Authentication
OAuth 2.0 with PSD2-compliant strong customer authentication.
All Arkéa Open Banking endpoints are protected with OAuth 2.0 bearer tokens issued through the PSD2 authorization flow.
Overview
- Register your application to obtain a
client_idandclient_secret. - Redirect the account holder to the Arkéa authorization endpoint to grant consent.
- Exchange the authorization code for an access token.
- Call the API with the token in the
Authorizationheader.
Access tokens are short-lived. Use the refresh token from the token exchange to obtain a new access token without re-prompting the account holder, as long as the underlying PSD2 consent remains valid.
Sandbox vs. production
Start in the sandbox — it accepts test credentials and returns deterministic mock data. Every example in these docs and in the partner guides calls the sandbox host; swap in the production host when you go live.