Tutorial
How the Account Information (PSD2) API works
- Request consent from the ABN AMRO account holder through the consent application.
- Retrieve account information.
The consent application
The consent application is used to obtain consent from an ABN AMRO account holder, and grant you with third-party access to execute a registered payment, or to access account information by using, for example, an E.dentifier. This is a so-called redirect. In the consent application, the ABN AMRO client can review the account number and the type of access granted to you.
The account holder consent process consists of three steps:
- Log on.
- Check requested access to account.
- Authorization.
The ABN AMRO client can either authorize or cancel the requested authorization.
All account information consents are valid for up to a maximum of 180 days. Consent can be given using the consent application by users of Internet Banking, Access Online, or the Dutch ABN AMRO Mobile banking app. All previously given consents for 90 days remain unchanged, the new duration only applies to new consents.
For testing purposes the validity of the consent in sandbox is set to 7 days. This will allow you to validate the consent expiry scenario as well as testing receiving multiple days of account data.
Notes:
- For details on how to access the consent application through the OAuth server, see Step 1.
- The account owner selects one account for which they authorize access.
- The ABN AMRO client can select the Dutch or English language in the consent application or app.
- The consent application uses Strong Customer Authentication (SCA). The authorization is done by clicking the "Finish" button. This completes the consent and will re-direct back to the 3rd party URL.
Authorization Code
The consent application is visible to the account owner only. It provides you with an access code for the requested authorization using an OAuth 2.0 authorization code process. This is described in Step 1.
Authorization is a grant to an account for one or multiple scopes. For more information, see Authorization Code.
Scopes in the authorization code process
A scope defines the type of access. For account information there are only read scopes. Here are some rules on how scopes can be combined in the authorization code:
- Scopes for different products cannot be combined; AIS scopes cannot be combined with PIS scopes.
- Write scopes can be combined with read scopes.
- Write scopes cannot be combined with write scopes.
- Delete scopes cannot be combined with other scopes.
For more information on required scopes, see the available operations, for example, the GET transactions operation.
Error messages
The following table describes consent application error scenarios. The error message is returned as parameter in the URL.
| Error message | Explanation |
|---|---|
| error=access_denied# | No current accounts are available to authorize or user declined access. |
Generic information
- A response is always sent. Ensure that your application does not time-out.
- If reposting, avoid using short retry periods to keep out of rate limiting scenarios.
- Consent information data will not change after 1st retrieval, and can be retrieved a maximum of 2 times per consent request.
Requirements
To use this API in a production environment, you must have the following:
PSD2 access:
- A PSD2 license for payment initiation.
- An EIDAS certificate.
- Your QWAC certificate MUST include Client Authentication (1.3.6.1.5.5.7.3.2) value for the certificate usage which can be found in the "Enhance Key Usage" tag of your certificate.
- Note: for certificates requested or renewed after the 1st of October 2025 Client Authentication might not by default be added in your certificate by your CA. Please specifically request this to your CA.
Open Banking UK access:
- A FCA license for payment initiation.
- An OBWAC certificate with the appropriate license details.
License
To use this API in a production environment, or if you require TPP access to ABN AMRO accounts, you must have a PSD2 license from a local competent authority. In the Netherlands, this is De Nederlandsche Bank (DNB). For access to UK accounts, a FCA license is required.
Licensing requirements
| API | AISP License | PISP License | Banking License | Payment Instrument Issuing License |
|---|---|---|---|---|
| Account Transactions | Y | N | Y | N |
| Account Balance | Y | N | Y | N |
| Account Details | Y | N | Y | N |
| Account Activities | Y | N | Y | N |
| CAF | N | Y | Y | Y |
EIDAS certificate
ABN AMRO accepts Qualified Website Authentication Certificates (QWAC) from Qualified Trusted Service Providers (QSTPs) that are on the trusted list with CEF Digital only. This certificate is used for identification, and is also required for OAuth authorization when accessing APIs.
Note: Inline with the PSD2 technical standard, wildcards are not permitted in certificates. Ensure the certificate usage includes " Client Authentication (1.3.6.1.5.5.7.3.2) "
Sandbox access
The sandbox and production environments are functionally identical. The sandbox is static, which means that you can perform all operations without making any transactions on an account. Transactions posted in the sandbox are cleaned everyday.
