PSD2 Overview
The revised Payment Services Directive (PSD2) opens bank account data and payment initiation to licensed Third Party Providers (TPPs), with the account holder’s explicit consent. The Arkéa Open Banking API implements this model.
Roles
- ASPSP — Account Servicing Payment Service Provider. That’s Arkéa.
- AISP — Account Information Service Provider. Reads accounts and balances.
- PISP — Payment Initiation Service Provider. Initiates transfers.
Consent lifecycle
Every access to account data is authorized by a consent the account holder grants. Consents move through a well-defined set of states:
Create a consent via the Consents endpoint, then reference its id
in the consentId header on account requests.
Recovering from an expired or revoked consent
expired and revokedByPsu are terminal: neither state can be reactivated, and requests
that pass the consent in the consentId header are rejected. Access is only restored by
obtaining a new consent — create one with the Consents
endpoint, send the account holder through authorization again, then use the new consent id.
Set recurringIndicator to true if your integration needs repeated access, and pick a
validUntil date that covers the period you need.