Salt Edge PSD2 Compliance Logo

V1

Tokens

These endpoints are responsible for implementing authentication and authorization of PSU. Process of token creation starts once PSU grants his consent to TPP. At the end of authorization, Connector should issue an access_token which can be used for furhter actions. You can find below sequence diagrams represeting embedded and oauth authorization flows.

OAuth Authentication Flow OAuth Authentication Flow
Embedded Authentication Flow Embedded Authentication Flow

Create

Create an access token with a set of access rights, named scopes. As a result, Connector should send an update or fail callback to Salt Edge PSD2 Compliance with the result of the operation, be it a success, fail or request for additional steps.

CURL

curl -i  \ 
 -H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7ImFwcF9uYW1lIjoiRXhhbXBsZSBOYW1lIiwicHJvdmlkZXJfY29kZSI6ImRlbW9iYW5rIiwib3JpZ2luYWxfcmVxdWVzdCI6eyJjbGllbnRfand0IjoiQmVhcmVyIGV5SjBlWEFpT2lKS1YxUWlMQ0poYkdjaU9pSlNVekkxTmlKOS5leUprWVhSaElqcDdJbkJ5YjNacFpHVnlYMk52WkdVaU9pSmtaVzF2WW1GdWF5SXNJbk5qYjNCbGN5STZXeUpoWTJOdmRXNTBjeUlzSW5SeVlXNXpZV04wYVc5dWN5SXNJbXQ1WXlJc0luQmhlVzFsYm5Seklpd2lablZ1WkhOZllYWmhhV3hoWW1sc2FYUjVJaXdpZEhKMWMzUmxaRjlpWlc1bFptbGphV0Z5YVdWeklsMHNJbU52Ym5ObGJuUmZjR1Z5YVc5a1gyUmhlWE1pT2prd0xDSm1iM0pqWlY5elkyRWlPbVpoYkhObExDSmpjbVZrWlc1MGFXRnNjeUk2ZXlKMGVYQmxJam9pYjJGMWRHZ2lMQ0poZFhSb2IzSnBlbUYwYVc5dVgzUjVjR1VpT2lKUVUwUmZRVWxUVUNKOUxDSnlaV1JwY21WamRGOTFjbXdpT2lKb2RIUndjem92TDNWelpYSXVkMmxzYkM1aVpTOXlaV1JwY21WamRHVmtMMmhsY21VaWZTd2laWGh3SWpveE5UYzBNRGt6TWpFd2ZRLk9lNFdIaFVyaFE0cHNmc2hUR2kzeWEyanRJTEJIY1EwSDZFYlktbjlIdWx3YjI4UVhDTm9kLUN5MlVLYlNEZjRxX2hrckdyQm5TeGd5SWhEQzNXbThNYkRSQ0tFRlFtci1LTko4M3ZYTnJSd29seVRZdUR3MGxJVHBySVFYU1pwel8xdWd2R0NnN2tnSEIzSlV0M0puQ2dNTzVlTGtZenpmUmN6V2NnNnNwdXpCWUk0Qi1yNHEwajFCOXp6Y0RKQmYxZkg1aWdaMW5QYm9FR21RUmJyc1hlMkNIWnEwT1BGSUNNbkNrR1pTdkRJbkNHdXVRMGtEUnhVNnZ4VF9WMFNNRWRHUk9SVmtZQnk2WEJ3aU1VdWFQM3JrWXF0NmN2c2pUeVZEd256N214OVF1T3JBSERtOXVVNHRWMnBGQ2dYdXpLdzlSQXBreFZETi1OUG9RaEl1ZyIsImNsaWVudF9wYXlsb2FkIjp7ImRhdGEiOnsiY29uc2VudF9wZXJpb2RfZGF5cyI6OTAsImNyZWRlbnRpYWxzIjp7ImF1dGhvcml6YXRpb25fdHlwZSI6ImxvZ2luX3Bhc3N3b3JkIn0sInByb3ZpZGVyX2NvZGUiOiJkZW1vYmFuayIsInNjb3BlcyI6WyJhY2NvdW50cyIsInRyYW5zYWN0aW9ucyIsImt5YyIsInBheW1lbnRzIiwiZnVuZHNfYXZhaWxhYmlsaXR5IiwidHJ1c3RlZF9iZW5lZmljaWFyaWVzIl19LCJleHAiOjE1NzQwOTMyMTB9fSwic2Vzc2lvbl9zZWNyZXQiOiI3MmF0a1R3X1l6VmFpQ0FxeDJ1aiJ9LCJleHAiOjE3MzcyNDE5NzIsImlzcyI6InByaW9yYS5zYWx0ZWRnZS5jb20ifQ.Sv2RhikvhRAkPULk_YsCPYe63xk39YUpzU6esfa6fVncL-Mhk51uOcgk88mQ-ldsBfYMEHR0GFbdtw6k1IO5UPdVB9nbnteGNZVF18F3JRhKJL5UGMjh-1rbibtRBfWPTMWNIPItvaVnOfavqvgU9G-6tyOA-fm90OCoLHxLzs9T8tg7lVNZi80hzZPxfx8TkGGTrcLipv_l0Bk7K6KjV5DbGX5FMeF3qNYZguXteeDAaFn0A64TY7Y2erJeQYMdqoRNdDG4U4j-Cx-n0jGb0imBT71nDHilBk8VVjHEW9D75tqgEywDs-5G0v1qSb2NHpgIgFrsK-eineSqGp8slw" \ 
 -H "Accept: application/json" \ 
 -H "Content-Type: application/json" \ 
 -H "Client-Id: 771" \ 
 -X POST "https://your.connector.url/api/priora/v1/tokens/create"

Example of request parameters

Request

POST https://your.connector.url/api/priora/v1/tokens/create

Headers
Header Type Description
Authorization string, required JSON Web Token containing payload, signed using RSA256 and application.private_key.
Accept string, required Media type that is acceptable for the response. Allowed values: application/json
Content-Type string, required The media type of the body of the request. Allowed values: application/json
Client-Id integer, required Client application identifier in Salt Edge PSD2 Compliance. Should be used to get public key for Authorization header validation.
Consent-Id integer, optional ID of the corresponding consent object as returned by an Account Information Consent Request.
Unpacked Request Authorization
Response headers
Header Type Description
Retry-After integer, optional Amount of time in seconds after which Salt Edge PSD2 Compliance Solution resends the previously failed request.
Response

Upon successful request, 200 status code should be returned.


Revoke

Revoke an already existing and active access token.

CURL

curl -i  \ 
 -H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7InByb3ZpZGVyX2NvZGUiOiJkZW1vYmFuayIsInNlc3Npb25fc2VjcmV0IjoiaDI5Yzk0MVBRNF9rNl82UG4tbzUifSwiZXhwIjoxNzM3MjQxOTcyLCJpc3MiOiJwcmlvcmEuc2FsdGVkZ2UuY29tIn0.kclER0v8VoedAVdxLpNiHM8FSJXYQoI0lPLaPZaBmaYZk8JQ6ZLzp3aC_1JObAJzH5bEeBhStuoW2g2V6qdufAXMFuG8P_TInTKwlrXBou2Om5pigf0j1qJPREOYvTri1jjR8EyFtOjQFnAgFmZZjOt2axHvh4JQLyGxXIF2Im85Y6DtlYCmWIqWor2EctBLccYqWw6RkO0SisXxGR18iw8Xq25hXWhuM_hNzmQok-oI2sbvaP2MSsqW-be9IEZ7pG3nwbapSM8ZcsPVGKiWPkKdWP52XZTFaV0-JsEMNStxwsKoAXESfojNgK1VIxCIlfHzs8q8CAN-XyOEevKXWw" \ 
 -H "Access-Token: 65adc909f5676f3902787ecb6f379c1c48bfc18a222157713808274b100b9e255f7b4b59a3ecd7689cb2abe26f8705dfd89b7a0cc9e9a07a587dc64a7c4572ad" \ 
 -H "Accept: application/json" \ 
 -H "Content-Type: application/json" \ 
 -H "Client-Id: 843" \ 
 -X POST "https://your.connector.url/api/priora/v1/tokens/revoke"

