openapi: 3.2.0 info: license: name: Yodlee Developer License url: https://developer.yodlee.com/terms/condition#_Services_1 contact: email: developer@yodlee.com description: This file describes the Yodlee Platform APIs using the swagger notation. termsOfService: https://developer.yodlee.com/terms/condition title: Yodlee Core Provider Accounts API version: 1.1.0 servers: - url: / tags: - name: Provider Accounts description: Provider Accounts API paths: /providerAccounts/{providerAccountId}/preferences: put: summary: Update Preferences deprecated: false description: 'This endpoint is used to update preferences like data extracts and auto refreshes without triggering refresh for the providerAccount. Setting isDataExtractsEnabled to false will not trigger data extracts notification and dataExtracts/events will not reflect any data change that is happening for the providerAccount. Modified data will not be provided in the dataExtracts/userData endpoint. Setting isAutoRefreshEnabled to false will not trigger auto refreshes for the provider account.' operationId: updatePreferences responses: 400: description: 'Y800 : Invalid value for preferences
Y800 : Invalid value for preferences.isDataExtractsEnabled
Y800 : Invalid value for preferences.isAutoRefreshEnabled
Y807 : Resource not found
Y830 : Data extracts feature has to be enabled to set preferences.isDataExtractsEnabled as true
Y830 : Auto refresh feature has to be enabled to set preferences.isAutoRefreshEnabled as true
Y868 : No action is allowed, as the data is being migrated to the Open Banking provider
' content: application/json;charset=UTF-8: schema: $ref: '#/components/schemas/YodleeError' 401: description: Unauthorized 204: description: OK 404: description: Not Found parameters: - in: path name: providerAccountId description: providerAccountId required: true schema: type: integer format: int64 tags: - Provider Accounts requestBody: content: application/json: schema: $ref: '#/components/schemas/ProviderAccountPreferencesRequest' description: preferences required: true /providerAccounts/{providerAccountId}: get: summary: Get Provider Account Details deprecated: false description: 'The get provider account details service is used to learn the status of adding accounts and updating accounts. This service has to be called continuously to know the progress level of the triggered process. This service also provides the MFA information requested by the provider site. When include = credentials, questions is passed as input, the service returns the credentials (non-password values) and questions stored in the Yodlee system for that provider account. Note: The password and answer fields are not returned in the response.' operationId: getProviderAccount responses: 200: description: OK content: application/json;charset=UTF-8: schema: $ref: '#/components/schemas/ProviderAccountDetailResponse' 400: description: 'Y800 : Invalid value for providerAccountId
Y816 : questions can only be requested for questionAndAnswer Supported Sites' content: application/json;charset=UTF-8: schema: $ref: '#/components/schemas/YodleeError' 401: description: Unauthorized 404: description: Not Found parameters: - in: query allowEmptyValue: false name: include description: include credentials,questions required: false schema: type: string - in: path name: providerAccountId description: providerAccountId required: true schema: type: integer format: int64 - in: query allowEmptyValue: false name: requestId description: The unique identifier for the request that returns contextual data required: false schema: type: string tags: - Provider Accounts delete: summary: Delete Provider Account deprecated: false description: 'The delete provider account service is used to delete a provider account from the Yodlee system. This service also deletes the accounts that are created in the Yodlee system for that provider account. This service does not return a response. The HTTP response code is 204 (Success with no content).' operationId: deleteProviderAccount responses: 200: description: OK 400: description: 'Y800 : Invalid value for providerAccountId
Y868 : No action is allowed, as the data is being migrated to the Open Banking provider
' content: application/json;charset=UTF-8: schema: $ref: '#/components/schemas/YodleeError' 401: description: Unauthorized 404: description: Not Found parameters: - in: path name: providerAccountId description: providerAccountId required: true schema: type: integer format: int64 tags: - Provider Accounts /providerAccounts: post: summary: Add Account deprecated: false description: 'The add account service is used to link the user''s account with the provider site in the Yodlee system. Providers that require multifactor authentication or open banking are also supported by this service. The response includes the Yodlee generated ID (providerAccountId) of the account along with the refresh information. Open Banking Implementation Notes: To link the user''s account of the Open Banking provider site in the Yodlee system, pass the field entity that contains: 1. id - From the authParameters provided in the get provider details service 2. value - From the redirect URL of the Open Banking site Credential-based Implementation Notes: 1. The loginForm or the field array are the objects under the provider object, obtained from the Get Provider Details service response. 2. The credentials provided by the user should be embedded in the loginForm or field array object. 3. While testing the PKI feature, encrypt the credentials using the Encryption Utility. 4. The data to be retrieved from the provider site can be passed using datasetName or dataset. If datasetName is passed, all the attributes that are implicitly configured for the dataset will be retrieved. 5. If the customer has not subscribed to the REFRESH event webhooks notification for accounts that require multifactor authentication (MFA), the get providerAccount service has to be called continuously till the login form (supported types are token, question & answer, and captcha) is returned in the response. 6. The Update Account service should be called to post the MFA information to continue adding the account. Generic Implementation Notes: 1. Refer to the Add Account flow chart for implementation. 2. The get provider account details has Webhooks Support. If the customer has subscribed to the REFRESH event notification and has invoked this service to add an account, relevant notifications will be sent to the callback URL. 3. If you had not subscribed for notifications, the Get Provider Account details service has to be polled continuously till the account addition status is FAILED or PARTIAL_SUCCESS or SUCCESS. 4. A dataset may depend on another dataset for retrieval, so the response will include the requested datasets and the dependent datasets. It is necessary to check all the dataset additional statuses returned in the response, as the provider account status is drawn from the dataset additional statuses. 