Salt Edge PSD2 Compliance Logo

V2

Payments

OAuth Payment Flow OAuth Payment Flow

Create

Create a payment. As a result, Connector should send a success, update or fail callback to Salt Edge PSD2 Compliance with the result of the operation, be it a success, fail or request for additional steps.

CURL

curl -i  \ 
 -H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7ImFwcF9uYW1lIjoiRmVudHVyeSIsInBheW1lbnRfcHJvZHVjdCI6ImludGVybmFsLXRyYW5zZmVyIiwicmVkaXJlY3RfdXJsIjoiaHR0cHM6Ly9wbGVhc2UtcmVkaXJlY3QtbXktcHN1LmhlcmUiLCJwc3VfaXBfYWRkcmVzcyI6IjE5Mi4xMS4yLjE4IiwicGF5bWVudF9pZGVudGlmaWNhdGlvbiI6MSwicGF5bWVudCI6eyJyZW1pdHRhbmNlX2luZm9ybWF0aW9uX3Vuc3RydWN0dXJlZCI6IlBheW1lbnQgZGVzY3JpcHRpb24iLCJjcmVkaXRvcl9uYW1lIjoiSm9obiBTbWl0aCIsImluc3RydWN0ZWRfYW1vdW50Ijp7ImN1cnJlbmN5IjoiRVVSIiwiYW1vdW50IjoiMTQ1LjMifSwiZW5kX3RvX2VuZF9pZGVudGlmaWNhdGlvbiI6ImNjNWE4MDIyLTVlNzEtNDYwZS04MmZhLWFiMGJlMTk5N2E1IiwiY3JlZGl0b3JfYWNjb3VudCI6eyJpYmFuIjoiRks1NFJBTkQ2MTA2ODQyMTQzNTQ1MiJ9LCJyZXF1ZXN0ZWRfZXhlY3V0aW9uX2RhdGUiOiIyMDE5LTA2LTExIiwiY3JlZGl0b3JfYWdlbnRfbmFtZSI6IkFnZW50IE5hbWUiLCJjcmVkaXRvcl9hZGRyZXNzIjp7InN0cmVldF9uYW1lIjoic3RyLiBGaXJzdCBvZiBNYXkiLCJidWlsZGluZ19udW1iZXIiOiI0M2MiLCJ0b3duX25hbWUiOiJCdWRhcGVzdCIsInBvc3RfY29kZSI6IjQ0NTUxMSIsImNvdW50cnkiOiJIVSJ9LCJ1bHRpbWF0ZV9kZWJ0b3IiOiJBbGV4IFNtaXRoIiwiZGVidG9yX2lkIjoiMDEwMTMwMzAxOSIsInVsdGltYXRlX2RlYnRvcl9pZCI6IjAxMDEzMDMwMTkiLCJjcmVkaXRvcl9pZCI6IjQ3MDMwMTM5MjAiLCJ1bHRpbWF0ZV9jcmVkaXRvciI6IkpvaG4gU21pdGgiLCJ1bHRpbWF0ZV9jcmVkaXRvcl9pZCI6IjQ3MDMwMTM5MjAiLCJpY2VsYW5kaWNfcHVycG9zZV9jb2RlIjp7ImNvZGUiOiJSMSIsImRlc2NyaXB0aW9uIjoiRmFzdGVpZ25hZ2rDtmxkIn19fSwiZXhwIjoxNzMyNDMwNTg3LCJpc3MiOiJwcmlvcmEuc2FsdGVkZ2UuY29tIn0.f_wSZqlV5xVz0-ZK4POv_pNbqUhZeRJXtS1jd6J_tmHv1kQ8w16jIAR6bB_gR5jLfSKXnWlfTzwBwk2ebyp4h5uRP_MaTaHLFTCoY65d_ZR2kghuTEvJZw_8PcaGny91II9ERK7nmPvuDrE82OnCxm1kFQPnkhxFKDAMV964FgRj8mWzvUa8n6TT3iCnCl3f-dRN-D48J8OL3gGaRLB1PrDTmz8E4ciczK1yTUlIpQo2FkBEV2dflrfvb-D2tcsKTNpjprSEERTTp-jOqPFuo04cxc8nqle_pfT33ycnRXgSzNCH6kp32AARwh2x5Zpr7daSLMHawwXQgUzQ_BRxBQ" \ 
 -H "Accept: application/json" \ 
 -H "Content-Type: application/json" \ 
 -H "Client-Id: 771" \ 
 -H "Psu-Corporate-ID: 999" \ 
 -X POST "https://your.connector.url/api/priora/v2/payments"

Example of request parameters

Request

POST https://your.connector.url/api/priora/v2/payments

Headers
Header Type Description
Authorization string, required JSON Web Token containing payload, signed using RSA256 and application.private_key.
Accept string, required Media type that is acceptable for the response. Allowed values: application/json
Content-Type string, required The media type of the body of the request. Allowed values: application/json
Client-Id integer, required TPP application identifier in Salt Edge PSD2 Compliance.
Psu-Device-ID string, optional UUID (Universally Unique Identifier) for a device, which is used by the PSU, if available. UUID identifies either a device or a device dependant application installation. In case of an installation identification this ID need to be unaltered until removal from device.
Psu-User-Agent string, optional The forwarded Agent header field of the HTTP request between PSU and TPP, if available.
Psu-Geo-Location string, optional The forwarded Geo Location of the corresponding HTTP request between PSU and TPP if available.
Psu-Corporate-ID string, optional PSU corporate identifier (optional).
TPP-Explicit-Authorisation-Preferred boolean, optional If it equals "true", the TPP prefers to start the authorisation process separately, e.g. because of the usage of a signing basket. This preference might be ignored by the ASPSP, if a signing basket is not supported as functionality. If it equals "false" or if the parameter is not used, there is no preference of the TPP. This especially indicates that the TPP assumes a direct authorisation of the transaction in the next step, without using a signing basket. Default value: false
Unpacked Request Authorization
Response headers
Header Type Description
Retry-After integer, optional Amount of time in seconds after which Salt Edge PSD2 Compliance Solution resends the previously failed request.
Response

Create a payment. As a result, Connector should send a success, update or fail callback to Salt Edge PSD2 Compliance with the result of the operation, be it a success, fail or request for additional steps.


