Connector Endpoints
Tokens
These endpoints are responsible for implementing authentication and authorization of PSU. Process of token creation starts once PSU grants his consent to TPP. At the end of authorization, Connector should issue an access_token
which can be used for furhter actions. You can find below sequence diagrams represeting embedded and oauth authorization flows.
Create
Create an access token with a set of access rights, named scopes. As a result, Connector should send an update or fail callback to Salt Edge PSD2 Compliance with the result of the operation, be it a success, fail or request for additional steps.
CURL
curl -i \
-H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7ImFwcF9uYW1lIjoiRXhhbXBsZSBOYW1lIiwicHJvdmlkZXJfY29kZSI6ImRlbW9iYW5rIiwib3JpZ2luYWxfcmVxdWVzdCI6eyJjbGllbnRfand0IjoiQmVhcmVyIGV5SjBlWEFpT2lKS1YxUWlMQ0poYkdjaU9pSlNVekkxTmlKOS5leUprWVhSaElqcDdJbkJ5YjNacFpHVnlYMk52WkdVaU9pSmtaVzF2WW1GdWF5SXNJbk5qYjNCbGN5STZXeUpoWTJOdmRXNTBjeUlzSW5SeVlXNXpZV04wYVc5dWN5SXNJbXQ1WXlJc0luQmhlVzFsYm5Seklpd2lablZ1WkhOZllYWmhhV3hoWW1sc2FYUjVJaXdpZEhKMWMzUmxaRjlpWlc1bFptbGphV0Z5YVdWeklsMHNJbU52Ym5ObGJuUmZjR1Z5YVc5a1gyUmhlWE1pT2prd0xDSm1iM0pqWlY5elkyRWlPbVpoYkhObExDSmpjbVZrWlc1MGFXRnNjeUk2ZXlKMGVYQmxJam9pYjJGMWRHZ2lMQ0poZFhSb2IzSnBlbUYwYVc5dVgzUjVjR1VpT2lKUVUwUmZRVWxUVUNKOUxDSnlaV1JwY21WamRGOTFjbXdpT2lKb2RIUndjem92TDNWelpYSXVkMmxzYkM1aVpTOXlaV1JwY21WamRHVmtMMmhsY21VaWZTd2laWGh3SWpveE5UYzBNRGt6TWpFd2ZRLk9lNFdIaFVyaFE0cHNmc2hUR2kzeWEyanRJTEJIY1EwSDZFYlktbjlIdWx3YjI4UVhDTm9kLUN5MlVLYlNEZjRxX2hrckdyQm5TeGd5SWhEQzNXbThNYkRSQ0tFRlFtci1LTko4M3ZYTnJSd29seVRZdUR3MGxJVHBySVFYU1pwel8xdWd2R0NnN2tnSEIzSlV0M0puQ2dNTzVlTGtZenpmUmN6V2NnNnNwdXpCWUk0Qi1yNHEwajFCOXp6Y0RKQmYxZkg1aWdaMW5QYm9FR21RUmJyc1hlMkNIWnEwT1BGSUNNbkNrR1pTdkRJbkNHdXVRMGtEUnhVNnZ4VF9WMFNNRWRHUk9SVmtZQnk2WEJ3aU1VdWFQM3JrWXF0NmN2c2pUeVZEd256N214OVF1T3JBSERtOXVVNHRWMnBGQ2dYdXpLdzlSQXBreFZETi1OUG9RaEl1ZyIsImNsaWVudF9wYXlsb2FkIjp7ImRhdGEiOnsiY29uc2VudF9wZXJpb2RfZGF5cyI6OTAsImNyZWRlbnRpYWxzIjp7ImF1dGhvcml6YXRpb25fdHlwZSI6ImxvZ2luX3Bhc3N3b3JkIn0sInByb3ZpZGVyX2NvZGUiOiJkZW1vYmFuayIsInNjb3BlcyI6WyJhY2NvdW50cyIsInRyYW5zYWN0aW9ucyIsImt5YyIsInBheW1lbnRzIiwiZnVuZHNfYXZhaWxhYmlsaXR5IiwidHJ1c3RlZF9iZW5lZmljaWFyaWVzIl19LCJleHAiOjE1NzQwOTMyMTB9fSwic2Vzc2lvbl9zZWNyZXQiOiI3MmF0a1R3X1l6VmFpQ0FxeDJ1aiJ9LCJleHAiOjE3MzcyNDE5NzIsImlzcyI6InByaW9yYS5zYWx0ZWRnZS5jb20ifQ.Sv2RhikvhRAkPULk_YsCPYe63xk39YUpzU6esfa6fVncL-Mhk51uOcgk88mQ-ldsBfYMEHR0GFbdtw6k1IO5UPdVB9nbnteGNZVF18F3JRhKJL5UGMjh-1rbibtRBfWPTMWNIPItvaVnOfavqvgU9G-6tyOA-fm90OCoLHxLzs9T8tg7lVNZi80hzZPxfx8TkGGTrcLipv_l0Bk7K6KjV5DbGX5FMeF3qNYZguXteeDAaFn0A64TY7Y2erJeQYMdqoRNdDG4U4j-Cx-n0jGb0imBT71nDHilBk8VVjHEW9D75tqgEywDs-5G0v1qSb2NHpgIgFrsK-eineSqGp8slw" \
-H "Accept: application/json" \
-H "Content-Type: application/json" \
-H "Client-Id: 771" \
-X POST "https://your.connector.url/api/priora/v1/tokens/create"
Example of request parameters
Request
POST
https://your.connector.url/api/priora/v1/tokens/create
Headers
Header | Type | Description |
---|---|---|
Authorization
|
string, required |
JSON Web Token containing payload, signed using RSA256 and application.private_key .
|
Accept
|
string, required | Media type that is acceptable for the response. Allowed values: application/json |
Content-Type
|
string, required | The media type of the body of the request. Allowed values: application/json |
Client-Id
|
integer, required | Client application identifier in Salt Edge PSD2 Compliance. Should be used to get public key for Authorization header validation. |
Consent-Id
|
integer, optional | ID of the corresponding consent object as returned by an Account Information Consent Request. |
Unpacked Request Authorization
Response headers
Header | Type | Description |
---|---|---|
Retry-After
|
integer, optional | Amount of time in seconds after which Salt Edge PSD2 Compliance Solution resends the previously failed request. |
Response
Upon successful request, 200 status code should be returned.
Revoke
Revoke an already existing and active access token.
CURL
curl -i \
-H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7InByb3ZpZGVyX2NvZGUiOiJkZW1vYmFuayIsInNlc3Npb25fc2VjcmV0IjoiaDI5Yzk0MVBRNF9rNl82UG4tbzUifSwiZXhwIjoxNzM3MjQxOTcyLCJpc3MiOiJwcmlvcmEuc2FsdGVkZ2UuY29tIn0.kclER0v8VoedAVdxLpNiHM8FSJXYQoI0lPLaPZaBmaYZk8JQ6ZLzp3aC_1JObAJzH5bEeBhStuoW2g2V6qdufAXMFuG8P_TInTKwlrXBou2Om5pigf0j1qJPREOYvTri1jjR8EyFtOjQFnAgFmZZjOt2axHvh4JQLyGxXIF2Im85Y6DtlYCmWIqWor2EctBLccYqWw6RkO0SisXxGR18iw8Xq25hXWhuM_hNzmQok-oI2sbvaP2MSsqW-be9IEZ7pG3nwbapSM8ZcsPVGKiWPkKdWP52XZTFaV0-JsEMNStxwsKoAXESfojNgK1VIxCIlfHzs8q8CAN-XyOEevKXWw" \
-H "Access-Token: 65adc909f5676f3902787ecb6f379c1c48bfc18a222157713808274b100b9e255f7b4b59a3ecd7689cb2abe26f8705dfd89b7a0cc9e9a07a587dc64a7c4572ad" \
-H "Accept: application/json" \
-H "Content-Type: application/json" \
-H "Client-Id: 843" \
-X POST "https://your.connector.url/api/priora/v1/tokens/revoke"
Example of request parameters
{"data":{"provider_code":"demobank","session_secret":"h29c941PQ4_k6_6Pn-o5"},"exp":1574093209}
Request
POST
https://your.connector.url/api/priora/v1/tokens/revoke
Headers
Header | Type | Description |
---|---|---|
Authorization
|
string, required |
JSON Web Token containing payload, signed using RSA256 and application.private_key .
