Bank Service Initiation API Guide
1. API Flows
1.1 Step 1: Agree Service Initiation Consent
The flow MUST begin with a User who provides consent to a TPP to stage a Bank Service Initiation operation, for a LFI that they already have a relationship with.
1.2 Step 2: Authorize Service Initiation Consent
The TPP MUST now request the User to authorize the consent. Please refer to the Authentication and Authorization page , to review the supported Authorization Flows.
The TPP MUST construct a Rich Authorization Request (RFC 9396: OAuth 2.0 Rich Authorization Requests) with the authorization_details
populated with the User’s Service Initiation consent
The TPP MUST include in a Service Initiation consent all mandatory data that the User intends to provide to the TPP for initiating a Service Initiation operation.
The TPP MUST include a UUID v4 as the ConsentId as a unique identifier for the Service Initiation consent.
The TPP MAY, within in the Service Initiation Consent (where applicable):
Set the
field to determine if only Single Authorizer flow supported.Set the
field to limit the overall time in which a Consent MUST be authorized.
1.2.1 Service Initiation Consent Types
The OFP MUST link both PaymentId
and ConsentId
In the Service Initiation resource
) setLinks.Related
to the authorizedConsentId
used to create the Service Initiation.In the Service Initiation consent resource (
) setLinks.Related
to thePaymentId
resource created for the Consent.
1.2.1 Security and Access Control
Authorization Code Grant
The TPP MUST use an authorization code grant to obtain a token to access all other API resources.
1.3 Step 3: Create Service Initiation
The TPP MUST have a valid access token (with scope) from the OFP authorization server.
The TPP MUST use the valid access token to create a Service Initiation resource with the OFP resource server.
The LFI MUST return a 201 Status Code
together to acknowledge the creation of the new Service Initiation resource when provided with a valid request from the OFP.
The OFP MUST return a 201 Status Code
together to acknowledge the creation of the new Service Initiation resource when provided with a valid access token request from the TPP.
1.4 Step 4: Access the Service Initiation Status
1.5.1 Request Data
The TPP MUST have a valid access token (with scope) from the OFP authorization server.
The TPP MUST set the Content-Type as application/jwt
when creating a Service Initiation resource with the OFP, together with the resource identifier from Step 3.
The OFP MUST respond with the TPP request with a signed JWT with a Service Initiation resource. This ensures non-repudiation for Service Initiation.
2. Service Initiation Sequence Diagrams
All sequence diagrams relating to Bank Service Initiation are now available in the API Hub Documentation.
3. Service Initiation Examples
The following are non-normative examples of API access and usage of the Service Initiation API.
3.1 The TPP Redirects the User to Authorize the Service Initiation Consent
3.1.1 Request: TPP Uses RAR (Rich Authorization Request) via a PAR (Pushed Authorization Request) Endpoint with the OFP to Obtain a Request URI
Create a RAR Request JWT with these values:
is a valid signing key ID for the TPP on the Open Finance Directoryiss
is client id (UUID v4)state
is a UUID v4 valueresponse_type
MUST becode
is the TPP’s redirect URI
The authorization_details contain the User’s service initiation consent details, and a UUID v4 which is a unique identifier for the Service Initiation consent.
The PersonalIdentifiableInformation
field is a JWE that is encrypted by the LFI’s public key, so that only the LFI can decrypt it. It allows the TPP to transmit personal identifiable information (such as the CreditorAccount
and personal information in the Risk
object) to the LFI, without the OFP having to store this information in the consent object. The structure of the decrypted JWE is document in the AEPaymentPII
schema in the OpenAPI document.
"typ": "JWT",
"alg": "PS256",
"kid": "e4ce77c498e77000a25aa7b40e4a83f9"
"iss": "s6BhdRkqt3",
"aud": "",
"response_type": "code",
"redirect_uri": "",
"scope": "openid payments",
"state": "2616df22-899e-468b-b7af-927145b067cc",
"authorization_details": [
"type": "urn:openfinanceuae:service-initiation-consent:v1.2",
"consent": {
"ConsentId": "aac-69255d98-ab0e-4758-92a7-cacbf3073efa",
"IsSingleAuthorization": true,
"AuthorizationExpirationDateTime": "2024-05-01T03:00:00.000Z",
"ExpirationDateTime": "2024-10-01T00:00:00.000Z",
"ControlParameters": {
"ConsentSchedule": {
"MultiPayment": {
"MaximumCumulativeNumberOfPayments": 10,
"PeriodicSchedule": {
"Type": "VariablePeriodicSchedule",
"PeriodType": "Day",
"PeriodStartDate": "2024-05-01",
"MaximumIndividualAmount": {
"Amount": "100.00",
"Currency": "AED"
"PersonalIdentifiableInformation": "eyJhbGciOiJSU0EtT0FFUCIsImVuYyI6IkEyNTZHQ00ifQ.UGhIOguC7...aQeF_PXwJZ4g.48V1_ALb6US04U3b.5eym5T...QzAAE=.XFBoMY...wifLw",
"DebtorReference": "string",
"CreditorReference": "string",
"PaymentPurposeCode": "ABCD"
Create the RAR Request using the signed JWT, and authenticated using private_key_jwt.
