...
Author
...
...
Version
...
1.0
...
Classification
...
Public
...
A User will initiate a consent from a TPP's mobile or web app.
The User will be redirected to the LFI's mobile or web app to authorise the consent.
The LFI need to adapt their mobile and/or web app to receive the redirect and parameters passed over from the TPP
The LFI will use the API Hub Authorisation Server to verify the request and the parameters
The User will go through SCA (Strong Customer Authentication), review the consent, and authorise/reject it.
The LFI needs to adapt their mobile and/or web app to display the consent authorisation screens.
Each consent type will have different information to display to the user
All screens and the required UX guideline will be provided as part of the Open Finance Standards
The LFI will use the Consent Manager and the Authorisation Server to communicate the outcome of the consent authorisation.
The User will be redirected back to the TPP's mobile or web app.
The API Hub will generate the redirect url & access token
The TPP will receive an access token to allow appropriate actions under the conditions of the consent on the User's account(s).
The Ozone Connect API will be responsible for serving data for action service initiation
...
3.1 API Hub Network Diagram
3.2 Infrastructure
...
Provide a single industry sandbox which simulates a single LFI, with rich synthetic data and a postman collection for each API request/response defined in the Open Finance Standard.
Provide each LFI with dedicated Pre-Production and Production API gateways accessible to TPPs.
Ensure that the externally facing API adheres strictly to the Open Finance Standard, including the FAPI security profile, data model, and API operations for each endpoint.
Integrate with the Open Finance Trust Framework (OFTF) to ensure that ONLY licensed TPPs can access the APIs and that they can ONLY access API sets within the scope of their licensed role(s).
Manage the User’s consent, to act as the single source of truth regarding this consent and to ensure that the TPP can only access APIs (for account informationdata sharing, service initiation or insurance) within the parameters of this consent.
Provide the CBUAE with all required reporting regarding usage, availability and performance.
...
The following sequence diagrams explain the interactions between the User, the TPP, the API Hub and the LFI.
Expand | ||||
---|---|---|---|---|
|
| |||
Expand | ||
---|---|---|
| ||
3.5 Key API Hub Components
In order to deliver the end to end journey for the User, the following APIs will be deployed.
The Authorisation Server and Consent Manager is built, deployed and maintained by Ozone.
The LFI is expected to build, deploy and maintain screens on their mobile and/or web app to support the Consent Authorisation flow.
The LFI is expected to build, deploy and maintain the Ozone Connect API for Data Sharing and Service Initiation.
Component | Provider | Consumer | Interface | Description | Connection | Usage |
---|---|---|---|---|---|---|
Authorisation Server | API Hub | LFI | API |
| MTLS | Authorisation Flow |
Consent Manager | API Hub | LFI | API |
| MTLS | Authorisation Flow Consent Dashboard |
Ozone Connect | LFI | API Hub | API |
| MTLSAccount | InformationData Sharing Service Initiation Insurance |
...
LFI and Ozone each deploy environment infrastructure for Pre-Production and Production
LFI creates certificates using the OFTF - Ozone to provide guidance
LFI and Ozone verifies MTLS connectivity in both directions
LFI to the Consent Manager and Authorisation server
Ozone to the LFI Ozone Connect server
LFI builds the Consent Authorisation flows by adapting their existing mobile and/or web apps
LFI builds the Ozone Connect API integrated with their Core Banking systems
Certification and go Testing, CX certification
Go live
4.3 API Hub
...
User Guide
The API Hub Software Development Kit (SDK) will include:
Detailed Sequence Diagrams
API Hub Ozone Connect API Specification Connectivity Requirements & Guides- Data Sharing
API Hub Ozone Connect API Specification - Service Initiation
Postman collection to simulate TPP journey and LFI / Ozone integration
Supporting documentation - FAQs, video tutorials, data mapping etc
API Hub Admin Portal User Guide
Additionally the Open Finance Standards will define the required UX for Consent Authorisation including
Account Information
4.4 Support for LFIs
Ozone will engage with LFIs who are onboarding onto the OFP via a series of open engagement sessions. These will be technically focused session and should be attended by the LFI’s technical teams. Dates and timing will be comminuted in due course. Ozone will then conduct bilateral sessions providing one-to-one support and guidance to LFIs through the integration lifecycle.
...