Related Errors
Class Code Description
CountryNameInvalid 400 Country doesn't exist or is invalid. Expected alpha 2 ISO3166 format.
ResourceUnknown 404 The addressed resource is unknown relative to the TPP

Revoke

Revoke a payment. As a result, Connector should send a success, update or fail callback to Salt Edge PSD2 Compliance with the result of the operation, be it a success, fail or request for additional steps.

CURL

curl -i  \ 
 -H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7InNlc3Npb25fc2VjcmV0IjoiY2M1YTgwMjItNWU3MS00NjBlLTkzZmEtYWIwYmUxOTk3YTU0IiwicHJvdmlkZXJfY29kZSI6ImRlbW9iYW5rIiwiYXBwX25hbWUiOiJGZW50dXJ5IiwicGF5bWVudF9wcm9kdWN0Ijoic2VwYS1jcmVkaXQtdHJhbnNmZXJzIiwicmVkaXJlY3RfdXJsIjoiaHR0cHM6Ly9wbGVhc2UtcmVkaXJlY3QtbXktcHN1LmhlcmUiLCJwYXltZW50X2lkZW50aWZpY2F0aW9uIjoiMSJ9LCJleHAiOjE3MzI0MzA1ODgsImlzcyI6InByaW9yYS5zYWx0ZWRnZS5jb20ifQ.OX8w5D6iftQ2Ns_fB9Qzt1hBY2NT12LFko_Uh5CN9XdphwdNcopX3etsGXZUzHOTGh_5fvte_go14ub4_mmp09TgdtR0-VY9Ev7TgCGsDOBIDWOmeCBwPhSzdduESn_G5uEJ5y8-KSBF0q7zzT3RMo3YNEqSKzoTNw4azm157v0YX0LnJCrEslhMuFQ4v54VoFlksi_cXTJ9TFMrdKr_6e6_Liq5i_Kc1FJo2wPQWUlynCDjiq3UNFWod_wDbU93_2o80TI92gYXg0YVOmiPxQu8DpYRzi3Cwrdbv5HomiwEHnJI5EUAFifdjV-qYdihh893nrVJ4l1TGhN77eBOYg" \ 
 -H "Accept: application/json" \ 
 -H "Content-Type: application/json" \ 
 -H "Client-Id: 771" \ 
 -X DELETE "https://your.connector.url/api/priora/v2/payments"

Example of request parameters

{"data":{"session_secret":"cc5a8022-5e71-460e-93fa-ab0be1997a54","provider_code":"demobank","app_name":"Fentury","payment_product":"sepa-credit-transfers","redirect_url":"https://please-redirect-my-psu.here","payment_identification":"1"},"exp":1574093210}
Request

DELETE https://your.connector.url/api/priora/v2/payments

Headers
Header Type Description
Authorization string, required JSON Web Token containing payload, signed using RSA256 and application.private_key.
Accept string, required Media type that is acceptable for the response. Allowed values: application/json
Content-Type string, required The media type of the body of the request. Allowed values: application/json
Client-Id integer, required TPP application identifier in Salt Edge PSD2 Compliance.
Psu-Device-ID string, optional UUID (Universally Unique Identifier) for a device, which is used by the PSU, if available. UUID identifies either a device or a device dependant application installation. In case of an installation identification this ID need to be unaltered until removal from device.
Psu-User-Agent string, optional The forwarded Agent header field of the HTTP request between PSU and TPP, if available.
Psu-Geo-Location string, optional The forwarded Geo Location of the corresponding HTTP request between PSU and TPP if available.
Unpacked Request Authorization
exp
integer, required
The lifetime of the request in timestamp UTC format. Values greater than: Current time.
Response headers
Header Type Description
Retry-After integer, optional Amount of time in seconds after which Salt Edge PSD2 Compliance Solution resends the previously failed request.
Response

Revoke a payment. As a result, Connector should send a success, update or fail callback to Salt Edge PSD2 Compliance with the result of the operation, be it a success, fail or request for additional steps.


Bulk Payments

Create

Create a payment. As a result, Connector should send a success, update or fail callback to Salt Edge PSD2 Compliance with the result of the operation, be it a success, fail or request for additional steps.

