This service is a prerequisite to enable the third-party provider (TPP) to request access to accounts held at SMBC Group, on behalf of a payment service user (PSU). Additionally, this service allows the TPP to delete or query existing consents.
It is used by the TPP, as required, to obtain a consents resource prior to interacting with the Bank account information and payment services on behalf of the PSU; and subsequently every 90 days to create a replacement consents resource. It is also used by the TPP to query and delete previously created consents resources.
To use this service, the TPP will first:
Using this service, The TPP can then:
The TPP can then:
The POST /consent, GET /authorize, and POST /token requests all feature OAuth2 and PKCE parameters. See the Token Service Description for the mandatory parameters and see the PSU Token Tutorial for an example.
The maximum allowed time period for a Consent Resource (i.e. the maximum validUntil date) is 180 days in the future.