Skip to main content
payments
Payments

Business Account Payment 1.2.10

  • Live

Initiate payments and retrieve information on the status of corporate account transactions.

Tutorial

Note: Starting December 12th 2025, initiated SEPA Credit Transfer batches will be processed over our new instant payment infrastructure. This means that, after authorization in your online channel, the transactions within a SEPA Credit Transfer batch will be processed instantly where possible. This also means that the validations on the Credit Transfer files will be enhanced to better align with the SEPA rules. Therefore make sure you follow our format guidelines. For an overview of the differences in the validations you can use the following document. You can also test if your files pass the validations by making use of MyStandards. For more generic information about the processing of instant SEPA Credit Transfer batches see our online channels website.

How the Business Account Payment API works

  1. Setup your application and integrate it with this API.
  2. Initiate payments.
  3. Authorize payments. Payments for authorization are available in your Internet Banking Business or Access Online portal.
  4. Once authorized, the payment is released for further execution.

Note: Payments are processed as single payments when an initiated batch only contains one payment.

Requirements

To use this API in a production environment as an ABN AMRO client, you must have the following:

  • An ABN AMRO business current account number that is registered in The Netherlands.
  • A contract for Internet Banking Business or Access Online.
  • A TLS certificate of the type Organisation Validation (OV) or Extended Validation (EV) from Digicert, Quo Vadis, Sectigo or Entrust without wildcard options.
  • Your TLS certificate MUST include Client Authentication (1.3.6.1.5.5.7.3.2) value for the certificate usage which can be found in the "Enhance Key Usage" tag of your certificate.
  • Note: for certificates requested or renewed after the 1st of October 2025 Client Authentication is not by default added in your certificate by your CA. Please specifically request this to your CA.
  • Note: Sectigo will only issue a public TLS certificate with the client authentication EKU if you have a Sectigo Enterprise Account or a Sectigo Certificate Manager Pro Account.

Make sure to check this before you order a Sectigo certificate.

  • The organisation name issued on the certificate must correspond to the name of the API contract holder.

To use this API in a production environment as a third party providing bank connectivity services, you must have the following:

  • Contract for bank connectivity
  • A TLS certificate of the type Organisation Validation (OV) or Extended Validation (EV) from Digicert, Quo Vadis, Sectigo or Entrust without wildcard options.
  • The organisation name issued on the certificate must correspond to the name of the API contract holder.
  • A signed request and approval from the account holder, to connect the accounts.

Note: If you are a third party bank connectivity service provider and you are interested in this service, please contact us through ABN AMRO's Embedded Finance page.

Sandbox access

The sandbox and production environments are functionally identical. The sandbox is static, which means that you can perform all operations without making any payments on an account. Payments posted in the sandbox environment are cleaned daily.

To use the Business Account Payment API in the sandbox environment, complete the following steps:

  1. Register and create an account:
    1. Click Sign up.
    2. Enter your details, and click Create new account.
    3. Developer Support will send you an activation link by email.
    4. Click the activation link.
  2. Create and register an application:
    1. Log in to your account.
    2. In the left-side navigation bar, click Apps.
    3. Click Add app.
    4. In the App name field, enter a name for your application.
    5. In the APIs field, select Business Account Payment API, and click Add app.
  3. Complete the How to use this API process.

To provide feedback on this API, see Contact.

Sandbox access details

  • Sandbox URL: https://api-sandbox.abnamro.com
  • Sandbox authorization URL: https://auth-mtls-sandbox.abnamro.com
Attribute Value
client_id test_client
API-Key The API Key for your application on the Developer Portal

Certificates

Certificate files
Download public certificate: Download
Download private key: Download

Production access

To get access to production for ABN AMRO clients:

  1. Log in to your account.
  2. In the left-side navigation, click Apps.
  3. Click Request Production Access.
  4. Select the API category that you want to request production access to.

    Note: It is not possible to request production access for multiple API categories in one request.

  5. Fill in the form, and click Submit.
  6. You receive a confirmation email and ticket-ID.
  7. ABN AMRO Developer Support validates the form.
  8. When the setup is complete, ABN AMRO Developer Support contacts you and supplies you with a client_id.
  9. A new app is added in Apps. This new app contains your API key.