Example of request parameters

{"data":{"provider_code":"demobank","session_secret":"h29c941PQ4_k6_6Pn-o5"},"exp":1574093209}
Request

POST https://your.connector.url/api/priora/v1/tokens/revoke

Headers
Header Type Description
Authorization string, required JSON Web Token containing payload, signed using RSA256 and application.private_key.
Access-Token string, required The token which is created by a connector as a result of successful authentication.
Accept string, required Media type that is acceptable for the response. Allowed values: application/json
Content-Type string, required The media type of the body of the request. Allowed values: application/json
Client-Id integer, required Client application identifier in Salt Edge PSD2 Compliance. Should be used to get public key for Authorization header validation.
Consent-Id integer, optional ID of the corresponding consent object as returned by an Account Information Consent Request.
Unpacked Request Authorization
exp
integer, required
The lifetime of the request in timestamp UTC format. Values greater than: Current time.
Response headers
Header Type Description
Retry-After integer, optional Amount of time in seconds after which Salt Edge PSD2 Compliance Solution resends the previously failed request.
Response

Upon successful request, 200 status code should be returned.


Reconnect Deprecated

This endpoint is invoked when a TPP asks to refresh an active token. ASPSP should determine behavior for this action: ASPSP can just return a new token sending it into session/success endpoint, ask for MFA using sessions/update endpoint or just deny using sessions/fail endpoint.

CURL

curl -i  \ 
 -H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7InByb3ZpZGVyX2NvZGUiOiJkZW1vYmFuayIsInNlc3Npb25fc2VjcmV0IjoieVU5VzYtQnU5dHpZTjJHWGlFckYifSwiZXhwIjoxNzM3MjQxOTczLCJpc3MiOiJwcmlvcmEuc2FsdGVkZ2UuY29tIn0.VaBS5cmfPmDdSL3cEnGi8nsyP3Ti06A5yyJiAe0DFERkRh8PxSd7ucUc-kxqVp6U8TQMrsF3HU1HnPW2Q3D1JA0vPROgm1uKi1fKGCOz8sKdg3W63t_P5ZaY4jiJZC3JkFTJ8MGHPSVzw6XKZqqlnhv-L9nHNFK9H-cqZoCZjzaAGZLF2zRPhuaqCjtbPxu5ze_GBizu-K3_b7X-kGnCrXYLQ27HFVmmcDx3d4dJpwMt6HQQ9cr6Our0FZvNi9EBPtPoOyp1jEY3vgAElzGPxh_yHwColB2kyqBcvKgcAPZFInlrrwGgFwFj_o24338hkPPJeIejY3GIMVi76pgcog" \ 
 -H "Access-Token: b8a2d37ea0ed40716deebb7c5fff81ce096c87141d45ef39cc7c4b2c455b09c8e338c1190267ab1bf56ffa6840662e2f3d3967a13985d0e0bd777059814e6954" \ 
 -H "Accept: application/json" \ 
 -H "Content-Type: application/json" \ 
 -H "Client-Id: 718" \ 
 -X POST "https://your.connector.url/api/priora/v1/tokens/reconnect"

Example of request parameters

{"data":{"provider_code":"demobank","session_secret":"yU9W6-Bu9tzYN2GXiErF"},"exp":1574093210}
Request

POST https://your.connector.url/api/priora/v1/tokens/reconnect

Headers
Header Type Description
Authorization string, required JSON Web Token containing payload, signed using RSA256 and application.private_key.
Access-Token string, required The token which is created by a connector as a result of successful authentication.
Accept string, required Media type that is acceptable for the response. Allowed values: application/json
Content-Type string, required The media type of the body of the request. Allowed values: application/json
Client-Id integer, required Client application identifier in Salt Edge PSD2 Compliance. Should be used to get public key for Authorization header validation.
Consent-Id integer, optional ID of the corresponding consent object as returned by an Account Information Consent Request.
Unpacked Request Authorization
exp
integer, required
The lifetime of the request in timestamp UTC format. Values greater than: Current time.
Response headers
Header Type Description
Retry-After integer, optional Amount of time in seconds after which Salt Edge PSD2 Compliance Solution resends the previously failed request.
Response

Upon successful request, 200 status code should be returned.


Confirm

This endpoint is used for processing additional interactive steps in the process of access token creation. As a result, Connector should send a success or fail callback to Salt Edge PSD2 Compliance with result of the operation.

CURL

curl -i  \ 
 -H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7InNlc3Npb25fc2VjcmV0Ijoic2NfZkt0VHRvSGM5SGtKc3R5ZnciLCJwcm92aWRlcl9jb2RlIjoiZGVtb2JhbmsiLCJvcmlnaW5hbF9yZXF1ZXN0Ijp7ImNsaWVudF9qd3QiOiJCZWFyZXIgZXlKMGVYQWlPaUpLVjFRaUxDSmhiR2NpT2lKU1V6STFOaUo5LmV5SmtZWFJoSWpwN0ltTnlaV1JsYm5ScFlXeHpJanA3SW5SNWNHVWlPaUp2WVhWMGFDSjlmU3dpWlhod0lqb3hOVGMwTURrek1qQTVmUS5IYUoyWksxVlZvUXJoUkZsSVBaTk01dzRtajhQVG9sT3BBbHJFRU9UY2VGSWFrYzQ1blFMd1BpUkNyUE9OQWl6blRJMTI1MEVkb01Vd1JmYVd6MUFRMEZBdi1Xc1dmb3ltTjNiaVljWlpwNEZlQXJMVzgyd3pzREZXVTlWV1VIU0h4MnpMX0k3dnZWaGxKY1BiX3R6SVJWcVJSTFRNTnp2SjJPX1hYZ0hPeG1TQXF6Q3B1UTdBVUV6QTVZdUQxWjgxZDVPcTMtNzNmMGRjenc1Nnk2cTV4blY4NnJuZ2s5M1FpYTdGR3oyRi1HY3dJbld6R0lsV2dtUXQxYk13SHltNnJ1RVVzeUxOZ09LanVObnFGaEtwOTh2V1FpaFFuVlZBdmU3bGNoUG9rWWFYMklGU0k4Z2FkT2FTZ1dyQ2FvMngySU1qQkZxMHZvaFYxQnFZbEVLYVEiLCJjbGllbnRfcGF5bG9hZCI6eyJkYXRhIjp7ImNyZWRlbnRpYWxzIjp7InNtc19waW5jb2RlIjoiNDg5NiJ9fSwiZXhwIjoxNTc0MDkzMjA5fX19LCJleHAiOjE3MzcyNDE5NzMsImlzcyI6InByaW9yYS5zYWx0ZWRnZS5jb20ifQ.FTYffPcvuaRlvGBasbsum07h4D9W3XnjdUk63lkzgTihX7SUGwbDsdmihCWikIOdGTYk6w37SFshPOjRXe028k1qQeCHWYziuEjppVv9QGfzN1-5-GUAUaWwMgIC5ie4GHgWP46ivwK2J0aFqH41ERkhqfjg2vkB7FX0R1b8NiV_Ix3dMml5t4z5oFVqwDHJ-MqaxZanSfFBYs_yi076Ak29025pypRVgDHtgNVJgn_1ryjlto_xlat5aE-31FgHJ5NkIEvr4HrsLxWrgVJ2UHcDfAgqCxfQzfOnHIdU1t9Mf3MXwlS7EQRvVvl5QWXkkSUCd8tq8A8Ab2ZwekYFGw" \ 
 -H "Accept: application/json" \ 
 -H "Content-Type: application/json" \ 
 -H "Client-Id: 501" \ 
 -X POST "https://your.connector.url/api/priora/v1/tokens/confirm"

