comdirect.de
comdirect is a German direct bank brand of Commerzbank. Its public developer-facing documentation on comdirect.de focuses on PSD2 open-banking access for third-party providers and customer account/brokerage API information.
comdirect exposes one documented HTTP integration surface on its own domain: a PSD2/XS2A Berlin Group REST API at `https://xs2a-api.comdirect.de` with a downloadable OpenAPI spec; no GraphQL, MCP server, or CLI were found on comdirect.de.
- comdirect PSD2 XS2A APIdiscovered
Obtain a valid PSD2 QWAC certificate from a qualified trust service provider listed in the eIDAS Trusted List. comdirect's PSD2 documentation says a valid QWAC certificate is required to access both the sandbox and the Berlin Group API, and access is denied with HTTP 403 if the certificate is invalid, untrusted, or revoked.
Follow the PSD2 OAuth2 flow described in the comdirect documentation and specific implementation guide. The TPP initiates consent, redirects the PSU to comdirect's authorization endpoint, and exchanges the returned code at POST /berlingroup/v1/token for an access token. comdirect states this access token is mandatory for AIS APIs in the redirect OAuth2 approach; it lasts 1 hour and can be refreshed for 180 days.
conventions · 0/8 published
- integrations.json✗
/.well-known/integrations.json - llms.txt✗
/llms.txt - API catalog✗
/.well-known/api-catalog - OpenAPI document✗
/api/schema/, /openapi.json, /swagger.json, /api/openapi.json, or /v1/openapi.json - MCP server card✗
/.well-known/mcp/server-card.json - OAuth protected resource✗
/.well-known/oauth-protected-resource - Agent card✗
/.well-known/agent-card.json - Agent skills✗
/.well-known/agent-skills/index.json
Publish these signals → /publishing