Skip to navigation

Authentication

OAuth 2.0 with PSD2-compliant strong customer authentication.
View as Markdown

All Arkéa Open Banking endpoints are protected with OAuth 2.0 bearer tokens issued through the PSD2 authorization flow.

Overview

  1. Register your application to obtain a client_id and client_secret.
  2. Redirect the account holder to the Arkéa authorization endpoint to grant consent.
  3. Exchange the authorization code for an access token.
  4. Call the API with the token in the Authorization header.
curl https://sandbox.api.getarkea.com/v1/accounts \
-H "Authorization: Bearer <ACCESS_TOKEN>" \
-H "consentId: <CONSENT_ID>"

Access tokens are short-lived. Use the refresh token from the token exchange to obtain a new access token without re-prompting the account holder, as long as the underlying PSD2 consent remains valid.

Sandbox vs. production

EnvironmentBase URL
Sandboxhttps://sandbox.api.getarkea.com/v1
Productionhttps://api.getarkea.com/v1

Start in the sandbox — it accepts test credentials and returns deterministic mock data. Every example in these docs and in the partner guides calls the sandbox host; swap in the production host when you go live.