|
Access-Token
|
string, required | The token which is created by a connector as a result of successful authentication. |
Accept
|
string, required | Media type that is acceptable for the response. Allowed values: application/json |
Content-Type
|
string, required | The media type of the body of the request. Allowed values: application/json |
Client-Id
|
integer, required | Client application identifier in Salt Edge PSD2 Compliance. Should be used to get public key for Authorization header validation. |
Consent-Id
|
integer, optional | ID of the corresponding consent object as returned by an Account Information Consent Request. |
Unpacked Request Authorization
Response headers
Header | Type | Description |
---|---|---|
Retry-After
|
integer, optional | Amount of time in seconds after which Salt Edge PSD2 Compliance Solution resends the previously failed request. |
Response
Upon successful request, 200 status code should be returned.
Reconnect Deprecated
This endpoint is invoked when a TPP asks to refresh an active token. ASPSP should determine behavior for this action: ASPSP can just return a new token sending it into session/success endpoint, ask for MFA using sessions/update endpoint or just deny using sessions/fail endpoint.
CURL
curl -i \
-H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7InByb3ZpZGVyX2NvZGUiOiJkZW1vYmFuayIsInNlc3Npb25fc2VjcmV0IjoieVU5VzYtQnU5dHpZTjJHWGlFckYifSwiZXhwIjoxNzM3MjQxOTczLCJpc3MiOiJwcmlvcmEuc2FsdGVkZ2UuY29tIn0.VaBS5cmfPmDdSL3cEnGi8nsyP3Ti06A5yyJiAe0DFERkRh8PxSd7ucUc-kxqVp6U8TQMrsF3HU1HnPW2Q3D1JA0vPROgm1uKi1fKGCOz8sKdg3W63t_P5ZaY4jiJZC3JkFTJ8MGHPSVzw6XKZqqlnhv-L9nHNFK9H-cqZoCZjzaAGZLF2zRPhuaqCjtbPxu5ze_GBizu-K3_b7X-kGnCrXYLQ27HFVmmcDx3d4dJpwMt6HQQ9cr6Our0FZvNi9EBPtPoOyp1jEY3vgAElzGPxh_yHwColB2kyqBcvKgcAPZFInlrrwGgFwFj_o24338hkPPJeIejY3GIMVi76pgcog" \
-H "Access-Token: b8a2d37ea0ed40716deebb7c5fff81ce096c87141d45ef39cc7c4b2c455b09c8e338c1190267ab1bf56ffa6840662e2f3d3967a13985d0e0bd777059814e6954" \
-H "Accept: application/json" \
-H "Content-Type: application/json" \
-H "Client-Id: 718" \
-X POST "https://your.connector.url/api/priora/v1/tokens/reconnect"
Example of request parameters
{"data":{"provider_code":"demobank","session_secret":"yU9W6-Bu9tzYN2GXiErF"},"exp":1574093210}
Request
POST
https://your.connector.url/api/priora/v1/tokens/reconnect
Headers
Header | Type | Description |
---|---|---|
Authorization
|
string, required |
JSON Web Token containing payload, signed using RSA256 and application.private_key .
|
Access-Token
|
string, required | The token which is created by a connector as a result of successful authentication. |
Accept
|
string, required | Media type that is acceptable for the response. Allowed values: application/json |
Content-Type
|
string, required | The media type of the body of the request. Allowed values: application/json |
Client-Id
|
integer, required | Client application identifier in Salt Edge PSD2 Compliance. Should be used to get public key for Authorization header validation. |
Consent-Id
|
integer, optional | ID of the corresponding consent object as returned by an Account Information Consent Request. |
Unpacked Request Authorization
Response headers
Header | Type | Description |
---|---|---|
Retry-After
|
integer, optional | Amount of time in seconds after which Salt Edge PSD2 Compliance Solution resends the previously failed request. |
Response
Upon successful request, 200 status code should be returned.
Confirm
This endpoint is used for processing additional interactive steps in the process of access token creation. As a result, Connector should send a success or fail callback to Salt Edge PSD2 Compliance with result of the operation.
CURL
curl -i \
-H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7InNlc3Npb25fc2VjcmV0Ijoic2NfZkt0VHRvSGM5SGtKc3R5ZnciLCJwcm92aWRlcl9jb2RlIjoiZGVtb2JhbmsiLCJvcmlnaW5hbF9yZXF1ZXN0Ijp7ImNsaWVudF9qd3QiOiJCZWFyZXIgZXlKMGVYQWlPaUpLVjFRaUxDSmhiR2NpT2lKU1V6STFOaUo5LmV5SmtZWFJoSWpwN0ltTnlaV1JsYm5ScFlXeHpJanA3SW5SNWNHVWlPaUp2WVhWMGFDSjlmU3dpWlhod0lqb3hOVGMwTURrek1qQTVmUS5IYUoyWksxVlZvUXJoUkZsSVBaTk01dzRtajhQVG9sT3BBbHJFRU9UY2VGSWFrYzQ1blFMd1BpUkNyUE9OQWl6blRJMTI1MEVkb01Vd1JmYVd6MUFRMEZBdi1Xc1dmb3ltTjNiaVljWlpwNEZlQXJMVzgyd3pzREZXVTlWV1VIU0h4MnpMX0k3dnZWaGxKY1BiX3R6SVJWcVJSTFRNTnp2SjJPX1hYZ0hPeG1TQXF6Q3B1UTdBVUV6QTVZdUQxWjgxZDVPcTMtNzNmMGRjenc1Nnk2cTV4blY4NnJuZ2s5M1FpYTdGR3oyRi1HY3dJbld6R0lsV2dtUXQxYk13SHltNnJ1RVVzeUxOZ09LanVObnFGaEtwOTh2V1FpaFFuVlZBdmU3bGNoUG9rWWFYMklGU0k4Z2FkT2FTZ1dyQ2FvMngySU1qQkZxMHZvaFYxQnFZbEVLYVEiLCJjbGllbnRfcGF5bG9hZCI6eyJkYXRhIjp7ImNyZWRlbnRpYWxzIjp7InNtc19waW5jb2RlIjoiNDg5NiJ9fSwiZXhwIjoxNTc0MDkzMjA5fX19LCJleHAiOjE3MzcyNDE5NzMsImlzcyI6InByaW9yYS5zYWx0ZWRnZS5jb20ifQ.FTYffPcvuaRlvGBasbsum07h4D9W3XnjdUk63lkzgTihX7SUGwbDsdmihCWikIOdGTYk6w37SFshPOjRXe028k1qQeCHWYziuEjppVv9QGfzN1-5-GUAUaWwMgIC5ie4GHgWP46ivwK2J0aFqH41ERkhqfjg2vkB7FX0R1b8NiV_Ix3dMml5t4z5oFVqwDHJ-MqaxZanSfFBYs_yi076Ak29025pypRVgDHtgNVJgn_1ryjlto_xlat5aE-31FgHJ5NkIEvr4HrsLxWrgVJ2UHcDfAgqCxfQzfOnHIdU1t9Mf3MXwlS7EQRvVvl5QWXkkSUCd8tq8A8Ab2ZwekYFGw" \
-H "Accept: application/json" \
-H "Content-Type: application/json" \
-H "Client-Id: 501" \
-X POST "https://your.connector.url/api/priora/v1/tokens/confirm"
Example of request parameters
{"data":{"session_secret":"sc_fKtTtoHc9HkJstyfw","provider_code":"demobank","original_request":{"client_jwt":"Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7ImNyZWRlbnRpYWxzIjp7InR5cGUiOiJvYXV0aCJ9fSwiZXhwIjoxNTc0MDkzMjA5fQ.HaJ2ZK1VVoQrhRFlIPZNM5w4mj8PTolOpAlrEEOTceFIakc45nQLwPiRCrPONAiznTI1250EdoMUwRfaWz1AQ0FAv-WsWfoymN3biYcZZp4FeArLW82wzsDFWU9VWUHSHx2zL_I7vvVhlJcPb_tzIRVqRRLTMNzvJ2O_XXgHOxmSAqzCpuQ7AUEzA5YuD1Z81d5Oq3-73f0dczw56y6q5xnV86rngk93Qia7FGz2F-GcwInWzGIlWgmQt1bMwHym6ruEUsyLNgOKjuNnqFhKp98vWQihQnVVAve7lchPokYaX2IFSI8gadOaSgWrCao2x2IMjBFq0vohV1BqYlEKaQ","client_payload":{"data":{"credentials":{"sms_pincode":"4896"}},"exp":1574093209}}},"exp":1574093209}
Request
POST
https://your.connector.url/api/priora/v1/tokens/confirm
Headers
Header | Type | Description |
---|---|---|
Authorization
|
string, required |
JSON Web Token containing payload, signed using RSA256 and application.private_key .
