Regulatory APIs
Find comprehensive answers to your queries about our APIs. Covering a range of topics from general questions to specific issues like certificates and on-boarding.
General Questions
How much does it cost to access the APIs?
Are there any API rate limits?
Are your APIs working in every country in the world or are they working only in specific
countries?
How does a TPP obtain access to the APIs in the Sandbox?
Is it necessary to create a client in the Sandbox environment first to be able to create a
client for the production APIs?
Do your APIs serve customer and business accounts?
What are the payment amount limits that Danske Bank currently has in place in production?
How and where do I turn to if I would like to file a complaint?
Certificates and On-boarding
What is a certificate (in terms of PSD2 and OB scope)?
Where does a TPP obtain a certificate?
Does your bank require an eIDAS certificate to include the full certificate chain (up to and
including Intuit's QTSP's (Multicert) root certification authority)?
Any references for hosting JWKS?
How to renew expiring certificates?
Is it possible for one TPP to have multiple certificates (QWAC, QSEAL) with the same
registration simultaneously?
If we register a new certificate, can we expect all the consents obtained with the old
certificate to expire?
For AIS endpoints, can we expect that the account-id assigned to each PSU will change once they
re-consent under new certificates?
Is it needed to communicate changes to your institution once the certificates are renewed?
How can a TPP update its existing registration with Danske Bank client Id?
How does re-registration to Danske Bank work?
Is it possible for a TPP to have 2 different registrations using the same set of certificates?
E.g. 2 sets of client credentials, one per application, but both using the same set of
certificates.
Is it possible for each application or set of client credentials to have different redirect URLs?
Consent
Can the lifetime of a consent be changed by the PSU during the SCA flow? Is the PSU able to change the scope (e.g., accounts, balances, transactions) of a consent during the SCA flow / after the SCA flow?
Is it possible for the PSU to revoke a consent via their online banking portal?
Is it possible for a TPP to revoke a consent via your API?
What happens if the user cancels consent or does not sign the payments? Will they be visible in
online banking?
What happens if payments in the request to create a consent and to create a basket do not match?
Is there a reason why payments cannot be approved after signing the consent instead of having to make another call?
Authentication and Authorization
What is the SCA validity window?
What are the Article 10 SCA rules?
Do you support other means of authorization besides redirect SCA approach?
Do you support decoupled flow?
Do you support NOK redirect uri? E.g., to redirect user in case of failed authorization.
How are the different tokens being used in the Danske Bank Open Banking flow?
Accounts and Transactions
What account types are currently accessible in Open Banking – United Kingdom?
What account types are supported through the PSD2 APIs (e.g., personal, business, corporate,
etc)?
Can the PSU individually per account decide if they wish to share that account or not? Or are
you applying an "all or nothing" approach?
Is there a rate limitation for AIS calls? E.g., is there a number of calls without PSU being
present before an error response?
Can I get transactions for a detailed account in a Zero Balancing cash pool?
Can I get balances for detailed accounts in a Zero Balancing cash pool?
What are the restrictions (maximum number of transactions in response and oldest transactions)
for transactions fetching?
How far back can we request transaction history?
Why are all transactions being returned with 'transactionMutability' set to 'MUTABLE' even for
transactions showing as being booked several days before?
If a transaction Id is provided by your API, is the provided Id consistent within a session
(access token), a consent or forever? Our clients would like to understand how reliable the Ids
are and if they might change over time.
When is EndToEndId populated in statements?
Payment Initiation Service
Do you share the status of a payment made through PSD2?
How does the status change when calling the GET payment status endpoint?
What exactly does "AcceptedSettlementCompleted" mean?
What are the possible statuses for scheduled payments?
What currencies are allowed for InstructedAmount?
How do you handle legacy values from v3 in Risk/PaymentContextCode?
Can the PSU cancel scheduled payments in District/eBanking or are they guaranteed to go out on
the day they are scheduled?
What payment types are currently accessible in Open Banking – United Kingdom?
What payment types are currently accessible in Open Banking – PSD2?
Can bulk payments be executed via the File Payment endpoints?
Is cancellation of payments supported?
Is there, after initiation of a payment, a possibility for the user to cancel a bank transfer,
via online banking interface or another channel like calling the bank?
Do you support SEPA Instant Credit Transfer in Finland?
What is the maximum number of payments in the file payment function?
Does your PIS API support confirmation of funds?
Is multi-authorization supported through Open Banking APIs?
What is a Payments Basket?
Where could the cut-off times for business customers be found?
Where can I find information on Payment Initiation details and changes to Domestic Standing Order Frequencies?
Sandbox
Can TPPs customise the test data?
Do endpoints with the business channel work in Sandbox?