/ics/v3/accounts

Returns a list of all accounts available in the given session. The account Ids in the response body can be used for the other /accounts calls.
This API will return a 1426 error if consent is required. API consumption is allowed only 4 times maximum in a day as per compliance.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Query Params
string

Provide scope for your request, possible values - (accounts, business-accounts).
Use accounts (default) for retail accounts.
Use business-accounts for business and corporate accounts.

integer
≥ 1
Defaults to 259200
Headers
string
required

The session Id returned in the response body when this session was created.

string
required

String that uniquely identifies a single end-user or device.

string
required

The IP Address of the end-user (PSU), which must be provided if the PSU actively requests information.
If this value is not provided, then the call will count towards the number of TPP calls without PSU interaction.
Leave it empty if the end user is not actively requesting account information, such as during automatic background updates.
Provided in either IPv4 or IPv6 format.

string

Identifier of the end-user, passed as the base64-encoded value of an encrypted string following
the guidelines given in Documentation > Development > Sensitive end-user data.
This parameter is required if the value of 'personalIdentificationRequired' returned from the /banks endpoint is "true".

string

Corporate identifier of the end-user's organisation, used for business/corporate consents (the business-accounts scope).

Currently effective for Länsförsäkringar and Sparebanken Vest (Folio, bank folio.noSPAVNOBB).

  • Länsförsäkringar: required in addition to x-psu-id, and both are distinct. x-psu-id carries the
    signing person's personnummer (SSN), type SSSN; x-psu-corporate-id carries the organisationsnummer
    (org number), type SON. Confirmed with the bank: both values must be exactly 12 numeric digits — a
    continuous digit string with no hyphens, spaces, letters, or special characters (e.g. 12345678-0987 is
    not valid). Fewer or more than 12 digits fails validation.
  • Sparebanken Vest / Folio: required on both consent initiation and every subsequent account/transaction
    read, not only at consent time. Carries the 9-digit Norwegian organisation number. x-psu-id is optional
    here and, if sent, must be the authorising person's national identifier — never the organisation number.

For all other banks this header is currently ignored, even those whose corporate flows rely on a corporate
identifier (e.g. DNB) — those flows continue to work via x-psu-id as today. Do not rely on this header for any
bank other than the ones listed above; support for additional banks may be added later.

Ignored for personal-scope consents.

string

The host where the request is originating from.
If you are using end to end encryption from our developer portal then this header is mandatory.

string

The request originating date.
If you are using end to end encryption from our developer portal then this header is mandatory.

string

The signature header consisting of the signature string
If you are using end to end encryption from our developer portal then this header is mandatory.

Responses

Language
Credentials
Bearer
JWT
URL
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json