Open Banking & PSD2 Flows
How regulated third parties access bank accounts and initiate payments on a customer's behalf — the PSD2 roles, the consent and SCA flows, the FAPI security profile, and the regional API standards (UK Open Banking, Berlin Group, STET) that implement them.
Regional API standards
PSD2 is regulation, not an API spec — so several standards bodies publish the concrete API definitions banks implement. They differ in payload format but share the PSD2 roles and SCA model above.
| Standard | Region | Notes |
|---|---|---|
| UK Open Banking (OBIE / OpenBanking Ltd) | United Kingdom | Most prescriptive; mandates FAPI, REST + JSON, defined endpoints for accounts, payments, confirmation of funds. |
| Berlin Group NextGenPSD2 (XS2A) | EU / EEA | Most widely adopted on the continent; supports redirect, decoupled and embedded SCA. |
| STET | France | French standard, ISO 20022-flavoured payloads. |
| Polish API | Poland | National standard aligned to PSD2. |
| FDX | US / Canada | Market-led (no PSD2 mandate); financial data sharing API. |
| CDR | Australia | Consumer Data Right — open banking plus broader data sharing. |
PSD3 and the Payment Services Regulation: what changes
The EU's replacement for PSD2 was politically agreed on 27 November 2025 and the final compromise texts were settled on 23 April 2026. The package splits the rulebook in two: a directive (PSD3) covering licensing and supervision of payment and e-money institutions — the Electronic Money Directive is folded in — and a directly applicable regulation (PSR) carrying the conduct-of-business rules, so the open-banking and SCA obligations stop varying by national transposition. Publication in the Official Journal was expected mid-2026; the PSR's core obligations apply roughly 18–21 months after, which points to late 2027 for most firms.
- Open banking — dedicated interfaces become the norm with tighter performance and availability obligations, a permission dashboard for users to see and revoke third-party access, and a narrower list of reasons a bank may refuse access.
- SCA — clarified for merchant-initiated and mail/telephone transactions, with explicit accessibility duties and the possibility of SCA that does not depend on a smartphone; the redirect/decoupled/embedded models above stay valid.
- Fraud — IBAN/name verification for all credit transfers (the Verification of Payee mechanism the Instant Payments Regulation already mandates for SEPA), fraud-data sharing between PSPs, and liability for impersonation fraud when the PSP failed to warn.
- Scope — cash-withdrawal and technical-service exemptions narrowed, and a unified licence for payment and e-money institutions.
Track the legislative dates on the open-banking news feed.
Beyond Europe: the A2A wave
Pix (Brazil)
Central-bank instant A2A scheme; QR and key-based addressing, near-universal adoption.
UPI (India)
Unified Payments Interface — real-time A2A via virtual payment addresses.
Open Finance
The next step: extending consent-based data sharing beyond payment accounts to savings, pensions, and insurance.
Related tools: IBAN Validator · ISO 20022 / SWIFT Validator · Webhook Signature Verifier