Example of request parameters

{"data":{"session_secret":"sc_fKtTtoHc9HkJstyfw","provider_code":"demobank","original_request":{"client_jwt":"Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7ImNyZWRlbnRpYWxzIjp7InR5cGUiOiJvYXV0aCJ9fSwiZXhwIjoxNTc0MDkzMjA5fQ.HaJ2ZK1VVoQrhRFlIPZNM5w4mj8PTolOpAlrEEOTceFIakc45nQLwPiRCrPONAiznTI1250EdoMUwRfaWz1AQ0FAv-WsWfoymN3biYcZZp4FeArLW82wzsDFWU9VWUHSHx2zL_I7vvVhlJcPb_tzIRVqRRLTMNzvJ2O_XXgHOxmSAqzCpuQ7AUEzA5YuD1Z81d5Oq3-73f0dczw56y6q5xnV86rngk93Qia7FGz2F-GcwInWzGIlWgmQt1bMwHym6ruEUsyLNgOKjuNnqFhKp98vWQihQnVVAve7lchPokYaX2IFSI8gadOaSgWrCao2x2IMjBFq0vohV1BqYlEKaQ","client_payload":{"data":{"credentials":{"sms_pincode":"4896"}},"exp":1574093209}}},"exp":1574093209}
Request

POST https://your.connector.url/api/priora/v1/tokens/confirm

Headers
Header Type Description
Authorization string, required JSON Web Token containing payload, signed using RSA256 and application.private_key.
Accept string, required Media type that is acceptable for the response. Allowed values: application/json
Content-Type string, required The media type of the body of the request. Allowed values: application/json
Client-Id integer, required Client application identifier in Salt Edge PSD2 Compliance. Should be used to get public key for Authorization header validation.
Consent-Id integer, optional ID of the corresponding consent object as returned by an Account Information Consent Request.
Unpacked Request Authorization
exp
integer, required
The lifetime of the request in timestamp UTC format. Values greater than: Current time.
Response headers
Header Type Description
Retry-After integer, optional Amount of time in seconds after which Salt Edge PSD2 Compliance Solution resends the previously failed request.
Response

Upon successful request, 200 status code should be returned.


Cancel

Cancel any access token that is in the process of enrollment, meaning it has not been confirmed yet.

CURL

curl -i  \ 
 -H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7InNlc3Npb25fc2VjcmV0IjoiZzRmeV9XNHh5YzZUUktzWVNBTXQifSwiZXhwIjoxNzM3MjQxOTczLCJpc3MiOiJwcmlvcmEuc2FsdGVkZ2UuY29tIn0.r8u57N4yyfhskX0PRkhZ0F3mzKIMTWkD_AfqzpspMswCLzbW5KzzcR1UvluC6TGYXPyirvlS_NwfVvAdpIfk7-182farRZJTdUz-EdFzBEAcmKBvgtkB6XUKjkTYBR71s2Dm0yWE3Kfx6b3UfyIuzNq9pyHat5JhLTxZApjsK0NX4M-iQR_z-vXNCzXjdFWjpUHgE1-UAUXZ3vRk0DVpcRJi8T9pf-MMTtXgtxIgqa52KnMGeKNUS0c9lVhKfhRFSaool-a8XUKDjU4MaucuCBg3HEgIzDbcIQSkM1DcmVDnOixEwW9nOmzBQbpq_RfTxgay8y7raqzEzeXs5eZ3Jw" \ 
 -H "Accept: application/json" \ 
 -H "Content-Type: application/json" \ 
 -H "Client-Id: 830" \ 
 -X POST "https://your.connector.url/api/priora/v1/tokens/cancel"

Example of request parameters

{"data":{"session_secret":"g4fy_W4xyc6TRKsYSAMt"},"exp":1574093209}
Request

POST https://your.connector.url/api/priora/v1/tokens/cancel

Headers
Header Type Description
Authorization string, required JSON Web Token containing payload, signed using RSA256 and application.private_key.
Accept string, required Media type that is acceptable for the response. Allowed values: application/json
Content-Type string, required The media type of the body of the request. Allowed values: application/json
Client-Id integer, required Client application identifier in Salt Edge PSD2 Compliance. Should be used to get public key for Authorization header validation.
Consent-Id integer, optional ID of the corresponding consent object as returned by an Account Information Consent Request.
Unpacked Request Authorization
exp
integer, required
The lifetime of the request in timestamp UTC format. Values greater than: Current time.
Response headers
Header Type Description
Retry-After integer, optional Amount of time in seconds after which Salt Edge PSD2 Compliance Solution resends the previously failed request.
Response

Upon successful request, 200 status code should be returned.


Accounts

This endpoint is responsible for fetching account information for Account Information Service.

Accounts Fetch Flow Accounts Fetch Flow

Fetch

Fetch list of accounts belonging to a PSU and all relevant information about them. Accounts available for making payments will be flagged accordingly.

CURL

curl -i  \ 
 -H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7InNlc3Npb25fc2VjcmV0IjoiY3ppYVRYZ0JhQ1llckVIRHZXRTkifSwiZXhwIjoxNzM3MjQxOTczLCJpc3MiOiJwcmlvcmEuc2FsdGVkZ2UuY29tIn0.sDSubIAmQnCEuiCCMWrXHRNC9LEnWMJXEHeDphRTKMIgvykr90f_aZGti5oYRXrIEd0Wt3xs1QHCwRbvi9l3TnKY_FbGZy-KWx5KFJoWSTm5L7W3TQ0igr3g9evd1LjTHbUEaLeYh9TO5z8NTOS5gPPzsFKhIpm8ttJnE4FBjDSv3oQGLOyyvxTvJB8yoHX3wILXisrPq5DJ88_Ldr4tN1qTFi5uo0wXkBffS_QbXckcmVjXqyRoaQFrglQS1QXqMhIURTqR4NmqYQrwx_Ch6rg_BwjnyxDkZwKJu-TVn_ZpoAhTs8JAGFcGcr_sMBK7sdhwFjhWZFqE-ozJI6mdiQ" \ 
 -H "Access-Token: e4649d535f5e3125bcc939e2f3b33a070127be520e2f1134ed8722976703e0b32d9354fb147014103ce39f6eed428ac65d82659b6289901449c73d12d939c28f" \ 
 -H "Accept: application/json" \ 
 -H "Content-Type: application/json" \ 
 -H "Client-Id: 765" \ 
 -X GET "https://your.connector.url/api/priora/v1/accounts"

Example of request parameters

{"data":{"session_secret":"cziaTXgBaCYerEHDvWE9"},"exp":1574093209}

Example of response

{"data":[{"id":"724","name":"Example Name","iban":"FK54RAND61068421435452","currency_code":"USD","extra":{},"number":"619656558","sort_code":"82-78-66","swift_code":"TBNFFR23PAR","nature":"credit","payment_account":false,"balance":"5000.00","available_amount":"4995.00","credit_limit":"7000","status":"active"}]}
Request

GET https://your.connector.url/api/priora/v1/accounts

Headers
Header Type Description
Authorization string, required JSON Web Token containing payload, signed using RSA256 and application.private_key.
Access-Token string, required The token which is created by a connector as a result of successful authentication.
Accept string, required Media type that is acceptable for the response. Allowed values: application/json
Content-Type string, required The media type of the body of the request. Allowed values: application/json
Client-Id integer, required Client application identifier in Salt Edge PSD2 Compliance. Should be used to get public key for Authorization header validation.
Consent-Id integer, optional ID of the corresponding consent object as returned by an Account Information Consent Request.
Unpacked Request Authorization
exp
integer, required
The lifetime of the request in timestamp UTC format. Values greater than: Current time.
Response headers
Header Type Description
Retry-After integer, optional Amount of time in seconds after which Salt Edge PSD2 Compliance Solution resends the previously failed request.
Response

Upon successful request, 200 status code should be returned.