|
Accept
|
string, required | Media type that is acceptable for the response. Allowed values: application/json |
Content-Type
|
string, required | The media type of the body of the request. Allowed values: application/json |
Client-Id
|
integer, required | Client application identifier in Salt Edge PSD2 Compliance. Should be used to get public key for Authorization header validation. |
Consent-Id
|
integer, optional | ID of the corresponding consent object as returned by an Account Information Consent Request. |
Unpacked Request Authorization
Response headers
Header | Type | Description |
---|---|---|
Retry-After
|
integer, optional | Amount of time in seconds after which Salt Edge PSD2 Compliance Solution resends the previously failed request. |
Response
Upon successful request, 200 status code should be returned.
Cancel
Cancel any access token that is in the process of enrollment, meaning it has not been confirmed yet.
CURL
curl -i \
-H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7InNlc3Npb25fc2VjcmV0IjoiZzRmeV9XNHh5YzZUUktzWVNBTXQifSwiZXhwIjoxNzM3MjQxOTczLCJpc3MiOiJwcmlvcmEuc2FsdGVkZ2UuY29tIn0.r8u57N4yyfhskX0PRkhZ0F3mzKIMTWkD_AfqzpspMswCLzbW5KzzcR1UvluC6TGYXPyirvlS_NwfVvAdpIfk7-182farRZJTdUz-EdFzBEAcmKBvgtkB6XUKjkTYBR71s2Dm0yWE3Kfx6b3UfyIuzNq9pyHat5JhLTxZApjsK0NX4M-iQR_z-vXNCzXjdFWjpUHgE1-UAUXZ3vRk0DVpcRJi8T9pf-MMTtXgtxIgqa52KnMGeKNUS0c9lVhKfhRFSaool-a8XUKDjU4MaucuCBg3HEgIzDbcIQSkM1DcmVDnOixEwW9nOmzBQbpq_RfTxgay8y7raqzEzeXs5eZ3Jw" \
-H "Accept: application/json" \
-H "Content-Type: application/json" \
-H "Client-Id: 830" \
-X POST "https://your.connector.url/api/priora/v1/tokens/cancel"
Example of request parameters
{"data":{"session_secret":"g4fy_W4xyc6TRKsYSAMt"},"exp":1574093209}
Request
POST
https://your.connector.url/api/priora/v1/tokens/cancel
Headers
Header | Type | Description |
---|---|---|
Authorization
|
string, required |
JSON Web Token containing payload, signed using RSA256 and application.private_key .
|
Accept
|
string, required | Media type that is acceptable for the response. Allowed values: application/json |
Content-Type
|
string, required | The media type of the body of the request. Allowed values: application/json |
Client-Id
|
integer, required | Client application identifier in Salt Edge PSD2 Compliance. Should be used to get public key for Authorization header validation. |
Consent-Id
|
integer, optional | ID of the corresponding consent object as returned by an Account Information Consent Request. |
Unpacked Request Authorization
Response headers
Header | Type | Description |
---|---|---|
Retry-After
|
integer, optional | Amount of time in seconds after which Salt Edge PSD2 Compliance Solution resends the previously failed request. |
Response
Upon successful request, 200 status code should be returned.
Accounts
This endpoint is responsible for fetching account information for Account Information Service.
Fetch
Fetch list of accounts belonging to a PSU and all relevant information about them. Accounts available for making payments will be flagged accordingly.
CURL
curl -i \
-H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7InNlc3Npb25fc2VjcmV0IjoiY3ppYVRYZ0JhQ1llckVIRHZXRTkifSwiZXhwIjoxNzM3MjQxOTczLCJpc3MiOiJwcmlvcmEuc2FsdGVkZ2UuY29tIn0.sDSubIAmQnCEuiCCMWrXHRNC9LEnWMJXEHeDphRTKMIgvykr90f_aZGti5oYRXrIEd0Wt3xs1QHCwRbvi9l3TnKY_FbGZy-KWx5KFJoWSTm5L7W3TQ0igr3g9evd1LjTHbUEaLeYh9TO5z8NTOS5gPPzsFKhIpm8ttJnE4FBjDSv3oQGLOyyvxTvJB8yoHX3wILXisrPq5DJ88_Ldr4tN1qTFi5uo0wXkBffS_QbXckcmVjXqyRoaQFrglQS1QXqMhIURTqR4NmqYQrwx_Ch6rg_BwjnyxDkZwKJu-TVn_ZpoAhTs8JAGFcGcr_sMBK7sdhwFjhWZFqE-ozJI6mdiQ" \
-H "Access-Token: e4649d535f5e3125bcc939e2f3b33a070127be520e2f1134ed8722976703e0b32d9354fb147014103ce39f6eed428ac65d82659b6289901449c73d12d939c28f" \
-H "Accept: application/json" \
-H "Content-Type: application/json" \
-H "Client-Id: 765" \
-X GET "https://your.connector.url/api/priora/v1/accounts"
Example of request parameters
{"data":{"session_secret":"cziaTXgBaCYerEHDvWE9"},"exp":1574093209}
Example of response
{"data":[{"id":"724","name":"Example Name","iban":"FK54RAND61068421435452","currency_code":"USD","extra":{},"number":"619656558","sort_code":"82-78-66","swift_code":"TBNFFR23PAR","nature":"credit","payment_account":false,"balance":"5000.00","available_amount":"4995.00","credit_limit":"7000","status":"active"}]}
Request
GET
https://your.connector.url/api/priora/v1/accounts
Headers
Header | Type | Description |
---|---|---|
Authorization
|
string, required |
JSON Web Token containing payload, signed using RSA256 and application.private_key .
|
Access-Token
|
string, required | The token which is created by a connector as a result of successful authentication. |
Accept
|
string, required | Media type that is acceptable for the response. Allowed values: application/json |
Content-Type
|
string, required | The media type of the body of the request. Allowed values: application/json |
Client-Id
|
integer, required | Client application identifier in Salt Edge PSD2 Compliance. Should be used to get public key for Authorization header validation. |
Consent-Id
|
integer, optional | ID of the corresponding consent object as returned by an Account Information Consent Request. |
Unpacked Request Authorization
Response headers
Header | Type | Description |
---|---|---|
Retry-After
|
integer, optional | Amount of time in seconds after which Salt Edge PSD2 Compliance Solution resends the previously failed request. |
Response
Upon successful request, 200 status code should be returned.
