C

comdirect.de

comdirect is a German direct bank brand of Commerzbank. Its public developer-facing documentation on comdirect.de focuses on PSD2 open-banking access for third-party providers and customer account/brokerage API information.

1 integration · REST

comdirect exposes one documented HTTP integration surface on its own domain: a PSD2/XS2A Berlin Group REST API at `https://xs2a-api.comdirect.de` with a downloadable OpenAPI spec; no GraphQL, MCP server, or CLI were found on comdirect.de.

discovered 2mo ago
REST · OpenAPI1
Credentials
PSD2 QWAC certificateappGet key ↗

Obtain a valid PSD2 QWAC certificate from a qualified trust service provider listed in the eIDAS Trusted List. comdirect's PSD2 documentation says a valid QWAC certificate is required to access both the sandbox and the Berlin Group API, and access is denied with HTTP 403 if the certificate is invalid, untrusted, or revoked.

TPP OAuth2 client / authorization-code token for PSD2oauth2Set up OAuth ↗

Follow the PSD2 OAuth2 flow described in the comdirect documentation and specific implementation guide. The TPP initiates consent, redirects the PSU to comdirect's authorization endpoint, and exchanges the returned code at POST /berlingroup/v1/token for an access token. comdirect states this access token is mandatory for AIS APIs in the redirect OAuth2 approach; it lasts 1 hour and can be refreshed for 180 days.

conventions · 0/8 published

Publish these signals → /publishing