To use the Account Information API (PSD2) in a sandbox environment, complete the following steps:
- Register and create an account:
- Click Sign up.
- Enter your details, and click Create new account.
- Developer Support will send you an activation link by email.
- Click the activation link.
- Create an register application:
- Log in to your account.
- In the left-side navigation click Apps.
- Click Add app.
- In the App name field, enter a name for your application.
- In the APIs field, select Account Information (PSD2) API, and click Add app.
- Complete the steps in How to use an API section.
Sandbox access details
The following accounts are available for testing:
| Account type | IBAN | Description |
|---|---|---|
| Corporate Account | NL62ABNA9999841479 | Returns a total of 310 transactions spread over most bookdays in the last 24 days. |
| Commercial Account | NL12ABNA9999876523 | Returns a total of 88 transactions spread over most bookdays in the last 24 days, and has 1 active reservation. |
| Retail Account | NL58ABNA9999142181 | Returns a total of 24 transactions spread over most bookdays in the last 24 days, and returns 2 active and 1 cancelled reservation. |
Sandbox URL: https://api-sandbox.abnamro.com
Sandbox token URL: https://auth-mtls-sandbox.abnamro.com
Sandbox authorization URL: https://auth-sandbox.abnamro.com
Use the following credentials for the sandbox:
| Attribute | Value for Sandbox |
|---|---|
| client_id | TPP_test |
| API-Key | The API Key for your app from the Developer Portal |
| redirect_uri | https://localhost/auth |
Note: Redirect URL's in sandbox cannot be modified. For production environment desired URL's can be specified in the setup process.
| Certificate files: |
|---|
| Download public certificate: Download |
| Download private key: Download |
Note: The sandbox handles functional error scenarios only.
Production access
Important: To use this API in a production environment, you must have a PSD2 license. For more information, see Requirements.
To get access to production:
- Log in to your account.
- In the left-side navigation, click Apps.
- Click Request Production Access.
- Select the API category that you want to request production access on.
Note: It is not possible to request production access for multiple API categories in one request.
- Fill in the form, and click Submit.
- You receive a confirmation email and ticket Id.
- ABN AMRO Developer Support validates the form, and if necessary contacts you.
- When the setup is complete, ABN AMRO Developer Support contacts you and supplies you with a client_id.
- A new App is added in Apps. This new app contains your API key.
Note: It is not possible for account holders to get API access on their own accounts.
Production access details
- Production URL: https://api.abnamro.com
- Production authorization URL: https://www.abnamro.nl/consent/v2/authorize?
- Production Token URL: https://auth-mtls.abnamro.com/as/token.oauth2
**Note:**The authorization URL supports accounts in all countries which the user can access through Internet Banking, Access Online or Dutch Mobile app. For other access see the related brands section on the developer portal.
Use the following credentials for production:
| Attribute | Value for Production |
|---|---|
| client_id | As supplied to you by ABN AMRO |
| API-Key | The API Key for your production app from the Developer Portal |
| redirect_uri | The URLs that you specified in your request access form |
Certificates
| Certificate files: |
|---|
| Certificate file : Your QWAC EIDAS certificate |
| Private key : Your private key |
How to use an API
This instruction describes the functionality of Account Information (PSD2) API and also how to connect to the sandbox environment.
Note: Before you start this process, you must complete the steps described in Sandbox access.
Note: In the production environment, the PSD2 compliant EIDAS QWAC SSL certificate, production redirect-uri, and production API-Key are used.
Step 1 - Obtain consent
In this step, OAuth 2.0 authorization code flow is used to obtain consent from an ABN AMRO account holder, and grant you with third-party access account information. This consent is given using the consent application. The account holder will need to provide the access separately for each account by selecting the desired account on the screen in case multiple accounts are available.