Refresh
In case the connector uses a different database from Core Banking, this endpoint enables the process of refreshing accounts and transactions on connector side before sending them to Salt Edge PSD2 Compliance Solution.
CURL
curl -i \
-H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7InNlc3Npb25fc2VjcmV0IjoieGRzUHNMd19lUkw2Tko4bTIzR2UiLCJmcm9tX2RhdGUiOiIyMDE5LTA4LTE4IiwidG9fZGF0ZSI6IjIwMTktMTEtMTgifSwiZXhwIjoxNzM3MjQxOTczLCJpc3MiOiJwcmlvcmEuc2FsdGVkZ2UuY29tIn0.FTXV7R9G41nGgZHM4QD3rs-Mc2vBj-kSzeMIKGvKsmi41M2VwWA-pcmM2rJ7UpSPbEG6aWwIXZwmZ-mDSbZ71q6T2guP9xQRAYAOQb_LxHXwmRAuATfxbUFnX6ARJXDey6i0BB53bir1lp5sa5waGP2IG1k45af4q7stANQ8l7U-940YXP0id5XtGfk65mbeSoibUVnwUskpxfksKxtR2tVcFct5GsTFSeaKL3QSiIOMoo688Ql7GcsvIVtXc7CSREdMihx9IQ1qzVssNO5X8Qh24Q0OaEesj0Z9qPICjeXGDCg8eqf2lxV4YNS633tc4f4l1TZsv-PHj2KEauXZLA" \
-H "Access-Token: 4fd12e851a9ed70420c3b2e8d5471ae56438e0875ba521c02bff802a176f4c99bebda2e3516e644fc99e37facf0c02e52836fefedcfc2dc9a44d993218bcda70" \
-H "Accept: application/json" \
-H "Content-Type: application/json" \
-H "Client-Id: 786" \
-X PUT "https://your.connector.url/api/priora/v1/accounts"
Example of request parameters
Request
PUT
https://your.connector.url/api/priora/v1/accounts
Headers
Header | Type | Description |
---|---|---|
Authorization
|
string, required |
JSON Web Token containing payload, signed using RSA256 and application.private_key .
|
Access-Token
|
string, required | The token which is created by a connector as a result of successful authentication. |
Accept
|
string, required | Media type that is acceptable for the response. Allowed values: application/json |
Content-Type
|
string, required | The media type of the body of the request. Allowed values: application/json |
Client-Id
|
integer, required | Client application identifier in Salt Edge PSD2 Compliance. Should be used to get public key for Authorization header validation. |
Consent-Id
|
integer, optional | ID of the corresponding consent object as returned by an Account Information Consent Request. |
Unpacked Request Authorization
Response headers
Header | Type | Description |
---|---|---|
Retry-After
|
integer, optional | Amount of time in seconds after which Salt Edge PSD2 Compliance Solution resends the previously failed request. |
Response
Upon successful request, 200 status code should be returned.
Confirm
This endpoint is used for processing additional interactive steps in the process of accounts refresh. As a result, Connector should send a success or fail callback to Salt Edge PSD2 Compliance with result of the operation.
CURL
curl -i \
-H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7InNlc3Npb25fc2VjcmV0IjoieGtlVE53UjNHSEgzY0hjcTNVQ3QiLCJwcm92aWRlcl9jb2RlIjoiZGVtb2JhbmsiLCJvcmlnaW5hbF9yZXF1ZXN0Ijp7ImNsaWVudF9qd3QiOiJCZWFyZXIgZXlKMGVYQWlPaUpLVjFRaUxDSmhiR2NpT2lKU1V6STFOaUo5LmV5SmtZWFJoSWpwN0ltTnlaV1JsYm5ScFlXeHpJanA3SW5OdGMxOXdhVzVqYjJSbElqb2lORFUyT0NKOWZTd2laWGh3SWpveE5UZ3pNalF5TnpZMGZRLlZPaGE4Rm13MTBQUkFoNjZHN3JwaVdWZS1ldEdYOVZGTzFjM185WFhRa2VtRGItS2N5STBMT2htM2xvd0c0MzJ6XzFnTzV6Z1p3cDdpVXdRQWVBTmk0aXJzU0MtOWNPQ01NdTNRY2RCU28zRHlpU2xLMDZObmRrZUZyYUYzb1puNVVMczF1YzYyVjFCNVJFRkJBS0NQaVNaeHQ4UWp0WWFWc3U4dGdYVFZ6N2FYMnNtNlZHOGJuSHp2cEdNcWt4LXQtclJEQ1lYTGlnTlpCR1hRTmhlTUE3RG1ERS14QzlEMzE3OWh6bUZpbGtVYktxYlgxOV93YnEzZFNaRk9SU2t3MHQ4bW1IeEwxV21lWFpTcm9OOXkzQmQwek9VQ3NjdGZUaXl1TzZsd05mYlhoZW5qcEJsdGM4dzEyZmRFU192cTVvOG56SDh0QzBJSnFQRFdYaFI4QSIsImNsaWVudF9wYXlsb2FkIjp7ImRhdGEiOnsiY3JlZGVudGlhbHMiOnsic21zX3BpbmNvZGUiOiI0NTY4In19LCJleHAiOjE1NzQwOTMyMTB9fX0sImV4cCI6MTczNzI0MTk3MywiaXNzIjoicHJpb3JhLnNhbHRlZGdlLmNvbSJ9.TMofdZMi-HkA2eww3W5EY1dUbBB9J2uplVB8Q66hd9dzlQ3BJGFYfe9uFXuaJ4WE6vJeO5hCDHWCUVjf8BxCC6B40rc9n9k4G1GHpLjYLvQFJSsdjdQTEqQNj1UQenOl3J4qd61eY1fCbZ4ML2zbZ5WB8-ZYW_pEC0is3PGJXQ6ZA1i4k47rajzvy0bnVyiYfweVu61tUmXiSGdUdleKvJC6tu7PP85H8qILV4-IwZG0w3_l9zsrUsHaC2NCiSGvZTmR5cBVqNkagwgcbKmT4khudpMthCTvEOJ9wkK3v9DoJnie4iZyF2hTcjV3dg99XqK2einK2jKf6eJGaN90bA" \
-H "Access-Token: 65adc909f5676f3902787ecb6f379c1c48bfc18a222157713808274b100b9e255f7b4b59a3ecd7689cb2abe26f8705dfd89b7a0cc9e9a07a587dc64a7c4572ad" \
-H "Accept: application/json" \
-H "Content-Type: application/json" \
-H "Client-Id: 843" \
-X POST "https://your.connector.url/api/priora/v1/accounts/confirm"
Example of request parameters
{"data":{"session_secret":"xkeTNwR3GHH3cHcq3UCt","provider_code":"demobank","original_request":{"client_jwt":"Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7ImNyZWRlbnRpYWxzIjp7InNtc19waW5jb2RlIjoiNDU2OCJ9fSwiZXhwIjoxNTgzMjQyNzY0fQ.VOha8Fmw10PRAh66G7rpiWVe-etGX9VFO1c3_9XXQkemDb-KcyI0LOhm3lowG432z_1gO5zgZwp7iUwQAeANi4irsSC-9cOCMMu3QcdBSo3DyiSlK06NndkeFraF3oZn5ULs1uc62V1B5REFBAKCPiSZxt8QjtYaVsu8tgXTVz7aX2sm6VG8bnHzvpGMqkx-t-rRDCYXLigNZBGXQNheMA7DmDE-xC9D3179hzmFilkUbKqbX19_wbq3dSZFORSkw0t8mmHxL1WmeXZSroN9y3Bd0zOUCsctfTiyuO6lwNfbXhenjpBltc8w12fdES_vq5o8nzH8tC0IJqPDWXhR8A","client_payload":{"data":{"credentials":{"sms_pincode":"4568"}},"exp":1574093210}}},"exp":1574093210}
Request
POST
https://your.connector.url/api/priora/v1/accounts/confirm
Headers
Header | Type | Description |
---|---|---|
Authorization
|
string, required |
JSON Web Token containing payload, signed using RSA256 and application.private_key .