The request parameter JWT includes the ConsentId, a UUID v4 that was originally generated by the TPP.
POST /open-finance/auth/v1.2/par HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Accept: application/json
3.1.2 Response: The OFP Provides the Request URI for the TPP
HTTP/1.1 201 Created
Content-Type: application/json
Cache-Control: no-cache, no-store
"request_uri": "urn:ietf:params:oauth:request_uri:6esc_11ACC5bwc014ltc14eY22c",
"expires_in": 60
3.4 The TPP Redirects the User to Their LFI with the Request URI to Authorize the Consent
GET /auth?client_id=c8422787-1dff-424d-b620-356c0870bed4&request_uri=urn:ietf:params:oauth:request_uri:6esc_11ACC5bwc014ltc14eY22c
3.5 The User Logs into Their LFI, Reviews and Authorizes the Consent
The LFI confirms the Service Initiation consent in the OFP.
POST /auth/aac-69255d98-ab0e-4758-92a7-cacbf3073efa/rp/doConfirm
Content-Type: application/x-www-form-urlencoded
3.6 The LFI Returns an Authorization Code to the TPP
302 Found
3.7 The TPP Exchanges the Authorization Code for an Service Initiation API Access Token with the OFP
POST /token HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Accept: application/json
3.8 The OFP Returns an Access Token, Refresh Token to the TPP
HTTP/1.1 200 OK
"access_token": "caa1b60d-61ff-4cd8-a4e1-2d18c8696de0",
"expires_in": 432000,
"token_type": "Bearer",
"scope": "openid payments",
"state": "2616df22-899e-468b-b7af-927145b067cc",
"refresh_token": "266f5f15-eb81-4a02-bf05-e25063ca445f"
The TPP can now initiate a Service Initiation resource using the access token.
3.9 The TPP Initiates a Service Initiation Request with the OFP
3.9.1 Request: payments
POST /open-finance/payment/v1.2/payments HTTP/1.1
Content-Type: application/jwt
Accept: application/jwt
x-fapi-interaction-id: 942a7ee7-d29a-45aa-93b7-c5f292d86602
x-idempotency-key: 78dae4513b8847f98e2d4173b4ed0eb6
Authorization: Bearer caa1b60d-61ff-4cd8-a4e1-2d18c8696de0
"alg": "PS256",
"kid": "e1be6bf3-76e6-4e53-92b9-c46423757ab1"
"iss": "string",
"exp": 0.5,
"nbf": 0.5,
"aud": [
"iat": 0.5,
"message": {
"Data": {
"ConsentId": "aac-69255d98-ab0e-4758-92a7-cacbf3073efa",
"Instruction": {
"Amount": {
"Amount": "100.00",
"Currency": "AED"
"PaymentSequenceNumber": "1"
"PaymentPurposeCode": "ABCD",
"DebtorReference": "string",
"CreditorReference": "string",
"OpenFinanceBilling": {
"Type": "PushP2P"
3.9.2 Response: payments
HTTP/1.1 201 Created
Content-Type: application/jwt
x-fapi-interaction-id: 942a7ee7-d29a-45aa-93b7-c5f292d86602
"alg": "PS256",
"kid": "e1be6bf3-76e6-4e53-92b9-c46423757ab1"
"iss": "string",
"exp": 0.5,
"nbf": 0.5,
"aud": [
"iat": 0.5,
"message": {
"Data": {
"PaymentId": "83b47199-90c2-4c05-9ef1-aeae68b0fc7c",
"ConsentId": "aac-69255d98-ab0e-4758-92a7-cacbf3073efa",
"PaymentTransactionId": "string",
"Status": "Pending",
"StatusUpdateDateTime": "2024-05-01T00:00:00.000Z",
"CreationDateTime": "2024-05-01T00:00:00.000Z",
"DebtorCharges": [
"Type": "VAT",
"Amount": {
"Amount": "100.00",
"Currency": "AED"
"Instruction": {
"Amount": {
"Amount": "100.00",
"Currency": "AED"
"PaymentSequenceNumber": "1"
"PaymentPurposeCode": "ABCD",
"DebtorReference": "string",
"CreditorReference": "string",
"OpenFinanceBilling": {
"Type": "PushP2P"
"Links": {
"Self": "/payments/83b47199-90c2-4c05-9ef1-aeae68b0fc7c",
"Related": "/payment-consents/aac-69255d98-ab0e-4758-92a7-cacbf3073efa"
"Meta": {}
3.10 The TPP Retrieves the Service Initiation Status from the OFP Using the Resource Identifier
Get the Service Initiation Status from the OFP as a JWT response
3.10.1 Request: /payments/{PaymentId
} Resource
GET /open-finance/payment/v1.2/payments/83b47199-90c2-4c05-9ef1-aeae68b0fc7c HTTP/1.1
Accept: application/jwt
x-fapi-interaction-id: 942a7ee7-d29a-45aa-93b7-c5f292d86602
Authorization: Bearer ad297304-1057-4c68-9e76-a96f300a27f1