Refresh

In case the connector uses a different database from Core Banking, this endpoint enables the process of refreshing accounts and transactions on connector side before sending them to Salt Edge PSD2 Compliance Solution.

CURL

curl -i  \ 
 -H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7InNlc3Npb25fc2VjcmV0IjoieGRzUHNMd19lUkw2Tko4bTIzR2UiLCJmcm9tX2RhdGUiOiIyMDE5LTA4LTE4IiwidG9fZGF0ZSI6IjIwMTktMTEtMTgifSwiZXhwIjoxNzM3MjQxOTczLCJpc3MiOiJwcmlvcmEuc2FsdGVkZ2UuY29tIn0.FTXV7R9G41nGgZHM4QD3rs-Mc2vBj-kSzeMIKGvKsmi41M2VwWA-pcmM2rJ7UpSPbEG6aWwIXZwmZ-mDSbZ71q6T2guP9xQRAYAOQb_LxHXwmRAuATfxbUFnX6ARJXDey6i0BB53bir1lp5sa5waGP2IG1k45af4q7stANQ8l7U-940YXP0id5XtGfk65mbeSoibUVnwUskpxfksKxtR2tVcFct5GsTFSeaKL3QSiIOMoo688Ql7GcsvIVtXc7CSREdMihx9IQ1qzVssNO5X8Qh24Q0OaEesj0Z9qPICjeXGDCg8eqf2lxV4YNS633tc4f4l1TZsv-PHj2KEauXZLA" \ 
 -H "Access-Token: 4fd12e851a9ed70420c3b2e8d5471ae56438e0875ba521c02bff802a176f4c99bebda2e3516e644fc99e37facf0c02e52836fefedcfc2dc9a44d993218bcda70" \ 
 -H "Accept: application/json" \ 
 -H "Content-Type: application/json" \ 
 -H "Client-Id: 786" \ 
 -X PUT "https://your.connector.url/api/priora/v1/accounts"

Example of request parameters

Request

PUT https://your.connector.url/api/priora/v1/accounts

Headers
Header Type Description
Authorization string, required JSON Web Token containing payload, signed using RSA256 and application.private_key.
Access-Token string, required The token which is created by a connector as a result of successful authentication.
Accept string, required Media type that is acceptable for the response. Allowed values: application/json
Content-Type string, required The media type of the body of the request. Allowed values: application/json
Client-Id integer, required Client application identifier in Salt Edge PSD2 Compliance. Should be used to get public key for Authorization header validation.
Consent-Id integer, optional ID of the corresponding consent object as returned by an Account Information Consent Request.
Unpacked Request Authorization
Response headers
Header Type Description
Retry-After integer, optional Amount of time in seconds after which Salt Edge PSD2 Compliance Solution resends the previously failed request.
Response

Upon successful request, 200 status code should be returned.


Confirm

This endpoint is used for processing additional interactive steps in the process of accounts refresh. As a result, Connector should send a success or fail callback to Salt Edge PSD2 Compliance with result of the operation.

CURL

curl -i  \ 
 -H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7InNlc3Npb25fc2VjcmV0IjoieGtlVE53UjNHSEgzY0hjcTNVQ3QiLCJwcm92aWRlcl9jb2RlIjoiZGVtb2JhbmsiLCJvcmlnaW5hbF9yZXF1ZXN0Ijp7ImNsaWVudF9qd3QiOiJCZWFyZXIgZXlKMGVYQWlPaUpLVjFRaUxDSmhiR2NpT2lKU1V6STFOaUo5LmV5SmtZWFJoSWpwN0ltTnlaV1JsYm5ScFlXeHpJanA3SW5OdGMxOXdhVzVqYjJSbElqb2lORFUyT0NKOWZTd2laWGh3SWpveE5UZ3pNalF5TnpZMGZRLlZPaGE4Rm13MTBQUkFoNjZHN3JwaVdWZS1ldEdYOVZGTzFjM185WFhRa2VtRGItS2N5STBMT2htM2xvd0c0MzJ6XzFnTzV6Z1p3cDdpVXdRQWVBTmk0aXJzU0MtOWNPQ01NdTNRY2RCU28zRHlpU2xLMDZObmRrZUZyYUYzb1puNVVMczF1YzYyVjFCNVJFRkJBS0NQaVNaeHQ4UWp0WWFWc3U4dGdYVFZ6N2FYMnNtNlZHOGJuSHp2cEdNcWt4LXQtclJEQ1lYTGlnTlpCR1hRTmhlTUE3RG1ERS14QzlEMzE3OWh6bUZpbGtVYktxYlgxOV93YnEzZFNaRk9SU2t3MHQ4bW1IeEwxV21lWFpTcm9OOXkzQmQwek9VQ3NjdGZUaXl1TzZsd05mYlhoZW5qcEJsdGM4dzEyZmRFU192cTVvOG56SDh0QzBJSnFQRFdYaFI4QSIsImNsaWVudF9wYXlsb2FkIjp7ImRhdGEiOnsiY3JlZGVudGlhbHMiOnsic21zX3BpbmNvZGUiOiI0NTY4In19LCJleHAiOjE1NzQwOTMyMTB9fX0sImV4cCI6MTczNzI0MTk3MywiaXNzIjoicHJpb3JhLnNhbHRlZGdlLmNvbSJ9.TMofdZMi-HkA2eww3W5EY1dUbBB9J2uplVB8Q66hd9dzlQ3BJGFYfe9uFXuaJ4WE6vJeO5hCDHWCUVjf8BxCC6B40rc9n9k4G1GHpLjYLvQFJSsdjdQTEqQNj1UQenOl3J4qd61eY1fCbZ4ML2zbZ5WB8-ZYW_pEC0is3PGJXQ6ZA1i4k47rajzvy0bnVyiYfweVu61tUmXiSGdUdleKvJC6tu7PP85H8qILV4-IwZG0w3_l9zsrUsHaC2NCiSGvZTmR5cBVqNkagwgcbKmT4khudpMthCTvEOJ9wkK3v9DoJnie4iZyF2hTcjV3dg99XqK2einK2jKf6eJGaN90bA" \ 
 -H "Access-Token: 65adc909f5676f3902787ecb6f379c1c48bfc18a222157713808274b100b9e255f7b4b59a3ecd7689cb2abe26f8705dfd89b7a0cc9e9a07a587dc64a7c4572ad" \ 
 -H "Accept: application/json" \ 
 -H "Content-Type: application/json" \ 
 -H "Client-Id: 843" \ 
 -X POST "https://your.connector.url/api/priora/v1/accounts/confirm"