CURL

curl -i  \ 
 -H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7InByb3ZpZGVyX2NvZGUiOiJkZW1vYmFuayIsImFwcF9uYW1lIjoiRmVudHVyeSIsInJlZGlyZWN0X3VybCI6Imh0dHBzOi8vcGxlYXNlLXJlZGlyZWN0LW15LXBzdS5oZXJlIiwicGF5bWVudF9wcm9kdWN0Ijoic2VwYS1jcmVkaXQtdHJhbnNmZXJzIiwiYnVsa19wYXltZW50X2lkZW50aWZpY2F0aW9uIjoiMSIsInBzdV9pcF9hZGRyZXNzIjoiMTkyLjExLjIuMTgiLCJwYXltZW50c19kYXRhIjp7InBheW1lbnRzIjpbeyJpbnN0cnVjdGVkX2Ftb3VudCI6eyJhbW91bnQiOiIxNDUuMyIsImN1cnJlbmN5IjoiRVVSIn0sImNyZWRpdG9yX25hbWUiOiJKb2huIFNtaXRoIiwiY3JlZGl0b3JfYWNjb3VudCI6eyJiYmFuIjoiODM2MDc2Nzk4In0sInJlbWl0dGFuY2VfaW5mb3JtYXRpb25fdW5zdHJ1Y3R1cmVkIjoiUGF5bWVudCBkZXNjcmlwdGlvbiJ9XSwiZGVidG9yX2FjY291bnQiOnsiYmJhbiI6IjgzNjA3Njc5OCJ9LCJwYXltZW50X2luZm9ybWF0aW9uX2lkIjoiY2M1YTgwMjItNWU3MS00NjBlLTgyZmEtYWIwYmUxOTk3YTU0IiwiYmF0Y2hfYm9va2luZ19wcmVmZXJyZWQiOmZhbHNlLCJyZXF1ZXN0ZWRfZXhlY3V0aW9uX2RhdGUiOiIyMDE5LTA2LTAxIiwicmVxdWVzdGVkX2V4ZWN1dGlvbl90aW1lIjoiMjAxOS0wNi0wMVQxMzo1MDo0OSswMzowMCJ9LCJzZXNzaW9uX3NlY3JldCI6ImNjNWE4MDIyLTVlNzEtNDYwZS05M2ZhLWFiMGJlMTk5N2E1NCJ9LCJleHAiOjE3MzI0MzA1ODksImlzcyI6InByaW9yYS5zYWx0ZWRnZS5jb20ifQ.jP6Zb4B03DXgaDsY21io0cRdnXj8-seVhAF6vjcvdQ_6M5GqUlGvtuD0oRwLo-J_irP_HbXV-VTTqX22FRQ17sX2jTOx2K93Hfx6esdJlPQQzKiTVa-Hnwzz3b4SeheJWwZboC9qiTOU--Wj3QLE4UBHgjmBdRI_qFgflE2d3W7Rfrolsb533r7-5Z76bHFmZE1FQD5MBPoezCy1OpXpnoqR06g9qx1fXTcWTHKfOOM876qs8pU7wvcTQQtEipTkX0IJrcRK8XHHTEFqvDJ-4zGT7ZQ8KPMdQ_5uUfjG1srHvJqMj8nCUkqzzD4Kn46fonsj6pbcuXNfPmU2WiFUlw" \ 
 -H "Accept: application/json" \ 
 -H "Content-Type: application/json" \ 
 -H "Client-Id: 771" \ 
 -X POST "https://your.connector.url/api/priora/v2/bulk_payments"

Example of request parameters

Request

POST https://your.connector.url/api/priora/v2/bulk_payments

Headers
Header Type Description
Authorization string, required JSON Web Token containing payload, signed using RSA256 and application.private_key.
Accept string, required Media type that is acceptable for the response. Allowed values: application/json
Content-Type string, required The media type of the body of the request. Allowed values: application/json
Client-Id integer, required TPP application identifier in Salt Edge PSD2 Compliance.
Psu-Device-ID string, optional UUID (Universally Unique Identifier) for a device, which is used by the PSU, if available. UUID identifies either a device or a device dependant application installation. In case of an installation identification this ID need to be unaltered until removal from device.
Psu-User-Agent string, optional The forwarded Agent header field of the HTTP request between PSU and TPP, if available.
Psu-Geo-Location string, optional The forwarded Geo Location of the corresponding HTTP request between PSU and TPP if available.
Psu-Corporate-ID string, optional PSU corporate identifier (optional).
TPP-Explicit-Authorisation-Preferred boolean, optional If it equals "true", the TPP prefers to start the authorisation process separately, e.g. because of the usage of a signing basket. This preference might be ignored by the ASPSP, if a signing basket is not supported as functionality. If it equals "false" or if the parameter is not used, there is no preference of the TPP. This especially indicates that the TPP assumes a direct authorisation of the transaction in the next step, without using a signing basket. Default value: false
Unpacked Request Authorization
Response headers
Header Type Description
Retry-After integer, optional Amount of time in seconds after which Salt Edge PSD2 Compliance Solution resends the previously failed request.
Response

Create a payment. As a result, Connector should send a success, update or fail callback to Salt Edge PSD2 Compliance with the result of the operation, be it a success, fail or request for additional steps.


Related Errors
Class Code Description
ResourceUnknown 404 The addressed resource is unknown relative to the TPP

Revoke

Revoke a payment. As a result, Connector should send a success, update or fail callback to Salt Edge PSD2 Compliance with the result of the operation, be it a success, fail or request for additional steps.

CURL

curl -i  \ 
 -H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7InNlc3Npb25fc2VjcmV0IjoiY2M1YTgwMjItNWU3MS00NjBlLTkzZmEtYWIwYmUxOTk3YTU0IiwicHJvdmlkZXJfY29kZSI6ImRlbW9iYW5rIiwiYXBwX25hbWUiOiJGZW50dXJ5IiwicGF5bWVudF9wcm9kdWN0Ijoic2VwYS1jcmVkaXQtdHJhbnNmZXJzIiwicmVkaXJlY3RfdXJsIjoiaHR0cHM6Ly9wbGVhc2UtcmVkaXJlY3QtbXktcHN1LmhlcmUiLCJidWxrX3BheW1lbnRfaWRlbnRpZmljYXRpb24iOiIxIn0sImV4cCI6MTczMjQzMDU5MCwiaXNzIjoicHJpb3JhLnNhbHRlZGdlLmNvbSJ9.O5w54KJojAaxFkf2Q9dYJUnJTFc11uP3IakTU6iJ_96SZiXNAQb0ftjo56giKnNFaE8s8X24ddoKeR-9uaXWo24qygZV4g3KTEOGKoDs68bymCwQK_y9GORRIx8FpT67E6YDhQkBz7hnlYDtkv7yffdhAcpO3JMZZwo-1LRavMTfVyVFzIpRcWfn7KQIyPXrnFsCLLypTMqZ18jahfH2JqYF_Nr7nVXFDZIqzIAh6zE3tNRiYYGJuyjR7cqRiiGHulnbBCRRHJvBvwqlLBLd3GyYJCc8JzpkLmO2fH2hozQjBJYy0sHD3_h4wi_ut6bEleGWZi6ecd9rz9RCobCttA" \ 
 -H "Accept: application/json" \ 
 -H "Content-Type: application/json" \ 
 -H "Client-Id: 771" \ 
 -X DELETE "https://your.connector.url/api/priora/v2/bulk_payments"

