C

comdirect PSD2 XS2A API

REST discovered

Details
URL
https://xs2a-api.comdirect.de
Spec
https://xs2a-developer.comdirect.de/sites/cdt/files/apidoc_specs/cdt-swagger.yaml
Docs
https://xs2a-developer.comdirect.de/apis
Authentication
PSD2 QWAC certificate Authorization: <credential> + TPP OAuth2 client / authorization-code token for PSD2 Authorization: Bearer <credential> discovered
PSD2 QWAC certificate app Get key ↗

Obtain a valid PSD2 QWAC certificate from a qualified trust service provider listed in the eIDAS Trusted List. comdirect's PSD2 documentation says a valid QWAC certificate is required to access both the sandbox and the Berlin Group API, and access is denied with HTTP 403 if the certificate is invalid, untrusted, or revoked.

TPP OAuth2 client / authorization-code token for PSD2 oauth2 Set up OAuth ↗

Follow the PSD2 OAuth2 flow described in the comdirect documentation and specific implementation guide. The TPP initiates consent, redirects the PSU to comdirect's authorization endpoint, and exchanges the returned code at POST /berlingroup/v1/token for an access token. comdirect states this access token is mandatory for AIS APIs in the redirect OAuth2 approach; it lasts 1 hour and can be refreshed for 180 days.

PSD2 QWAC certificate app discovered Get key ↗
Authorization: <credential>