|
Access-Token
|
string, required | The token which is created by a connector as a result of successful authentication. |
Accept
|
string, required | Media type that is acceptable for the response. Allowed values: application/json |
Content-Type
|
string, required | The media type of the body of the request. Allowed values: application/json |
Client-Id
|
integer, required | Client application identifier in Salt Edge PSD2 Compliance. Should be used to get public key for Authorization header validation. |
Consent-Id
|
integer, optional | ID of the corresponding consent object as returned by an Account Information Consent Request. |
Unpacked Request Authorization
Response headers
Header | Type | Description |
---|---|---|
Retry-After
|
integer, optional | Amount of time in seconds after which Salt Edge PSD2 Compliance Solution resends the previously failed request. |
Response
Upon successful request, 200 status code should be returned.
Transactions
This endpoint is responsible for fetching transactions which belong to previously fetched accounts.
Fetch
Fetch all transactions related to a bank account.
CURL
curl -i \
-H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7InNlc3Npb25fc2VjcmV0IjoieVBzZXRDeVA3Y0d6bnZiOVNERkMiLCJhY2NvdW50X2lkIjoiODciLCJmcm9tX2RhdGUiOiIyMDE5LTExLTE4VDE2OjA0OjQ5LjU4NVoiLCJ0b19kYXRlIjoiMjAxOS0xMS0xOFQxNjowNDo0OS41ODVaIn0sImV4cCI6MTczNzI0MTk3MywiaXNzIjoicHJpb3JhLnNhbHRlZGdlLmNvbSJ9.Hy1NWylAYwb7M2FF0G74LqfT9Kw5WyxRdZkeSs2QeicGzozR9sapldbZ9gBckbusLd89YjIB4gOgHzU_kZNeUP6KO8G_O9n_-UzAcMyk5Ka9l2VnPOmhWD7SpY80pChtBYguU8uvSgyZijvmVcOfbRIIGi0sGPEpaMudUPzOlUh-qcov9gzjDPkPhXYs2rJQAp5yrypDJsQeOYlTVlzLZw5VT07Ga4YnqQcF3baZq5wW-70W3BJuK8Xy5JWFd2hf5emHzZqD5Q92NG_oMoLJoAgVbnlUhitEQ-MkYv96bmczPOCulTCliyzwRq77N8CDrKof8JnsmuWXzNG-ZApZyw" \
-H "Access-Token: 2cab054fa0dfd20d725ef46c533b537701c29d47ebea97893374d4e47714e49e2e331764e4f4a20d5e285dbb08af9566e14a8f597230bca6d9f5b3b2048a71f5" \
-H "Accept: application/json" \
-H "Content-Type: application/json" \
-H "Client-Id: 866" \
-X GET "https://your.connector.url/api/priora/v1/transactions"
Example of request parameters
{"data":{"session_secret":"yPsetCyP7cGznvb9SDFC","account_id":"87","from_date":"2019-11-18T16:04:49.585Z","to_date":"2019-11-18T16:04:49.585Z"},"exp":1574093209}
Example of response
{"data":[{"id":"378","account_id":"241","amount":"38.85","currency_code":"GBP","description":"Test transaction","made_on":"2019-11-18T16:04:49.573Z","status":"posted","fees":[{}],"extra":{"mcc":"example_data.extra.mcc","original_amount":"38.85","original_currency_code":"GBP"}}]}
Request
GET
https://your.connector.url/api/priora/v1/transactions
Headers
Header | Type | Description |
---|---|---|
Authorization
|
string, required |
JSON Web Token containing payload, signed using RSA256 and application.private_key .
|
Access-Token
|
string, required | The token which is created by a connector as a result of successful authentication. |
Accept
|
string, required | Media type that is acceptable for the response. Allowed values: application/json |
Content-Type
|
string, required | The media type of the body of the request. Allowed values: application/json |
Client-Id
|
integer, required | Client application identifier in Salt Edge PSD2 Compliance. Should be used to get public key for Authorization header validation. |
Consent-Id
|
integer, optional | ID of the corresponding consent object as returned by an Account Information Consent Request. |
Unpacked Request Authorization
Response headers
Header | Type | Description |
---|---|---|
Retry-After
|
integer, optional | Amount of time in seconds after which Salt Edge PSD2 Compliance Solution resends the previously failed request. |
Response
Upon successful request, 200 status code should be returned.
KYC
This endpoint is responsible for fetching personal data of PSU.
Fetch
Extract PSU’s personal data. Response should contain a JSON object representing a PSU.
CURL
curl -i \
-H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7InNlc3Npb25fc2VjcmV0IjoieVBzZXRDeVA3Y0d6bnZiOVNERkMifSwiZXhwIjoxNzM3MjQxOTczLCJpc3MiOiJwcmlvcmEuc2FsdGVkZ2UuY29tIn0.CASYGXSz248cLhNjecKTna0CzEczYNX0xYFvUvi1Gso2kBLMaSUynpM63uEylKUgzpMyWn6RQ3hVcHn-wlNMCLAXW3qv74Z47BBpjQ4DG4eX4QnCkV5CM5jydxAOrrcb42ln88hhHkAvYal_027DWuYCUgwniqW1o7fRcjHusp8yAKMfMqbzXI1M09lxAIgpfR2vLD72yHllbkxe8geOqMYnbJhBiDyRPyZKySlN_W-dkjAFS9jEtHnSjCzO19m0im6zzRI19_-WACWxOtSnVW0Vr3glA7xX5pDpqq4X7zoCLioFLQym2i5rv5w-VkwttBchuKOsMSBVxRH32f9qpg" \
-H "Access-Token: 3a0b2f004410dca9713cd484a02bb565292e3945500334798274584c7448e9171d1ec9e3d74392792021a7698c7fdee0df041eccc9706871907686770f47833a" \
-H "Accept: application/json" \
-H "Content-Type: application/json" \
-H "Client-Id: 552" \
-X GET "https://your.connector.url/api/priora/v1/kyc"
Example of request parameters
{"data":{"session_secret":"yPsetCyP7cGznvb9SDFC"},"exp":1574093209}
Example of response
{"data":{"name":"Example Name"}}
Request
GET
https://your.connector.url/api/priora/v1/kyc
Headers
Header | Type | Description |
---|---|---|
Authorization
|
string, required |
JSON Web Token containing payload, signed using RSA256 and application.private_key .
|
Access-Token
|
string, required | The token which is created by a connector as a result of successful authentication. |
Accept
|
string, required | Media type that is acceptable for the response. Allowed values: application/json |
Content-Type
|
string, required | The media type of the body of the request. Allowed values: application/json |
Client-Id
|
integer, required | Client application identifier in Salt Edge PSD2 Compliance. Should be used to get public key for Authorization header validation. |
Consent-Id
|
integer, optional | ID of the corresponding consent object as returned by an Account Information Consent Request. |
Unpacked Request Authorization
Response headers
Header | Type | Description |
---|---|---|
Retry-After
|
integer, optional | Amount of time in seconds after which Salt Edge PSD2 Compliance Solution resends the previously failed request. |
Response
Upon successful request, 200 status code should be returned.
