Overview
The SMBC XS2A APIs enable authorised or registered Third Party Providers (TPPs) to access account information and initiate payments for eligible SMBC corporate customers, subject to customer consent and, where required, payment authorisation.
The APIs are based on the Berlin Group NextGenPSD2 1.3 framework. TPPs should use the Berlin Group Implementation Guidelines together with this documentation and the SMBC API Catalogue.
Where the Berlin Group framework provides multiple implementation options, this documentation and the API Catalogue identify the options supported by SMBC.
Use this documentation for SMBC-specific journeys and rules, the API Catalogue for operation-level definitions, and Sandbox Mock Data for published test values and outcomes.
The SMBC corporate customer model
The SMBC XS2A service supports eligible corporate customer accounts held with the supported SMBC institutions.
A corporate customer may have multiple online-banking users with different account access, payment permissions and payment authorisation responsibilities.
An administrator authorised by the corporate customer manages its users and the banking access assigned to them. The XS2A APIs do not create corporate users or grant banking permissions.
For the purposes of the XS2A service, an individual corporate user is a Payment Service User (PSU).
The account access available under an authorised consent is derived from the permissions assigned to the PSU by the corporate customer. It is also limited by the services that the TPP is authorised or registered to provide and the capabilities supported by the selected SMBC institution.
The PSU's existing permissions also determine whether the PSU may create or authorise payments.
The PSU is not asked to select individual accounts during consent Strong Customer Authentication (SCA). After the consent has been authorised, the TPP uses the Consents and Accounts APIs to determine the account access available under that consent.
A payment may require authorisation by more than one eligible PSU. See Payment Authorisation Rules and Payment Status Guide.
What the APIs support
The SMBC XS2A APIs provide the following principal capabilities:
Consents
Create, retrieve, check and terminate the customer consent required for supported account-information and payment-related journeys.
Account information
Retrieve eligible account details, balances and transaction reports for accounts available under an authorised consent.
Payments
Initiate supported payment products, retrieve payment details and status, start customer authorisation, and request cancellation where the