Request attributes
The table below defines the usage of attributes in a request.
| Attributes | Description |
|---|---|
| scope | Indicates for which scope consent is requested. This can be more than one scope. You can find the available scopes in the operation table below. |
| redirect_uri | In sandbox, you must use https://localhost/auth. In production, this URI must be identical to the URL that was configured on your request. |
| state | Value that is returned to the calling party. This is used for session management. For example, this could be a reference number, informing you that a certain account holder completed consent. |
Operations
| Operation | Request for scope |
|---|---|
| Read the balance of an account | psd2:account:balance:read |
| Read the transactions and/or activities on an account | psd2:account:transaction:read |
| Read the details of an account, such as address and currency | psd2:account:details:read |
| Check availability of funds on an account | psd2:account:funds:read |
Notes:
- When using the attributes please make sure the total length of the URL will not exceed 256 characters.
- When registering an redirect URL please note app deeplinking requires a browser to be launched on the device. For optimal user experience use a internet URL or a universal links.
- In the sandbox, a simplified version of the consent application is used. This application lacks the e.dentifier or mobile APP authorization in favor of easier development.
For more information, see Consent application
Sample request
The following example will start the consent application. In the consent application, the ABN AMRO client reviews and authorizes the requested account access. As a result, you will receive an access code. This is used to get access to the clients account.
https://auth-sandbox.abnamro.com/as/authorization.oauth2?scope=psd2:account:balance:read+psd2:account:transaction:read+psd2:account:details:read&client_id=TPP_test&response_type=code&flow=code&redirect_uri=https://localhost/auth&state=SilverAdministration-123
Sample response
In the response, you will receive an authorization code, which must be exchanged within 60 seconds for an access_token and a refresh_token. This is described in the next step.
https://localhost/auth?code=9C6UrsGZ0Z3XJymRAOAgl7hKPLlWKUo9GBfMQQEs&state=SilverAdministration-123
Note: For more information, see The consent application and the getConsentInfo operation.
Step 2 - Exchange the access token
The authorization code obtained in Step 1 must be exchanged within 60 seconds for an access_token and a refresh_token.
The access_token is used to access the API, and is valid for 2 hours. When the access_token has expired, the refresh_token can be used to obtain a new access_token and refresh_token.
For more information, see Refresh the access token.
Request attributes
| Attribute | Description |
|---|---|
| grant_type | Indicates which type of authorization is used. It must contain 'Authorization_code'. |
| code | Authorization code from Step 1. |
| redirect_uri | This field is mandatory when redirect_uri is used in Step 1. |
Sample request
curl -X POST -k https://auth-mtls-sandbox.abnamro.com/as/token.oauth2 \
-v \
--cert TPPCertificate.crt \
--key TPPprivateKey.key \
-H 'Cache-Control: no-cache' \
-H 'Content-Type: application/x-www-form-urlencoded' \
-d 'grant_type=authorization_code&client_id=TPP_test&code=9C6UrsGZ0Z3XJymRAOAgl7hKPLlWKUo9GBfMQQEs&redirect_uri=https://localhost/auth'
Sample response
{
"access_token": "{GPgYglX4sO1WhzfChx4tmjr4y7Qg}",
"refresh_token": "{UHjIAzBZfLGh4dLm8cvEcH6d8BrOmCZXumOpznQBP1}",
"token_type": "Bearer",
"expires_in": 7193
}
Notes: The
access_tokenis needed to access the account.
Step 3 - Check authorization using consent information
To access an account, you must have an access_token, obtained in Step 2 and the accountNumber which you have been authorized to access in Step 4.
By requesting consent information, the IBAN of the account number associated with the access_token received in Step 2 can be requested. Scopes are also returned in the response.
The data returned in this step does not change after the initial retrieval. Therefore the amount of times this step can be executed is twice per consent.
Request attributes
| Attribute | Description |
|---|---|
| authorization | Use the access_token received in Step 2 and send this as a Bearer token. |
Sample request
curl -X GET -k https://api-sandbox.abnamro.com/v1/consentinfo \
-H 'Accept: application/json' \
-H 'API-Key: X1QTWZre0fnW72l263yrhAWB2FDwx3tg' \
-H 'Authorization: Bearer GPgYglX4sO1WhzfChx4tmjr4y7Qg'
For more information, see getConsentInfo.
Sample response
{
"iban": "NL12ABNA9999876523",
"transactionId": null,
"scopes": "psd2:account:details:read psd2:account:balance:read",
"valid": "1525691979"
"consentStatus": "FULLY_SIGNED",
"consentExpiresIn": "26 days, 23 hours, 57 minutes, and 5 seconds"
}
Store the IBAN with the access_token and refresh_token to retrieve account information in the next step.
