Related topics:

Introduction to OBIE Account Information APIs (AISP)

This module covers the APIs for the Account Information Service (OBIE Read/Write API ver. 3.1) and includes the consent management and information requests. Some OBIE conditional or optional APIs may not be included.

Click here to understand the terms and abbreviations used in describing this module.

This module covers the following interface or regulation version:

  • OBIE v3.1.

Temenos Transact Account Access APIs help customers to access their account details through any authorised Third Party Provider (TPP) interface that connects to the bank. These APIs are based on the UK OBIE (Open Banking Implementation Entity) standards as defined as part of the PSD2 (Revised Payment Service Directive).

A TPP that facilitates enquires on an account is denoted AISP (Account Information Service Provider). The bank that owns the account details and shares the information through the TPP is denoted ASPSP (Account Servicing Payment Service Provider). The customer who uses the TPP is denoted PSU (Payment Services User).

The Payment Service User has to create a consent in order to access his or her account details through a TPP.

When a Payment Service User (PSU) requests account information with Accounts information Service Provider (AISP), the AISP invokes the related API request to ASPSP which holds the account. AISP is permitted to access only the accounts information approved by the PSU in the consent. For this purpose the TPP must raise a consent request prior to the account information request that needs to be authorised by the PSU.

The ASPSP has to check that the consent given by the PSU of the requesting TPP has not expired or has been granted with the necessary permissions, in order to provide the requested account information. Also ASPSP has to check that the PSU is still allowed to access the account and this right has not been revoked since the consent request has been authorized.

The ASPSP connects to Infinity Spotlight database to validate the PSU login. Once the authentication is successful, the unique user Id of the PSU will be received in the response from the Spotlight. Now the PSU is now known by the ASPSP.

This module provides a set of APIs to support the Temenos client offering account information services for the TPPs according to the UK standards.

The APIs allows a TPP to create a consent resource and request account information. The APIs follow version v3.1 of the OBIE standard.

Please note that only the APIs listed in the APIs section are currently supported.

The following components, including the third party software, are required in addition to this module for the implementation of an end-to-end infrastructure:

  • The UK OBIE Account Information API Gateway (e.g. SaltEdge Gateway), is an application that interface the APIs to the internet. It needs to covers the TPP registration, fraud detection and security.
  • The Identity provider (such as HID Global), performs Strong Customer Authentication (SCA) to identify a PSU at the Account Servicing Payment Service Provider (ASPSP).
  • The User Agent- online screens that allows account selection and leads the PSU through the process of consent authorisation.
  • Access Dashboard - PSU must have to possibility to view and manage the connections and the consent given to Account Service Providers. The Access Dashboard should be an integrated part of the ASPSP.

The PSU is an online banking user in the Infinity Spotlight, during the consent creation as well as during the execution of the GET APIs the system will check in the Spotlight if the PSU has still permission to access the account.

Those components does not come with this module and have to acquired separately by the Temenos client. The additional integration effort should be considered for implementation.

Account Information APIs Integration with Infinity

Temenos Transact modules help customers to accomplish their role as an Account Servicing Payment Service Provider (ASPSP) to comply with the PDS2 (Revised Payment Service Directive) regulation.

The scope of this module, depends on the online banking features, offered by the respective financial institution. As a common rule, all the services offered for payment accounts to customers have to be available through APIs to Third Party Providers. Payments accounts are basically DDA accounts hence savings and loan accounts are excluded as well as wealth management products.

Third Party Providers (TPPs) can access the service through APIs based on the UK OBIE (Open Banking Implementation Entity) standards as defined as part of the PSD2.

This module provides a set of APIs to support the Temenos client offering Account Information Services (AIS) according to the standards.

These modules do not provide an end-to-end solution and additional components are required for the implementation.

The figure below is a high-level functional overview of the Temenos scope and the additional components that are required. The Restful APIs are used for interfacing between those components. While the boxes and arrows in blue show the functionalities and interfaces in scope of the OBIE Account Information APIs (AISP) and OBIE Payment Initiation APIs (PISP) modules, boxes and arrows in yellow are the additional components and interfaces.

Capture the External Consent ID and Consent Deletion API

Once the PSU provides the consent, the Account Information Service Provider (AISP) can request the account information from the Account Servicing Payment Service Provider (ASPSP). The validity of the consent can has-the current or an expiry date.If the consent expired the AISP will no longer have access to it.

If the PSU decides to revoke the consent before it expires, then the consent will be marked as a consent deletion. However, the consent resources held by the ASPSP are never physically deleted, their status will be changed to Revoked instead to allow enquiry of historic data.

User Agent provides the Salt Edge ConsentId to Temenos during the creation of the Temenos Consent Resource. The Salt Edge ConsentId is stored in the AA consent arrangement for the purpose of the consent deletion at the Online Banking Access Dashboard. Temenos returns the Temenos ConsentId to Salt Edge after is created in Temenos Transact.

Whenever a PSU deletes the consent at the AISP, the AISP must send an OBIE consent request deletion to the ASPSP. The ConsentId received by the AISP from the ASPSP during the consent creation is used for the identification as a path parameter.

Temenos clients acting as an ASPSP using the Salt Edge as an API Gateway will allow the AISP Open Banking access. The API Gateway is liable for the TPP onboarding and validation of the TPP requests.

Both system, the Salt Edge and Temenos, maintain their own consent resources hence uses different ConsentIds for the same connection. The TPP, in this case AISP, will only use the Salt Edge ConsentId for communication. For forwarding requests to Temenos, Salt Edge needs to translate the Salt Edge ConsentId into the Temenos ConsentId.

Whenever the AISP invokes a deletion of a consent request at Salt Edge, Salt Edge will forward the request by translating the Salt Edge ConsentId into the Temenos ConsentId and invoking the appropriate OBIE API at Temenos IRIS.

This functionality allows the Payment Service User (PSU) to view and revoke consent at the Account Information Service Provider (AISP).


Field Name
|
Application/Table name

Temenos Headquarters SA
2 Rue de l'Ecole-de-Chimie
CH - 1205 Geneva
Switzerland

Copyright © 2020- Temenos Headquarters SA

Published on :
Tuesday, May 23, 2023 6:46:51 PM IST