Open Banking & PSD2 Flows
How regulated third parties access bank accounts and initiate payments on a customer's behalf — the PSD2 roles, the consent and SCA flows, the FAPI security profile, and the regional API standards (UK Open Banking, Berlin Group, STET) that implement them.
Regional API standards
PSD2 is regulation, not an API spec — so several standards bodies publish the concrete API definitions banks implement. They differ in payload format but share the PSD2 roles and SCA model above.
| Standard | Region | Notes |
|---|---|---|
| UK Open Banking (OBIE / OpenBanking Ltd) | United Kingdom | Most prescriptive; mandates FAPI, REST + JSON, defined endpoints for accounts, payments, confirmation of funds. |
| Berlin Group NextGenPSD2 (XS2A) | EU / EEA | Most widely adopted on the continent; supports redirect, decoupled and embedded SCA. |
| STET | France | French standard, ISO 20022-flavoured payloads. |
| Polish API | Poland | National standard aligned to PSD2. |
| FDX | US / Canada | Market-led (no PSD2 mandate); financial data sharing API. |
| CDR | Australia | Consumer Data Right — open banking plus broader data sharing. |
Beyond Europe: the A2A wave
Pix (Brazil)
Central-bank instant A2A scheme; QR and key-based addressing, near-universal adoption.
UPI (India)
Unified Payments Interface — real-time A2A via virtual payment addresses.
Open Finance
The next step: extending consent-based data sharing beyond payment accounts to savings, pensions, and insurance.
Related tools: IBAN Validator · ISO 20022 / SWIFT Validator · Webhook Signature Verifier