3.10.2 Response: /payments/{PaymentId
} Resource
HTTP/1.1 200 OK
Content-Type: application/jwt
x-fapi-interaction-id: 942a7ee7-d29a-45aa-93b7-c5f292d86602
"alg": "PS256",
"kid": "e1be6bf3-76e6-4e53-92b9-c46423757ab1"
"iss": "string",
"exp": 0.5,
"nbf": 0.5,
"aud": [
"iat": 0.5,
"message": {
"Data": {
"PaymentId": "83b47199-90c2-4c05-9ef1-aeae68b0fc7c",
"ConsentId": "aac-69255d98-ab0e-4758-92a7-cacbf3073efa",
"PaymentTransactionId": "string",
"Status": "Pending",
"StatusUpdateDateTime": "2024-05-01T00:00:00.000Z",
"CreationDateTime": "2024-05-01T00:00:00.000Z",
"DebtorCharges": [
"Type": "VAT",
"Amount": {
"Amount": "100.00",
"Currency": "AED"
"Instruction": {
"Amount": {
"Amount": "100.00",
"Currency": "AED"
"PaymentSequenceNumber": "1"
"PaymentPurposeCode": "ABCD",
"DebtorReference": "string",
"CreditorReference": "string",
"OpenFinanceBilling": {
"Type": "PushP2P"
"Links": {
"Self": "/payments/83b47199-90c2-4c05-9ef1-aeae68b0fc7c",
"Related": "/payment-consents/aac-69255d98-ab0e-4758-92a7-cacbf3073efa"
"Meta": {}
4. Further Service Initiation Examples
4.1 The TPP Queries the Service Initiation Resource Using an Expired Access Token
4.1.1 Request: payments/{PaymentId
} Resource
GET /open-finance/payment/v1.2/payments/83b47199-90c2-4c05-9ef1-aeae68b0fc7c HTTP/1.1
Accept: application/jwt
x-fapi-interaction-id: 942a7ee7-d29a-45aa-93b7-c5f292d86602
Authorization: Bearer ad297304-1057-4c68-9e76-a96f300a27f1
4.1.2 Response: payments/{PaymentId
} Resource
HTTP/1.1 401 Unauthorized
x-fapi-interaction-id: 942a7ee7-d29a-45aa-93b7-c5f292d86602
Content-Type: application/jwt
"alg": "PS256",
"kid": "e1be6bf3-76e6-4e53-92b9-c46423757ab1"
"iss": "string",
"exp": 0,
"nbf": 0,
"aud": [
"iat": 0,
"message": {
"Errors": [
"Code": "AccessToken.Unauthorized",
"Message": "max_age_exceeded: Token has expired",
"Path": "Authorization",
"Url": ""
4.2 Webhooks
4.2.1 The TPP Creates a Service Initiation Consent Request on Behalf of the User with a Webhook Subscription Request: Service Initiation Consent and Webhook Subscription
"typ": "JWT",
"alg": "PS256",
"kid": "e4ce77c498e77000a25aa7b40e4a83f9"
"iss": "s6BhdRkqt3",
"iat": 1669393154,
"exp": 1669393496,
"nbf": 1669393154,
"aud": "",
"response_type": "code",
"redirect_uri": "",
"scope": "openid payments",
"state": "af0ifjsldkj",
"authorization_details": [
"type": "urn:openfinanceuae:service-initiation-consent:v1.2",
"consent": {
"ConsentId": "aac-69255d98-ab0e-4758-92a7-cacbf3073efa",
"IsSingleAuthorization": true,
"AuthorizationExpirationDateTime": "2024-05-01T03:00:00.000Z",
"ExpirationDateTime": "2024-10-01T00:00:00.000Z",
"ControlParameters": {
"ConsentSchedule": {
"MultiPayment": {
"MaximumCumulativeNumberOfPayments": 10,
"PeriodicSchedule": {
"Type": "VariablePeriodicSchedule",
"PeriodType": "Day",
"PeriodStartDate": "2024-05-01",
"MaximumIndividualAmount": {
"Amount": "100.00",
"Currency": "AED"
"PersonalIdentifiableInformation": "eyJhbGciOiJSU0EtT0FFUCIsImVuYyI6IkEyNTZHQ00ifQ.UGhIOguC7...aQeF_PXwJZ4g.48V1_ALb6US04U3b.5eym5T...QzAAE=.XFBoMY...wifLw",,
"DebtorReference": "string",
"CreditorReference": "string",
"PaymentPurposeCode": "ABCD"
"Subscription": {
"Webhook": {
"Url": "",
"IsActive": true
4.2.2 The TPP updates a Webhook Subscription preference with the OFP Request: Activate Webhook events
PATCH /open-finance/payment/v1.2/payment-consents/aac-69255d98-ab0e-4758-92a7-cacbf3073efa HTTP/1.1
Content-Type: application/jwt
Accept: application/jwt
x-fapi-interaction-id: 3424a379-8274-4686-99bd-f420d08acead
Authorization: Bearer ad297304-1057-4c68-9e76-a96f300a27f1
"alg": "PS256",
"kid": "e1be6bf3-76e6-4e53-92b9-c46423757ab1"
"iss": "string",
"exp": 0,
"nbf": 0,
"aud": [
"iat": 0,
"message": {
"Subscription": {
"Webhook": {
"IsActive": true
<<signature>> Response: Webhook events activated
x-fapi-interaction-id: 3424a379-8274-4686-99bd-f420d08acead
