/ics/v3/payments/{paymentProduct}/{paymentId}/authorize

Gets the authorization URL for the specified paymentId after initiating a payment when SCA is required. Note that x-psu-ip-address is required for Swedish Banks and Handelsbanken Finland.

Response Structure:

  • For single payments: The response includes paymentIds array in the meta object
  • For batch payments (paymentProduct = 'batch-transfer'): The response includes batchPayments array in the meta object with paymentId to referenceId mapping

Note for Batch Payments: When paymentProduct is 'batch-transfer', the paymentId parameter should be the batchId returned from the batch payment initiation.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Path Params
string
required

The payment ID returned when the payment was initiated. For batch payments (when paymentProduct is 'batch-transfer'),
this should be the batchId returned from the batch payment initiation.

string
required

Specific method used for a payment, which is one of the following values: 'sepa-credit', 'domestic-transfer', 'domestic-scheduled-transfer', 'sepa-scheduled-credit', 'batch-transfer'.

Headers
string
required

The session Id returned in the response body when this session was created.

string
required

String that uniquely identifies a single end-user or device.

string
required

The IP Address of the end-user (PSU), which must be provided if the PSU actively requests information.
If this value is not provided, then the call will count towards the number of TPP calls without PSU interaction.
Leave it empty if the end user is not actively requesting account information, such as during automatic background updates.
Provided in either IPv4 or IPv6 format.

string

Identifier of the end-user, passed as the base64-encoded value of an encrypted string following
the guidelines given in Documentation > Development > Sensitive end-user data.
This parameter is required if the value of 'personalIdentificationRequired' returned from the /banks endpoint is "true".

string

Corporate identifier of the end-user's organisation, used for business/corporate consents (the business-accounts scope).

Currently effective for Länsförsäkringar and Sparebanken Vest (Folio, bank folio.noSPAVNOBB).

  • Länsförsäkringar: required in addition to x-psu-id, and both are distinct. x-psu-id carries the
    signing person's personnummer (SSN), type SSSN; x-psu-corporate-id carries the organisationsnummer
    (org number), type SON. Confirmed with the bank: both values must be exactly 12 numeric digits — a
    continuous digit string with no hyphens, spaces, letters, or special characters (e.g. 12345678-0987 is
    not valid). Fewer or more than 12 digits fails validation.
  • Sparebanken Vest / Folio: required on both consent initiation and every subsequent account/transaction
    read, not only at consent time. Carries the 9-digit Norwegian organisation number. x-psu-id is optional
    here and, if sent, must be the authorising person's national identifier — never the organisation number.

For all other banks this header is currently ignored, even those whose corporate flows rely on a corporate
identifier (e.g. DNB) — those flows continue to work via x-psu-id as today. Do not rely on this header for any
bank other than the ones listed above; support for additional banks may be added later.

Ignored for personal-scope consents.

string

The host where the request is originating from.
If you are using end to end encryption from our developer portal then this header is mandatory.

string

The request originating date.
If you are using end to end encryption from our developer portal then this header is mandatory.

string

The signature header consisting of the signature string
If you are using end to end encryption from our developer portal then this header is mandatory.

Responses

Language
Credentials
Bearer
JWT
URL
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json