Step 4 - Call the Account Information (PSD2) API
In this step we interact with the Account Information API (PSD2) and its functionality.
- Get consent information: Provides authorization information on a resource.
- Get account details: Retrieves the details of the account, such as: Currency and account holder name.
- Get balance: Retrieves Book balance of the account and currency.
- Get transactions: Lists transactions for a specific account number. A maximum of 50 transactions are returned.
- Get funds: Verifies if the amount specified in the request is available in the account. This includes any credit line.
- Get activities: Lists transactions or reservations for a specific account number.
- Get transactions using next page key: Transaction results are paginated. This query fetches the next set of transactions.
- Refresh the access token: The access token is valid for 2 hours. When your access token expires, use this query to request a new access token.
Additional operations
Refresh the access token
When the short-lived access_token obtained in Step 2 has expired, the long-lived refresh_token can be used to get a new access_token and a new refresh_token. This renders the used refresh token as invalid.
Sample request
curl -X POST -k https://auth-mtls-sandbox.abnamro.com/as/token.oauth2 \
-v \
--cert TPPCertificate.crt \
--key TPPprivateKey.key \
-H 'Cache-Control: no-cache' \
-H 'Content-Type: application/x-www-form-urlencoded' \
-d 'grant_type=refresh_token&client_id=TPP_test&refresh_token=UHjIAzBZfLGh4dLm8cvEcH6d8BrOmCZXumOpznQBP1&scope=psd2:account:balance:read&psd2:account:transaction:read'
Sample response
{
"access_token": "{your_new_access_token}",
"refresh_token": "{your_new_refresh_token}",
"token_type": "Bearer",
"expires_in": 7193
}
Store the access_token to access the API, and the refresh_token to request a new access_token when it expires.
Get transactions using nextPageKey
Transaction results are paginated. Use this query to fetch the next set of transactions.
This value is null when no more transactions are present. There are two exceptions. For a getTransaction for a non-NL account and for reservations, where the total number of transactions is a factor 50, a nextPageKey will be provided while the last page will not contain any transactions.
If a response contains a nextPageKey property, it indicates that the result set for the request is larger than 50 transactions. This enables you to get the complete result set by performing multiple queries.
The nextPageKey of the previous response can be used as input.
Note: If filters were used in your initial request, for example, bookDateFrom or bookDateTo, these must be repeated in the
nextPageKeyquery.
Sample request
curl -X GET -k https://api-sandbox.abnamro.com/v1/accounts/{accountNumberRequested}/transactions?nextPageKey=2018-10-24T11:50:27.810000 \
-H 'Authorization: Bearer GPgYglX4sO1WhzfChx4tmjr4y7Qg' \
-H 'API-Key: X1QTWZre0fnW72l263yrhAWB2FDwx3tg'
The above query must be repeated with a nextPageKey query parameter, that contains the property with the same name in the response. When the response no longer contains this property we know that we have all the records for that day.
Regulatory fallback
The PSD2 compliant functionality, used to establish access to the account for licensed third-party payment service providers, is available through a solution that enables you to use the interfaces of ABN AMRO Bank N.V.
This functionality is used until ABN AMRO is exempted from offering this functionality. When this occurs, you are notified and will be required to transfer the connection to the PSD2 APIs.
Requirements
For a full list of PSD2 requirements, see Requirements.
Fallback registration
- Send us the request to onboard stating this is for the fallback solution, using the Support option on the Developer Portal and include your QWAC EIDAS SSL certificate.
- You will receive a confirmation after the setup in completed.
- You can start connecting to https://tpa.abnamro.nl using the certificate. The only exception would be for ABN AMRO Bank Private Banking Belgium for which you can connect to https://tpp.abnamroprivatebanking.be/.
How it works
- You can request access to the website by sending your credentials using mutual TLS based on an x.509 certificate.
- You are authenticated based on public key, private key, and certificate chain, and will be granted access to the website.
- If the authentication fails you will get an "Access Denied". For support, please copy the 'Reference' ID and send it to us by clicking on 'Go to Support'.
Need help?