HTTP/1.1 204 No Content
4.2.3 The TPP unsubscribes their Webhook Subscription with the OFP Request: De-Activate Webhook events
PATCH /open-finance/payment/v1.2/payment-consents/aac-69255d98-ab0e-4758-92a7-cacbf3073efa HTTP/1.1
Content-Type: application/jwt
x-fapi-interaction-id: 3424a379-8274-4686-99bd-f420d08acead
Authorization: Bearer ad297304-1057-4c68-9e76-a96f300a27f1
"alg": "PS256",
"kid": "e1be6bf3-76e6-4e53-92b9-c46423757ab1"
"iss": "string",
"exp": 0,
"nbf": 0,
"aud": [
"iat": 0,
"message": {
"Subscription": {
"Webhook": {
"IsActive": false
<<signature>> Response: Webhook events de-activated
x-fapi-interaction-id: 3424a379-8274-4686-99bd-f420d08acead
HTTP/1.1 204 No Content
4.2.4 The TPP receives Service Initiation Consent data from the OFP via its Webhook The OFP generates a Self Signed JWT Authorization Token for Client Authentication with the TPP
This JWT Authorization Token MUST be set in the Authorization Header.
"alg": "PS256",
"typ": "JOSE",
"cty": "json",
"kid": "e1be6bf3-76e6-4e53-92b9-c46423757ab1"
"iss": "",
"sub": "e75c26bf-1682-401a-a227-ec125f6636ab",
"aud": "",
"exp": 1661378066,
"iat": 1661378036,
"nbf": 1661378036,
"jti": "274aa39d-d77a-46a9-b832-b2ced47919dd"
<<signature>> Request: OFP publishes signed/encrypted Service Initiation Data to the registered Webhook Url provided by the TPP
The example below shows a signed and encrypted payload with the JWT Authorization Token set in the Authorization Header
POST /webhook/callbackUrl HTTP/1.1
x-fapi-interaction-id: 77b0e830-b095-4c6c-94e8-20f83eaa799f
Content-Type: application/jwt
Date: Wed, 24 Aug 2022 07:28:00 AST
Authorization: Bearer eyJhbGciO9.eyJzdWImlhdCI6MTUxNjIzOTAyMn0.iOeN9eg
Here, <<jwe>>
is a signed and encrypted payload. The inner JWS has the structure below.
"alg": "PS256",
"kid": "e1be6bf3-76e6-4e53-92b9-c46423757ab1"
"iss": "string",
"exp": 0.5,
"nbf": 0.5,
"aud": [
"iat": 0.5,
"message": {
"Data": {
"ConsentId": "aac-69255d98-ab0e-4758-92a7-cacbf3073efa",
"BaseConsentId": "abc-19877d98-ab0e-4758-92a7-vvffr1234abv",
"IsSingleAuthorization": true,
"AuthorizationExpirationDateTime": "2024-05-01T03:00:00.000Z",
"ExpirationDateTime": "2024-10-01T00:00:00.000Z",
"ConsentStatus": "AwaitingAuthorization",
"ConsentStatusUpdateDateTime": "2024-05-01T00:00:00.000Z",
"CreationDateTime": "2024-05-01T00:00:00.000Z",
"ControlParameters": {
"ConsentSchedule": {
"MultiPayment": {
"MaximumCumulativeNumberOfPayments": 10,
"PeriodicSchedule": {
"Type": "VariablePeriodicSchedule",
"PeriodType": "Day",
"PeriodStartDate": "2024-05-01",
"MaximumIndividualAmount": {
"Amount": "100.00",
"Currency": "AED"
"PersonalIdentifiableInformation": "eyJhbGciOiJSU0EtT0FFUCIsImVuYyI6IkEyNTZHQ00ifQ.UGhIOguC7...aQeF_PXwJZ4g.48V1_ALb6US04U3b.5eym5T...QzAAE=.XFBoMY...wifLw",,
"DebtorReference": "string",
"CreditorReference": "string",
"PaymentPurposeCode": "ABCD",
"PaymentConsumption": {
"CumulativeValueOfPayments": {
"Amount": "1000.00",
"Currency": "AED"
"CumulativeNumberOfPayments": 10
"Links": {
"Self": "/payment-consents/aac-69255d98-ab0e-4758-92a7-cacbf3073efa",
"Related": []
"EventMeta": {
"EventDateTime": "2024-05-01T00:00:00.000Z",
"EventResource": "/payment-consents/aac-69255d98-ab0e-4758-92a7-cacbf3073efa",
"EventType": "Resource.Created",
"ConsentId": "aac-69255d98-ab0e-4758-92a7-cacbf3073efa"
<<signature>> Response: TPP validates the Self Signed JWT Authorization Token from OFP, stores Payment consent data and acknowledges a success response to the OFP
x-fapi-interaction-id: 77b0e830-b095-4c6c-94e8-20f83eaa799f
HTTP/1.1 202 Accepted
4.3 Multiple Authorizations
4.3.1 Request: Service Initiation consent resource requesting Multi-Authorization
The TPP creates a Service Initiation consent with IsSingleAuthorization
as false
denoting its support for a Multi-Authorization consent.