Example of request parameters

{"data":{"session_secret":"xkeTNwR3GHH3cHcq3UCt","provider_code":"demobank","original_request":{"client_jwt":"Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7ImNyZWRlbnRpYWxzIjp7InNtc19waW5jb2RlIjoiNDU2OCJ9fSwiZXhwIjoxNTgzMjQyNzY0fQ.VOha8Fmw10PRAh66G7rpiWVe-etGX9VFO1c3_9XXQkemDb-KcyI0LOhm3lowG432z_1gO5zgZwp7iUwQAeANi4irsSC-9cOCMMu3QcdBSo3DyiSlK06NndkeFraF3oZn5ULs1uc62V1B5REFBAKCPiSZxt8QjtYaVsu8tgXTVz7aX2sm6VG8bnHzvpGMqkx-t-rRDCYXLigNZBGXQNheMA7DmDE-xC9D3179hzmFilkUbKqbX19_wbq3dSZFORSkw0t8mmHxL1WmeXZSroN9y3Bd0zOUCsctfTiyuO6lwNfbXhenjpBltc8w12fdES_vq5o8nzH8tC0IJqPDWXhR8A","client_payload":{"data":{"credentials":{"sms_pincode":"4568"}},"exp":1574093210}}},"exp":1574093210}
Request

POST https://your.connector.url/api/priora/v1/accounts/confirm

Headers
Header Type Description
Authorization string, required JSON Web Token containing payload, signed using RSA256 and application.private_key.
Access-Token string, required The token which is created by a connector as a result of successful authentication.
Accept string, required Media type that is acceptable for the response. Allowed values: application/json
Content-Type string, required The media type of the body of the request. Allowed values: application/json
Client-Id integer, required Client application identifier in Salt Edge PSD2 Compliance. Should be used to get public key for Authorization header validation.
Consent-Id integer, optional ID of the corresponding consent object as returned by an Account Information Consent Request.
Unpacked Request Authorization
exp
integer, required
The lifetime of the request in timestamp UTC format. Values greater than: Current time.
Response headers
Header Type Description
Retry-After integer, optional Amount of time in seconds after which Salt Edge PSD2 Compliance Solution resends the previously failed request.
Response

Upon successful request, 200 status code should be returned.


Transactions

This endpoint is responsible for fetching transactions which belong to previously fetched accounts.

Fetch

Fetch all transactions related to a bank account.

CURL

curl -i  \ 
 -H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7InNlc3Npb25fc2VjcmV0IjoieVBzZXRDeVA3Y0d6bnZiOVNERkMiLCJhY2NvdW50X2lkIjoiODciLCJmcm9tX2RhdGUiOiIyMDE5LTExLTE4VDE2OjA0OjQ5LjU4NVoiLCJ0b19kYXRlIjoiMjAxOS0xMS0xOFQxNjowNDo0OS41ODVaIn0sImV4cCI6MTczNzI0MTk3MywiaXNzIjoicHJpb3JhLnNhbHRlZGdlLmNvbSJ9.Hy1NWylAYwb7M2FF0G74LqfT9Kw5WyxRdZkeSs2QeicGzozR9sapldbZ9gBckbusLd89YjIB4gOgHzU_kZNeUP6KO8G_O9n_-UzAcMyk5Ka9l2VnPOmhWD7SpY80pChtBYguU8uvSgyZijvmVcOfbRIIGi0sGPEpaMudUPzOlUh-qcov9gzjDPkPhXYs2rJQAp5yrypDJsQeOYlTVlzLZw5VT07Ga4YnqQcF3baZq5wW-70W3BJuK8Xy5JWFd2hf5emHzZqD5Q92NG_oMoLJoAgVbnlUhitEQ-MkYv96bmczPOCulTCliyzwRq77N8CDrKof8JnsmuWXzNG-ZApZyw" \ 
 -H "Access-Token: 2cab054fa0dfd20d725ef46c533b537701c29d47ebea97893374d4e47714e49e2e331764e4f4a20d5e285dbb08af9566e14a8f597230bca6d9f5b3b2048a71f5" \ 
 -H "Accept: application/json" \ 
 -H "Content-Type: application/json" \ 
 -H "Client-Id: 866" \ 
 -X GET "https://your.connector.url/api/priora/v1/transactions"

Example of request parameters

{"data":{"session_secret":"yPsetCyP7cGznvb9SDFC","account_id":"87","from_date":"2019-11-18T16:04:49.585Z","to_date":"2019-11-18T16:04:49.585Z"},"exp":1574093209}

Example of response

{"data":[{"id":"378","account_id":"241","amount":"38.85","currency_code":"GBP","description":"Test transaction","made_on":"2019-11-18T16:04:49.573Z","status":"posted","fees":[{}],"extra":{"mcc":"example_data.extra.mcc","original_amount":"38.85","original_currency_code":"GBP"}}]}
Request

GET https://your.connector.url/api/priora/v1/transactions

Headers
Header Type Description
Authorization string, required JSON Web Token containing payload, signed using RSA256 and application.private_key.
Access-Token string, required The token which is created by a connector as a result of successful authentication.
Accept string, required Media type that is acceptable for the response. Allowed values: application/json
Content-Type string, required The media type of the body of the request. Allowed values: application/json
Client-Id integer, required Client application identifier in Salt Edge PSD2 Compliance. Should be used to get public key for Authorization header validation.
Consent-Id integer, optional ID of the corresponding consent object as returned by an Account Information Consent Request.
Unpacked Request Authorization
exp
integer, required
The lifetime of the request in timestamp UTC format. Values greater than: Current time.
Response headers
Header Type Description
Retry-After integer, optional Amount of time in seconds after which Salt Edge PSD2 Compliance Solution resends the previously failed request.
Response

Upon successful request, 200 status code should be returned.


KYC

This endpoint is responsible for fetching personal data of PSU.

Fetch

Extract PSU’s personal data. Response should contain a JSON object representing a PSU.

CURL

curl -i  \ 
 -H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7InNlc3Npb25fc2VjcmV0IjoieVBzZXRDeVA3Y0d6bnZiOVNERkMifSwiZXhwIjoxNzM3MjQxOTczLCJpc3MiOiJwcmlvcmEuc2FsdGVkZ2UuY29tIn0.CASYGXSz248cLhNjecKTna0CzEczYNX0xYFvUvi1Gso2kBLMaSUynpM63uEylKUgzpMyWn6RQ3hVcHn-wlNMCLAXW3qv74Z47BBpjQ4DG4eX4QnCkV5CM5jydxAOrrcb42ln88hhHkAvYal_027DWuYCUgwniqW1o7fRcjHusp8yAKMfMqbzXI1M09lxAIgpfR2vLD72yHllbkxe8geOqMYnbJhBiDyRPyZKySlN_W-dkjAFS9jEtHnSjCzO19m0im6zzRI19_-WACWxOtSnVW0Vr3glA7xX5pDpqq4X7zoCLioFLQym2i5rv5w-VkwttBchuKOsMSBVxRH32f9qpg" \ 
 -H "Access-Token: 3a0b2f004410dca9713cd484a02bb565292e3945500334798274584c7448e9171d1ec9e3d74392792021a7698c7fdee0df041eccc9706871907686770f47833a" \ 
 -H "Accept: application/json" \ 
 -H "Content-Type: application/json" \ 
 -H "Client-Id: 552" \ 
 -X GET "https://your.connector.url/api/priora/v1/kyc"

Example of request parameters

{"data":{"session_secret":"yPsetCyP7cGznvb9SDFC"},"exp":1574093209}

Example of response

{"data":{"name":"Example Name"}}
Request

GET https://your.connector.url/api/priora/v1/kyc

Headers
Header Type Description
Authorization string, required JSON Web Token containing payload, signed using RSA256 and application.private_key.
Access-Token string, required The token which is created by a connector as a result of successful authentication.
Accept string, required Media type that is acceptable for the response. Allowed values: application/json
Content-Type string, required The media type of the body of the request. Allowed values: application/json
Client-Id integer, required Client application identifier in Salt Edge PSD2 Compliance. Should be used to get public key for Authorization header validation.
Consent-Id integer, optional ID of the corresponding consent object as returned by an Account Information Consent Request.
Unpacked Request Authorization
exp
integer, required
The lifetime of the request in timestamp UTC format. Values greater than: Current time.
Response headers
Header Type Description
Retry-After integer, optional Amount of time in seconds after which Salt Edge PSD2 Compliance Solution resends the previously failed request.
Response

Upon successful request, 200 status code should be returned.