To get access to production for third party bank connectivity service providers:

For production access, contact us.

Production access details

Attribute Value for Production
client_id As supplied to you by ABN AMRO
API-Key The API Key for your production appliction on the Developer Portal

Certificates

Certificate files:
Certificate file : Your Organisation Validated (OV) or Extended Validated (EV) SSL certificate
Private key : Your private key

How to use this API

This instruction describes how to connect an application to the Business Account Payment API in the sandbox environment, and execute payments.

Note: Before you start this process, you must complete the steps described in Sandbox access.

Postman collection

Use the following Postman collection to try out the functionality of this API:

  • This collection highlights all available operations of the API: open in Postman.

For additional information on how to configure Postman and import a collection, see Postman.

Step 1 - Request an access token

In this step, the OAuth 2.0 client credentials flow is used to obtain access to the Business Account Payment API.

Request attributes

The table below defines the usage of attributes in a request.

Attribute Value
client_id test_client
API-Key The API Key for your application on the Developer Portal
scope Indicates for which scope consent is requested. This can be more than one scope. You can find the available scopes in the operation table below.

Certificates

Certificate files
Download public certificate: Download
Download private key: Download

Different scopes are required for clients who use the API directly versus third parties who provide bank connectivity services. The below table shows which scopes are applicable.

Use Operation Request for scope
Direct access Register an unsiged payment for processing. payment:unsigned:write
Direct access Check the processing status of a payment. payment:status:read
Third party access Register an unsiged payment for processing. boekhoudkoppeling:payment:write-unsigned
Third party access Check the processing status of a payment. boekhoudkoppeling:payment:read-status

Sample request

Request an access token using the following sample:

    curl -X POST "https://auth-mtls-sandbox.abnamro.com/as/token.oauth2" \
    -v \
    --cert CertificateCommercial.crt \
    --key PrivateKeyCommercial.key \
    -H 'Cache-Control: no-cache' \
    -H 'Content-Type: application/x-www-form-urlencoded' \
    -d 'grant_type=client_credentials&client_id=test_client&scope=payment:unsigned:write payment:status:read'

Sample response

    {
      "token_type": "Bearer",
      "access_token": "X1PTWZre0fnW72l263yrhAWB2FDwx3tg",
      "expires_in": 7199
    }

Step 2 - Initiate a payment

All ISO XML formatted payments have an initiating account number. The initiating account number is referred to as the DbtrAcct variable in a PAIN.001 for Credit Transfers, and the CdtrAcct variable in the PAIN.008 for Direct Debits. For more information, see ABN AMRO SEPA implementation guidelines. For documentation on Cross Border payments, contact us.

Note: For Credit Transfers the pain.001 version 3 and 9 are supported. For SEPA Direct Debits the pain.008 version 2 and 8 are supported.

For this step, depending on which type of payment you want to process, download and use one following samples files: SCT, or SDD .

Complete the followings steps:

  1. GZIP the SCT or SDD file.

    Note: This part of the process describes an SCT payment.

  2. Encode the file in BASE64 using UTF-8.
  3. Initiate a payment as described in SCT payments sample below. Each file can contain one batch only, whereas a single payment is a batch of 1. For more information, see the InitiatePayment operation.

Payment initiation attributes

Name Type In Required Description
Authorization String Header true Access token to be passed as a bearer token. Use the access_token obtained in Step 1.
X-Request-Id String Header true ID of the payment initiation, unique to the call, as determined by the initiating party.
API-Key String Header true The API Key for your app on the Developer Portal.
fileName String Body true Specifies the name of the file. A unique filename is recommended.
fileData String Body true A GZIP compressed SCT or SDD Payments file. The binary GZIP file must be BASE64 encoded using UTF-8.