"typ": "JWT",
"alg": "PS256",
"kid": "e4ce77c498e77000a25aa7b40e4a83f9"
"iss": "s6BhdRkqt3",
"aud": "",
"response_type": "code",
"redirect_uri": "",
"scope": "openid payments",
"state": "af0ifjsldkj",
"authorization_details": [
"type": "urn:openfinanceuae:service-initiation-consent:v1.2",
"consent": {
"ConsentId": "aac-69255d98-ab0e-4758-92a7-cacbf3073efa",
"IsSingleAuthorization": false,
"AuthorizationExpirationDateTime": "2024-05-01T03:00:00.000Z",
"ExpirationDateTime": "2024-10-01T00:00:00.000Z",
"ControlParameters": {
"ConsentSchedule": {
"MultiPayment": {
"MaximumCumulativeNumberOfPayments": 10,
"PeriodicSchedule": {
"Type": "VariablePeriodicSchedule",
"PeriodType": "Day",
"PeriodStartDate": "2024-05-01",
"MaximumIndividualAmount": {
"Amount": "100.00",
"Currency": "AED"
"PersonalIdentifiableInformation": "eyJhbGciOiJSU0EtT0FFUCIsImVuYyI6IkEyNTZHQ00ifQ.UGhIOguC7...aQeF_PXwJZ4g.48V1_ALb6US04U3b.5eym5T...QzAAE=.XFBoMY...wifLw",,
"DebtorReference": "string",
"CreditorReference": "string",
"PaymentPurposeCode": "ABCD"
4.4 The TPP Queries the existence of a Service Initiation Resource Using the X-Idempotency-Key
This is a negative scenario whereby the OFP fails to return any payments
response and the TPP has no way of identifying the resource PaymentId
The PaymentId
is returned within the HTTP Location
Header URL under the /payments
4.4.1 Request to /payments Resource
HEAD /open-finance/payment/v1.2/payments HTTP/1.1
Accept: application/jwt
x-fapi-interaction-id: 942a7ee7-d29a-45aa-93b7-c5f292d86602
Authorization: Bearer ad297304-1057-4c68-9e76-a96f300a27f1
x-idempotency-key: 78dae4513b8847f98e2d4173b4ed0eb6
4.4.2 Response to /payments Resource
HTTP/1.1 204 No Content
x-fapi-interaction-id: 3424a379-8274-4686-99bd-f420d08acead
Location: /open-finance/payment/v1.2/payments/83b47199-90c2-4c05-9ef1-aeae68b0fc7c
4.5 The TPP Initiates a Bulk File Payment
4.5.1 Request: TPP Uses RAR (Rich Authorization Request) to Request Initial Base Consent
The authorization_details contain the User’s service initiation consent details, and a UUID v4 which is a unique identifier for the Service Initiation consent.
"typ": "JWT",
"alg": "PS256",
"kid": "e4ce77c498e77000a25aa7b40e4a83f9"
"iss": "s6BhdRkqt3",
"aud": "",
"response_type": "code",
"redirect_uri": "",
"scope": "openid payments",
"state": "2616df22-899e-468b-b7af-927145b067cc",
"authorization_details": [
"type": "urn:openfinanceuae:service-initiation-consent:v1.2",
"consent": {
"ConsentId": "aac-69255d98-ab0e-4758-92a7-cacbf3073efa",
"IsSingleAuthorization": true,
"AuthorizationExpirationDateTime": "2024-05-01T03:00:00.000Z",
"ExpirationDateTime": "2024-10-01T00:00:00.000Z",
"ControlParameters": {
"ConsentSchedule": {
"FilePayment": {
"FileType": "pain.001.001.08",
"FileHash": "m5ah/h1UjLvJYMxqAoZmj9dKdjZnsGNm+yMkJp/KuqQ",
"NumberOfTransactions": 5,
"ControlSum": "10003.40"
Create the RAR Request using the signed JWT, and authenticated using private_key_jwt.
The request parameter JWT includes the ConsentId, a UUID v4 that was originally generated by the TPP.
