> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://arkea.ferndocs.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://arkea.ferndocs.com/_mcp/server.

# PSD2 Overview

The revised Payment Services Directive (PSD2) opens bank account data and payment
initiation to licensed Third Party Providers (TPPs), with the account holder's explicit
consent. The Arkéa Open Banking API implements this model.

## Roles

* **ASPSP** — Account Servicing Payment Service Provider. That's Arkéa.
* **AISP** — Account Information Service Provider. Reads accounts and balances.
* **PISP** — Payment Initiation Service Provider. Initiates transfers.

## Consent lifecycle

Every access to account data is authorized by a **consent** the account holder grants.
Consents move through a well-defined set of states:

| Status         | Meaning                                  |
| -------------- | ---------------------------------------- |
| `received`     | Consent created, awaiting authorization. |
| `valid`        | Authorized and active.                   |
| `expired`      | Past its `validUntil` date.              |
| `revokedByPsu` | Revoked by the account holder.           |

> **Info**
>
> Create a consent via the [Consents](/open-banking/api-reference/consents/create-consent) endpoint, then reference its id
> in the `consentId` header on account requests.

### Recovering from an expired or revoked consent

`expired` and `revokedByPsu` are terminal: neither state can be reactivated, and requests
that pass the consent in the `consentId` header are rejected. Access is only restored by
obtaining a new consent — create one with the [Consents](/open-banking/api-reference/consents/create-consent)
endpoint, send the account holder through authorization again, then use the new consent id.
Set `recurringIndicator` to `true` if your integration needs repeated access, and pick a
`validUntil` date that covers the period you need.