjZN7/yBqIzIXUyGAuAuFB/zQm1O73JLhkeLJA6+5NYRgPGYMANjsMmQvUu68Ztk8wX1+HYXcHIQ6NHuDhjtzYwMPio9rr2uXBvIopKwkOivic6vHMb4pEiowZjBswIaN2ppjtn8Z+VFDb8/2fKyA== - name: Date in: header required: false description: A standard HTTP header element defines the date and time at which the request originated (as defined by RFC 7231). schema: type: string example: Thu, 18 Apr 2024 11:02:45 GMT responses: '200': description: A JSON array of accounts. headers: X-Rate-Limit-Limit: schema: type: integer example: 4 description: The number of requests allowed per day. required: true X-Rate-Limit-Remaining: schema: type: integer example: 4 description: The number of remaining requests. required: true X-Rate-Limit-Reset: schema: type: integer example: 3566 description: A number of seconds remaining until a limit reset. required: true X-Request-Id: schema: type: string example: 39c97edf-7469-42af-96ca-169a902fd8a6 description: The same value as provided in the request. required: true content: application/json: schema: $ref: '#/components/schemas/AccountListResponse' '400': description: A generic error response. content: application/json: schema: $ref: '#/components/schemas/Error' '401': description: Unauthorized, e.g., expired token. content: application/json: schema: $ref: '#/components/schemas/UnauthorizedError' '403': description: Forbidden, not allowed to access the resource. content: application/json: schema: $ref: '#/components/schemas/ForbiddenError' '405': description: A forbidden HTTP method. content: application/json: schema: $ref: '#/components/schemas/NotAllowedError' '406': description: An unsupported Accept header. content: application/json: schema: $ref: '#/components/schemas/NotAcceptableError' '429': description: Too many requests. content: application/json: schema: $ref: '#/components/schemas/AccessExceededError' '500': description: An Internal Server Error. content: application/json: schema: $ref: '#/components/schemas/InternalServerError' /accounts/{accountId}: get: tags: - Account summary: Returns details of a single account. description: '**Scope:** `accounts`' parameters: - name: accountId in: path required: true description: The account ID. Identical to `accountId` from the [Get account list](#actions--accounts--get-/v2/accounts) action. schema: type: string - name: Digest in: header description: A hash (SHA256, SHA512) of the request content encoded in base64. required: false schema: type: string example: SHA-256=LsUn8L4rScYKhYKf8eNr5QIbiB+1n9wFioBJ0C3XSU8= - name: X-Request-Id in: header description: A randomly generated request ID - must be a valid UUID. required: true schema: type: string example: 39c97edf-7469-42af-96ca-169a902fd8a6 - name: Signature in: header description: A calculated HTTP Signature for the request. required: false schema: type: string example: keyId="SN=3595A71FCB74E837959C3F0CF5F73A03B31F1952,CA=TribePayments CA",algorithm="rsa-sha256",headers="digest x-request-id x-client-id",signature="fNQmDCpFT5K8qAx0bNvNQsRfCm9mGKN/Srv7pufS07s8VuEGGk7HTVGVfwkYFrhpnXxtWimu77/3o+U+v61ZYsLdfOyKpv3v8u3jwee3warI6u+FyZbBvMFDnzWND68lecWB5OTdh6GlNQp8fQKp/ef/mJOVGhZ1wMVVTMH9kbH6/hVV6OoYpMs0kpIpfglnWXDJSiu8glTAGi7iC5n9eWCDunoH0a2QT2vr/gI6acEvPIin2Cqm8rIGCYk43G8K1fhdVaMDvhkyG76ld/IM7wVWzBkxiwrDYf1h3nDpzxPhJKHUv4d/BMcUd2JuVW+y5yYMd8RUnf6Ti5mmSEC90w==" - name: Tpp-Signature-Certificate in: header description: A certificate that was used to sign the request. Provided as a base64 encoded value. required: false schema: type: string example: MIIFLjCCBBagAwIBAgIBEzANBgkqhkiG9w0BAQsFADCBszElMCMGCSqGSIb3DQEJARYWaW5mb0B0cmliZXBheW1lbnRzLmNvbTElMCMGA1UEAwwcVHBwU2FuZGJveCBRc2VhbCBDZXJ0aWZpY2F0ZTEZMBcGA1UECwwQT3BlbmJhbmtpbmcgVGVhbTEZMBcGA1UECgwQVHJpYmVQYXltZW50cyBDQTEPMA0GA1UEBwwGTG9uZG9uMQ8wDQYDVQQIDAZMb25kb24xCzAJBgNVBAYTAkdCMB4XDTIxMDkyODE1MTA0NVoXDTMxMDkyNjE1MTA0NVowgcsxCzAJBgNVBAYTAkdCMQ8wDQYDVQQIDAZMb25kb24xDzANBgNVBAcMBkxvbmRvbjEWMBQGA1UECgwNVHJpYmVQYXltZW50czEZMBcGA1UECwwQT3BlbmJhbmtpbmcgVGVhbTElMCMGA1UEAwwcVHBwU2FuZGJveCBRc2VhbCBDZXJ0aWZpY2F0ZTElMCMGCSqGSIb3DQEJARYWaW5mb0B0cmliZXBheW1lbnRzLmNvbTEZMBcGA1UEYQwQR0ItVFNULTAwMDAwMDAwMDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANxZeuMSN1RyuMj/xNfwPzfW3ffepWQ4PYSE6kdja75EALosifw6n5RhDte9De57xxXnQAzyJcCGC/4GCpMfzecN/hcmSxHZhe8zbITqRmyLPXbcaEswDnGYRxIGNqGG2RWKZ6I0wSGK89t1Fw1Kz8ob8Lzh6k0UQNfujYOItTaVM4JCgKp5yjTb0HWcqp7X2Jb0eamMWfY5cxKolbJYSIlclt4loAhpEdCiqVJi5hc05+GrsSjchjNQzUpwot/GZFfm2faBPSR5sfxV0B+pXLehmzXdF7nA6Q2hAqXb8jjpbIXgDzcSRdaP7kNBLzXzNuUUUNf2LL4rFkTn5k2XgrcCAwEAAaOCATEwggEtMB0GA1UdDgQWBBSmFBRxrHvtWHkjDHg6Do6GrW5evDAfBgNVHSMEGDAWgBSmFBRxrHvtWHkjDHg6Do6GrW5evDAJBgNVHRMEAjAAMAsGA1UdDwQEAwIFoDBKBgNVHREEQzBBggtleGFtcGxlLmNvbYIPd3d3LmV4YW1wbGUuY29tghBtYWlsLmV4YW1wbGUuY29tgg9mdHAuZXhhbXBsZS5jb20wLAYJYIZIAYb4QgENBB8WHU9wZW5TU0wgR2VuZXJhdGVkIENlcnRpZmljYXRlMEQGCCsGAQUFBwEBBDgwNjA0BggrBgEFBQcwAYYoaHR0cDovL3RwcC12YWxpZGF0b3Iub3BlbmJhbmsubG9jYWwvb2NzcDATBgNVHSUEDDAKBggrBgEFBQcDCTANBgkqhkiG9w0BAQsFAAOCAQEAXgIfFYqAv/KKh/7l8XfnsQC6QXhQ6h+0Cm9lO03XxoUcZDGlPLYrjhaiTs7gfGcQjktBRnY+mSLMVfea+bSHI3tj+e8fkRNKryU2wLQpFfmTN2e7lF5tIc1KxHusxU5nSqRxVq/tmGx4Jt2G2lVmdjdrBGnpzbce8+YjPJGAHB+lxC7rX2qp8yNvFXWAEn8T6FjZN7/yBqIzIXUyGAuAuFB/zQm1O73JLhkeLJA6+5NYRgPGYMANjsMmQvUu68Ztk8wX1+HYXcHIQ6NHuDhjtzYwMPio9rr2uXBvIopKwkOivic6vHMb4pEiowZjBswIaN2ppjtn8Z+VFDb8/2fKyA== - name: Date in: header required: false description: A standard HTTP header element defines the date and time at which the request originated (as defined by RFC 7231). schema: type: string example: Thu, 18 Apr 2024 11:02:45 GMT responses: '200': description: Details of the account. headers: X-Rate-Limit-Limit: schema: type: integer example: 4 description: The number of requests allowed per day. required: true X-Rate-Limit-Remaining: schema: type: integer example: 4 description: The number of remaining requests. required: true X-Rate-Limit-Reset: schema: type: integer example: 3566 description: A number of seconds remaining until a limit reset. required: true X-Request-Id: schema: type: string example: 39c97edf-7469-42af-96ca-169a902fd8a6 description: The same value as provided in the request. required: true content: application/json: schema: $ref: '#/components/schemas/AccountResponse' '400': description: A generic error response. content: application/json: schema: $ref: '#/components/schemas/Error' '401': description: Unauthorized, e.g., expired token. content: application/json: schema: $ref: '#/components/schemas/UnauthorizedError' '403': description: Forbidden, not allowed to access the resource. content: application/json: schema: $ref: '#/components/schemas/ForbiddenError' '404': description: Forbidden, not allowed to access the resource. content: application/json: schema: $ref: '#/components/schemas/NotFoundError' '405': description: A forbidden HTTP method. content: application/json: schema: $ref: '#/components/schemas/NotAllowedError' '406': description: An unsupported Accept header. content: application/json: schema: $ref: '#/components/schemas/NotAcceptableError' '429': description: Too many requests. content: application/json: schema: $ref: '#/components/schemas/AccessExceededError' '500': description: An Internal Server Error. content: application/json: schema: $ref: '#/components/schemas/InternalServerError' /accounts/{accountId}/balances: get: tags: - Account summary: Returns a list of account balances. description: '**Scope:** `accounts.balances`' parameters: - name: accountId in: path required: true description: The account ID. Identical to `accountId` from the [Get account list](#actions--accounts--get-/v2/accounts) action. schema: type: string - name: Digest in: header description: A hash (SHA256, SHA512) of the request content encoded in base64. required: false schema: type: string example: SHA-256=LsUn8L4rScYKhYKf8eNr5QIbiB+1n9wFioBJ0C3XSU8= - name: X-Request-Id in: header description: A randomly generated request ID - must be a valid UUID. required: true schema: type: string example: 39c97edf-7469-42af-96ca-169a902fd8a6 - name: Signature in: header description: A calculated HTTP Signature for the request. required: false schema: type: string example: keyId="SN=3595A71FCB74E837959C3F0CF5F73A03B31F1952,CA=TribePayments CA",algorithm="rsa-sha256",headers="digest x-request-id x-client-id",signature="fNQmDCpFT5K8qAx0bNvNQsRfCm9mGKN/Srv7pufS07s8VuEGGk7HTVGVfwkYFrhpnXxtWimu77/3o+U+v61ZYsLdfOyKpv3v8u3jwee3warI6u+FyZbBvMFDnzWND68lecWB5OTdh6GlNQp8fQKp/ef/mJOVGhZ1wMVVTMH9kbH6/hVV6OoYpMs0kpIpfglnWXDJSiu8glTAGi7iC5n9eWCDunoH0a2QT2vr/gI6acEvPIin2Cqm8rIGCYk43G8K1fhdVaMDvhkyG76ld/IM7wVWzBkxiwrDYf1h3nDpzxPhJKHUv4d/BMcUd2JuVW+y5yYMd8RUnf6Ti5mmSEC90w==" - name: Tpp-Signature-Certificate in: header description: A certificate that was used to sign the request. Provided as a base64 encoded value. required: false schema: type: string example: MIIFLjCCBBagAwIBAgIBEzANBgkqhkiG9w0BAQsFADCBszElMCMGCSqGSIb3DQEJARYWaW5mb0B0cmliZXBheW1lbnRzLmNvbTElMCMGA1UEAwwcVHBwU2FuZGJveCBRc2VhbCBDZXJ0aWZpY2F0ZTEZMBcGA1UECwwQT3BlbmJhbmtpbmcgVGVhbTEZMBcGA1UECgwQVHJpYmVQYXltZW50cyBDQTEPMA0GA1UEBwwGTG9uZG9uMQ8wDQYDVQQIDAZMb25kb24xCzAJBgNVBAYTAkdCMB4XDTIxMDkyODE1MTA0NVoXDTMxMDkyNjE1MTA0NVowgcsxCzAJBgNVBAYTAkdCMQ8wDQYDVQQIDAZMb25kb24xDzANBgNVBAcMBkxvbmRvbjEWMBQGA1UECgwNVHJpYmVQYXltZW50czEZMBcGA1UECwwQT3BlbmJhbmtpbmcgVGVhbTElMCMGA1UEAwwcVHBwU2FuZGJveCBRc2VhbCBDZXJ0aWZpY2F0ZTElMCMGCSqGSIb3DQEJARYWaW5mb0B0cmliZXBheW1lbnRzLmNvbTEZMBcGA1UEYQwQR0ItVFNULTAwMDAwMDAwMDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANxZeuMSN1RyuMj/xNfwPzfW3ffepWQ4PYSE6kdja75EALosifw6n5RhDte9De57xxXnQAzyJcCGC/4GCpMfzecN/hcmSxHZhe8zbITqRmyLPXbcaEswDnGYRxIGNqGG2RWKZ6I0wSGK89t1Fw1Kz8ob8Lzh6k0UQNfujYOItTaVM4JCgKp5yjTb0HWcqp7X2Jb0eamMWfY5cxKolbJYSIlclt4loAhpEdCiqVJi5hc05+GrsSjchjNQzUpwot/GZFfm2faBPSR5sfxV0B+pXLehmzXdF7nA6Q2hAqXb8jjpbIXgDzcSRdaP7kNBLzXzNuUUUNf2LL4rFkTn5k2XgrcCAwEAAaOCATEwggEtMB0GA1UdDgQWBBSmFBRxrHvtWHkjDHg6Do6GrW5evDAfBgNVHSMEGDAWgBSmFBRxrHvtWHkjDHg6Do6GrW5evDAJBgNVHRMEAjAAMAsGA1UdDwQEAwIFoDBKBgNVHREEQzBBggtleGFtcGxlLmNvbYIPd3d3LmV4YW1wbGUuY29tghBtYWlsLmV4YW1wbGUuY29tgg9mdHAuZXhhbXBsZS5jb20wLAYJYIZIAYb4QgENBB8WHU9wZW5TU0wgR2VuZXJhdGVkIENlcnRpZmljYXRlMEQGCCsGAQUFBwEBBDgwNjA0BggrBgEFBQcwAYYoaHR0cDovL3RwcC12YWxpZGF0b3Iub3BlbmJhbmsubG9jYWwvb2NzcDATBgNVHSUEDDAKBggrBgEFBQcDCTANBgkqhkiG9w0BAQsFAAOCAQEAXgIfFYqAv/KKh/7l8XfnsQC6QXhQ6h+0Cm9lO03XxoUcZDGlPLYrjhaiTs7gfGcQjktBRnY+mSLMVfea+bSHI3tj+e8fkRNKryU2wLQpFfmTN2e7lF5tIc1KxHusxU5nSqRxVq/tmGx4Jt2G2lVmdjdrBGnpzbce8+YjPJGAHB+lxC7rX2qp8yNvFXWAEn8T6FjZN7/yBqIzIXUyGAuAuFB/zQm1O73JLhkeLJA6+5NYRgPGYMANjsMmQvUu68Ztk8wX1+HYXcHIQ6NHuDhjtzYwMPio9rr2uXBvIopKwkOivic6vHMb4pEiowZjBswIaN2ppjtn8Z+VFDb8/2fKyA== - name: Date in: header required: false description: A standard HTTP header element defines the date and time at which the request originated (as defined by RFC 7231). schema: type: string example: Thu, 18 Apr 2024 11:02:45 GMT responses: '200': description: A JSON array of account balances. headers: X-Rate-Limit-Limit: schema: type: integer example: 4 description: The number of requests allowed per day. required: true X-Rate-Limit-Remaining: schema: type: integer example: 4 description: The number of remaining requests. required: true X-Rate-Limit-Reset: schema: type: integer example: 3566 description: A number of seconds remaining until a limit reset. required: true X-Request-Id: schema: type: string example: 39c97edf-7469-42af-96ca-169a902fd8a6 description: The same value as provided in the request. required: true content: application/json: schema: $ref: '#/components/schemas/AccountBalanceList' '400': description: A generic error response. content: application/json: schema: $ref: '#/components/schemas/Error' '401': description: Unauthorized, e.g., expired token. content: application/json: schema: $ref: '#/components/schemas/UnauthorizedError' '403': description: Forbidden, not allowed to access the resource. content: application/json: schema: $ref: '#/components/schemas/ForbiddenError' '404': description: Forbidden, not allowed to access the resource. content: application/json: schema: $ref: '#/components/schemas/NotFoundError' '405': description: A forbidden HTTP method. content: application/json: schema: $ref: '#/components/schemas/NotAllowedError' '406': description: An unsupported Accept header. content: application/json: schema: $ref: '#/components/schemas/NotAcceptableError' '429': description: Too many requests. content: application/json: schema: $ref: '#/components/schemas/AccessExceededError' '500': description: An Internal Server Error. content: application/json: schema: $ref: '#/components/schemas/InternalServerError' /accounts/{accountId}/transactions: get: tags: - Account summary: Returns a list of account transactions. description: '**Scope:** `accounts.transactions`' parameters: - name: accountId in: path required: true description: The account ID. Identical to `accountId` from the [Get account list](#actions--accounts--get-/v2/accounts) action. schema: type: string - name: Digest in: header description: A hash (SHA256, SHA512) of the request content encoded in base64. required: false schema: type: string example: SHA-256=LsUn8L4rScYKhYKf8eNr5QIbiB+1n9wFioBJ0C3XSU8= - name: X-Request-Id in: header description: A randomly generated request ID - must be a valid UUID. required: true schema: type: string example: 39c97edf-7469-42af-96ca-169a902fd8a6 - name: Signature in: header description: A calculated HTTP Signature for the request. required: false schema: type: string example: keyId="SN=3595A71FCB74E837959C3F0CF5F73A03B31F1952,CA=TribePayments CA",algorithm="rsa-sha256",headers="digest x-request-id x-client-id",signature="fNQmDCpFT5K8qAx0bNvNQsRfCm9mGKN/Srv7pufS07s8VuEGGk7HTVGVfwkYFrhpnXxtWimu77/3o+U+v61ZYsLdfOyKpv3v8u3jwee3warI6u+FyZbBvMFDnzWND68lecWB5OTdh6GlNQp8fQKp/ef/mJOVGhZ1wMVVTMH9kbH6/hVV6OoYpMs0kpIpfglnWXDJSiu8glTAGi7iC5n9eWCDunoH0a2QT2vr/gI6acEvPIin2Cqm8rIGCYk43G8K1fhdVaMDvhkyG76ld/IM7wVWzBkxiwrDYf1h3nDpzxPhJKHUv4d/BMcUd2JuVW+y5yYMd8RUnf6Ti5mmSEC90w==" - name: Tpp-Signature-Certificate in: header description: A certificate that was used to sign the request. Provided as a base64 encoded value. required: false schema: type: string example: MIIFLjCCBBagAwIBAgIBEzANBgkqhkiG9w0BAQsFADCBszElMCMGCSqGSIb3DQEJARYWaW5mb0B0cmliZXBheW1lbnRzLmNvbTElMCMGA1UEAwwcVHBwU2FuZGJveCBRc2VhbCBDZXJ0aWZpY2F0ZTEZMBcGA1UECwwQT3BlbmJhbmtpbmcgVGVhbTEZMBcGA1UECgwQVHJpYmVQYXltZW50cyBDQTEPMA0GA1UEBwwGTG9uZG9uMQ8wDQYDVQQIDAZMb25kb24xCzAJBgNVBAYTAkdCMB4XDTIxMDkyODE1MTA0NVoXDTMxMDkyNjE1MTA0NVowgcsxCzAJBgNVBAYTAkdCMQ8wDQYDVQQIDAZMb25kb24xDzANBgNVBAcMBkxvbmRvbjEWMBQGA1UECgwNVHJpYmVQYXltZW50czEZMBcGA1UECwwQT3BlbmJhbmtpbmcgVGVhbTElMCMGA1UEAwwcVHBwU2FuZGJveCBRc2VhbCBDZXJ0aWZpY2F0ZTElMCMGCSqGSIb3DQEJARYWaW5mb0B0cmliZXBheW1lbnRzLmNvbTEZMBcGA1UEYQwQR0ItVFNULTAwMDAwMDAwMDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANxZeuMSN1RyuMj/xNfwPzfW3ffepWQ4PYSE6kdja75EALosifw6n5RhDte9De57xxXnQAzyJcCGC/4GCpMfzecN/hcmSxHZhe8zbITqRmyLPXbcaEswDnGYRxIGNqGG2RWKZ6I0wSGK89t1Fw1Kz8ob8Lzh6k0UQNfujYOItTaVM4JCgKp5yjTb0HWcqp7X2Jb0eamMWfY5cxKolbJYSIlclt4loAhpEdCiqVJi5hc05+GrsSjchjNQzUpwot/GZFfm2faBPSR5sfxV0B+pXLehmzXdF7nA6Q2hAqXb8jjpbIXgDzcSRdaP7kNBLzXzNuUUUNf2LL4rFkTn5k2XgrcCAwEAAaOCATEwggEtMB0GA1UdDgQWBBSmFBRxrHvtWHkjDHg6Do6GrW5evDAfBgNVHSMEGDAWgBSmFBRxrHvtWHkjDHg6Do6GrW5evDAJBgNVHRMEAjAAMAsGA1UdDwQEAwIFoDBKBgNVHREEQzBBggtleGFtcGxlLmNvbYIPd3d3LmV4YW1wbGUuY29tghBtYWlsLmV4YW1wbGUuY29tgg9mdHAuZXhhbXBsZS5jb20wLAYJYIZIAYb4QgENBB8WHU9wZW5TU0wgR2VuZXJhdGVkIENlcnRpZmljYXRlMEQGCCsGAQUFBwEBBDgwNjA0BggrBgEFBQcwAYYoaHR0cDovL3RwcC12YWxpZGF0b3Iub3BlbmJhbmsubG9jYWwvb2NzcDATBgNVHSUEDDAKBggrBgEFBQcDCTANBgkqhkiG9w0BAQsFAAOCAQEAXgIfFYqAv/KKh/7l8XfnsQC6QXhQ6h+0Cm9lO03XxoUcZDGlPLYrjhaiTs7gfGcQjktBRnY+mSLMVfea+bSHI3tj+e8fkRNKryU2wLQpFfmTN2e7lF5tIc1KxHusxU5nSqRxVq/tmGx4Jt2G2lVmdjdrBGnpzbce8+YjPJGAHB+lxC7rX2qp8yNvFXWAEn8T6FjZN7/yBqIzIXUyGAuAuFB/zQm1O73JLhkeLJA6+5NYRgPGYMANjsMmQvUu68Ztk8wX1+HYXcHIQ6NHuDhjtzYwMPio9rr2uXBvIopKwkOivic6vHMb4pEiowZjBswIaN2ppjtn8Z+VFDb8/2fKyA== - name: Date in: header required: false description: A standard HTTP header element defines the date and time at which the request originated (as defined by RFC 7231). schema: type: string example: Thu, 18 Apr 2024 11:02:45 GMT - name: bookingStatus in: query required: true description: 'The type of transaction to return. Possible values: `booked`, `pending`, `both`.' schema: type: string enum: - booked - pending - both - name: pageSize in: query required: false allowEmptyValue: true description: The number of transactions in a single response. The default value is `100`. schema: type: integer example: 100 - name: pageKey in: query required: false allowEmptyValue: true description: A parameter used when paging value points to the page following the previous API call. schema: type: string example: ZDU0N2M0YTVkZTk3NGIxODkxMjNmZWVmYzEwNjQxZDg - name: dateFrom in: query required: false allowEmptyValue: true description: Filters transactions since a specific date in the `YYYY-MM-DD` format. schema: type: string example: '2023-01-01' - name: dateTo in: query required: false allowEmptyValue: true description: Filters transactions until a specific date in the `YYYY-MM-DD` format. schema: type: string example: '2023-01-01' responses: '200': description: A JSON array of account transactions. headers: X-Rate-Limit-Limit: schema: type: integer example: 4 description: The number of requests allowed per day. required: true X-Rate-Limit-Remaining: schema: type: integer example: 4 description: The number of remaining requests. required: true X-Rate-Limit-Reset: schema: type: integer example: 3566 description: A number of seconds remaining until a limit reset. required: true X-Request-Id: schema: type: string example: 39c97edf-7469-42af-96ca-169a902fd8a6 description: The same value as provided in the request. required: true content: application/json: schema: $ref: '#/components/schemas/AccountTransactionsResponse' '400': description: A generic error response. content: application/json: schema: $ref: '#/components/schemas/Error' '401': description: Unauthorized, e.g., expired token. content: application/json: schema: $ref: '#/components/schemas/UnauthorizedError' '403': description: Forbidden, not allowed to access the resource. content: application/json: schema: $ref: '#/components/schemas/ForbiddenError' '404': description: Forbidden, not allowed to access the resource. content: application/json: schema: $ref: '#/components/schemas/NotFoundError' '405': description: A forbidden HTTP method. content: application/json: schema: $ref: '#/components/schemas/NotAllowedError' '406': description: An unsupported Accept header. content: application/json: schema: $ref: '#/components/schemas/NotAcceptableError' '429': description: Too many requests. content: application/json: schema: $ref: '#/components/schemas/AccessExceededError' '500': description: An Internal Server Error. content: application/json: schema: $ref: '#/components/schemas/InternalServerError' components: schemas: AccountReference: type: object description: The identifier of the addressed account. properties: iban: description: The IBAN of the account. type: string example: GB29NWBK60161331926819 maxLength: 34 bban: type: string description: The local ASPSP identifier of the account. example: '29823529' maxLength: 30 accountNumber: type: string description: 'The account number. Used to identify the account in the