Example of request parameters

{"data":{"session_secret":"cc5a8022-5e71-460e-93fa-ab0be1997a54","provider_code":"demobank","app_name":"Fentury","payment_product":"sepa-credit-transfers","redirect_url":"https://please-redirect-my-psu.here","bulk_payment_identification":"1"},"exp":1574093210}
Request

DELETE https://your.connector.url/api/priora/v2/bulk_payments

Headers
Header Type Description
Authorization string, required JSON Web Token containing payload, signed using RSA256 and application.private_key.
Accept string, required Media type that is acceptable for the response. Allowed values: application/json
Content-Type string, required The media type of the body of the request. Allowed values: application/json
Client-Id integer, required TPP application identifier in Salt Edge PSD2 Compliance.
Psu-Device-ID string, optional UUID (Universally Unique Identifier) for a device, which is used by the PSU, if available. UUID identifies either a device or a device dependant application installation. In case of an installation identification this ID need to be unaltered until removal from device.
Psu-User-Agent string, optional The forwarded Agent header field of the HTTP request between PSU and TPP, if available.
Psu-Geo-Location string, optional The forwarded Geo Location of the corresponding HTTP request between PSU and TPP if available.
Unpacked Request Authorization
exp
integer, required
The lifetime of the request in timestamp UTC format. Values greater than: Current time.
Response headers
Header Type Description
Retry-After integer, optional Amount of time in seconds after which Salt Edge PSD2 Compliance Solution resends the previously failed request.
Response

Revoke a payment. As a result, Connector should send a success, update or fail callback to Salt Edge PSD2 Compliance with the result of the operation, be it a success, fail or request for additional steps.


Periodic Payments

Create

Create a payment. As a result, Connector should send a success, update or fail callback to Salt Edge PSD2 Compliance with the result of the operation, be it a success, fail or request for additional steps.

CURL

curl -i  \ 
 -H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7ImFwcF9uYW1lIjoiRmVudHVyeSIsInBheW1lbnRfcHJvZHVjdCI6InRhcmdldC0yLXBheW1lbnRzIiwicmVkaXJlY3RfdXJsIjoiaHR0cHM6Ly9wbGVhc2UtcmVkaXJlY3QtbXktcHN1LmhlcmUiLCJwZXJpb2RpY19wYXltZW50X2lkZW50aWZpY2F0aW9uIjoiMSIsInBzdV9pcF9hZGRyZXNzIjoiMTkyLjExLjIuMTgiLCJwYXltZW50Ijp7ImVuZF90b19lbmRfaWRlbnRpZmljYXRpb24iOiIxMjM0NTVpZCIsImNyZWRpdG9yX25hbWUiOiJKb2huIFNtaXRoIiwic3RhcnRfZGF0ZSI6IjIwMTktMDYtMDEiLCJlbmRfZGF0ZSI6IjIwMjAtMDYtMDEiLCJleGVjdXRpb25fcnVsZSI6InByZWNlZGluZyIsImZyZXF1ZW5jeSI6Ik1vbnRobHkiLCJkYXlfb2ZfZXhlY3V0aW9uIjoiMDUiLCJjcmVkaXRvcl9hY2NvdW50Ijp7ImliYW4iOiJGSzU0UkFORDYxMDY4NDIxNDM1NDUyIn0sImRlYnRvcl9hY2NvdW50Ijp7ImliYW4iOiJGSzUzUkFORDYxMDY4NDIxNDM1NDIyIn0sImluc3RydWN0ZWRfYW1vdW50Ijp7ImFtb3VudCI6Ijk2IiwiY3VycmVuY3kiOiJVU0QifSwicmVtaXR0YW5jZV9pbmZvcm1hdGlvbl91bnN0cnVjdHVyZWQiOiJQYXltZW50IGRlc2NyaXB0aW9uIiwiY3JlZGl0b3JfYWdlbnRfbmFtZSI6IkFnZW50IE5hbWUiLCJjcmVkaXRvcl9hZGRyZXNzIjp7InN0cmVldF9uYW1lIjoic3RyLiBGaXJzdCBvZiBNYXkiLCJidWlsZGluZ19udW1iZXIiOiI0M2MiLCJ0b3duX25hbWUiOiJCdWRhcGVzdCIsInBvc3RfY29kZSI6IjQ0NTUxMSIsImNvdW50cnkiOiJIVSJ9fSwic2Vzc2lvbl9zZWNyZXQiOiJjYzVhODAyMi01ZTcxLTQ2MGUtOTNmYS1hYjBiZTE5OTdhNTQiLCJwcm92aWRlcl9jb2RlIjoiZGVtb2JhbmsifSwiZXhwIjoxNzMyNDMwNTkwLCJpc3MiOiJwcmlvcmEuc2FsdGVkZ2UuY29tIn0.AWLoU6UMMm29mMRXF8MYaccReDMhiMy-XEsA6l7kN1WXVG-HT5zZ0wl-N5C_5jcGD474-mnwFASu8k978mL0AXhdYdVyIlEgVPlh8vgEsDqWF5sC-jK0-NFhSv7b61_HszBeEOfOcJYJaoxtvhZ7x0q1LfRiz9Anw6opQi1a--nsvSFxMwptxyBAhj7DvbxdqLM43obkB4-WyrgOx30GNfQJgS4bPMlRCgWVj6Ke0AV8bR81Flv6TvxwQrsyU8AJsqkbvm7iUu0pE0SNBoTwWC59B8XigLR_QPyu2CmpjxWVtrCgCd1QaOCrw-s0wpQB2GrhlqAOArPtF6zmnTPHsA" \ 
 -H "Accept: application/json" \ 
 -H "Content-Type: application/json" \ 
 -H "Client-Id: 771" \ 
 -H "Psu-Corporate-ID: 999" \ 
 -X POST "https://your.connector.url/api/priora/v2/periodic_payments"