5. Pass linkedProviderAccountId in the input to link a user''s credential-based providerAccount with the open banking providerAccount. Ensure that the credential-based providerAccount belongs to the same institution. 6. The content type has to be passed as application/json in the body parameter. 7. Only for the REDSYS/PSD2 UK OB integration, passing the state parameter is mandatory during the add or update account process. The state parameter key can be found in the authParameter attribute of the get provider or get provider details API response. The value for the state parameter is present in the Authorization URL. Append the callback URL to the state parameter while adding or updating an account. 8. configName is included as an optional parameter in the body of the request, which is used to enable the billing metrics for the customers based on the instance configs, when logged in with client credentials.' operationId: linkProviderAccount responses: 200: description: OK content: application/json;charset=UTF-8: schema: $ref: '#/components/schemas/AddedProviderAccountResponse' 400: description: 'Y803 : providerId is mandatory
Y803 : Invalid value for credentialsParam
Y400 : id and value in credentialsParam are mandatory
Y901 : Service not supported' content: application/json;charset=UTF-8: schema: $ref: '#/components/schemas/YodleeError' 401: description: Unauthorized 404: description: Not Found parameters: - in: query allowEmptyValue: false name: providerId description: providerId required: true schema: type: integer format: int64 tags: - Provider Accounts requestBody: content: application/json: schema: $ref: '#/components/schemas/ProviderAccountRequest' description: loginForm or field entity required: true get: summary: Get Provider Accounts deprecated: false description: 'The get provider accounts service is used to return all the provider accounts added by the user. This includes the failed and successfully added provider accounts.' operationId: getAllProviderAccounts responses: 200: description: OK content: application/json;charset=UTF-8: schema: $ref: '#/components/schemas/ProviderAccountResponse' 401: description: Unauthorized 404: description: Not Found parameters: - in: query name: include description: include required: false schema: type: string - in: query allowEmptyValue: false name: providerIds description: Comma separated providerIds. required: false schema: type: string tags: - Provider Accounts put: summary: Update Account deprecated: false description: 'Credential-based Implementation Notes: The update account API is used to: • Retrieve the latest information for accounts that belong to one providerAccount from the provider site.' operationId: editCredentialsOrRefreshProviderAccount responses: 200: description: OK content: application/json;charset=UTF-8: schema: $ref: '#/components/schemas/UpdatedProviderAccountResponse' 400: description: 'Y805 : Multiple providerAccountId not supported for updating credentials
Y800 : Invalid value for credentialsParam
Y400 : id and value in credentialsParam are mandatory
Y806 : Invalid input
Y823 : Credentials are not applicable for real estate aggregated / manual accounts
Y868 : No action is allowed, as the data is being migrated to the Open Banking provider
' content: application/json;charset=UTF-8: schema: $ref: '#/components/schemas/YodleeError' 401: description: Unauthorized 404: description: Not Found parameters: - in: query allowEmptyValue: false name: providerAccountIds description: comma separated providerAccountIds required: true schema: type: string tags: - Provider Accounts requestBody: content: application/json: schema: $ref: '#/components/schemas/ProviderAccountRequest' description: loginForm or field entity /providerAccounts/refresh: put: summary: Refresh Provider Account deprecated: false description: 'This api service will allow you to refresh the Non-MFA provider accounts against a configName, i.e refresh will respect the configurations of the configName while refreshing the account. Note: this service will only work with FastLink 4 users.' operationId: refreshProviderAccount responses: 201: description: CREATED content: application/json;charset=UTF-8: schema: $ref: '#/components/schemas/RefreshProviderAccountResponse' 400: description: 'Y800 : Invalid value for configName
Y803 : configName required
Y812 : Required field/value providerAccountId missing in the request
Y800 : Invalid value for providerAccountId
Y825 : Update not allowed. Reason: providerAccountId {id} REFRESHED_RECENTLY
' content: application/json;charset=UTF-8: schema: $ref: '#/components/schemas/YodleeError' 401: description: Unauthorized 404: description: Not Found tags: - Provider Accounts requestBody: content: application/json: schema: $ref: '#/components/schemas/ProviderAccountRefreshRequest' description: refreshRequest required: true /providerAccounts/profile: get: summary: Get User Profile Details deprecated: true description: 'Refer GET /verification/holderProfile The get provider accounts profile service is used to return the user profile details that are associated to the provider account.' operationId: getProviderAccountProfiles responses: 200: description: OK content: application/json;charset=UTF-8: schema: $ref: '#/components/schemas/ProviderAccountUserProfileResponse' 401: description: Unauthorized 404: description: Not Found parameters: - in: query allowEmptyValue: false name: providerAccountId description: Comma separated providerAccountIds. required: false schema: type: string tags: - Provider Accounts components: schemas: StatusLink: type: object title: StatusLink properties: methodType: readOnly: true type: string rel: readOnly: true type: string href: readOnly: true type: string ProviderAccountDetailResponse: type: object title: ProviderAccountDetailResponse properties: providerAccount: readOnly: true type: array items: $ref: '#/components/schemas/ProviderAccountDetail' ProviderAccountRefreshRequest: type: object title: ProviderAccountRefreshRequest required: - configName - providerAccountIds properties: configName: description: The name of configuration created at the time onboarding or configuration creation. type: string providerAccountIds: description: Comma separated providerAccountIds. type: array items: format: int64 type: integer ProviderAccountUserProfileResponse: type: object title: ProviderAccountUserProfileResponse properties: providerAccount: readOnly: true type: array items: $ref: '#/components/schemas/ProviderAccountProfile' ProviderAccountPreferences: type: object title: ProviderAccountPreferences properties: isDataExtractsEnabled: description: Indicates if the updates to the provider account should be part of the data extracts event notification or the data extract data retrieval service.

