Tutorial
Note: Starting December 12th 2025, initiated SEPA Credit Transfer batches will be processed over our new instant payment infrastructure. This means that, after authorization in your online channel, the transactions within a SEPA Credit Transfer batch will be processed instantly where possible. This also means that the validations on the Credit Transfer files will be enhanced to better align with the SEPA rules. Therefore make sure you follow our format guidelines. For an overview of the differences in the validations you can use the following document. You can also test if your files pass the validations by making use of MyStandards. For more generic information about the processing of instant SEPA Credit Transfer batches see our online channels website.
How the Business Account Payment API works
- Setup your application and integrate it with this API.
- Initiate payments.
- Authorize payments. Payments for authorization are available in your Internet Banking Business or Access Online portal.
- Once authorized, the payment is released for further execution.
Note: Payments are processed as single payments when an initiated batch only contains one payment.
Requirements
To use this API in a production environment as an ABN AMRO client, you must have the following:
- An ABN AMRO business current account number that is registered in The Netherlands.
- A contract for Internet Banking Business or Access Online.
- A TLS certificate of the type Organisation Validation (OV) or Extended Validation (EV) from Digicert, Quo Vadis, Sectigo or Entrust without wildcard options.
- Your TLS certificate MUST include Client Authentication (1.3.6.1.5.5.7.3.2) value for the certificate usage which can be found in the "Enhance Key Usage" tag of your certificate.
- Note: for certificates requested or renewed after the 1st of October 2025 Client Authentication is not by default added in your certificate by your CA. Please specifically request this to your CA.
- Note: Sectigo will only issue a public TLS certificate with the client authentication EKU if you have a Sectigo Enterprise Account or a Sectigo Certificate Manager Pro Account.
Make sure to check this before you order a Sectigo certificate.
- The organisation name issued on the certificate must correspond to the name of the API contract holder.
To use this API in a production environment as a third party providing bank connectivity services, you must have the following:
- Contract for bank connectivity
- A TLS certificate of the type Organisation Validation (OV) or Extended Validation (EV) from Digicert, Quo Vadis, Sectigo or Entrust without wildcard options.
- The organisation name issued on the certificate must correspond to the name of the API contract holder.
- A signed request and approval from the account holder, to connect the accounts.
Note: If you are a third party bank connectivity service provider and you are interested in this service, please contact us through ABN AMRO's Embedded Finance page.
Sandbox access
The sandbox and production environments are functionally identical. The sandbox is static, which means that you can perform all operations without making any payments on an account. Payments posted in the sandbox environment are cleaned daily.
To use the Business Account Payment API in the sandbox environment, complete the following steps:
- Register and create an account:
- Click Sign up.
- Enter your details, and click Create new account.
- Developer Support will send you an activation link by email.
- Click the activation link.
- Create and register an application:
- Log in to your account.
- In the left-side navigation bar, click Apps.
- Click Add app.
- In the App name field, enter a name for your application.
- In the APIs field, select Business Account Payment API, and click Add app.
- Complete the How to use this API process.
To provide feedback on this API, see Contact.
Sandbox access details
- Sandbox URL: https://api-sandbox.abnamro.com
- Sandbox authorization URL: https://auth-mtls-sandbox.abnamro.com
| Attribute | Value |
|---|---|
| client_id | test_client |
| API-Key | The API Key for your application on the Developer Portal |
Certificates
| Certificate files |
|---|
| Download public certificate: Download |
| Download private key: Download |
Production access
To get access to production for ABN AMRO clients:
- Log in to your account.
- In the left-side navigation, click Apps.
- Click Request Production Access.
- Select the API category that you want to request production access to.
Note: It is not possible to request production access for multiple API categories in one request.
- Fill in the form, and click Submit.
- You receive a confirmation email and ticket-ID.
- ABN AMRO Developer Support validates the form.
- When the setup is complete, ABN AMRO Developer Support contacts you and supplies you with a client_id.
- A new app is added in Apps. This new app contains your API key.
To get access to production for third party bank connectivity service providers:
For production access, contact us.
Production access details
- Production URL: https://api.abnamro.com
- Production Token URL: https://auth-mtls.abnamro.com/as/token.oauth2
| Attribute | Value for Production |
|---|---|
| client_id | As supplied to you by ABN AMRO |
| API-Key | The API Key for your production appliction on the Developer Portal |
Certificates
| Certificate files: |
|---|
| Certificate file : Your Organisation Validated (OV) or Extended Validated (EV) SSL certificate |
| Private key : Your private key |
How to use this API
This instruction describes how to connect an application to the Business Account Payment API in the sandbox environment, and execute payments.
Note: Before you start this process, you must complete the steps described in Sandbox access.
Postman collection
Use the following Postman collection to try out the functionality of this API:
- This collection highlights all available operations of the API: open in Postman.
For additional information on how to configure Postman and import a collection, see Postman.
Step 1 - Request an access token
In this step, the OAuth 2.0 client credentials flow is used to obtain access to the Business Account Payment API.
Request attributes
The table below defines the usage of attributes in a request.
| Attribute | Value |
|---|---|
| client_id | test_client |
| API-Key | The API Key for your application on the Developer Portal |
| scope | Indicates for which scope consent is requested. This can be more than one scope. You can find the available scopes in the operation table below. |
Certificates
| Certificate files |
|---|
| Download public certificate: Download |
| Download private key: Download |
Different scopes are required for clients who use the API directly versus third parties who provide bank connectivity services. The below table shows which scopes are applicable.
| Use | Operation | Request for scope |
|---|---|---|
| Direct access | Register an unsiged payment for processing. | payment:unsigned:write |
| Direct access | Check the processing status of a payment. | payment:status:read |
| Third party access | Register an unsiged payment for processing. | boekhoudkoppeling:payment:write-unsigned |
| Third party access | Check the processing status of a payment. | boekhoudkoppeling:payment:read-status |
Sample request
Request an access token using the following sample:
curl -X POST "https://auth-mtls-sandbox.abnamro.com/as/token.oauth2" \
-v \
--cert CertificateCommercial.crt \
--key PrivateKeyCommercial.key \
-H 'Cache-Control: no-cache' \
-H 'Content-Type: application/x-www-form-urlencoded' \
-d 'grant_type=client_credentials&client_id=test_client&scope=payment:unsigned:write payment:status:read'
Sample response
{
"token_type": "Bearer",
"access_token": "X1PTWZre0fnW72l263yrhAWB2FDwx3tg",
"expires_in": 7199
}
Step 2 - Initiate a payment
All ISO XML formatted payments have an initiating account number. The initiating account number is referred to as the DbtrAcct variable in a PAIN.001 for Credit Transfers, and the CdtrAcct variable in the PAIN.008 for Direct Debits. For more information, see ABN AMRO SEPA implementation guidelines.
For documentation on Cross Border payments, contact us.
Note: For Credit Transfers the pain.001 version 3 and 9 are supported. For SEPA Direct Debits the pain.008 version 2 and 8 are supported.
For this step, depending on which type of payment you want to process, download and use one following samples files: SCT, or SDD .
Complete the followings steps:
- GZIP the SCT or SDD file.
Note: This part of the process describes an SCT payment.
- Encode the file in BASE64 using UTF-8.
- Initiate a payment as described in SCT payments sample below. Each file can contain one batch only, whereas a single payment is a batch of 1. For more information, see the InitiatePayment operation.
Payment initiation attributes
| Name | Type | In | Required | Description |
|---|---|---|---|---|
| Authorization | String | Header | true | Access token to be passed as a bearer token. Use the access_token obtained in Step 1. |
| X-Request-Id | String | Header | true | ID of the payment initiation, unique to the call, as determined by the initiating party. |
| API-Key | String | Header | true | The API Key for your app on the Developer Portal. |
| fileName | String | Body | true | Specifies the name of the file. A unique filename is recommended. |
| fileData | String | Body | true | A GZIP compressed SCT or SDD Payments file. The binary GZIP file must be BASE64 encoded using UTF-8. |
SCT payment sample
Note: To upload a SDD payment, add a SDD payment to the
fileDatafield in the sample below.
curl -X POST -k https://api-sandbox.abnamro.com/v1/customer-api/payments \
-v \
-H 'Accept: application/json' \
-H 'Authorization: Bearer X1PTWZre0fnW72l263yrhAWB2FDwx3tg' \
-H 'X-Request-Id: bc69c490-9524-413f-971a-21f1aecd9fe5' \
-H 'Content-Type: application/json' \
-H 'API-Key: X1QTWZre0fnW72l263yrhAWB2FDwx3tg' \
-d '{
"fileName": "SampleSCT.xml.gz",
"fileData": "H4sIAAAAAAAAA7VVUXOiMBB+91c4vGsgtmoZTEdR77yqdZTe3JtDSURmJHohVnu//pagVSG093KZUch+u9/usruJ83iMN9U3JpJoyzuGVTeNKuPBlkY87Bgv3rDWNh5Jxelvg33MuARtnnSMveB2lGztRFL1xKaJsS1ZsLaPCbV3fsTrpmllv4ZRUWYARR1jLeXORuhwONQPjfpWhAiMLfRrMl4Eaxb7tYgn0ucBM0ilCstxExkLl0pPrEY8kjwTK+ib2H2n4iJQwkkSjigx02U5KNvdariC9aUXE2xaDzWzUcOWZ7Xse2zjloPO4K3J9PV55R0TAozn1xynFJvFPiZWHZtActrd6qThhzP5TpxpTJ42Ppfc92NgzCuiD81LriifrDOL5YivcqaZEFJeuN5y4C0n3vLHnrMlhsg/sILJRFLizYdKJX3/D8kDs7crxKugxVswftsUgYwbUhnMukBLNaZIZ6vS0Dhz5uw3HRwDyfvyqvgOupbfWvRfpdC4hYr12Wsk2V7oyle0UkTdIJAasnxBLkCvOyXTcRN3e9PuA6z2nXXXeoD2SAHNxyiUFundZtGEumCGER/BAPLSoHojl6TxTMcYipLuNIGUsZwCynt23LUIe4IsxoOfUOhsk9NQB4B31HdQ2tllAQ849bbwBwrP/A+rCrZiAo6yiNlVCzfu7psOutLRZFPC7nRjzRdUSJo8BbjqBu8dY/AyN06zcQZ0bvRiSFxfKoV+VS6l9A8lyyL4jC0dwLKmSZESThgOOFFpyahciMsy146Mgr8aG+syNq3mPW6UjU0Wwycp66d2rjl9bxReEikombNVPT1q4BpsQ6NlQo0nHZ3yX+z680F+uh9R8YKEMTvd1+Qvryawd+EHAAA="
}'
Response attributes
| Name | Type | In | Required | Description |
|---|---|---|---|---|
| X-Request-Id | String | Header | true | ID of the payment initiation, unique to the call, as determined by the initiating party. |
| Trace-Id | String | Header | true | Unique end-to-end trace ID generated by the Enterprise API Gateway EAG |
| accountNumber | String | Body | true | The initiating accountnumber in IBAN format for the delivered payment(s). |
| paymentId | String | Body | true | Unique Payment ID attached to the the delivered payment(s). This ID is also known as Transaction ID. |
Sample response
{
"accountNumber": "NL12ABNA9999876523",
"paymentId": "FCF000001414BC80"
}
For more information, see the postInitiatePayment operation.
Step 3 - Retrieve the status of a payment
The statuses retrieved provide insight into your batch processing and can be used for rejection alerts.
For details on the statuses that can be retrieved for a given paymentId see the getPaymentStatus operation.
Note: For reconciliation purposes, it is recommended to use the Business Account Insight API or another form of account statements.
Important: In the sandbox environment, it is not possible to retrieve the status on the test file initiated in Step 2. The following paymentIds are available for testing.
| paymentId | Status |
|---|---|
| FCF000001414BC80 | ACCEPTED |
| FCF000001517BC90 | INPROGRESS |
Step 4 - Execute the payment
The payment is available for authorization in Internet Banking Business or Access Online. The account holder must log in and authorize it. Once authorized, the payment is executed.
For more information on how to authorize a batch, read Internet Banking Business or Access Online.
Note: To execute direct debits, the account holder must have a direct debit contract with adequate settings for the number and total value of transactions that are submitted.
Note: The payment limits of the online channel in which the batch is signed will be applied. That means for example that batches signed in Internet Banking Business will be subject to the Internet Banking Business limits.
Need help?