Example of request parameters

Request

POST https://your.connector.url/api/priora/v2/periodic_payments

Headers
Header Type Description
Authorization string, required JSON Web Token containing payload, signed using RSA256 and application.private_key.
Accept string, required Media type that is acceptable for the response. Allowed values: application/json
Content-Type string, required The media type of the body of the request. Allowed values: application/json
Client-Id integer, required TPP application identifier in Salt Edge PSD2 Compliance.
Psu-Device-ID string, optional UUID (Universally Unique Identifier) for a device, which is used by the PSU, if available. UUID identifies either a device or a device dependant application installation. In case of an installation identification this ID need to be unaltered until removal from device.
Psu-User-Agent string, optional The forwarded Agent header field of the HTTP request between PSU and TPP, if available.
Psu-Geo-Location string, optional The forwarded Geo Location of the corresponding HTTP request between PSU and TPP if available.
Psu-Corporate-ID string, optional PSU corporate identifier (optional).
TPP-Explicit-Authorisation-Preferred boolean, optional If it equals "true", the TPP prefers to start the authorisation process separately, e.g. because of the usage of a signing basket. This preference might be ignored by the ASPSP, if a signing basket is not supported as functionality. If it equals "false" or if the parameter is not used, there is no preference of the TPP. This especially indicates that the TPP assumes a direct authorisation of the transaction in the next step, without using a signing basket. Default value: false
Unpacked Request Authorization
Response headers
Header Type Description
Retry-After integer, optional Amount of time in seconds after which Salt Edge PSD2 Compliance Solution resends the previously failed request.
Response

Create a payment. As a result, Connector should send a success, update or fail callback to Salt Edge PSD2 Compliance with the result of the operation, be it a success, fail or request for additional steps.


Related Errors
Class Code Description
CountryNameInvalid 400 Country doesn't exist or is invalid. Expected alpha 2 ISO3166 format.
ResourceUnknown 404 The addressed resource is unknown relative to the TPP

Revoke

Revoke a payment. As a result, Connector should send a success, update or fail callback to Salt Edge PSD2 Compliance with the result of the operation, be it a success, fail or request for additional steps.

CURL

curl -i  \ 
 -H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7InNlc3Npb25fc2VjcmV0IjoiY2M1YTgwMjItNWU3MS00NjBlLTkzZmEtYWIwYmUxOTk3YTU0IiwicHJvdmlkZXJfY29kZSI6ImRlbW9iYW5rIiwiYXBwX25hbWUiOiJGZW50dXJ5IiwicGF5bWVudF9wcm9kdWN0Ijoic2VwYS1jcmVkaXQtdHJhbnNmZXJzIiwicmVkaXJlY3RfdXJsIjoiaHR0cHM6Ly9wbGVhc2UtcmVkaXJlY3QtbXktcHN1LmhlcmUiLCJwZXJpb2RpY19wYXltZW50X2lkZW50aWZpY2F0aW9uIjoiMSJ9LCJleHAiOjE3MzI0MzA1OTEsImlzcyI6InByaW9yYS5zYWx0ZWRnZS5jb20ifQ.VlNk1PLrCJtVi9cOvogSYM6o2rutUN0SYa-wap2_GSFvIIPId4dTk_YxBW2eEt6X5Oh8I-OKjg5qqdqhk-7O5ReqS-z6MbZBGUNv9SEuv5OsUPpHEuEymjQCL72E342-5KDqJjtZJX_6J7wbKoXeu8lrFIWcphuY3QhN4UpBkTFNO-QbI3osZOcGkzSshcKzp8nLNNELFBVhUlZej6pkoqd2e0GH7G_GtzeKTg171mMJeVHlT5KItDEki0Z0UDTn5su0hnYmzULNaIueUXXOvqTb0cqLPGK24a3C4anKLTD-HAFy6OyWskpfd6jn0eks2qAVGuJ_gNmrE80zQzUCUA" \ 
 -H "Accept: application/json" \ 
 -H "Content-Type: application/json" \ 
 -H "Client-Id: 771" \ 
 -X DELETE "https://your.connector.url/api/priora/v2/periodic_payments"

Example of request parameters

{"data":{"session_secret":"cc5a8022-5e71-460e-93fa-ab0be1997a54","provider_code":"demobank","app_name":"Fentury","payment_product":"sepa-credit-transfers","redirect_url":"https://please-redirect-my-psu.here","periodic_payment_identification":"1"},"exp":1574093210}
Request

DELETE https://your.connector.url/api/priora/v2/periodic_payments

Headers
Header Type Description
Authorization string, required JSON Web Token containing payload, signed using RSA256 and application.private_key.
Accept string, required Media type that is acceptable for the response. Allowed values: application/json
Content-Type string, required The media type of the body of the request. Allowed values: application/json
Client-Id integer, required TPP application identifier in Salt Edge PSD2 Compliance.
Psu-Device-ID string, optional UUID (Universally Unique Identifier) for a device, which is used by the PSU, if available. UUID identifies either a device or a device dependant application installation. In case of an installation identification this ID need to be unaltered until removal from device.
Psu-User-Agent string, optional The forwarded Agent header field of the HTTP request between PSU and TPP, if available.
Psu-Geo-Location string, optional The forwarded Geo Location of the corresponding HTTP request between PSU and TPP if available.
Unpacked Request Authorization
exp
integer, required
The lifetime of the request in timestamp UTC format. Values greater than: Current time.
Response headers
Header Type Description
Retry-After integer, optional Amount of time in seconds after which Salt Edge PSD2 Compliance Solution resends the previously failed request.
Response

Revoke a payment. As a result, Connector should send a success, update or fail callback to Salt Edge PSD2 Compliance with the result of the operation, be it a success, fail or request for additional steps.


