C
comdirect PSD2 XS2A API
Details
- URL
-
https://xs2a-api.comdirect.de - Spec
- https://xs2a-developer.comdirect.de/sites/cdt/files/apidoc_specs/cdt-swagger.yaml
- Docs
- https://xs2a-developer.comdirect.de/apis
Authentication
PSD2 QWAC certificate
Authorization: <credential> + TPP OAuth2 client / authorization-code token for PSD2 Authorization: Bearer <credential> discovered Obtain a valid PSD2 QWAC certificate from a qualified trust service provider listed in the eIDAS Trusted List. comdirect's PSD2 documentation says a valid QWAC certificate is required to access both the sandbox and the Berlin Group API, and access is denied with HTTP 403 if the certificate is invalid, untrusted, or revoked.
Follow the PSD2 OAuth2 flow described in the comdirect documentation and specific implementation guide. The TPP initiates consent, redirects the PSU to comdirect's authorization endpoint, and exchanges the returned code at POST /berlingroup/v1/token for an access token. comdirect states this access token is mandatory for AIS APIs in the redirect OAuth2 approach; it lasts 1 hour and can be refreshed for 180 days.
Authorization: <credential>