Skip to navigation
Getting Started

PSD2 Overview

How the Second Payment Services Directive shapes the API.
View as Markdown

The revised Payment Services Directive (PSD2) opens bank account data and payment initiation to licensed Third Party Providers (TPPs), with the account holder’s explicit consent. The Arkéa Open Banking API implements this model.

Roles

  • ASPSP — Account Servicing Payment Service Provider. That’s Arkéa.
  • AISP — Account Information Service Provider. Reads accounts and balances.
  • PISP — Payment Initiation Service Provider. Initiates transfers.

Every access to account data is authorized by a consent the account holder grants. Consents move through a well-defined set of states:

StatusMeaning
receivedConsent created, awaiting authorization.
validAuthorized and active.
expiredPast its validUntil date.
revokedByPsuRevoked by the account holder.

Create a consent via the Consents endpoint, then reference its id in the consentId header on account requests.

expired and revokedByPsu are terminal: neither state can be reactivated, and requests that pass the consent in the consentId header are rejected. Access is only restored by obtaining a new consent — create one with the Consents endpoint, send the account holder through authorization again, then use the new consent id. Set recurringIndicator to true if your integration needs repeated access, and pick a validUntil date that covers the period you need.