Errors

Additional endpoints to be implemented on connector side to improve communication between Salt Edge PSD2 Compliance Solution and Connector.

Notify

This endpoint is responsible for receiving validation errors of responses which Connector sends to Salt Edge PSD2 Compliance Solution

CURL

curl -i  \ 
 -H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7InJlcXVlc3QiOnsibWV0aG9kIjoiZGVsZXRlIiwidXJsIjoiaHR0cHM6Ly91c2VyLndpbGwuYmUvcmVkaXJlY3RlZC9oZXJlIiwiaGVhZGVycyI6e319LCJlcnJvciI6eyJlcnJvcl9tZXNzYWdlIjoic29tZXRoaW5nIHdlbnQgd3JvbmciLCJlcnJvcl9jbGFzcyI6IkludGVybmFsUHJvdmlkZXJFcnJvciJ9fSwiZXhwIjoxNzM3MjQxOTczLCJpc3MiOiJwcmlvcmEuc2FsdGVkZ2UuY29tIn0.DVyjgDIeDayaaFr-RuWlP_95ctiDAsJtWtK7p1rYmGW7ciHd-1JVitw2hdDdlxWZ1UzIs7Yg0Sjg11vloLQHce8bolx9saGPyDToql4G1f50YYY9fCLjHtIhUaJHwyKuRUoW6S1PbHNzVUHVkQEsYdxIDMVWJuCRdu1CMjueLhLFB17XtsKxhgmLX_ymuYnN1fVUbZ8B2ib08NC7aLgtRMdD_sTxx_QAHVW7SEnXYRApp0bBaLpRnkC6ckB_gtLkXa-vBe3_jsNwq3pBOBd1RCPUQavn05fwcbgz_vRyOsGMAXpjLKfZP7DQEjLjo787YA4SjmkUVP8tV0Gi7u_71A" \ 
 -H "Access-Token: b2077c5c020a5e262767aac63fdbc75fd64461afc660784fbc3451766f586bb4836e3405007c2caf497a1125ba58fb49be65b3c352285dea68328aded84e2f91" \ 
 -H "Accept: application/json" \ 
 -H "Content-Type: application/json" \ 
 -H "Client-Id: 685" \ 
 -X POST "https://your.connector.url/api/priora/v1/errors"

Example of request parameters

{"data":{"request":{"method":"delete","url":"https://user.will.be/redirected/here","headers":{}},"error":{"error_message":"something went wrong","error_class":"InternalProviderError"}},"exp":1574093209}
Request

POST https://your.connector.url/api/priora/v1/errors

Headers
Header Type Description
Authorization string, required JSON Web Token containing payload, signed using RSA256 and application.private_key.
Access-Token string, required The token which is created by a connector as a result of successful authentication.
Accept string, required Media type that is acceptable for the response. Allowed values: application/json
Content-Type string, required The media type of the body of the request. Allowed values: application/json
Client-Id integer, required Client application identifier in Salt Edge PSD2 Compliance. Should be used to get public key for Authorization header validation.
Consent-Id integer, optional ID of the corresponding consent object as returned by an Account Information Consent Request.
Unpacked Request Authorization
exp
integer, required
The lifetime of the request in timestamp UTC format. Values greater than: Current time.
Response headers
Header Type Description
Retry-After integer, optional Amount of time in seconds after which Salt Edge PSD2 Compliance Solution resends the previously failed request.
Response

Upon successful request, 200 status code should be returned.


Sessions

Success

Success callback should be sent to Salt Edge PSD2 Compliance when all required verification steps have been passed, and therefore access is granted.

CURL

curl -i  \ 
 -H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7InNlc3Npb25fc2VjcmV0IjoiR2NRXzF1cW1reFlUSzFYV1EydTMiLCJ0b2tlbiI6ImFpeXVUVGdwYTRKdndRZUtoRHpmIiwidG9rZW5fZXhwaXJlc19hdCI6IjIwMTktMTEtMThUMTY6MDQ6NDguNzk5WiJ9LCJleHAiOjE3MzcyNDE5NzMsImlzcyI6InByaW9yYS5zYWx0ZWRnZS5jb20ifQ.tNzzkL_4ZowIPYHtcdE90_McHVBKFVIjt-3Yf-ALccBULlnWTjT-U7JOL-X4UKDBRWNCjJZ25TPgVxeJFkKsrG2y48DES1qvFx2kG8i7-PVbVIDbpB_MulZLPA_RhcpI_aXHyonSINYoAzcilCUfv3yvYyr-quWUfQK9jYtio5rHgP-ICH_EfrBLoUbQQCyWba-qH-99kJHzns0CJ-5W2XGCd1r3i91gq4F5Z16107LgpLgwxAv2Z4PJr3_mpGuwWY0L9S1vM6lZB-vKGNw1K2TiBzbyLKh89zTnp7t_6ld9oDf4FbDG5t3NCwEsWlfjV4ER6MY05fRI0VL4YNCBsQ" \ 
 -H "App-Id: qjQYP-jCx-8FBsZSgNVzIw" \ 
 -H "App-Secret: -XeeN2UhtdphUGtI-FZpzg" \ 
 -X POST "/api/connectors/v1/sessions/success"

Example of request parameters

Example of response

{"data":{},"meta":{"time":"2019-11-18T16:04:48.773Z"}}
Request

POST /api/connectors/v1/sessions/success

Headers
Header Type Description
Authorization string, required JSON Web Token containing payload, signed using RSA256 and application.private_key. Can raise: AuthorizationMissing
App-Id string, required Provider's app_id from connection details tab. Can raise: ProviderNotFound, ProviderDisabled, ConfigurationError
App-Secret string, required Provider's app_secret from connection details tab.
Unpacked Request Authorization
Response

Upon successful request, 200 status code will be returned. See ‘Related Errors’ table for other possibilities.


data
hash, optional
Wrapper for the data.
Related Errors
Class Code Description
SessionClosed 400 Session specified in request is already closed and cannot be modified.
ConfigurationError 400 Missing configurations in dashboard.
SessionExpired 401 Found session is expired and cannot be processed anymore.
AuthorizationMissing 401 Authorization header is missing.
SessionNotFound 404 Session specified in request does not exist or cannot be retrieved.
ProviderNotFound 404 Provider specified in request does not exist or cannot be retrieved.
ActionNotAllowed 406 You're not allowed to perform this action. This might be a configuration problem or parameters incompatibility.
ProviderDisabled 406 Cooperation with specified Provider is impossible.

Update

Update callback may be accessed multiple times in order to request multiple steps of authorization or to send other updates to Salt Edge PSD2 Compliance session.

