Tutorial
Using the the Business Account Insight API you can:
- Request an access token.
- Retrieve account information.
Requirements
To use this API in a production environment as an ABN AMRO client, you must have the following:
- An ABN AMRO business current account number that is registered in The Netherlands.
- A contract for Internet Banking Business or Access Online.
- A TLS certificate of the type Organisation Validation (OV) or Extended Validation (EV) from Digicert, Quo Vadis, Sectigo or Entrust without wildcard options.
- Your TLS certificate MUST include Client Authentication (1.3.6.1.5.5.7.3.2) value for the certificate usage which can be found in the "Enhance Key Usage" tag of your certificate.
Note: For certificates requested or renewed after the 1st of October 2025, Client Authentication is not by default added in your certificate by your CA. Please specifically request this from your CA. Note: Sectigo will only issue a public TLS certificate with the client authentication EKU if you have a Sectigo Enterprise Account or a Sectigo Certificate Manager Pro Account. Make sure to check this before you order a Sectigo certificate. Note: Certain providers such as DigiCert have extended the hard deadline from May 2026 to 1st of March 2027 for the removal of the client authentication EKU. Those changes are the result of changes in the worldwide certificate community.
- The organisation name issued on the certificate must correspond to the name of the API contract holder.
To use this API in a production environment as a third party providing bank connectivity services, you must have the following:
- Contract for bank connectivity.
- A TLS certificate of the type Organisation Validation (OV) or Extended Validation (EV) from Digicert, Quo Vadis, Sectigo or Entrust without wildcard options.
- Your TLS certificate MUST include Client Authentication (1.3.6.1.5.5.7.3.2) value for the certificate usage which can be found in the "Enhance Key Usage" tag of your certificate.
**Note:**for certificates requested or renewed after the 1st of October 2025 Client Authentication is not by default added in your certificate by your CA. Please specifically request this to your CA. Note: Sectigo will only issue a public TLS certificate with the client authentication EKU if you have a Sectigo Enterprise Account or a Sectigo Certificate Manager Pro Account. Make sure to check this before you order a Sectigo certificate. Note: Certain providers such as DigiCert have exentended the hard deadline from May 2026 to 1st of March 2027 for the removal of the client authentication EKU. Those changes are the result of changes in the worldwide certificate community.
- The organisation name issued on the certificate must correspond to the name of the API contract holder.
- A signed request and approval from the account holder, to connect the accounts.
Note: If you are a third party bank connectivity service provider and you are interested in this service, please contact us through ABN AMRO's Embedded Finance page.
Sandbox access
The sandbox and production environments are functionally identical. The sandbox is static, which means that you can perform all operations without making any transactions on an account. Transactions posted in the sandbox environment are cleaned daily.
To use the Business Account Insight API in a sandbox environment, complete the following steps:
- Register and create an account:
- Click Sign up.
- Enter your details, and click Create new account
- Developer Support will send you an activation link by email.
- Click the activation link.
- Create and register application:
- Log in to your account.
- In the left-side navigation click Apps.
- Click Add app.
- In the App name field, enter a name for your application.
- In the APIs field, select Business Account Insight API, and click Add app.
- Complete the steps in How to use this API.
To provide feedback on this API, see Contact.
Sandbox access details
The following accounts are available for testing transaction details for a specific account:
| Account type | IBAN | Description |
|---|---|---|
| Corporate Account | NL62ABNA9999841479 | Returns a total of 310 transactions, spread over most bookdays in the last 24 days. |
| Commercial Account | NL12ABNA9999876523 | Returns a total of 88 transactions, spread over most bookdays in the last 24 days, and has 1 active reservation. |
| Commercial Account | NL58ABNA9999142181 | Returns a total of 24 transactions spread over most bookdays in the last 24 days, and returns 2 active and 1 cancelled reservation. |
- Sandbox URL: https://api-sandbox.abnamro.com
- Sandbox token URL: https://auth-mtls-sandbox.abnamro.com
Use the following credentials for the sandbox:
| Attribute | Value |
|---|---|
| client_id | test_client |
| API-Key | API Key for your application on the Developer Portal |
Certificates
| Certificate files |
|---|
| Download public certificate: Download |
| Download private key: Download |
Note: The sandbox environment handles functional error scenarios only.
Production access
To get access to production for ABN AMRO clients:
- Log in to your account.
- In the top navigation bar, click Apps.
- Click Request Production Access.
- Select the API category that you want to request production access for.
- Fill in the form, and click Submit.
- You receive a confirmation email and ticket Id.
- ABN AMRO Developer Support validates the form.
- When the form is validated and the setup is complete, ABN AMRO Developer Support contacts you and supplies you with a client_id.
- A new app is added in Apps. This new app contains your API key.
To get access to production for third-party bank connectivity providers:
For production access, contact us.
Production access details
- Production URL: https://api.abnamro.com
- Production Token URL: https://auth-mtls.abnamro.com/as/token.oauth2
Use the following credentials for production:
| Attribute | Value for Production |
|---|---|
| client_id | As supplied to you by ABN AMRO |
| API-Key | The API Key for your production application on the Developer Portal |
Certificates
| Certificate files: |
|---|
| Certificate file : Your OV or EV SSL certificate |
| Private key : Your private key |
How to use this API
This instruction describes how to connect an application to the Business Account Insight API in the sandbox environment.
Note: Before you start this process, you must complete the steps described in Sandbox access.
Postman collection
Use the following Postman collections to try out the functionality of this API:
- This collection combines individual operations to try out usage scenarios: run this API in Postman
For additional information on how to configure Postman and import a collection, see Postman.