Errors
Additional endpoints to be implemented on connector side to improve communication between Salt Edge PSD2 Compliance Solution and Connector.
Notify
This endpoint is responsible for receiving validation errors of responses which Connector sends to Salt Edge PSD2 Compliance Solution
CURL
curl -i \
-H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7InJlcXVlc3QiOnsibWV0aG9kIjoiZGVsZXRlIiwidXJsIjoiaHR0cHM6Ly91c2VyLndpbGwuYmUvcmVkaXJlY3RlZC9oZXJlIiwiaGVhZGVycyI6e319LCJlcnJvciI6eyJlcnJvcl9tZXNzYWdlIjoic29tZXRoaW5nIHdlbnQgd3JvbmciLCJlcnJvcl9jbGFzcyI6IkludGVybmFsUHJvdmlkZXJFcnJvciJ9fSwiZXhwIjoxNzM3MjQxOTczLCJpc3MiOiJwcmlvcmEuc2FsdGVkZ2UuY29tIn0.DVyjgDIeDayaaFr-RuWlP_95ctiDAsJtWtK7p1rYmGW7ciHd-1JVitw2hdDdlxWZ1UzIs7Yg0Sjg11vloLQHce8bolx9saGPyDToql4G1f50YYY9fCLjHtIhUaJHwyKuRUoW6S1PbHNzVUHVkQEsYdxIDMVWJuCRdu1CMjueLhLFB17XtsKxhgmLX_ymuYnN1fVUbZ8B2ib08NC7aLgtRMdD_sTxx_QAHVW7SEnXYRApp0bBaLpRnkC6ckB_gtLkXa-vBe3_jsNwq3pBOBd1RCPUQavn05fwcbgz_vRyOsGMAXpjLKfZP7DQEjLjo787YA4SjmkUVP8tV0Gi7u_71A" \
-H "Access-Token: b2077c5c020a5e262767aac63fdbc75fd64461afc660784fbc3451766f586bb4836e3405007c2caf497a1125ba58fb49be65b3c352285dea68328aded84e2f91" \
-H "Accept: application/json" \
-H "Content-Type: application/json" \
-H "Client-Id: 685" \
-X POST "https://your.connector.url/api/priora/v1/errors"
Example of request parameters
{"data":{"request":{"method":"delete","url":"https://user.will.be/redirected/here","headers":{}},"error":{"error_message":"something went wrong","error_class":"InternalProviderError"}},"exp":1574093209}
Request
POST
https://your.connector.url/api/priora/v1/errors
Headers
Header | Type | Description |
---|---|---|
Authorization
|
string, required |
JSON Web Token containing payload, signed using RSA256 and application.private_key .
|
Access-Token
|
string, required | The token which is created by a connector as a result of successful authentication. |
Accept
|
string, required | Media type that is acceptable for the response. Allowed values: application/json |
Content-Type
|
string, required | The media type of the body of the request. Allowed values: application/json |
Client-Id
|
integer, required | Client application identifier in Salt Edge PSD2 Compliance. Should be used to get public key for Authorization header validation. |
Consent-Id
|
integer, optional | ID of the corresponding consent object as returned by an Account Information Consent Request. |
Unpacked Request Authorization
Response headers
Header | Type | Description |
---|---|---|
Retry-After
|
integer, optional | Amount of time in seconds after which Salt Edge PSD2 Compliance Solution resends the previously failed request. |
Response
Upon successful request, 200 status code should be returned.
Salt Edge Endpoints
Sessions
Success
Success callback should be sent to Salt Edge PSD2 Compliance when all required verification steps have been passed, and therefore access is granted.
CURL
curl -i \
-H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7InNlc3Npb25fc2VjcmV0IjoiR2NRXzF1cW1reFlUSzFYV1EydTMiLCJ0b2tlbiI6ImFpeXVUVGdwYTRKdndRZUtoRHpmIiwidG9rZW5fZXhwaXJlc19hdCI6IjIwMTktMTEtMThUMTY6MDQ6NDguNzk5WiJ9LCJleHAiOjE3MzcyNDE5NzMsImlzcyI6InByaW9yYS5zYWx0ZWRnZS5jb20ifQ.tNzzkL_4ZowIPYHtcdE90_McHVBKFVIjt-3Yf-ALccBULlnWTjT-U7JOL-X4UKDBRWNCjJZ25TPgVxeJFkKsrG2y48DES1qvFx2kG8i7-PVbVIDbpB_MulZLPA_RhcpI_aXHyonSINYoAzcilCUfv3yvYyr-quWUfQK9jYtio5rHgP-ICH_EfrBLoUbQQCyWba-qH-99kJHzns0CJ-5W2XGCd1r3i91gq4F5Z16107LgpLgwxAv2Z4PJr3_mpGuwWY0L9S1vM6lZB-vKGNw1K2TiBzbyLKh89zTnp7t_6ld9oDf4FbDG5t3NCwEsWlfjV4ER6MY05fRI0VL4YNCBsQ" \
-H "App-Id: qjQYP-jCx-8FBsZSgNVzIw" \
-H "App-Secret: -XeeN2UhtdphUGtI-FZpzg" \
-X POST "/api/connectors/v1/sessions/success"
Example of request parameters
Example of response
{"data":{},"meta":{"time":"2019-11-18T16:04:48.773Z"}}
Request
POST
/api/connectors/v1/sessions/success
Headers
Header | Type | Description |
---|---|---|
Authorization
|
string, required |
JSON Web Token containing payload, signed using RSA256 and application.private_key .
Can raise:
AuthorizationMissing
|
App-Id
|
string, required |
Provider's app_id from connection details tab.
Can raise:
ProviderNotFound, ProviderDisabled, ConfigurationError
|
App-Secret
|
string, required |
Provider's app_secret from connection details tab.
|
Unpacked Request Authorization
Response
Upon successful request, 200 status code will be returned. See ‘Related Errors’ table for other possibilities.
Related Errors
Class | Code | Description |
---|---|---|
SessionClosed | 400 | Session specified in request is already closed and cannot be modified. |
ConfigurationError | 400 | Missing configurations in dashboard. |
SessionExpired | 401 | Found session is expired and cannot be processed anymore. |
AuthorizationMissing | 401 | Authorization header is missing. |
SessionNotFound | 404 | Session specified in request does not exist or cannot be retrieved. |
ProviderNotFound | 404 | Provider specified in request does not exist or cannot be retrieved. |
ActionNotAllowed | 406 | You're not allowed to perform this action. This might be a configuration problem or parameters incompatibility. |
ProviderDisabled | 406 | Cooperation with specified Provider is impossible. |
Update
Update callback may be accessed multiple times in order to request multiple steps of authorization or to send other updates to Salt Edge PSD2 Compliance session.