Sessions

Session Callback Endpoints are responsible for assuring communication between ASPSP and TPP, where ASPSP notifies about its Redirect SCA authorisation page and if the authorisation process is successful or failed.

Success

Success callback should be sent to Salt Edge PSD2 Compliance when all required verification steps have been passed, and therefore access is granted.

CURL

curl -i  \ 
 -H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7InVzZXJfaWQiOjEsInNlc3Npb25fc2VjcmV0IjoiQlZ1dmVTTFFDckE1akJZVXl4WGUifSwiZXhwIjoxNzMyNDMwNTkyLCJpc3MiOiJwcmlvcmEuc2FsdGVkZ2UuY29tIn0.TzHKfWMckv0EroyO2JP5SDVFa_DvEltO777QhvXoz_tkaXaq6k-dmiy2XcNt3JOPOJiL7YToda52cSAwuv2HtJ3VoENi_mor3MzOQY8GRlPNmhCOctjcSCJn56pc32Omgg8KPGIPHcPeerLj8b3Z-xRxoLzSbmOHdq4C1pPZZnBECVYq8ge0kBqqDa42RKTJQIjHuFrSKwrlXQ0VGadx9Ne-g6Wow5jUyWuDN3W8pi6mcGsJPDqWBF8eE77hWlOy24QNO1Lb_ZGwOmUTbLrtMcSSk8l_-PRu2SjI4x9TGaCaTebM4y2FGQvyz9w0ytLK2eaOar8CN-yGH1XV5w8_oQ" \ 
 -H "App-Id: qjQYP-jCx-8FBsZSgNVzIw" \ 
 -H "App-Secret: -XeeN2UhtdphUGtI-FZpzg" \ 
 -X PATCH "/api/connectors/v2/sessions/:session_secret/success"

Example of request parameters

Example of response

{"data":{},"meta":{"time":"2019-11-18T16:04:48.773Z"}}
Request

PATCH /api/connectors/v2/sessions/:session_secret/success

Headers
Header Type Description
Authorization string, required JSON Web Token containing payload, signed using RSA256 and application.private_key. Can raise: AuthorizationMissing
App-Id string, required Provider's app_id from connection details tab. Can raise: ProviderNotFound, ProviderDisabled, ConfigurationError
App-Secret string, required Provider's app_secret from connection details tab.
Unpacked Request Authorization
Response

Upon successful request, 200 status code will be returned. See ‘Related Errors’ table for other possibilities.


data
hash, optional
Wrapper for the data.
Related Errors
Class Code Description
SessionClosed 400 Session specified in request is already closed and cannot be modified.
ConfigurationError 400 Missing configurations in dashboard.
SessionExpired 401 Found session is expired and cannot be processed anymore.
AuthorizationMissing 401 Authorization header is missing.
SessionFinalised 403 Session specified in request is already finalised and cannot be processed.
SessionNotFound 404 Session specified in request does not exist or cannot be retrieved.
ProviderNotFound 404 Provider specified in request does not exist or cannot be retrieved.
ProviderDisabled 406 Cooperation with specified Provider is impossible.

Update

Update callback may be accessed multiple times in order to request multiple steps of authorization or to send other updates to Salt Edge PSD2 Compliance session.

CURL

curl -i  \ 
 -H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7InNlc3Npb25fZXhwaXJlc19hdCI6IjIwMjAtMDMtMTBUMTI6MzM6NTAuMjE1WiIsInN0YXR1cyI6InJlY2VpdmVkIiwic2NhX3N0YXR1cyI6InJlY2VpdmVkIiwicmVkaXJlY3RfdXJsIjoiaHR0cHM6Ly9yZWRpcmVjdC11cmwuY29tIiwiZXh0cmEiOnt9LCJzZXNzaW9uX3NlY3JldCI6IkJWdXZlU0xRQ3JBNWpCWVV5eFhlIn0sImV4cCI6MTczMjQzMDU5MiwiaXNzIjoicHJpb3JhLnNhbHRlZGdlLmNvbSJ9.UpS5cBJ_498qYOyJ_v3wEJvtkJFIVSwDAC2tb-5WiGt4_4Bxsy48k4XqHnlPMWj1lSMEFeuPDOyHvLGqeexEmCKU_XwaGnGHlLCWb3ImaUCIO21aHr0qGde2YWnjixP14w1uDOtYBN-P6H_3iaL9ZAavZiquRRMNIWmziyPSD-9llnZwBKpWnxyeyraWFHOEC0O-qGwqyeBCiMcoTy33iC90rJdRVGH5BL1ns7E3ET3WHZ9E_u63sxXfm61kt2VakiHr70Z5_Glv7s6ful4TDdjnHIc-UEq2IoLo1UxtaFBaWAOw_kUVe4qAI7nHOrs-22NuCXkhybI9ZEBpSu-CpQ" \ 
 -H "App-Id: q5QE7Dqlpm1d5weLS5pn7w" \ 
 -H "App-Secret: y8imt1cgG8x2zmBMrF-oxw" \ 
 -X PATCH "/api/connectors/v2/sessions/:session_secret/update"

Example of request parameters

Example of response

{"data":{},"meta":{"time":"2019-11-18T16:04:48.853Z"}}
Request

PATCH /api/connectors/v2/sessions/:session_secret/update

Headers
Header Type Description
Authorization string, required JSON Web Token containing payload, signed using RSA256 and application.private_key. Can raise: AuthorizationMissing
App-Id string, required Provider's app_id from connection details tab. Can raise: ProviderNotFound, ProviderDisabled, ConfigurationError
App-Secret string, required Provider's app_secret from connection details tab.
Unpacked Request Authorization
Response

Upon successful request, 200 status code will be returned. See ‘Related Errors’ table for other possibilities.


data
hash, optional
Wrapper for the data.
Related Errors
Class Code Description
SessionClosed 400 Session specified in request is already closed and cannot be modified.
ConfigurationError 400 Missing configurations in dashboard.
SessionExpired 401 Found session is expired and cannot be processed anymore.
AuthorizationMissing 401 Authorization header is missing.
SessionFinalised 403 Session specified in request is already finalised and cannot be processed.
SessionNotFound 404 Session specified in request does not exist or cannot be retrieved.
ProviderNotFound 404 Provider specified in request does not exist or cannot be retrieved.
ProviderDisabled 406 Cooperation with specified Provider is impossible.

