Skip to main content
Logo
API Documentation Status page Submit a request
Sign in
  1. Bank Account Data
  2. Bank Account Data API
  3. Authentication

Authentication flow types

The purpose of PSD2 APIs is to securely access bank account data of end users through regulated APIs. Ideally using these regulated APIs should also imply that end user sensitive data is only ever input in the bank interface, and never with the Account Information Service Provider (GoCardless). However, this is not always possible and is dependent on what authentication flow the bank uses and their specific API implementation.

Banks generally provide 3 different authentication flows for PSD2 APIs:

  • Redirect - End User is redirected to the Bank's page to authorize their consent. This might also include initial authentication. 
  • Decoupled - End User uses a device to authorize their consent without being redirected to the Bank's page. In this case GoCardless checks if the End User has finished authorizing their consent.
  • Embedded - GoCardless asks the End User to receive a One-Time-Password (most commonly via SMS) and then enter it in GoCardless view.
Where technically possible, GoCardless opts for an authentication flow that asks the End User to authenticate fully within their bank, to ensure there is less risk of compromising sensitive data as well as a quicker authentication. In this scenario end users inputs their login details directly within their banks, and no third party (GoCardless or our customer) has access.

For certain banks though, GoCardless must ask and in rare cases also temporarily store the sensitive credentials (such as User ID or IBAN, or in some cases password) on our side, because this is how the specific bank API has been designed by the bank themselves. In almost all cases though, GoCardless is working as solely as an intermediary, where we pass over the respective data to the bank, and delete it right after. 

Affected Banks

In the following banks, GoCardless has to ask for the following sensitive data points from End User, in order to pass this information on to the banks that provide decoupled flow. This information is deleted from GoCardless immediately after.

  • Banks that require to request End User ID
  • Banks that require to request Password
  • Banks that require to request IBAN

Special Case 

DKB (Deutsche Kreditbank) in Germany is the only bank, where in addition to asking for the sensitive data, GoCardless also has to store it temporarily, until the access expires (for a maximum 90 days). To ensure information security of said data, the information is encrypted, transfered over https and certificates are in place. The sensitive data is thereafter deleted permanently after the access has expired (between 0-90 days).

Was this article helpful?
  • Promoted articles

    • Bank Account Data API Usage - how is your usage number calculated
    • EEA 180-day access
    • Bank Account Data API Rate Limits
    • How to recognise and handle end user authentication errors
    • Account Endpoint Errors and Suspended Accounts
  • Recently Added Articles

  • Top Articles

Bank Account Data Quickstart Guide

Simple and streamlined guide to start using our Bank Accoun Data API

Quickstart Guide

Demo page of our Bank Account Data API

See the product in action with few easy clicks

Bank Account Data Demo

Need Support?

Contact us

We're available Monday to Friday, 9am-5pm GMT

Quick links

Knowledge base

About GoCardless

Legal
Privacy
Security
Blog

Support

Contact support
Complaints
Contact sales

API Documentation

Developer documents

GoCardless Ltd, Sutton Yard, 65 Goswell Road, London, EC1V 7EN, United Kingdom


GoCardless Ltd (company registration number 07495895) is authorised by the Financial Conduct Authority under the Payment Services Regulations 2017, registration number 597190, for the provision of payment services.





https://docs.google.com/spreadsheets/d/1EZ5n7QDGaRIot5M86dwqd5UFSGEDTeTRzEq3D9uEDkM/edit?gid=976380583#gid=976380583
/hc/theming_assets/01JVYEMDH4NW2KMNM8HG9Y2GXA
Detailed bank coverage
A detailed list of the available institutions and specifications.
custom
https://gocardless.com/stories/bondora/
/hc/theming_assets/01JKWXK6T8QZWQQSYYJAD0X703
Our latest customer story
Learn about how companies are using our technology.
custom
https://developer.gocardless.com/bank-account-data/overview
/hc/theming_assets/01JVYEMQ0208DBSNG2GPZRZ36T
Developer Docs
All the documentation you need to integrate with our API.
Rate Limits, Access expired, Requisition