CURL

curl -i  \ 
 -H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7ImV4dHJhIjp7fSwiaW50ZXJhY3RpdmVfc3RlcF9pbnN0cnVjdGlvbiI6eyJpbnN0cnVjdGlvbiI6e30sImludGVyYWN0aXZlX2ZpZWxkIjoic21zX3BpbmNvZGUifSwic3RhdHVzIjoid2FpdGluZ19jb25maXJtYXRpb25fY29kZSIsInNlc3Npb25fZXhwaXJlc19hdCI6IjIwMjAtMDMtMDJUMTU6Mzc6MzAuOTIzWiIsInNlc3Npb25fc2VjcmV0IjoiSHMteGM4b3pBV0xrMXh0X3pUNHYifSwiZXhwIjoxNzM3MjQxOTczLCJpc3MiOiJwcmlvcmEuc2FsdGVkZ2UuY29tIn0.KalLPVkllxw1Y7oCnDzJFCyVLsCMsInCmmW-XdEZ0M3IOULgxRaoGUzD-qB1eGj3C-VWCwQadz-zBqamZuSPJwZc3EyqRNX80AKxowNKOcNprgS2Zax2qH1bURmH6H304BTL6xUXeCjB1yCKrOQX3JejMmpPCHH-mL8c84beCR0ngKv5rqEaPMPM1FSpLEYFos9lGnPLIXC4Pi54x21iy7WqvVhCGgw8fCN4MfzoBBFEDPaN8uwW_wCgohBjSjFML50dAygYnz3X1A6L-rinIwEUhiYfmX9XMB1tgo7rRwolBPnrhP3sQH0KJayN3QNHQ1gDl83Hv3BktXNCfbWHlw" \ 
 -H "App-Id: q5QE7Dqlpm1d5weLS5pn7w" \ 
 -H "App-Secret: y8imt1cgG8x2zmBMrF-oxw" \ 
 -X POST "/api/connectors/v1/sessions/update"

Example of request parameters

Example of response

{"data":{},"meta":{"time":"2019-11-18T16:04:48.853Z"}}
Request

POST /api/connectors/v1/sessions/update

Headers
Header Type Description
Authorization string, required JSON Web Token containing payload, signed using RSA256 and application.private_key. Can raise: AuthorizationMissing
App-Id string, required Provider's app_id from connection details tab. Can raise: ProviderNotFound, ProviderDisabled, ConfigurationError
App-Secret string, required Provider's app_secret from connection details tab.
Unpacked Request Authorization
Response

Upon successful request, 200 status code will be returned. See ‘Related Errors’ table for other possibilities.


data
hash, optional
Wrapper for the data.
Related Errors
Class Code Description
SessionClosed 400 Session specified in request is already closed and cannot be modified.
ConfigurationError 400 Missing configurations in dashboard.
SessionExpired 401 Found session is expired and cannot be processed anymore.
AuthorizationMissing 401 Authorization header is missing.
SessionNotFound 404 Session specified in request does not exist or cannot be retrieved.
ProviderNotFound 404 Provider specified in request does not exist or cannot be retrieved.
ActionNotAllowed 406 You're not allowed to perform this action. This might be a configuration problem or parameters incompatibility.
ProviderDisabled 406 Cooperation with specified Provider is impossible.

Fail

Fail callback should be used when authorization process has been compromised for any reason: broken request, invalid credentials, etc.

CURL

curl -i  \ 
 -H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7InNlc3Npb25fc2VjcmV0IjoiM1BRaXB1RFBvV3BhMTFGY1ZFVjYiLCJlcnJvcl9jbGFzcyI6IkludGVybmFsUHJvdmlkZXJFcnJvciIsImVycm9yX21lc3NhZ2UiOiJJbnRlcm5hbCBlcnJvciIsImV4dHJhIjp7fX0sImV4cCI6MTczNzI0MTk3MywiaXNzIjoicHJpb3JhLnNhbHRlZGdlLmNvbSJ9.HPF0ADkZHkgbZ8VyXwHSd7t08YFZJpDa0SyT18ByQJ5pvPrCYOhYzxa7N_de4t9eDH82-B_HvyJU3rJ4HqGVMIeFlzA6VKPeDnNwp8Ty64w5dv2tRnN-0ElPx6dUD0pZSqpFGtEOLK2nYbLNLKiOh9rOWNDCl_84mi4smoFMkEN8eRBy0DOvUrYlRlakyDBiHpZ7k0_NjSCz--smuY32HpOwl-LiKJf-nJJ0cQaxpD01H0umOwaNYlKj-D_VaQhGv9uFbeiIAcds3WgCwHiewenNUk8XbKqSvCmwke0bboIGelvNlZcRmSEM8Y5lIkvpLWV-hUT02a8JTjcQxnEySQ" \ 
 -H "App-Id: xU7SyhPrd95GAPSMNo_XMQ" \ 
 -H "App-Secret: BVSkESo7zpRdzk_hWUUwCQ" \ 
 -X POST "/api/connectors/v1/sessions/fail"

Example of request parameters

{"data":{"session_secret":"3PQipuDPoWpa11FcVEV6","error_class":"InternalProviderError","error_message":"Internal error","extra":{}},"exp":1574093208}

Example of response

{"data":{},"meta":{"time":"2019-11-18T16:04:48.710Z"}}
Request

POST /api/connectors/v1/sessions/fail

Headers
Header Type Description
Authorization string, required JSON Web Token containing payload, signed using RSA256 and application.private_key. Can raise: AuthorizationMissing
App-Id string, required Provider's app_id from connection details tab. Can raise: ProviderNotFound, ProviderDisabled, ConfigurationError
App-Secret string, required Provider's app_secret from connection details tab.
Unpacked Request Authorization
exp
integer, required
The lifetime of the request in timestamp UTC format. Values greater than: Current time.
Response

Upon successful request, 200 status code will be returned. See ‘Related Errors’ table for other possibilities.


data
hash, optional
Wrapper for the data.
Related Errors
Class Code Description
SessionClosed 400 Session specified in request is already closed and cannot be modified.
ConfigurationError 400 Missing configurations in dashboard.
SessionExpired 401 Found session is expired and cannot be processed anymore.
AuthorizationMissing 401 Authorization header is missing.
SessionNotFound 404 Session specified in request does not exist or cannot be retrieved.
ProviderNotFound 404 Provider specified in request does not exist or cannot be retrieved.
ActionNotAllowed 406 You're not allowed to perform this action. This might be a configuration problem or parameters incompatibility.
ProviderDisabled 406 Cooperation with specified Provider is impossible.

Tokens

Index

Returns the list of access tokens issued by Provider for Salt Edge PSD2 Compliance Solution.

CURL

curl -i  \ 
 -H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7ImtpbmQiOiJyZXZva2VkIiwiZnJvbV9pZCI6MzAyLCJmcm9tX2RhdGUiOiIyMDE5LTA4LTIwVDE2OjA0OjQ5LjAyMVoiLCJwZXJfcGFnZSI6NTAsImN1c3RvbWVyX2lkIjo4MjF9LCJleHAiOjE3MzcyNDE5NzMsImlzcyI6InByaW9yYS5zYWx0ZWRnZS5jb20ifQ.FDcrAGOjwqM6MZs9buXcVKUwmOlBtlIgKihkiDiAIUqqOuPIh8DSm-dZrGMdGC7wHxxnC6HATaS7QOQmQbx5Oe7Jz8HC4b5AURUUci36gf-NO032qvwY7szmgRJt_oz3ok4t03mgiwBZcPi3u6tNZrrCfVhBOYF_ibym3c-SxN7_vWomvkF52laGouZCfQtotK953QAXPGdBh5mgvvRPn3e1z6-IU1cSXxYj3yi2cuD62Jh1oc4F2O4CftWxd3DmJgZjzobojXC5sF_PhrHjdjOYJ88YxY_lKCuxTwuOQclzvPU8xmC6WObvBwSEokQ6UyGtcRsFnXpY-aMMIWg5bg" \ 
 -H "App-Id: G9SgwyF-RdxsjCu3f3mLnw" \ 
 -H "App-Secret: Az6qAhT6pdezVjAex58qqQ" \ 
 -X GET "/api/connectors/v1/tokens/index"

Example of request parameters

{"data":{"kind":"revoked","from_id":302,"from_date":"2019-08-20T16:04:49.021Z","per_page":50,"customer_id":821},"exp":1574093209}

Example of response

{"meta":{"next_id":303,"time":"2019-11-18T16:04:49.001Z"},"data":{"tokens":[]}}
Request

GET /api/connectors/v1/tokens/index

Headers
Header Type Description
Authorization string, required JSON Web Token containing payload, signed using RSA256 and application.private_key. Can raise: AuthorizationMissing
App-Id string, required Provider's app_id from connection details tab. Can raise: ProviderNotFound, ProviderDisabled, ConfigurationError
App-Secret string, required Provider's app_secret from connection details tab.
Unpacked Request Authorization
exp
integer, required
The lifetime of the request in timestamp UTC format. Values greater than: Current time.
Response

Upon successful request, 200 status code will be returned. See ‘Related Errors’ table for other possibilities.