Fail

Fail callback should be used when authorization process has been compromised for any reason: broken request, invalid credentials, etc.

CURL

curl -i  \ 
 -H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7InNlc3Npb25fc2VjcmV0IjoiM1BRaXB1RFBvV3BhMTFGY1ZFVjYiLCJlcnJvcl9jbGFzcyI6IkludGVybmFsUHJvdmlkZXJFcnJvciIsImVycm9yX21lc3NhZ2UiOiJJbnRlcm5hbCBlcnJvciIsImV4dHJhIjp7fX0sImV4cCI6MTczMjQzMDU5MiwiaXNzIjoicHJpb3JhLnNhbHRlZGdlLmNvbSJ9.JGWTH7EEBaxb9hd_6V2Lp_pM2uj2ZtsT8nQlOVmNTt8EuSxMlySIovilnfyK_ik1MP9urKaU6MSzjtWYTHWr1EojVZrDo1ImO9sRXpjJIpfvfOtHPQgMLKqfx5Yk1a-73C20zL-ICHHWb4ctImewoKrUOnn9exOcRCBvbG_LPCPPT_tQuyIGFPAB1dGRH0oMLHl3b4OSDxQXP45VBrha-EQ4-ugHU9Yw2EXIEJVhjmgUHqR-ZoCbvem1PdxD78GNHXySMSvS2wuhOWwSyy4Qgkq_8HnJjI1cdUpJ1hbEPiC3-ExZmEelD7tqkcrD0DOksUnFJAOjsuXMm65n5CfZiw" \ 
 -H "App-Id: xU7SyhPrd95GAPSMNo_XMQ" \ 
 -H "App-Secret: BVSkESo7zpRdzk_hWUUwCQ" \ 
 -X PATCH "/api/connectors/v2/sessions/:session_secret/fail"

Example of request parameters

{"data":{"session_secret":"3PQipuDPoWpa11FcVEV6","error_class":"InternalProviderError","error_message":"Internal error","extra":{}},"exp":1574093208}

Example of response

{"data":{},"meta":{"time":"2019-11-18T16:04:48.710Z"}}
Request

PATCH /api/connectors/v2/sessions/:session_secret/fail

Headers
Header Type Description
Authorization string, required JSON Web Token containing payload, signed using RSA256 and application.private_key. Can raise: AuthorizationMissing
App-Id string, required Provider's app_id from connection details tab. Can raise: ProviderNotFound, ProviderDisabled, ConfigurationError
App-Secret string, required Provider's app_secret from connection details tab.
Unpacked Request Authorization
Response

Upon successful request, 200 status code will be returned. See ‘Related Errors’ table for other possibilities.


data
hash, optional
Wrapper for the data.
Related Errors
Class Code Description
SessionClosed 400 Session specified in request is already closed and cannot be modified.
ConfigurationError 400 Missing configurations in dashboard.
SessionExpired 401 Found session is expired and cannot be processed anymore.
AuthorizationMissing 401 Authorization header is missing.
SessionFinalised 403 Session specified in request is already finalised and cannot be processed.
SessionNotFound 404 Session specified in request does not exist or cannot be retrieved.
ProviderNotFound 404 Provider specified in request does not exist or cannot be retrieved.
ProviderDisabled 406 Cooperation with specified Provider is impossible.

Payments

Revoke

Revoke callback needs to be called any time a payment is revoked on the Provider Connector side.

CURL

curl -i  \ 
 -H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7fSwiZXhwIjoxNzMyNDMwNTkzLCJpc3MiOiJwcmlvcmEuc2FsdGVkZ2UuY29tIn0.tUAtCMhgCF8rK3R6rdvPm3rIDiIgdPFpseRXeeslyTi21RF4PEIp_bX4gv7vyjA9pyxk4stRnQOaRBJdxz0gbUT1a2ZhehY9KknD0NcM4dUPwBH59zeU4x-pAmyUy88MAqWE5uFIDLOIfwo7CmwMqAtwzfX_Gw5mv26AB1UBok9b8bVH1_U0Trcign_AVYcBGPC93CScrEgYDpVlV1aB4rftT4C04AzCTEZ00nbUlfQbfgJiGKyqK0j6n3uLUNfOh6LTwpLfbpTZnxR0_s75jKteBor3Vdw5fhjUbYS6SGNzz1tnSlZRDkDOccDzRySaPVor0I_MQTSi3lbW17ublA" \ 
 -H "App-Id: cfOK5P9RVooLksNv8il3rw" \ 
 -H "App-Secret: rwkTbW41SPT55uo1I_-UGQ" \ 
 -X PATCH "/api/connectors/v2/payments/:payment_id/revoke"

Example of request parameters

{"data":{},"exp":1574093208}

Example of response

{"data":{"revoked":true},"meta":{"time":"2019-11-18T16:04:48.928Z"}}
Request

PATCH /api/connectors/v2/payments/:payment_id/revoke

Headers
Header Type Description
Authorization string, required JSON Web Token containing payload, signed using RSA256 and application.private_key. Can raise: AuthorizationMissing
App-Id string, required Provider's app_id from connection details tab. Can raise: ProviderNotFound, ProviderDisabled, ConfigurationError
App-Secret string, required Provider's app_secret from connection details tab.
Unpacked Request Authorization
payment_id (path)
string, required
Payment order identifier on Connector side. Used to map Salt Edge PSD2 Compliance payments to Connector ones.
Response

Revoke callback needs to be called any time a payment is revoked on the Provider Connector side.