POST /open-finance/auth/v1.2/par HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Accept: application/json
4.5.2 Response: The OFP Provides the Request URI for the TPP
HTTP/1.1 201 Created
Content-Type: application/json
Cache-Control: no-cache, no-store
"request_uri": "urn:ietf:params:oauth:request_uri:6esc_11ACC5bwc014ltc14eY22c",
"expires_in": 60
4.5.3 The TPP Uploads File Payment
POST /open-finance/payment/v1.2/payment-consents/aac-69255d98-ab0e-4758-92a7-cacbf3073efa/file HTTP/1.1
Authorization: Bearer ad297304-1057-4c68-9e76-a96f300a27f1
Content-Type: text/xml
Accept: application/json
4.5.4 The TPP Redirects the User to Their LFI with the Request URI to Authorize the Consent
GET /auth?client_id=c8422787-1dff-424d-b620-356c0870bed4&request_uri=urn:ietf:params:oauth:request_uri:6esc_11ACC5bwc014ltc14eY22c
4.5.5 The User Logs into Their LFI, Reviews and Authorizes the Consent
The LFI confirms the Service Initiation consent in the OFP.
POST /auth/aac-69255d98-ab0e-4758-92a7-cacbf3073efa/rp/doConfirm
Content-Type: application/x-www-form-urlencoded
4.5.6 The LFI Returns an Authorization Code to the TPP
302 Found
4.5.7 The TPP Exchanges the Authorization Code for an Service Initiation API Access Token with the OFP
POST /token HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Accept: application/json
4.5.8 The OFP Returns an Access Token, Refresh Token to the TPP
HTTP/1.1 200 OK
"access_token": "caa1b60d-61ff-4cd8-a4e1-2d18c8696de0",
"expires_in": 432000,
"token_type": "Bearer",
"scope": "openid payments",
"state": "2616df22-899e-468b-b7af-927145b067cc",
"refresh_token": "266f5f15-eb81-4a02-bf05-e25063ca445f"
The TPP can now initiate a Service Initiation resource using the access token.
4.5.9 The TPP Initiates a Service Initiation Request with the OFP Request: file-payments
POST /open-finance/payment/v1.2/file-payments HTTP/1.1
Content-Type: application/jwt
Accept: application/jwt
x-fapi-interaction-id: 942a7ee7-d29a-45aa-93b7-c5f292d86602
x-idempotency-key: 78dae4513b8847f98e2d4173b4ed0eb6
Authorization: Bearer caa1b60d-61ff-4cd8-a4e1-2d18c8696de0
"alg": "PS256",
"kid": "e1be6bf3-76e6-4e53-92b9-c46423757ab1"
"iss": "string",
"exp": 0.5,
"nbf": 0.5,
"aud": [
"iat": 0.5,
"message": {
"Data": {
"ConsentId": "aac-69255d98-ab0e-4758-92a7-cacbf3073efa",
"Instruction": {
"FileType": "pain.001.001.08",
"FileHash": "m5ah/h1UjLvJYMxqAoZmj9dKdjZnsGNm+yMkJp/KuqQ",
"NumberOfTransactions": 5,
"ControlSum": "10003.40"
"PaymentPurposeCode": "ABCD",
"DebtorReference": "string"
<<signature>> Response: file-payments
HTTP/1.1 201 Created
Content-Type: application/jwt
x-fapi-interaction-id: 942a7ee7-d29a-45aa-93b7-c5f292d86602
"alg": "PS256",
"kid": "e1be6bf3-76e6-4e53-92b9-c46423757ab1"
"iss": "string",
"exp": 0.5,
"nbf": 0.5,
"aud": [
"iat": 0.5,
"message": {
"Data": {
"PaymentId": "83b47199-90c2-4c05-9ef1-aeae68b0fc7c",
"ConsentId": "aac-69255d98-ab0e-4758-92a7-cacbf3073efa",
"PaymentTransactionId": "string",
"Status": "Received",
"StatusUpdateDateTime": "2024-05-01T00:00:00.000Z",
"CreationDateTime": "2024-05-01T00:00:00.000Z",
"Instruction": {
"FileType": "pain.001.001.08",
"FileHash": "m5ah/h1UjLvJYMxqAoZmj9dKdjZnsGNm+yMkJp/KuqQ",
"NumberOfTransactions": 5,
"ControlSum": "10003.40"
"PaymentPurposeCode": "ABCD",
"DebtorReference": "string"
"Links": {
"Self": "/file-payments/83b47199-90c2-4c05-9ef1-aeae68b0fc7c",
"Related": "/payment-consents/aac-69255d98-ab0e-4758-92a7-cacbf3073efa"
"Meta": {}
4.6 The TPP Requests Refund Account Details
4.6.1 Request: payment-consents/{ConsentId
}/refund Resource
GET /open-finance/payment/v1.2/payment-consents/83b47199-90c2-4c05-9ef1-aeae68b0fc7c/refund HTTP/1.1
Accept: application/jwt
x-fapi-interaction-id: 942a7ee7-d29a-45aa-93b7-c5f292d86602
Authorization: Bearer ad297304-1057-4c68-9e76-a96f300a27f1
4.6.2 Response: payment-consents/{ConsentId
}/refund Resource
HTTP/1.1 200 OK
Content-Type: application/jwt
x-fapi-interaction-id: 942a7ee7-d29a-45aa-93b7-c5f292d86602
"alg": "PS256",
"kid": "e1be6bf3-76e6-4e53-92b9-c46423757ab1"
"iss": "string",
"exp": 0.5,
"nbf": 0.5,
"aud": [
"iat": 0.5,
"message": {
"Data": {
"BaseConsentId": "aac-69255d98-ab0e-4758-92a7-cacbf3073efa",
"ConsentId": "aac-69255d98-ab0e-4758-92a7-cacbf3073efa",
"RefundAccount": {
"SchemeName": "IBAN",
"Identification": "string",
"Name": {
"en": "string",
"ar": "string"
"Links": {
"Self": "/payment-consents/aac-69255d98-ab0e-4758-92a7-cacbf3073efa/refund"
"Meta": {}
4.7 The TPP Uses the BaseConsentId
to Link Consents
A TPP may update the parameters of an existing consent, by (1) revoking the existing consent, and (2) creating a new consent for the User with the new agreed consent parameters. The BaseConsentId
allows TPPs to chain and link consents together, so that there is a history of linked consents.
