Visit the Contact page to get in touch or view our frequently asked questions.
The Consents Service allows a regulated Third-Party Provider (TPP) to create and manage customer consent for the SMBC XS2A API service.
A successfully authorised consent provides a Consent ID. A valid, authorised Consent ID is required for protected account-information and payment operations. A payment-enabled consent does not itself authorise an individual payment.
API connectivity uses mutual TLS (mTLS) with the TPP's accepted Qualified Website Authentication Certificate (QWAC).
The service does not require a Developer Portal account, application registration, Dynamic Client Registration, client credentials, an API key or an OAuth2 access token.
SMBC uses a bank-offered consent model. The TPP does not nominate individual accounts or permissions in the consent request. By default, without any prior access-configuration step, the accounts and services available under the consent match the Payment Service User's existing SMBC permissions. A corporate customer may optionally configure restrictions for a specific TPP identity outside the XS2A API before the consent is used. These restrictions can reduce, but cannot extend, the access otherwise available to the PSU.
The Payment Service User (PSU) confirms the consent through Strong Customer Authentication (SCA).
After creating a consent, redirect the PSU to SMBC using the URL returned by the API. The PSU must complete SCA before the consent can be used.
Retrieve the consent and SCA status through the API rather than relying only on the PSU's return to the TPP application.
A valid, authorised Consent ID is required for protected payment operations. The consent permits access to the relevant payment service but does not approve an individual payment.
Payment authorisation and signing-basket authorisation require separate SCA journeys.
Use the institution-specific endpoint for the SMBC institution where the customer's account is held. No separate SMBC branch code is required.
A Consent ID remains associated with the TPP identity, PSU and SMBC institution endpoint under which it was created. It cannot be transferred or reused through another institution endpoint.
If a customer holds eligible accounts with more than one supported SMBC institution, create and authorise a separate consent through each applicable institution endpoint.
PSUs are corporate users of SMBC's online banking services. Their access through the XS2A API reflects the permissions assigned to them by their corporate administrator.
TPPs cannot create, manage or modify PSUs or their SMBC permissions through the API.
Visit the Contact page to get in touch or view our frequently asked questions.