Related Errors
Class Code Description
ConfigurationError 400 Missing configurations in dashboard.
AuthorizationMissing 401 Authorization header is missing.
CustomerNotFound 404 PSU specified in request does not exist or cannot be retrieved.
ProviderNotFound 404 Provider specified in request does not exist or cannot be retrieved.
ProviderDisabled 406 Cooperation with specified Provider is impossible.

Revoke

Revoke callback needs to be called any time a token is revoked on the Provider Connector side.

CURL

curl -i  \ 
 -H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7fSwiZXhwIjoxNzM3MjQxOTczLCJpc3MiOiJwcmlvcmEuc2FsdGVkZ2UuY29tIn0.IYlxlOoG47SrPKsX6ibHErvIzuJ1fTwhgli6vzL9zhUS8okO5Uka1nwSFrC2sy9nkYGPLy8dA3qb0fhMPiknPUpRZ1n33W5MwICwDRjg0_-0b8zjc-R4aIDh41Vq5KZpUEws4Z99SX7qrRM7XdpV_Cu8Lzrmp5H8ZpyOp2XFlT9h6EtfM-XLVR0kWyggL9PyEIfRO8VXd6wHuCrp2YAWN0-BHyf1_EGPyXzbF35Ht7QW_kaiqS2ChAJAha4uesvacCe8gRa9oczx9NqfpR02YU6mkYyirvHkm9Ob9q6_Ylh0xs4049xFXJCk9V8WoH5Yrd96cBj7mHYdCI05vQEFgA" \ 
 -H "App-Id: cfOK5P9RVooLksNv8il3rw" \ 
 -H "App-Secret: rwkTbW41SPT55uo1I_-UGQ" \ 
 -H "Token: example_Token" \ 
 -X DELETE "/api/connectors/v1/tokens/revoke"

Example of request parameters

{"data":{},"exp":1574093208}

Example of response

{"data":{"revoked":true},"meta":{"time":"2019-11-18T16:04:48.928Z"}}
Request

DELETE /api/connectors/v1/tokens/revoke

Headers
Header Type Description
Authorization string, required JSON Web Token containing payload, signed using RSA256 and application.private_key. Can raise: AuthorizationMissing
App-Id string, required Provider's app_id from connection details tab. Can raise: ProviderNotFound, ProviderDisabled, ConfigurationError
App-Secret string, required Provider's app_secret from connection details tab.
Token string, required Token for which we are requesting info. Can raise: TokenMissing, TokenNotFound, TokenRevoked, TokenExpired
Unpacked Request Authorization
data
hash, required
Wrapper for the data.
exp
integer, required
The lifetime of the request in timestamp UTC format. Values greater than: Current time.
Response

Upon successful request, 200 status code will be returned. See ‘Related Errors’ table for other possibilities.


Related Errors
Class Code Description
ConfigurationError 400 Missing configurations in dashboard.
TokenMissing 400 This request cannot be performed without TOKEN header.
AuthorizationMissing 401 Authorization header is missing.
TokenNotFound 401 Token specified in request does not exist or cannot be retrieved.
TokenRevoked 401 Token specified in request is revoked and cannot be used anymore.
TokenExpired 401 Token specified in request is expired and cannot be used.
ProviderNotFound 404 Provider specified in request does not exist or cannot be retrieved.
ProviderDisabled 406 Cooperation with specified Provider is impossible.

Clients

Info

All requests that are forwarded by Salt Edge PSD2 Compliance Solution are signed by TPP applications. Provider can decide whether to decode the original request by itself or use decoded payload by Salt Edge PSD2 Compliance Solution which is stored in client_payload key. In order to decode the client_jwt, Connector has to perform the following request to obtain TPP's public key. The client_id is present in Client-Id header along with Authorization header.

CURL

curl -i  \ 
 -H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7ImNsaWVudF9pZCI6NTE3fSwiZXhwIjoxNzM3MjQxOTczLCJpc3MiOiJwcmlvcmEuc2FsdGVkZ2UuY29tIn0.coNiIyhE_8_GROwlkJKiMN_uTcDDqHfgsOFaB4ShTi0gn7Ecg8BZqeGItRgU1fvN3ZbK6uAXHbtNY6pedg882OLfj9AHuDOECpHKn0HEDJQqLySXSDS6xDUlLfq1_B47SFTGltA_hRKAlZrvXrtXHEv4615nPKORw1BE1ZmA7EbEgssVbeNIrRqfyPUAJ5-GqrVrzqayp1Twpd9Fwbz2Jk_6rzSnFVm61xsPjBMMBCW9Kxfv7o52e3graXsWmmaZDR5MS0p_yWCbOwfls53-00fzkr11WMVpzpJwfbh5HFqil7v8sdl09oQhWacZoaMRUN8sWL2ljPneoqshwkPvUQ" \ 
 -H "App-Id: hAnmNmGFFBN3W_jNWJd_fQ" \ 
 -H "App-Secret: h6rzA_lw2wVuCpDaBKlxAA" \ 
 -X GET "/api/connectors/v1/clients/info"

Example of request parameters

{"data":{"client_id":517},"exp":1574093208}

Example of response

{"data":{"name":"Fentury","scopes":["accounts","transactions","kyc"],"public_key":"-----BEGIN PUBLIC KEY-----\nMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCqGKukO1De7zhZj6+H0qtjTkVxwTCpvKe4eCZ0\nFPqri0cb2JZfXJ/DgYSF6vUpwmJG8wVQZKjeGcjDOL5UlsuusFncCzWBQ7RKNUSesmQRMSGkVb1/\n3j+skZ6UtW+5u09lHNsj6tQ51s1SPrCBkedbNf0Tp0GbMJDyR4e9T04ZZwIDAQAB\n-----END PUBLIC KEY-----"},"meta":{"time":"2019-11-18T16:04:48.271Z"}}
Request

GET /api/connectors/v1/clients/info

Headers
Header Type Description
Authorization string, required JSON Web Token containing payload, signed using RSA256 and application.private_key. Can raise: AuthorizationMissing
App-Id string, required Provider's app_id from connection details tab. Can raise: ProviderNotFound, ProviderDisabled, ConfigurationError
App-Secret string, required Provider's app_secret from connection details tab.
Unpacked Request Authorization
exp
integer, required
The lifetime of the request in timestamp UTC format. Values greater than: Current time.
Response

Upon successful request, 200 status code will be returned. See ‘Related Errors’ table for other possibilities.


Related Errors
Class Code Description
ConfigurationError 400 Missing configurations in dashboard.
AuthorizationMissing 401 Authorization header is missing.
ProviderNotFound 404 Provider specified in request does not exist or cannot be retrieved.
ProviderDisabled 406 Cooperation with specified Provider is impossible.