This flow gives an example of how a TPP will link consents together.
4.7.1 TPP Creates a new Consent as the Base Consent
The authorization_details contain the User’s service initiation consent details, and a UUID v4 which is a unique identifier for the Service Initiation consent.
"typ": "JWT",
"alg": "PS256",
"kid": "e4ce77c498e77000a25aa7b40e4a83f9"
"iss": "s6BhdRkqt3",
"aud": "",
"response_type": "code",
"redirect_uri": "",
"scope": "openid payments",
"state": "2616df22-899e-468b-b7af-927145b067cc",
"authorization_details": [
"type": "urn:openfinanceuae:service-initiation-consent:v1.2",
"consent": {
"BaseConsentId": "aac-69255d98-ab0e-4758-92a7-cacbf3073efa",
"ConsentId": "aac-69255d98-ab0e-4758-92a7-cacbf3073efa",
"IsSingleAuthorization": true,
"AuthorizationExpirationDateTime": "2024-05-01T03:00:00.000Z",
"ExpirationDateTime": "2024-10-01T00:00:00.000Z",
"ControlParameters": {
"ConsentSchedule": {
"MultiPayment": {
"MaximumCumulativeNumberOfPayments": 10,
"PeriodicSchedule": {
"Type": "VariablePeriodicSchedule",
"PeriodType": "Day",
"PeriodStartDate": "2024-05-01",
"MaximumIndividualAmount": {
"Amount": "100.00",
"Currency": "AED"
Create the RAR Request using the signed JWT, and authenticated using private_key_jwt.
The request parameter JWT includes the ConsentId, a UUID v4 that was originally generated by the TPP.
POST /open-finance/auth/v1.2/par HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Accept: application/json
4.7.2 Standard Authorization Flow
The standard authorization flow proceeds with the User authorizing the consent. The TPP now has a valid consent in an Authorized
4.7.3 Alternative Flow - the TPP may Revoke the Existing Consent
In the scenario that the TPP wants to update the consent parameters in the original consent - the TPP would take steps to:
Revoke the original consent
Create a new consent that the User would authorise this new consent (as per 4.7.1)
If the TPP would like to link the original consent with the new consent - the TPP would populate the
with theBaseConsentId
of the original consent TPP Revokes Original Consent
PATCH /open-finance/payment/v1.2/payment-consents/aac-69255d98-ab0e-4758-92a7-cacbf3073efa HTTP/1.1
Content-Type: application/jwt
Accept: application/jwt
x-fapi-interaction-id: 942a7ee7-d29a-45aa-93b7-c5f292d86602
x-idempotency-key: 78dae4513b8847f98e2d4173b4ed0eb6
Authorization: Bearer caa1b60d-61ff-4cd8-a4e1-2d18c8696de0
"alg": "PS256",
"kid": "e1be6bf3-76e6-4e53-92b9-c46423757ab1"
"iss": "string",
"exp": 0.5,
"nbf": 0.5,
"aud": [
"iat": 0.5,
"message": {
"Data": {
"Status": "Revoked"
<<signature>> TPP Creates a new Consent with the same BaseConsentId
"typ": "JWT",
"alg": "PS256",
"kid": "e4ce77c498e77000a25aa7b40e4a83f9"
"iss": "s6BhdRkqt3",
"aud": "",
"response_type": "code",
"redirect_uri": "",
"scope": "openid payments",
"state": "00e8460b-167e-44b9-a9d1-e1f79d998d27",
"authorization_details": [
"type": "urn:openfinanceuae:service-initiation-consent:v1.2",
"consent": {
"BaseConsentId": "aac-69255d98-ab0e-4758-92a7-cacbf3073efa",
"ConsentId": "28ec6225-d9f4-4d8a-8904-bb62ce7e6cff",
"IsSingleAuthorization": true,
"ControlParameters": {
"ConsentSchedule": {
"MultiPayment": {
"PeriodicSchedule": {
"Type": "VariablePeriodicSchedule",
"PeriodType": "Day",
"PeriodStartDate": "2024-07-01",
"MaximumIndividualAmount": {
"Amount": "200.00",
"Currency": "AED"
5. Open API Specification
See the Bank Service Initiation OpenAPI page.