United Kingdom. ' minLength: 8 maxLength: 8 example: '29823529' sortCode: type: string description: The sort code. Used to identify the account in the United Kingdom. minLength: 6 maxLength: 6 example: '902127' NextLink: type: object description: The link pointing to the following page. properties: href: type: string description: The URL of the following page. example: /tpp/v2/banks?page=4&limit=5 NotFoundError: type: object description: Not found. required: - code - requestId - timestamp properties: code: type: string description: The message code to explain the nature of the underlying error. example: RESOURCE_NOT_FOUND title: type: string description: The short, human-readable description of the error. example: Account not found maxLength: 70 timestamp: type: string description: ISO-8601 timestamp example: 2023-04-19T13:33:42+0000 requestId: type: string description: The request ID as communicated in the `X-Request-Id` header. example: 39c97edf-7469-42af-96ca-169a902fd8a6 additionalErrors: $ref: '#/components/schemas/EmptyAdditionalErrors' NextLinks: type: object description: Links pointing to other pages. properties: next: $ref: '#/components/schemas/NextLink' NotAcceptableError: type: object description: An unsupported `Accept` header. required: - code - requestId - timestamp properties: code: type: string description: The message code to explain the nature of the underlying error. example: REQUESTED_FORMATS_INVALID title: type: string description: The short, human-readable description of the error. example: Only application/json supported maxLength: 70 timestamp: type: string description: ISO-8601 timestamp example: 2023-04-19T13:33:42+0000 requestId: type: string description: The request ID as communicated in the `X-Request-Id` header. example: 39c97edf-7469-42af-96ca-169a902fd8a6 additionalErrors: $ref: '#/components/schemas/EmptyAdditionalErrors' EmptyAdditionalErrors: type: array example: [] items: $ref: '#/components/schemas/AdditionalError' AccountTransactionsResponse: type: object description: The response object containing a list of transactions. properties: transactions: $ref: '#/components/schemas/AccountTransactionList' _links: $ref: '#/components/schemas/NextLinks' NotAllowedError: type: object description: A forbidden HTTP method. required: - code - requestId - timestamp properties: code: type: string description: The message code to explain the nature of the underlying error. example: SERVICE_INVALID title: type: string description: The short, human-readable description of the error. example: Used HTTP method not supported for current action maxLength: 70 timestamp: type: string description: ISO-8601 timestamp example: 2023-04-19T13:33:42+0000 requestId: type: string description: The request ID as communicated in the `X-Request-Id` header. example: 39c97edf-7469-42af-96ca-169a902fd8a6 additionalErrors: $ref: '#/components/schemas/EmptyAdditionalErrors' ForbiddenError: type: object description: The forbidden error object example. required: - code - requestId - timestamp properties: code: type: string description: The message code to explain the nature of the underlying error. example: ROLE_INVALID title: type: string description: The short, human-readable description of the error. example: Role not valid for current resource maxLength: 70 timestamp: type: string description: ISO-8601 timestamp example: 2023-04-19T13:33:42+0000 requestId: type: string description: The request ID as communicated in the `X-Request-Id` header. example: 39c97edf-7469-42af-96ca-169a902fd8a6 additionalErrors: $ref: '#/components/schemas/EmptyAdditionalErrors' InternalServerError: type: object description: The forbidden error object example. required: - code - requestId - timestamp properties: code: type: string description: The message code to explain the nature of the underlying error. example: INTERNAL_ERROR title: type: string description: The short, human-readable description of the error. example: Internal Error maxLength: 70 timestamp: type: string description: ISO-8601 timestamp example: 2023-04-19T13:33:42+0000 requestId: type: string description: The request ID as communicated in the `X-Request-Id` header. example: 39c97edf-7469-42af-96ca-169a902fd8a6 additionalErrors: $ref: '#/components/schemas/EmptyAdditionalErrors' Account: type: object required: - resourceId - currency properties: resourceId: type: string description: The account ID. example: '123' maxLength: 255 iban: description: The IBAN of the account. For some providers, certain accounts might not have this information (e.g., an account for a credit card). type: string example: GB29NWBK60161331926819 maxLength: 34 bban: type: string description: The local ASPSP identifier of the account. example: '29823529' maxLength: 30 accountNumber: type: string description: The account number. Used to identify the account in the United Kingdom. minLength: 8 maxLength: 8 example: '29823529' sortCode: type: string description: The sort code. Used to identify the account in the United Kingdom. minLength: 6 maxLength: 6 example: '902127' currency: type: string description: The account currency in ISO 4217 alpha-3 currency code. example: EUR maxLength: 3 minLength: 3 paymentSchemes: type: array description: A list of possible [Payment Schemes](#appendix--enum--payment-schemes) when the account is used as debtor during the payment. items: type: string example: SCT description: Describes which payment scheme is used. See [Payment Schemes](#appendix--enum--payment-schemes) for possible values. enum: - FPS - BACS - CHAPS - SCT - SCTI - SWIFT name: type: string description: The name of the account. example: Main checking account maxLength: 255 UnauthorizedError: type: object description: The unauthorized error object example. required: - code - requestId - timestamp properties: code: type: string description: The message code to explain the nature of the underlying error. example: TOKEN_INVALID title: type: string description: The short, human-readable description of the error. example: OAuth token not valid maxLength: 70 timestamp: type: string description: ISO-8601 timestamp example: 2023-04-19T13:33:42+0000 requestId: type: string description: The request ID as communicated in the `X-Request-Id` header. example: 39c97edf-7469-42af-96ca-169a902fd8a6 additionalErrors: $ref: '#/components/schemas/EmptyAdditionalErrors' Error: type: object description: The generic error object example. required: - code - requestId - timestamp properties: code: type: string description: The message code to explain the nature of the underlying error. example: FORMAT_ERROR title: type: string description: The short, human-readable description of the error. example: Error in provided content maxLength: 70 timestamp: type: string description: ISO-8601 timestamp example: 2023-04-19T13:33:42+0000 requestId: type: string description: The request ID as communicated in the `X-Request-Id` header. example: 39c97edf-7469-42af-96ca-169a902fd8a6 additionalErrors: type: array description: Might be used if more than one error is to be communicated. items: $ref: '#/components/schemas/AdditionalError' AccountResponse: type: object required: - account properties: account: $ref: '#/components/schemas/Account' AccessExceededError: type: object description: The forbidden error object example. required: - code - requestId - timestamp properties: code: type: string description: The message code to explain the nature of the underlying error. example: ACCESS_EXCEEDED title: type: string description: The short, human-readable description of the error. example: Exceeded API limit maxLength: 70 timestamp: type: string description: ISO-8601 timestamp example: 2023-04-19T13:33:42+0000 