Related Errors
Class Code Description
ConfigurationError 400 Missing configurations in dashboard.
AuthorizationMissing 401 Authorization header is missing.
ProviderNotFound 404 Provider specified in request does not exist or cannot be retrieved.
ProviderDisabled 406 Cooperation with specified Provider is impossible.

Bulk Payments

Revoke

Revoke callback needs to be called any time a bulk payment is revoked on the Provider Connector side.

CURL

curl -i  \ 
 -H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7fSwiZXhwIjoxNzMyNDMwNTkzLCJpc3MiOiJwcmlvcmEuc2FsdGVkZ2UuY29tIn0.tUAtCMhgCF8rK3R6rdvPm3rIDiIgdPFpseRXeeslyTi21RF4PEIp_bX4gv7vyjA9pyxk4stRnQOaRBJdxz0gbUT1a2ZhehY9KknD0NcM4dUPwBH59zeU4x-pAmyUy88MAqWE5uFIDLOIfwo7CmwMqAtwzfX_Gw5mv26AB1UBok9b8bVH1_U0Trcign_AVYcBGPC93CScrEgYDpVlV1aB4rftT4C04AzCTEZ00nbUlfQbfgJiGKyqK0j6n3uLUNfOh6LTwpLfbpTZnxR0_s75jKteBor3Vdw5fhjUbYS6SGNzz1tnSlZRDkDOccDzRySaPVor0I_MQTSi3lbW17ublA" \ 
 -H "App-Id: cfOK5P9RVooLksNv8il3rw" \ 
 -H "App-Secret: rwkTbW41SPT55uo1I_-UGQ" \ 
 -X PATCH "/api/connectors/v2/bulk_payments/:bulk_payment_id/revoke"

Example of request parameters

{"data":{},"exp":1574093208}

Example of response

{"data":{"revoked":true},"meta":{"time":"2019-11-18T16:04:48.928Z"}}
Request

PATCH /api/connectors/v2/bulk_payments/:bulk_payment_id/revoke

Headers
Header Type Description
Authorization string, required JSON Web Token containing payload, signed using RSA256 and application.private_key. Can raise: AuthorizationMissing
App-Id string, required Provider's app_id from connection details tab. Can raise: ProviderNotFound, ProviderDisabled, ConfigurationError
App-Secret string, required Provider's app_secret from connection details tab.
Unpacked Request Authorization
bulk_payment_id (path)
string, required
Bulk Payment order identifier on Connector side. Used to map Salt Edge PSD2 Compliance payments to Connector ones.
Response

Revoke callback needs to be called any time a bulk payment is revoked on the Provider Connector side.


Related Errors
Class Code Description
ConfigurationError 400 Missing configurations in dashboard.
AuthorizationMissing 401 Authorization header is missing.
ProviderNotFound 404 Provider specified in request does not exist or cannot be retrieved.
ProviderDisabled 406 Cooperation with specified Provider is impossible.

Periodic Payments

Revoke

Revoke callback needs to be called any time a periodic payment is revoked on the Provider Connector side.

CURL

curl -i  \ 
 -H "Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjp7fSwiZXhwIjoxNzMyNDMwNTk0LCJpc3MiOiJwcmlvcmEuc2FsdGVkZ2UuY29tIn0.CDttb24hn4qY6pjlC-uvRIhexvE22GBz0CkHmuc8ZmVo76jpiEh2gafxPpAVjIvM6Y-CEIxxE6BXRg9CJCFVcbWaK_CO8Amn4dIvFnC8RmGo8GfQ-0aY4rHlDT0t53PvSIcoBu2uTBtmghe3miQmh5QFb_v8b50iMoZ-CplujdFHVzSHKTXkOFPAgttu0Bt6GFg7Ly3R_i8BiShRzrItypj5CAqjELGC3QiDmMerLdCVSWdFswojWYBo4XZ2kj2ttcYbG926V3emi72GWphctoIgtmuK3Dsd9NtQxmxOeOsu9LnslEurkXTLi3sSL1EKyGfTFTiDTqwybYijT87unQ" \ 
 -H "App-Id: cfOK5P9RVooLksNv8il3rw" \ 
 -H "App-Secret: rwkTbW41SPT55uo1I_-UGQ" \ 
 -X PATCH "/api/connectors/v2/periodic_payments/:periodic_payment_id/revoke"

Example of request parameters

{"data":{},"exp":1574093208}

Example of response

{"data":{"revoked":true},"meta":{"time":"2019-11-18T16:04:48.928Z"}}
Request

PATCH /api/connectors/v2/periodic_payments/:periodic_payment_id/revoke

Headers
Header Type Description
Authorization string, required JSON Web Token containing payload, signed using RSA256 and application.private_key. Can raise: AuthorizationMissing
App-Id string, required Provider's app_id from connection details tab. Can raise: ProviderNotFound, ProviderDisabled, ConfigurationError
App-Secret string, required Provider's app_secret from connection details tab.
Unpacked Request Authorization
periodic_payment_id (path)
string, required
Periodic Payment order identifier on Connector side. Used to map Salt Edge PSD2 Compliance payments to Connector ones.
Response

Revoke callback needs to be called any time a periodic payment is revoked on the Provider Connector side.


Related Errors
Class Code Description
ConfigurationError 400 Missing configurations in dashboard.
AuthorizationMissing 401 Authorization header is missing.
ProviderNotFound 404 Provider specified in request does not exist or cannot be retrieved.
ProviderDisabled 406 Cooperation with specified Provider is impossible.