CURL
curl -i \
-H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7ImV4dHJhIjp7fSwiaW50ZXJhY3RpdmVfc3RlcF9pbnN0cnVjdGlvbiI6eyJpbnN0cnVjdGlvbiI6e30sImludGVyYWN0aXZlX2ZpZWxkIjoic21zX3BpbmNvZGUifSwic3RhdHVzIjoid2FpdGluZ19jb25maXJtYXRpb25fY29kZSIsInNlc3Npb25fZXhwaXJlc19hdCI6IjIwMjAtMDMtMDJUMTU6Mzc6MzAuOTIzWiIsInNlc3Npb25fc2VjcmV0IjoiSHMteGM4b3pBV0xrMXh0X3pUNHYifSwiZXhwIjoxNzM3MjQxOTczLCJpc3MiOiJwcmlvcmEuc2FsdGVkZ2UuY29tIn0.KalLPVkllxw1Y7oCnDzJFCyVLsCMsInCmmW-XdEZ0M3IOULgxRaoGUzD-qB1eGj3C-VWCwQadz-zBqamZuSPJwZc3EyqRNX80AKxowNKOcNprgS2Zax2qH1bURmH6H304BTL6xUXeCjB1yCKrOQX3JejMmpPCHH-mL8c84beCR0ngKv5rqEaPMPM1FSpLEYFos9lGnPLIXC4Pi54x21iy7WqvVhCGgw8fCN4MfzoBBFEDPaN8uwW_wCgohBjSjFML50dAygYnz3X1A6L-rinIwEUhiYfmX9XMB1tgo7rRwolBPnrhP3sQH0KJayN3QNHQ1gDl83Hv3BktXNCfbWHlw" \
-H "App-Id: q5QE7Dqlpm1d5weLS5pn7w" \
-H "App-Secret: y8imt1cgG8x2zmBMrF-oxw" \
-X POST "/api/connectors/v1/sessions/update"
Example of request parameters
Example of response
{"data":{},"meta":{"time":"2019-11-18T16:04:48.853Z"}}
Request
POST
/api/connectors/v1/sessions/update
Headers
Header | Type | Description |
---|---|---|
Authorization
|
string, required |
JSON Web Token containing payload, signed using RSA256 and application.private_key .
Can raise:
AuthorizationMissing
|
App-Id
|
string, required |
Provider's app_id from connection details tab.
Can raise:
ProviderNotFound, ProviderDisabled, ConfigurationError
|
App-Secret
|
string, required |
Provider's app_secret from connection details tab.
|
Unpacked Request Authorization
Response
Upon successful request, 200 status code will be returned. See ‘Related Errors’ table for other possibilities.
Related Errors
Class | Code | Description |
---|---|---|
SessionClosed | 400 | Session specified in request is already closed and cannot be modified. |
ConfigurationError | 400 | Missing configurations in dashboard. |
SessionExpired | 401 | Found session is expired and cannot be processed anymore. |
AuthorizationMissing | 401 | Authorization header is missing. |
SessionNotFound | 404 | Session specified in request does not exist or cannot be retrieved. |
ProviderNotFound | 404 | Provider specified in request does not exist or cannot be retrieved. |
ActionNotAllowed | 406 | You're not allowed to perform this action. This might be a configuration problem or parameters incompatibility. |
ProviderDisabled | 406 | Cooperation with specified Provider is impossible. |
Fail
Fail callback should be used when authorization process has been compromised for any reason: broken request, invalid credentials, etc.
CURL
curl -i \
-H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7InNlc3Npb25fc2VjcmV0IjoiM1BRaXB1RFBvV3BhMTFGY1ZFVjYiLCJlcnJvcl9jbGFzcyI6IkludGVybmFsUHJvdmlkZXJFcnJvciIsImVycm9yX21lc3NhZ2UiOiJJbnRlcm5hbCBlcnJvciIsImV4dHJhIjp7fX0sImV4cCI6MTczNzI0MTk3MywiaXNzIjoicHJpb3JhLnNhbHRlZGdlLmNvbSJ9.HPF0ADkZHkgbZ8VyXwHSd7t08YFZJpDa0SyT18ByQJ5pvPrCYOhYzxa7N_de4t9eDH82-B_HvyJU3rJ4HqGVMIeFlzA6VKPeDnNwp8Ty64w5dv2tRnN-0ElPx6dUD0pZSqpFGtEOLK2nYbLNLKiOh9rOWNDCl_84mi4smoFMkEN8eRBy0DOvUrYlRlakyDBiHpZ7k0_NjSCz--smuY32HpOwl-LiKJf-nJJ0cQaxpD01H0umOwaNYlKj-D_VaQhGv9uFbeiIAcds3WgCwHiewenNUk8XbKqSvCmwke0bboIGelvNlZcRmSEM8Y5lIkvpLWV-hUT02a8JTjcQxnEySQ" \
-H "App-Id: xU7SyhPrd95GAPSMNo_XMQ" \
-H "App-Secret: BVSkESo7zpRdzk_hWUUwCQ" \
-X POST "/api/connectors/v1/sessions/fail"
Example of request parameters
{"data":{"session_secret":"3PQipuDPoWpa11FcVEV6","error_class":"InternalProviderError","error_message":"Internal error","extra":{}},"exp":1574093208}
Example of response
{"data":{},"meta":{"time":"2019-11-18T16:04:48.710Z"}}
Request
POST
/api/connectors/v1/sessions/fail
Headers
Header | Type | Description |
---|---|---|
Authorization
|
string, required |
JSON Web Token containing payload, signed using RSA256 and application.private_key .
Can raise:
AuthorizationMissing
|
App-Id
|
string, required |
Provider's app_id from connection details tab.
Can raise:
ProviderNotFound, ProviderDisabled, ConfigurationError
|
App-Secret
|
string, required |
Provider's app_secret from connection details tab.
|
Unpacked Request Authorization
Response
Upon successful request, 200 status code will be returned. See ‘Related Errors’ table for other possibilities.
Related Errors
Class | Code | Description |
---|---|---|
SessionClosed | 400 | Session specified in request is already closed and cannot be modified. |
ConfigurationError | 400 | Missing configurations in dashboard. |
SessionExpired | 401 | Found session is expired and cannot be processed anymore. |
AuthorizationMissing | 401 | Authorization header is missing. |
SessionNotFound | 404 | Session specified in request does not exist or cannot be retrieved. |
ProviderNotFound | 404 | Provider specified in request does not exist or cannot be retrieved. |
ActionNotAllowed | 406 | You're not allowed to perform this action. This might be a configuration problem or parameters incompatibility. |
ProviderDisabled | 406 | Cooperation with specified Provider is impossible. |
Tokens
Index
Returns the list of access tokens issued by Provider for Salt Edge PSD2 Compliance Solution.
CURL
curl -i \
-H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7ImtpbmQiOiJyZXZva2VkIiwiZnJvbV9pZCI6MzAyLCJmcm9tX2RhdGUiOiIyMDE5LTA4LTIwVDE2OjA0OjQ5LjAyMVoiLCJwZXJfcGFnZSI6NTAsImN1c3RvbWVyX2lkIjo4MjF9LCJleHAiOjE3MzcyNDE5NzMsImlzcyI6InByaW9yYS5zYWx0ZWRnZS5jb20ifQ.FDcrAGOjwqM6MZs9buXcVKUwmOlBtlIgKihkiDiAIUqqOuPIh8DSm-dZrGMdGC7wHxxnC6HATaS7QOQmQbx5Oe7Jz8HC4b5AURUUci36gf-NO032qvwY7szmgRJt_oz3ok4t03mgiwBZcPi3u6tNZrrCfVhBOYF_ibym3c-SxN7_vWomvkF52laGouZCfQtotK953QAXPGdBh5mgvvRPn3e1z6-IU1cSXxYj3yi2cuD62Jh1oc4F2O4CftWxd3DmJgZjzobojXC5sF_PhrHjdjOYJ88YxY_lKCuxTwuOQclzvPU8xmC6WObvBwSEokQ6UyGtcRsFnXpY-aMMIWg5bg" \
-H "App-Id: G9SgwyF-RdxsjCu3f3mLnw" \
-H "App-Secret: Az6qAhT6pdezVjAex58qqQ" \
-X GET "/api/connectors/v1/tokens/index"
Example of request parameters
{"data":{"kind":"revoked","from_id":302,"from_date":"2019-08-20T16:04:49.021Z","per_page":50,"customer_id":821},"exp":1574093209}
Example of response
{"meta":{"next_id":303,"time":"2019-11-18T16:04:49.001Z"},"data":{"tokens":[]}}
Request
GET
/api/connectors/v1/tokens/index
Headers
Header | Type | Description |
---|---|---|
Authorization
|
string, required |
JSON Web Token containing payload, signed using RSA256 and application.private_key .