requestId: type: string description: The request ID as communicated in the `X-Request-Id` header. example: 39c97edf-7469-42af-96ca-169a902fd8a6 additionalErrors: $ref: '#/components/schemas/EmptyAdditionalErrors' AccountBalanceList: type: object required: - balances properties: balances: type: array description: The array containing a list of balances. items: $ref: '#/components/schemas/AccountBalance' AccountBalance: type: object description: The object with the balance amount and currency. required: - balanceAmount - balanceType properties: balanceAmount: $ref: '#/components/schemas/StructuredAmount' balanceType: type: string description: '[Balance type](#appendix--enum--balance-type)' example: interimBooked enum: - openingBooked - interimAvailable - interimBooked - forwardAvailable - nonInvoiced StructuredAmount: description: An amount with a currency. type: object required: - amount - currency properties: amount: type: string description: The amount of funds in the balance. The decimal separator is dot. example: '123.22' maxLength: 14 currency: type: string description: The account currency in ISO 4217 alpha-3 currency code. example: EUR maxLength: 3 minLength: 3 RemittanceInformationStructured: type: object required: - reference description: The reference as contained in the structured remittance reference structure. properties: reference: type: string description: The actual reference. example: ORD123 maxLength: 35 referenceType: type: string description: The remittance information type. example: UNSTRUCTURED maxLength: 35 AdditionalError: type: object description: The error object providing additional error information. required: - code properties: code: type: string description: The message code to explain the nature of the underlying error. example: FORMAT_ERROR title: type: string description: The short, human-readable description of the error. example: Error in provided content maxLength: 70 details: type: string description: The longer, human-readable description of the error. example: Longer description of error maxLength: 500 AccountListResponse: type: object required: - accounts properties: accounts: type: array description: The list of accounts. items: $ref: '#/components/schemas/Account' AccountTransactionList: type: object description: The object containing a list of booked and pending transactions. properties: booked: type: array description: A list of booked transactions of the account. items: $ref: '#/components/schemas/AccountTransaction' pending: type: array description: A list of pending transactions of the account. items: $ref: '#/components/schemas/AccountTransaction' AccountTransaction: type: object required: - transactionAmount properties: transactionId: type: string description: The transaction ID. example: '123' maxLength: 255 creditorName: type: string description: The name of the creditor/receiver. example: John Doe maxLength: 70 creditorAccount: $ref: '#/components/schemas/AccountReference' debtorName: type: string description: The name of the debtor/sender. example: John Doe maxLength: 70 debtorAccount: $ref: '#/components/schemas/AccountReference' remittanceInformationUnstructured: type: string description: An unstructured reference of the transaction. example: Ref1234 maxLength: 140 remittanceInformationStructured: $ref: '#/components/schemas/RemittanceInformationStructured' transactionAmount: $ref: '#/components/schemas/StructuredAmount' valueDate: type: string description: The date in the YYYY-MM-DD format at which assets become available. example: '2022-10-10' maxLength: 10 minLength: 10 bookingDate: type: string description: The date when an entry is posted to an account in the YYYY-MM-DD format. example: '2022-10-10' maxLength: 10 minLength: 10 securitySchemes: tokenAuth: type: http scheme: bearer clientId: type: apiKey in: header name: X-Client-ID