Step 1 - Request an access token
In this step, the OAuth 2.0 client credentials flow is used to obtain access to the Business Account Insight API.
Request attributes
The table below defines the usage of attributes in a request.
| Attribute | Value |
|---|---|
| client_id | test_client |
| API-Key | The API Key for your application on the Developer Portal |
| scope | Indicates for which scope consent is requested. This can be more than one scope. You can find the available scopes in the operation table below. |
Different scopes are required for clients who use the API directly versus third parties who provide bank connectivity services. The below table shows which scopes are applicable.
| Use | Operation | Request for scope |
|---|---|---|
| Direct access | Read the balance of an account | account:balance:read |
| Direct access | Read the transactions/mutations on an account | account:transaction:read |
| Direct access | Read the details of an account, such as address and currency | account:details:read |
| Third party access | Read the balance of an account | bankconnection:account-balance:read |
| Third party access | Read the transactions/mutations on an account | bankconnection:account-transaction:read |
| Third party access | Read the details of an account, such as address and currency | bankconnection:account-details:read |
Certificates
| Certificate files |
|---|
| Download public certificate: Download |
| Download private key: Download |
Sample request
Request an access token using the following sample:
```shell
curl -X POST "https://auth-mtls-sandbox.abnamro.com/as/token.oauth2" \
-v \
--cert CertificateCommercial.crt \
--key PrivateKeyCommercial.key \
-H 'Cache-Control: no-cache' \
-H 'Content-Type: application/x-www-form-urlencoded' \
-d 'grant_type=client_credentials&client_id=test_client&scope=account:details:read account:balance:read account:transaction:read'
```
Sample response
```json
{
"token_type": "Bearer",
"access_token": "X1PTWZre0fnW72l263yrhAWB2FDwx3tg",
"expires_in": 7199
}
```
Step 2 - Call the Business Account Insight API
In this step, you will call the Business Account Insight API using all available operations.
- To retrieve account details, such as account holder name, see the getAccountDetails operation.
Sample request
```shell
curl -X GET "https://api-sandbox.abnamro.com/v1/accounts/NL12ABNA9999876523/details" \
-H 'Authorization: Bearer X1PTWZre0fnW72l263yrhAWB2FDwx3tg' \
-H 'API-Key: YourApiKeyHere'
```
Sample response
```json
{
"currency":"EUR",
"accountHolderName":"Commercial Account",
"accountNumber":"NL12ABNA9999876523"
}
```
- To retrieve the balance for a given
accountnumber, see the getAccountBalances operation.
Sample request
```shell
curl -X GET "https://api-sandbox.abnamro.com/v1/accounts/NL12ABNA9999876523/balances" \
-H 'Authorization: Bearer X1PTWZre0fnW72l263yrhAWB2FDwx3tg' \
-H 'API-Key: YourApiKeyHere'
```
Sample response
```json
{
"accountNumber":"NL12ABNA9999876523",
"currency":"EUR",
"balanceType":"BOOKBALANCE",
"amount":557.35
}
```
- To retrieve transaction details for an account, see the getAccountTransactions operation.
Sample request
```shell
curl -X GET "https://api-sandbox.abnamro.com/v1/accounts/NL12ABNA9999876523/transactions" \
-H 'Authorization: Bearer X1PTWZre0fnW72l263yrhAWB2FDwx3tg' \
-H 'API-Key: YourApiKeyHere'
```
Sample response
```json
{
"accountNumber":"NL62ABNA9999841479",
"nextPageKey":"2021-07-02-22:43:03:900",
"transactions":[
{
"mutationCode":"658",
"descriptionLines":[
"SEPA Overboeking",
"IBAN: NL40ABNA9999501141",
"BIC: ABNANL2A",
"Naam: Opdrachtgever 32",
"Omschrijving: regel 0005/00244",
",
,"
],
"transactionTimestamp":"2021-07-02-22:54:51:450",
"bookDate":"2021-07-02",
"balanceAfterMutation":380403.07,
"counterPartyAccountNumber":"NL58ABNA9991330577",
"counterPartyName":" Opdrachtgever 32",
"amount":557.35,
"currency":"EUR",
"transactionId":"9854L3153139691S1BI",
"status": "EXECUTED"
}
]
}
```
- To retrieve reservations or transaction details for an account, see the getActivities operation.
Sample request
```shell
curl -X GET "https://api-sandbox.abnamro.com/v1/accounts/NL12ABNA9999876523/activities" \
-H 'Authorization: Bearer X1PTWZre0fnW72l263yrhAWB2FDwx3tg' \
-H 'API-Key: YourApiKeyHere'
```
### Sample response
```json
{
"accountNumber":"NL62ABNA9999841479",
"nextPageKey":"2024-08-21-14:10:31.010000",
"activities": {
"reservations": [
{
"id": "2024-10-11-08:53:09.140000",
"amount": 30.00,
"creditDebitIndicator": "DBIT",
"currency": "EUR",
"counterpartyName": "INTEG-A10(2).1",
"timestamp": "2024-10-11T06:53:09.151Z",
"lastUpdateDateTime": "2024-10-11T06:53:27.595Z",
"expirationDate": "2024-10-18",
"status": "ACTIVE",
"descriptionLines": [
"BEA, BETAALPAS",
"INTEG-A10(2).1,PAS001",
"NR:INTA10-2, 11.10.24/08:53",
"AMSTERDAM"
]
}
]
}
}
```
Note: You can store the IBAN and scopes for your own administration, and for access to the Business Account Insight API.
Note: It's recommended to not only use transactional data but also include either the transactionId or transactionTimeStamp in your reconciliation logic to be able to uniquely identify a booking on your account.
Need help?