6. Service Initiation Notes
6.1 Staging a Service Initiation Consent
To manage the creation and execution of a Single Instant payment;
The TPP:
MUST provide a
in the Consent object within theauthorization_details
of a Rich Authorization Request.MUST include the response from the Confirmation operation at the Confirmation of Payee API in the property
when Confirmation of Payee has been performed by the TPP for theCreditorAccount
details. This property must be included in the value of the JWE created to populate the propertyPersonalIdentifiableInformation
.MAY use
to manage any Webhook configurations for the entire duration of a payment consent.MAY use a
to the/payments/{PaymentId}
resource to poll for Payment Statuses.
The OFP:
MUST reject the Service Initiation consent if a globally unique UUID v4
does not exist in the RAR object.MUST validate the Consent parameters and create a Consent resource (
) that isAwaitingAuthorization
when a valid RAR object is staged at the PAR endpoint.MUST immediately stage the payment with the LFI once a valid Service Initiation resource is created by the TPP.
MUST send payment status events to the TPP if an active Webhook Subscription is registered within the Consent object.
The LFI:
MUST immediately stage the payment with the Payment Rails once a valid payment is staged by the OFP.
MUST emit payment status events to the OFP.
6.2 Service Initiation Consent Parameters
6.2.1 Single Payment Consent Parameters Single Instant Payment
A Single Instant Payment MUST meet the following criteria:
MUST be set toSingleInstantPayment
The Consent Start date is the
. The Consent end date (ExpirationDateTime
) MUST be set to the current date. Single Future Dated Payment
A Single Future Dated Payment MUST meet the following criteria:
MUST be set toSingleFutureDatedPayment
The Consent Start date is the
. The Consent end date (ExpirationDateTime
) MUST NOT exceed 1 year from the current date.RequestedExecutionDate
MUST NOT be set to the current day. It MUST be set to a future date/time beyond the current day when the payment is to be scheduled for execution.
6.2.2 Multi-Payment Consent Parameters
These consent parameters are defined to control the limits for a long lived Multi-Payment consent:
MUST be set to confirm the total payment amount for the whole consent duration.MaximumCumulativeNumberOfPayments
MUST be set to confirm the total number of payments for the whole consent duration.PeriodicSchedule
MAY further define any period specific maximum payment numbers and/or amounts, and is one of these Types:FixedDefinedSchedule
- a Payment Schedule denoting a list of pre-defined future dated payments each with a fixed amount and date.VariableDefinedSchedule
- a Payment Schedule denoting a list of pre-defined future dated payments each with a fixed date and maximum amount.FixedPeriodicSchedule
- The payments for this consent have a fixed amount and must be executed only on the PeriodStartDate, and dates recurring based on the PeriodType.VariablePeriodicSchedule
- The payments for this consent have a variable amount and must be executed only on the PeriodStartDate, and dates recurring based on the PeriodType.FixedOnDemand
- The payments for this consent have a fixed amount and may be executed on any date, as long as they are within the Controls for a PeriodType.VariableOnDemand
- The payments for this consent have a variable amount and may be executed on any date, as long as they are within the Controls for a PeriodType.
6.2.3 Combined Payment Consent Parameters
A Combined Service Initiation MUST be:
Any one Type of Single Payment
Any one Type of Multi-Payment
6.2.4 File Payment Consent Parameters
A File Payment consent MUST contain these metadata fields of the file being uploaded:
MUST be set to the file payment type that is accepted by the LFI.FileHash
MUST be set to the base64 encoding of a SHA256 hash of the file to be uploaded.NumberOfTransactions
MUST be set to the number of payments contained in the file.ControlSum
MUST be set to the total of all individual amounts included in the file, irrespective of currencies.
6.3 OFP Service Initiation Responsibilities
MUST associate all TPP requests (including retries) with an
MUST reject all requests where an
is not provided by the TPP for the/payments
resourceOn receiving the RAR request from the TPP, MUST proceed to:
Create a Service Initiation Consents resource (
).Set Consent Status to
where multiple authorizations are required to authorize the Service Initiation
On a User Authorizing the Service Initiation, MUST set the following Consent Status to confirm Service Initiation details:
Set Consent Status to
On Payment rails completion, MUST set the following status based on the Payment rails outcome:
to eitherPending
When all Service Initiations have been successfully completed in a consent, the OFP MUST set the Service Initiation Consent Status to
MUST set the
object across both the Payment resource and Consent resource enabling the TPP to locate those resourcesMUST validate that a Payment is within any of the Consent Control parameter limits authorized by the User.
MUST send payment status Events to the TPP where a Webhook subscription has been received in the Payment request
MAY return an HTTP
header for the201
Status code indicating the URI of the primary resource that has been created (rfc9110)MUST use
to provide the TPP with up-to-date cumulative number and value totals of Payments (initiated under the consent schedule, excluding instructions in a Rejected state) associated with theAuthorized
7. Security
A payments
scope (with the ConsentId
) is used for POST /payments
© CBUAE 2025
Open License and Contribution Agreement | Attribution Notice