SCT payment sample

Note: To upload a SDD payment, add a SDD payment to the fileData field in the sample below.

    curl -X POST -k https://api-sandbox.abnamro.com/v1/customer-api/payments  \
    -v \
    -H 'Accept: application/json' \
    -H 'Authorization: Bearer X1PTWZre0fnW72l263yrhAWB2FDwx3tg' \
    -H 'X-Request-Id: bc69c490-9524-413f-971a-21f1aecd9fe5' \
    -H 'Content-Type: application/json' \
    -H 'API-Key: X1QTWZre0fnW72l263yrhAWB2FDwx3tg' \
    -d '{ 
          "fileName": "SampleSCT.xml.gz",
          "fileData": "H4sIAAAAAAAAA7VVUXOiMBB+91c4vGsgtmoZTEdR77yqdZTe3JtDSURmJHohVnu//pagVSG093KZUch+u9/usruJ83iMN9U3JpJoyzuGVTeNKuPBlkY87Bgv3rDWNh5Jxelvg33MuARtnnSMveB2lGztRFL1xKaJsS1ZsLaPCbV3fsTrpmllv4ZRUWYARR1jLeXORuhwONQPjfpWhAiMLfRrMl4Eaxb7tYgn0ucBM0ilCstxExkLl0pPrEY8kjwTK+ib2H2n4iJQwkkSjigx02U5KNvdariC9aUXE2xaDzWzUcOWZ7Xse2zjloPO4K3J9PV55R0TAozn1xynFJvFPiZWHZtActrd6qThhzP5TpxpTJ42Ppfc92NgzCuiD81LriifrDOL5YivcqaZEFJeuN5y4C0n3vLHnrMlhsg/sILJRFLizYdKJX3/D8kDs7crxKugxVswftsUgYwbUhnMukBLNaZIZ6vS0Dhz5uw3HRwDyfvyqvgOupbfWvRfpdC4hYr12Wsk2V7oyle0UkTdIJAasnxBLkCvOyXTcRN3e9PuA6z2nXXXeoD2SAHNxyiUFundZtGEumCGER/BAPLSoHojl6TxTMcYipLuNIGUsZwCynt23LUIe4IsxoOfUOhsk9NQB4B31HdQ2tllAQ849bbwBwrP/A+rCrZiAo6yiNlVCzfu7psOutLRZFPC7nRjzRdUSJo8BbjqBu8dY/AyN06zcQZ0bvRiSFxfKoV+VS6l9A8lyyL4jC0dwLKmSZESThgOOFFpyahciMsy146Mgr8aG+syNq3mPW6UjU0Wwycp66d2rjl9bxReEikombNVPT1q4BpsQ6NlQo0nHZ3yX+z680F+uh9R8YKEMTvd1+Qvryawd+EHAAA="
        }'

Response attributes

Name Type In Required Description
X-Request-Id String Header true ID of the payment initiation, unique to the call, as determined by the initiating party.
Trace-Id String Header true Unique end-to-end trace ID generated by the Enterprise API Gateway EAG
accountNumber String Body true The initiating accountnumber in IBAN format for the delivered payment(s).
paymentId String Body true Unique Payment ID attached to the the delivered payment(s). This ID is also known as Transaction ID.
Sample response
    {
        "accountNumber": "NL12ABNA9999876523",
        "paymentId": "FCF000001414BC80"
    }

For more information, see the postInitiatePayment operation.

Step 3 - Retrieve the status of a payment

The statuses retrieved provide insight into your batch processing and can be used for rejection alerts.

For details on the statuses that can be retrieved for a given paymentId see the getPaymentStatus operation.

Note: For reconciliation purposes, it is recommended to use the Business Account Insight API or another form of account statements.

Important: In the sandbox environment, it is not possible to retrieve the status on the test file initiated in Step 2. The following paymentIds are available for testing.

paymentId Status
FCF000001414BC80 ACCEPTED
FCF000001517BC90 INPROGRESS

Step 4 - Execute the payment

The payment is available for authorization in Internet Banking Business or Access Online. The account holder must log in and authorize it. Once authorized, the payment is executed.

For more information on how to authorize a batch, read Internet Banking Business or Access Online.

Note: To execute direct debits, the account holder must have a direct debit contract with adequate settings for the number and total value of transactions that are submitted.


Note: The payment limits of the online channel in which the batch is signed will be applied. That means for example that batches signed in Internet Banking Business will be subject to the Internet Banking Business limits.

TelephoneNeed help?

Check the frequently asked questions or contact us. We are happy to help.
 

Get support Learn the basics