Can raise:
AuthorizationMissing
|
App-Id
|
string, required |
Provider's app_id from connection details tab.
Can raise:
ProviderNotFound, ProviderDisabled, ConfigurationError
|
App-Secret
|
string, required |
Provider's app_secret from connection details tab.
|
Unpacked Request Authorization
Response
Upon successful request, 200 status code will be returned. See ‘Related Errors’ table for other possibilities.
Related Errors
Class | Code | Description |
---|---|---|
ConfigurationError | 400 | Missing configurations in dashboard. |
AuthorizationMissing | 401 | Authorization header is missing. |
CustomerNotFound | 404 | PSU specified in request does not exist or cannot be retrieved. |
ProviderNotFound | 404 | Provider specified in request does not exist or cannot be retrieved. |
ProviderDisabled | 406 | Cooperation with specified Provider is impossible. |
Revoke
Revoke callback needs to be called any time a token is revoked on the Provider Connector side.
CURL
curl -i \
-H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7fSwiZXhwIjoxNzM3MjQxOTczLCJpc3MiOiJwcmlvcmEuc2FsdGVkZ2UuY29tIn0.IYlxlOoG47SrPKsX6ibHErvIzuJ1fTwhgli6vzL9zhUS8okO5Uka1nwSFrC2sy9nkYGPLy8dA3qb0fhMPiknPUpRZ1n33W5MwICwDRjg0_-0b8zjc-R4aIDh41Vq5KZpUEws4Z99SX7qrRM7XdpV_Cu8Lzrmp5H8ZpyOp2XFlT9h6EtfM-XLVR0kWyggL9PyEIfRO8VXd6wHuCrp2YAWN0-BHyf1_EGPyXzbF35Ht7QW_kaiqS2ChAJAha4uesvacCe8gRa9oczx9NqfpR02YU6mkYyirvHkm9Ob9q6_Ylh0xs4049xFXJCk9V8WoH5Yrd96cBj7mHYdCI05vQEFgA" \
-H "App-Id: cfOK5P9RVooLksNv8il3rw" \
-H "App-Secret: rwkTbW41SPT55uo1I_-UGQ" \
-H "Token: example_Token" \
-X DELETE "/api/connectors/v1/tokens/revoke"
Example of request parameters
{"data":{},"exp":1574093208}
Example of response
{"data":{"revoked":true},"meta":{"time":"2019-11-18T16:04:48.928Z"}}
Request
DELETE
/api/connectors/v1/tokens/revoke
Headers
Header | Type | Description |
---|---|---|
Authorization
|
string, required |
JSON Web Token containing payload, signed using RSA256 and application.private_key .
Can raise:
AuthorizationMissing
|
App-Id
|
string, required |
Provider's app_id from connection details tab.
Can raise:
ProviderNotFound, ProviderDisabled, ConfigurationError
|
App-Secret
|
string, required |
Provider's app_secret from connection details tab.
|
Token
|
string, required | Token for which we are requesting info. Can raise: TokenMissing, TokenNotFound, TokenRevoked, TokenExpired |
Unpacked Request Authorization
Response
Upon successful request, 200 status code will be returned. See ‘Related Errors’ table for other possibilities.
Related Errors
Class | Code | Description |
---|---|---|
ConfigurationError | 400 | Missing configurations in dashboard. |
TokenMissing | 400 | This request cannot be performed without TOKEN header. |
AuthorizationMissing | 401 | Authorization header is missing. |
TokenNotFound | 401 | Token specified in request does not exist or cannot be retrieved. |
TokenRevoked | 401 | Token specified in request is revoked and cannot be used anymore. |
TokenExpired | 401 | Token specified in request is expired and cannot be used. |
ProviderNotFound | 404 | Provider specified in request does not exist or cannot be retrieved. |
ProviderDisabled | 406 | Cooperation with specified Provider is impossible. |
Clients
Info
All requests that are forwarded by Salt Edge PSD2 Compliance Solution are signed by TPP applications. Provider can decide whether to decode the original request by itself or use decoded payload by Salt Edge PSD2 Compliance Solution which is stored in client_payload
key. In order to decode the client_jwt
, Connector has to perform the following request to obtain TPP's public key. The client_id
is present in Client-Id
header along with Authorization
header.
CURL
curl -i \
-H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7ImNsaWVudF9pZCI6NTE3fSwiZXhwIjoxNzM3MjQxOTczLCJpc3MiOiJwcmlvcmEuc2FsdGVkZ2UuY29tIn0.coNiIyhE_8_GROwlkJKiMN_uTcDDqHfgsOFaB4ShTi0gn7Ecg8BZqeGItRgU1fvN3ZbK6uAXHbtNY6pedg882OLfj9AHuDOECpHKn0HEDJQqLySXSDS6xDUlLfq1_B47SFTGltA_hRKAlZrvXrtXHEv4615nPKORw1BE1ZmA7EbEgssVbeNIrRqfyPUAJ5-GqrVrzqayp1Twpd9Fwbz2Jk_6rzSnFVm61xsPjBMMBCW9Kxfv7o52e3graXsWmmaZDR5MS0p_yWCbOwfls53-00fzkr11WMVpzpJwfbh5HFqil7v8sdl09oQhWacZoaMRUN8sWL2ljPneoqshwkPvUQ" \
-H "App-Id: hAnmNmGFFBN3W_jNWJd_fQ" \
-H "App-Secret: h6rzA_lw2wVuCpDaBKlxAA" \
-X GET "/api/connectors/v1/clients/info"
Example of request parameters
{"data":{"client_id":517},"exp":1574093208}
Example of response
{"data":{"name":"Fentury","scopes":["accounts","transactions","kyc"],"public_key":"-----BEGIN PUBLIC KEY-----\nMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCqGKukO1De7zhZj6+H0qtjTkVxwTCpvKe4eCZ0\nFPqri0cb2JZfXJ/DgYSF6vUpwmJG8wVQZKjeGcjDOL5UlsuusFncCzWBQ7RKNUSesmQRMSGkVb1/\n3j+skZ6UtW+5u09lHNsj6tQ51s1SPrCBkedbNf0Tp0GbMJDyR4e9T04ZZwIDAQAB\n-----END PUBLIC KEY-----"},"meta":{"time":"2019-11-18T16:04:48.271Z"}}
Request
GET
/api/connectors/v1/clients/info
Headers
Header | Type | Description |
---|---|---|
Authorization
|
string, required |
JSON Web Token containing payload, signed using RSA256 and application.private_key .
Can raise:
AuthorizationMissing
|
App-Id
|
string, required |
Provider's app_id from connection details tab.
Can raise:
ProviderNotFound, ProviderDisabled, ConfigurationError
|
App-Secret
|
string, required |
Provider's app_secret from connection details tab.
|
Unpacked Request Authorization
Response
Upon successful request, 200 status code will be returned. See ‘Related Errors’ table for other possibilities.
Related Errors
Class | Code | Description |
---|---|---|
ConfigurationError | 400 | Missing configurations in dashboard. |
AuthorizationMissing | 401 | Authorization header is missing. |
ProviderNotFound | 404 | Provider specified in request does not exist or cannot be retrieved. |
ProviderDisabled | 406 | Cooperation with specified Provider is impossible. |