> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://arkea.ferndocs.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://arkea.ferndocs.com/_mcp/server.

# Authentication

All Arkéa Open Banking endpoints are protected with OAuth 2.0 bearer tokens issued
through the PSD2 authorization flow.

## Overview

1. Register your application to obtain a `client_id` and `client_secret`.
2. Redirect the account holder to the Arkéa authorization endpoint to grant consent.
3. Exchange the authorization code for an access token.
4. Call the API with the token in the `Authorization` header.

```bash
curl https://sandbox.api.getarkea.com/v1/accounts \
  -H "Authorization: Bearer <ACCESS_TOKEN>" \
  -H "consentId: <CONSENT_ID>"
```

> **Info**
>
> Access tokens are short-lived. Use the refresh token from the token exchange to
> obtain a new access token without re-prompting the account holder, as long as the
> underlying PSD2 consent remains valid.

## Sandbox vs. production

| Environment | Base URL                              |
| ----------- | ------------------------------------- |
| Sandbox     | `https://sandbox.api.getarkea.com/v1` |
| Production  | `https://api.getarkea.com/v1`         |

Start in the sandbox — it accepts test credentials and returns deterministic mock data.
Every example in these docs and in the partner guides calls the sandbox host; swap in the
production host when you go live.