Tutorial
How the Confirmation Availability Funds (PSD2) API works
- Request consent from the ABN AMRO account holder through the consent application.
- Retrieve availability confirmation.
The consent application
The consent application is used to obtain consent from an ABN AMRO account holder, and grant access account to verify the available balance for an account.
The account holder consent process consists of three steps:
- Log in.
- Check requested access to account.
- Authorization.
All confirmation availability funds consents are valid for 180 days. Consent can be given by users of Internet Banking, Access Online or Dutch Mobile Banking app. All previously given consents for 90 days remain unchanged, the new duration only applies to new consents.
The ABN AMRO client can either authorize or cancel the requested authorization.
Notes:
- For details on how to access the consent application through the OAuth server, see Step 1.
- The account owner selects one account for which they authorize access.
- The ABN AMRO client can select the Dutch or English language in the consent application or app.
- The consent application uses Strong Customer Authentication (SCA). The authorization is done by clicking the "Finish" button. This completes the consent flow and the user will be re-directed.
Authorization Code
The consent application is visible to the account owner only. It provides you with an access code for the requested authorization using an OAuth 2.0 authorization code process. This is described in Step 1.
Authorization is a grant to an account for one or multiple scopes. For more information, see Authorization Code.
Scopes in the authorization code process
A scope defines the type of access. For confirmation on the availability of funds there are only read scopes. Here are some rules on how scopes can be combined in the authorization code:
- Scopes for different products cannot be combined; AIS/CAF scopes cannot be combined with PIS scopes.
- Write scopes can be combined with read scopes.
- Write scopes cannot be combined with write scopes.
- Delete scopes cannot be combined with other scopes.
For more information on required scopes, see the available operations, for example, the GET funds operation.
Error messages
The following table describes consent application error scenarios. The error message is returned as parameter in the URL.
| Error message | Explanation |
| :-- | :-- |
| error=access_denied# |No current accounts are available to authorize or user declined access.
Generic information
- A response is always sent. Ensure that your application does not time-out.
- If reposting, avoid using short retry periods to keep out of rate limiting scenarios.
Requirements
To use this API in a production environment, you must have the following:
- A PSD2 license for Card-Based Payment Instrument Issuer (CBPII) or Payment Initiation Service Provider (PISP).
- An EIDAS certificate.
- Your QWAC certificate MUST include Client Authentication (1.3.6.1.5.5.7.3.2) value for the certificate usage which can be found in the "Enhance Key Usage" tag of your certificate.
- Note: for certificates requested or renewed after the 1st of October 2025 Client Authentication might not by default be added in your certificate by your CA. Please specifically request this to your CA.
Open Banking UK access:
- A FCA license for payment initiation.
- An OBWAC certificate with the appropriate license details.
License
To use this API in a production environment, or if you require TPP access to ABN AMRO accounts, you must have a PSD2 license from a local competent authority. In the Netherlands, this is De Nederlandsche Bank (DNB). For access to UK accounts, a FCA license is required.
EIDAS certificate
ABN AMRO only accepts Qualified Website Authentication Certificates (QWAC) from Qualified Trusted Service Providers (QSTPs) that are on the trusted list with CEF Digital. This certificate is used for identification, and is also required for OAUTH authorization when accessing APIs.
Note: Inline with the PSD2 technical standard, wildcards are not permitted in certificates. Ensure the certificate usage includes " Client Authentication (1.3.6.1.5.5.7.3.2) "
Sandbox access
The sandbox and production environments are functionally identical. The sandbox is static, which means that you can perform all operations without making any transactions on an account. Transactions posted in the sandbox are cleaned everyday.
To use the Confirmation Availability Funds API (PSD2) in a sandbox environment, complete the following steps:
- Register and create an account:
- Click Sign up.
- Enter your details, and click Create new account.
- Developer Support will send you an activation link by email.
- Click the activation link.
- Create an register application:
- Log in to your account.
- In the left-side navigation bar, click Apps.
- Click Add app.
- In the App name field, enter a name for your application.
- In the APIs field, select Confirmation Availability Funds (PSD2) API, and click Add app.
- Complete the steps in How to use this API process.
Sandbox access details
The following accounts are available for testing:
| Account type | IBAN | Available funds |
|---|---|---|
| Corporate Account | NL62ABNA9999841479 | EUR 557,35 |
| Commercial Account | NL12ABNA9999876523 | EUR 16,03 |
| Retail Account | NL58ABNA9999142181 | EUR -4,99 |
- Sandbox URL: https://api-sandbox.abnamro.com/v1
- Sandbox URL for Token Generation: https://auth-mtls-sandbox.abnamro.com
- Sandbox authorization URL (URL for consent): https://auth-sandbox.abnamro.com
Use the following credentials for the sandbox:
| Attribute | Value for Sandbox |
|---|---|
| client_id | TPP_test |
| API-Key | The API Key for your Sandbox app from the Developer Portal |
| redirect_uri | https://localhost/auth |
Note: Redirect URL's in sandbox cannot be modified. For production environment desired URL's can be specified in the setup process.
| Certificate files: |
|---|
| Download public certificate: Download |
| Download private key: Download |
Note: The sandbox handles functional error scenarios only.
Production access
Important: To use this API in a production environment, you must have a PSD2 license. For more information, see Requirements.
To get access to production:
- Request Access to the CAF (PSD2) production environment:
- Go to Support.
- Click Request production access.
- In the API Product field, select Confirmation Availability Funds.
- Fill in the remaining fields, and click Send.
- ABN AMRO validates the technical setup form and EIDAS certificate, and starts the production access process for the PSD2 APIs.
- The API Services team provides you with production access details.
Note: It is not possible for account holders to get API access on their own accounts.
Production access details
- Production URL: https://api.abnamro.com
- Production authorization URL: https://www.abnamro.nl/consent/v2/authorize?
- Production Token URL: https://auth-mtls.abnamro.com/as/token.oauth2
Note: The authorization URL supports accounts in all countries which the user can access through Internet Banking, Access Online or Dutch Mobile app. For other access see the related brands section on the developer portal.
Use the following credentials for production:
| Attribute | Value for Production |
|---|---|
| client_id | As supplied to you by ABN AMRO |
| API-Key | The API Key for your production app from the Developer Portal |
| redirect_uri | The URLs that you specified in your request access form |
Certificates
| Certificate files: |
|---|
| Certificate file : Your QWAC EIDAS certificate |
| Private key : Your private key |
How to use this API
This instruction describes the functionality of Confirmation Availability Funds (PSD2) API and also how to connect to the sandbox environment.
Note: Before you start this process, you must complete the steps described in Sandbox access. In the production environment, the PSD2 compliant EIDAS QWAC SSL certificate, production redirect-uri, and production API-Key are used.
Note: If you are a Payment Service Provider (PSP) with a payment initiation service access token for checking the one time confirmation of the availability of funds, proceed to Step 4.
Step 1 - Obtain consent
In this step, the OAuth 2.0 authorization code flow is used to obtain consent from an ABN AMRO account holder, and grant you with third-party access. This consent is given using the consent application. The account holder will need to provide the access separately for each account by selecting the desired account on the screen in case multiple accounts are available.
Request attributes
The table below defines the usage of attributes in a request.
| Attributes | Description |
|---|---|
| scope | Indicates for which scope consent is requested. This can be more than one scope. You can find the available scopes in the operation table below. |
| redirect_uri | In sandbox, you must use https://localhost/auth. In production, this URI must be identical to the URL that was configured on your request. |
| bank | Denotes the bank where the account is held. If omitted, this value will revert to NLAA01. See the bank parameter table below for possible values. |
| state | Value that is returned to the calling party. This is used for session management. For example, this could be a reference number, informing you that a certain account holder completed consent. |
Note: When using the attributes make sure the total length of the URL will not exceed 256 characters.
| Operation | Request for scope |
|---|---|
| Check availability of funds on an account | psd2:account:funds:read |
Note: In the sandbox, a simplified version of the consent application is used. This application lacks the e.dentifier authorization in favor of easier development.
For more information, see Consent application
Sample request
The following example will start the consent application. In the consent application, the ABN AMRO client reviews and authorizes the requested account access. As a result, you will receive an access code. This is used to get access to the clients account.
https://auth-sandbox.abnamro.com/as/authorization.oauth2?scope=psd2:account:balance:read+psd2:account:transaction:read+psd2:account:details:read&client_id=TPP_test&response_type=code&flow=code&redirect_uri=https://localhost/auth&bank=NLAA01&state=SilverAdministration-123
Sample response
In the response, you will receive an authorization code, which must be exchanged within 60 seconds for an access_token and a refresh_token. This is described in the next step.
https://localhost/auth?code=9C6UrsGZ0Z3XJymRAOAgl7hKPLlWKUo9GBfMQQEs&state=SilverAdministration-123
Note: For more information, see The consent application and the getConsentInfo operation.
Step 2 - Exchange the access token
The authorization code obtained in Step 1 must be exchanged within 60 seconds for an access_token and a refresh_token.
The access_token is used to access the API, and is valid for 2 hours. When the access_token has expired, the refresh_token can be used to obtain a new access_token and refresh_token.
For more information, see Refresh the access token.
Request attributes
| Attribute | Description |
|---|---|
| grant_type | Indicates which type of authorization is used. It must contain 'Authorization_code'. |
| code | Authorization code from Step 1. |
| redirect_uri | This field is mandatory when redirect_uri is used in Step 1. |
Sample request
```shell
curl -X POST -k https://auth-mtls-sandbox.abnamro.com/as/token.oauth2 \
-v \
--cert TPPCertificate.crt \
--key TPPprivateKey.key \
-H 'Cache-Control: no-cache' \
-H 'Content-Type: application/x-www-form-urlencoded' \
-d 'grant_type=authorization_code&client_id=TPP_test&code=9C6UrsGZ0Z3XJymRAOAgl7hKPLlWKUo9GBfMQQEs&redirect_uri=https://localhost/auth'
```
Sample Response
```json
{
"access_token": "{GPgYglX4sO1WhzfChx4tmjr4y7Qg}",
"refresh_token": "{UHjIAzBZfLGh4dLm8cvEcH6d8BrOmCZXumOpznQBP1}",
"token_type": "Bearer",
"expires_in": 7193
}
```
Notes: The
access_tokenis needed to access the account.
Step 3 - Check authorization using consent information
To access an account, you must have an access_token, obtained in Step 2 and the accountNumber which you have been authorized to access in Step 4.
By requesting consent information, the IBAN of the account number associated with the access_token received in Step 2 can be requested. Scopes are also returned in the response.
Request attributes
| Attribute | Description |
|---|---|
| authorization | Use the access_token received in Step 2 and send this as a Bearer token. |
Sample request
```shell
curl -X GET -k https://api-sandbox.abnamro.com/v1/consentinfo \
-H 'Accept: application/json' \
-H 'API-Key: X1QTWZre0fnW72l263yrhAWB2FDwx3tg' \
-H 'Authorization: Bearer GPgYglX4sO1WhzfChx4tmjr4y7Qg'
```
For more information, see getConsentInfo.
Sample Response
```json
{
"iban": "NL12ABNA9999876523",
"transactionId": null,
"scopes": "psd2:account:details:read psd2:account:balance:read",
"valid": "1525691979"
"consentStatus": "FULLY_SIGNED",
"consentExpiresIn": "26 days, 23 hours, 57 minutes, and 5 seconds"
}
```
Store the IBAN with the access_token and refresh_token to retrieve balance check information in the next step.
Step 4 - Call the Confirmation of Availability of Funds (PSD2) API
In this step we interact with the Confirmation of Availability and its functionality.
- Get consent information: Provides authorization information on a resource.
- Get funds: Verifies if the amount specified in the request is available in the account. This includes any credit line.
- Refresh the access token: The access token is valid for 2 hours. When your access token expires, use this query to request a new access token.
Additional operations
Refresh the access token
When the short-lived access_token obtained in Step 2 has expired, the long-lived refresh_token can be used to get a new access_token and a new refresh_token. This renders the used refresh token as invalid.
Sample request
```shell
curl -X POST -k https://auth-mtls-sandbox.abnamro.com/as/token.oauth2 \
-v \
--cert TPPCertificate.crt \
--key TPPprivateKey.key \
-H 'Cache-Control: no-cache' \
-H 'Content-Type: application/x-www-form-urlencoded' \
-d 'grant_type=refresh_token&client_id=TPP_test&refresh_token=UHjIAzBZfLGh4dLm8cvEcH6d8BrOmCZXumOpznQBP1&scope=psd2:account:balance:read&psd2:account:transaction:read'
```
Sample response
```json
{
"access_token": "{your_new_access_token}",
"refresh_token": "{your_new_refresh_token}",
"token_type": "Bearer",
"expires_in": 7193
}
```
Store the access_token to access the API, and the refresh_token to request a new access_token when it expires.
Regulatory fallback
The PSD2 compliant functionality, used to establish access to the account for licensed third-party payment service providers, is available through a solution that enables you to use the interfaces of ABN AMRO Bank N.V.
This functionality is used until ABN AMRO is exempted from offering this functionality. When this occurs, you are notified and will be required to transfer the connection to the PSD2 APIs.
Requirements
For a full list of PSD2 requirements, see Requirements.
Fallback registration
- Send us the request to onboard stating this is for the fallback solution, using the Support option on the developer portal and include your QWAC EIDAS SSL certificate.
- You will receive a confirmation after the setup in completed.
- You can start connecting to https://tpa.abnamro.nl using the certificate. The only exception would be for ABN AMRO Bank Private Banking Belgium for which you can connect to https://tpp.abnamroprivatebanking.be/.
How it works
- You can request access to the website by sending your credentials using mutual TLS based on an x.509 certificate.
- You are authenticated based on public key, private key, and certificate chain, and will be granted access to the website.
- If the authentication fails you will get an "Access Denied". For support, please copy the 'Reference' ID and send it to us by clicking on 'Go to Support'.
Need help?