Skip to main content

Status & Maintenance

Stay informed about current system status and

planned maintenance activities

Go to announcements     Go to Generic Error Codes

Overview

PSD2 and Business Account APIs – Maintenance (12.05.2026)

Due to scheduled backend maintenance on 12 July 2026, between 02:00 and 04:00 CET, payment processing and status updates may be delayed. We apologize for any inconvenience.


Public SSL/TLS Certificate update

Find more information about the public SSL/TLS Certificate update below.

Environments

In this section, we provide information on the availability of our environments. 

Production Operational

Production environment is operational.

Sandbox Operational

Sandbox environment is operational.

Development Operational

Development environment is operational.

 

API Products

In this section, we provide information on availability per API. We show our availability with the following terms: Operational, Outage, Maintenance.

Payment Initiation (PSD2) Operational

This API is operational.

Account Information (PSD2) Operational

This API is operational.

Confirmation Availability Funds (PSD2) Operational

This API is operational.

Business Account Insight Operational

This API is operational.

Business Account Insight - Batch Transaction Details Operational

This API is operational.

Business Account Notification Operational

This API is operational.

Business Account Payment Operational

This API is operational.

Business Account Payment - Instant Operational

This API is operational.

BUUT - Account Information (PSD2) Operational

This API is operational.

BUUT - Payment Initiation (PSD2) Operational

This API is operational.

Consumer Investments Instrument Operational

This API is operational.

FX Trade Operational

This API is operational.

IBAN-Name Check Operational

This API is operational.

Investment Asset Report Operational

This API is operational.

Pay By Invoice Operational

This API is operational.

Tikkie Operational

This API is operational.

Tikkie Cashback Operational

This API is operational.

Wero Merchant Payment Operational

This API is operational.


Go to this report for PSD2 APIs availability per month (Dutch only).

Public SSL/TLS Certificate update: Action might be required

This notice applies to developer portal users who use a public SSL/TLS certificate for client authentication (mutual TLS) when connecting to the ABN AMRO APIs. Please find information below on what is changing, the deadlines, and what you need to do. For questions, contact support. 

What is changing? 
Public CAs will stop including Client Authentication (id-kp-clientAuth) in the Extended Key Usage (EKU) of newly issued public SSL/TLS certificates. This change is driven by browser and root program security requirements (led by Google Chrome). Public SSL/TLS certificates previously included both Server Authentication and Client Authentication EKUs. Client Authentication is now being phased out for public certificates.  

Which certificates are affected? 
Only newly issued, renewed, or reissued public SSL/TLS certificates (DV, OV, EV). Existing certificates remain valid until expiry. 

What is the timeline? 

Below you can find the timelines for DigiCert and Sectigo CAs. Both have a soft and hard deadline. 

Soft deadline 
After the soft deadline, Client Authentication EKU is no longer included by default. It may still be available if explicitly requested (CAdependent)  

Hard deadline 
After the hard deadline, the Client Authentication EKU will no longer be issued at all. Public certificates can no longer be used for client authentication.

Deadlines (DigiCert and Sectigo): 
DigiCert 

  • Soft deadline: 1st of October 2025 

  • Hard deadline: 1st of March 2027 

Sectigo 

  • Soft deadline: 14th of October 2025 

  • Hard deadline: 10th of February 2027 

Note:  If you use another CA, check their published timelines. 

What do you need to do? 
If you use mutual TLS with our APIs, please check the applicable timelines. Until your CAs hard deadline, renew or request new public SSL/TLS certificates with the Client Authentication EKU. This may require an explicit request with your CA. How to include the Client Authentication EKU depends on your CA, for example: 

  • Some CAs keep including it by default until their hard deadline. 

  • Some CAs provide an option (for example, a checkbox) to include it. 

  • Some CAs require a support ticket. 

  • Some CAs require a special account or software package to request the certificate with the Client Authentication EKU 

  • If you are unsure, check with your CA. 

How will we provide access to our APIs in the future?
Public SSL/TLS certificates will no longer be usable for client authentication. Client authentication will require a separate, nonpublicly trusted certificate type. 

We are implementing alternatives to maintain secure TLS connections. The approach may vary per API product, check the API product requirements page on the developer portal for updates.

More information 
Check the requirements for your specific API Product and for any questions, contact support.

image

Report bug or issue

Security is a top priority for ABN AMRO. To ensure secure banking for our customers, we are continuously improving our systems and processes to maintain their reliability. However, if you notice anything we would appreciate it if you would report it to us. Any vulnerabilities, bugs, or errors regarding APIs, please report it by contacting us via support. If you want to pro-actively help, view our HackerOne page to see how you can help by becoming a bug hunter.

TelephoneNeed help?

Check the frequently asked questions or contact us. We are happy to help.
 

Get support Learn the basics