Endpoints: type: boolean linkedProviderAccountId: format: int64 description: LinkedproviderAccountd is a providerAccountId linked by the user to the primary provider account.
LinkedProviderAccountId and the providerAccountId belongs to the same institution.

Endpoints: type: integer isAutoRefreshEnabled: description: Indicates if auto-refreshes have to be triggered for the provider account.

Endpoints: type: boolean AccountDataset: type: object title: AccountDataset properties: lastUpdated: description: 'Indicate when the dataset is last updated successfully for the given provider account.

Account Type: Aggregated
Endpoints:' readOnly: true type: string updateEligibility: description: 'Indicate whether the dataset is eligible for update or not.

Account Type: Aggregated
Endpoints:Applicable Values
' readOnly: true type: string enum: - ALLOW_UPDATE - ALLOW_UPDATE_WITH_CREDENTIALS - DISALLOW_UPDATE additionalStatus: description: 'The status of last update attempted for the dataset.

Account Type: Aggregated
Endpoints:Applicable Values
' readOnly: true type: string enum: - LOGIN_IN_PROGRESS - DATA_RETRIEVAL_IN_PROGRESS - ACCT_SUMMARY_RECEIVED - AVAILABLE_DATA_RETRIEVED - PARTIAL_DATA_RETRIEVED - DATA_RETRIEVAL_FAILED - DATA_NOT_AVAILABLE - ACCOUNT_LOCKED - ADDL_AUTHENTICATION_REQUIRED - BETA_SITE_DEV_IN_PROGRESS - CREDENTIALS_UPDATE_NEEDED - INCORRECT_CREDENTIALS - PROPERTY_VALUE_NOT_AVAILABLE - INVALID_ADDL_INFO_PROVIDED - REQUEST_TIME_OUT - SITE_BLOCKING_ERROR - UNEXPECTED_SITE_ERROR - SITE_NOT_SUPPORTED - SITE_UNAVAILABLE - TECH_ERROR - USER_ACTION_NEEDED_AT_SITE - SITE_SESSION_INVALIDATED - NEW_AUTHENTICATION_REQUIRED - DATASET_NOT_SUPPORTED - ENROLLMENT_REQUIRED_FOR_DATASET - CONSENT_REQUIRED - CONSENT_EXPIRED - CONSENT_REVOKED - INCORRECT_OAUTH_TOKEN - MIGRATION_IN_PROGRESS nextUpdateScheduled: description: 'Indicates when the next attempt to update the dataset is scheduled.

Account Type: Aggregated
Endpoints:' readOnly: true type: string name: description: 'The name of the dataset requested from the provider site

Account Type: Manual
Endpoints:Applicable Values
' type: string enum: - BASIC_AGG_DATA - ADVANCE_AGG_DATA - ACCT_PROFILE - DOCUMENT lastUpdateAttempt: description: 'Indicate when the last attempt was performed to update the dataset for the given provider account

Account Type: Aggregated
Endpoints:' readOnly: true type: string additionalStatusErrorCode: description: 'The status error code of last update attempted for the dataset.

Account Type: Aggregated
Endpoints:' readOnly: true type: string ProviderAccount: type: object title: ProviderAccount properties: preferences: description: User preference values for Auto-Refresh and DataExtracts Notification

Endpoints: readOnly: true $ref: '#/components/schemas/ProviderAccountPreferences' oauthMigrationStatus: description: Indicates the migration status of the provider account from screen-scraping provider to the Open Banking provider.

Endpoints: readOnly: true type: string enum: - IN_PROGRESS - TO_BE_MIGRATED - COMPLETED - MIGRATED isManual: description: Indicates whether account is a manual or aggregated provider account.

Endpoints: readOnly: true type: boolean isRealTimeMFA: description: Attribute to specify whether the user has to input(credentials/MFA) for refreshing an account

Endpoints: