Allica Bank Account and Transaction Information API

Allica Bank's UK Open Banking Account Information Service (AIS) API, conformant to the OBIE Read/Write Standard v3.1, exposing account access consents, accounts, balances, transactions, beneficiaries, direct debits, standing orders, scheduled payments, parties, offers, and product data for Allica Business Rewards accounts. FAPI-secured (OAuth2/OIDC, mTLS, PSD2 SCA); requires OBIE Directory onboarding and eIDAS/OB certificates.

OpenAPI Specification

allica-bank-account-information-openapi.yaml Raw ↑
openapi: 3.0.0
info:
  title: Account and Transaction API Specification
  description: |
    # AISP API Overview

    These APIs can be used to access account information for Allica Business Rewards accounts.

    ## Base URL
    The base URL for all AIS APIs is: `https://rs1.api.ob.allica.bank/open-banking/v4.0/aisp/**`

    ## Account Access Consents
    [Account Access Consents API](/perry/developer/documentation?resource=ukhub-allica-portal&document=swagger/account-info-openapi.yaml#operations-tag-Account_Access)

    ## Accounts
    [Accounts API](/perry/developer/documentation?resource=ukhub-allica-portal&document=swagger/account-info-openapi.yaml#operations-tag-Accounts)

    Accounts API supports only Business Rewards Account and Savings Pot.

    ## Balances
    [Balances API](/perry/developer/documentation?resource=ukhub-allica-portal&document=swagger/account-info-openapi.yaml#operations-tag-Balances)

    Balances shown in this endpoint provide the `InterimAvailable` value.

    `InterimAvailable` balance is the value displayed most widely to our customers within the Allica apps.

    ## Transactions
    [Transactions API](/perry/developer/documentation?resource=ukhub-allica-portal&document=swagger/account-info-openapi.yaml#operations-tag-Transactions)

    Pagination is supported on GET /accounts/{AccountId}/transactions end point with a page size of 100 transactions.

    > Please note GET /transactions end point is not supported

    ## Beneficiaries
    [Beneficiaries API](/perry/developer/documentation?resource=ukhub-allica-portal&document=swagger/account-info-openapi.yaml#operations-tag-Beneficiaries)

    Payment recipients are accessible via the Beneficiaries API. This API is useful when setting up payments.

    ## Direct Debits
    [Direct Debits API](/perry/developer/documentation?resource=ukhub-allica-portal&document=swagger/account-info-openapi.yaml#operations-tag-Direct_Debits)

    Only GET /accounts/{accountId}/direct-debits is supported.

    ## Standing Orders
    [Standing Orders API](/perry/developer/documentation?resource=ukhub-allica-portal&document=swagger/account-info-openapi.yaml#operations-tag-Standing_Orders)

    Only GET /acccounts/{accountId}/standing-orders are supported

    
    ## Offers
    [Offers API](/perry/developer/documentation?resource=ukhub-allica-portal&document=swagger/account-info-openapi.yaml#operations-tag-Offers)

    Not currently supported.

    ## Parties
    [Parties API](/perry/developer/documentation?resource=ukhub-allica-portal&document=swagger/account-info-openapi.yaml#operations-tag-Parties)

    Not currently supported.

    ## Scheduled Payments
    [Scheduled Payments API](/perry/developer/documentation?resource=ukhub-allica-portal&document=swagger/account-info-openapi.yaml#operations-tag-Scheduled_Payments)

    Only GET /accounts/{accountId}/scheduled-payments is supported.

    
  termsOfService: https://www.openbanking.org.uk/terms
  contact:
    name: Service Desk
    email: ServiceDesk@openbanking.org.uk
  license:
    name: open-licence
    url: https://www.openbanking.org.uk/open-licence
  version: 3.1.10
paths:
  /account-access-consents:
    post:
      tags:
        - Account Access
      summary: Create Account Access Consents
      operationId: CreateAccountAccessConsents
      parameters:
        - in: header
          name: x-fapi-auth-date
          required: false
          description: |-
            The time when the PSU last logged in with the TPP.
            All dates in the HTTP headers are represented as RFC 7231 Full Dates. An example is below:
            Sun, 10 Sep 2017 19:43:31 UTC
          schema:
            type: string
            pattern: ^(Mon|Tue|Wed|Thu|Fri|Sat|Sun), \d{2} (Jan|Feb|Mar|Apr|May|Jun|Jul|Aug|Sep|Oct|Nov|Dec) \d{4} \d{2}:\d{2}:\d{2} (GMT|UTC)$
        - in: header
          name: x-fapi-customer-ip-address
          required: false
          description: The PSU's IP address if the PSU is currently logged in with the TPP.
          schema:
            type: string
        - in: header
          name: x-fapi-interaction-id
          required: false
          description: An RFC4122 UID used as a correlation id.
          schema:
            type: string
        - in: header
          name: Authorization
          required: true
          description: An Authorisation Token as per https://tools.ietf.org/html/rfc6750
          schema:
            type: string
        - in: header
          name: x-customer-user-agent
          description: Indicates the user-agent that the PSU is using.
          required: false
          schema:
            type: string
      requestBody:
        content:
          application/json; charset=utf-8:
            schema:
              type: object
              required:
                - Data
                - Risk
              properties:
                Data:
                  type: object
                  required:
                    - Permissions
                  properties:
                    Permissions:
                      type: array
                      items:
                        description: Specifies the Open Banking account access data types. This is a list of the data clusters being consented by the PSU, and requested for authorisation with the ASPSP.
                        type: string
                        enum:
                          - ReadAccountsBasic
                          - ReadAccountsDetail
                          - ReadBalances
                          - ReadBeneficiariesBasic
                          - ReadBeneficiariesDetail
                          - ReadDirectDebits
                          - ReadOffers
                          - ReadPAN
                          - ReadParty
                          - ReadPartyPSU
                          - ReadProducts
                          - ReadScheduledPaymentsBasic
                          - ReadScheduledPaymentsDetail
                          - ReadStandingOrdersBasic
                          - ReadStandingOrdersDetail
                          - ReadStatementsBasic
                          - ReadStatementsDetail
                          - ReadTransactionsBasic
                          - ReadTransactionsCredits
                          - ReadTransactionsDebits
                          - ReadTransactionsDetail
                      minItems: 1
                    ExpirationDateTime:
                      description: |-
                        Specified date and time the permissions will expire.
                        If this is not populated, the permissions will be open ended.All dates in the JSON payloads are represented in ISO 8601 date-time format.
                        All date-time fields in responses must include the timezone. An example is below:
                        2017-04-05T10:43:07+00:00
                      type: string
                      format: date-time
                    TransactionFromDateTime:
                      description: |-
                        Specified start date and time for the transaction query period.
                        If this is not populated, the start date will be open ended, and data will be returned from the earliest available transaction.All dates in the JSON payloads are represented in ISO 8601 date-time format.
                        All date-time fields in responses must include the timezone. An example is below:
                        2017-04-05T10:43:07+00:00
                      type: string
                      format: date-time
                    TransactionToDateTime:
                      description: |-
                        Specified end date and time for the transaction query period.
                        If this is not populated, the end date will be open ended, and data will be returned to the latest available transaction.All dates in the JSON payloads are represented in ISO 8601 date-time format.
                        All date-time fields in responses must include the timezone. An example is below:
                        2017-04-05T10:43:07+00:00
                      type: string
                      format: date-time
                Risk:
                  description: The Risk section is sent by the initiating party to the ASPSP. It is used to specify additional details for risk scoring for Account Info.
                  type: object
                  properties: {}
                  additionalProperties: false
              additionalProperties: false
          application/json:
            schema:
              type: object
              required:
                - Data
                - Risk
              properties:
                Data:
                  type: object
                  required:
                    - Permissions
                  properties:
                    Permissions:
                      type: array
                      items:
                        description: Specifies the Open Banking account access data types. This is a list of the data clusters being consented by the PSU, and requested for authorisation with the ASPSP.
                        type: string
                        enum:
                          - ReadAccountsBasic
                          - ReadAccountsDetail
                          - ReadBalances
                          - ReadBeneficiariesBasic
                          - ReadBeneficiariesDetail
                          - ReadDirectDebits
                          - ReadOffers
                          - ReadPAN
                          - ReadParty
                          - ReadPartyPSU
                          - ReadProducts
                          - ReadScheduledPaymentsBasic
                          - ReadScheduledPaymentsDetail
                          - ReadStandingOrdersBasic
                          - ReadStandingOrdersDetail
                          - ReadStatementsBasic
                          - ReadStatementsDetail
                          - ReadTransactionsBasic
                          - ReadTransactionsCredits
                          - ReadTransactionsDebits
                          - ReadTransactionsDetail
                      minItems: 1
                    ExpirationDateTime:
                      description: |-
                        Specified date and time the permissions will expire.
                        If this is not populated, the permissions will be open ended.All dates in the JSON payloads are represented in ISO 8601 date-time format.
                        All date-time fields in responses must include the timezone. An example is below:
                        2017-04-05T10:43:07+00:00
                      type: string
                      format: date-time
                    TransactionFromDateTime:
                      description: |-
                        Specified start date and time for the transaction query period.
                        If this is not populated, the start date will be open ended, and data will be returned from the earliest available transaction.All dates in the JSON payloads are represented in ISO 8601 date-time format.
                        All date-time fields in responses must include the timezone. An example is below:
                        2017-04-05T10:43:07+00:00
                      type: string
                      format: date-time
                    TransactionToDateTime:
                      description: |-
                        Specified end date and time for the transaction query period.
                        If this is not populated, the end date will be open ended, and data will be returned to the latest available transaction.All dates in the JSON payloads are represented in ISO 8601 date-time format.
                        All date-time fields in responses must include the timezone. An example is below:
                        2017-04-05T10:43:07+00:00
                      type: string
                      format: date-time
                Risk:
                  description: The Risk section is sent by the initiating party to the ASPSP. It is used to specify additional details for risk scoring for Account Info.
                  type: object
                  properties: {}
                  additionalProperties: false
              additionalProperties: false
          application/jose+jwe:
            schema:
              type: object
              required:
                - Data
                - Risk
              properties:
                Data:
                  type: object
                  required:
                    - Permissions
                  properties:
                    Permissions:
                      type: array
                      items:
                        description: Specifies the Open Banking account access data types. This is a list of the data clusters being consented by the PSU, and requested for authorisation with the ASPSP.
                        type: string
                        enum:
                          - ReadAccountsBasic
                          - ReadAccountsDetail
                          - ReadBalances
                          - ReadBeneficiariesBasic
                          - ReadBeneficiariesDetail
                          - ReadDirectDebits
                          - ReadOffers
                          - ReadPAN
                          - ReadParty
                          - ReadPartyPSU
                          - ReadProducts
                          - ReadScheduledPaymentsBasic
                          - ReadScheduledPaymentsDetail
                          - ReadStandingOrdersBasic
                          - ReadStandingOrdersDetail
                          - ReadStatementsBasic
                          - ReadStatementsDetail
                          - ReadTransactionsBasic
                          - ReadTransactionsCredits
                          - ReadTransactionsDebits
                          - ReadTransactionsDetail
                      minItems: 1
                    ExpirationDateTime:
                      description: |-
                        Specified date and time the permissions will expire.
                        If this is not populated, the permissions will be open ended.All dates in the JSON payloads are represented in ISO 8601 date-time format.
                        All date-time fields in responses must include the timezone. An example is below:
                        2017-04-05T10:43:07+00:00
                      type: string
                      format: date-time
                    TransactionFromDateTime:
                      description: |-
                        Specified start date and time for the transaction query period.
                        If this is not populated, the start date will be open ended, and data will be returned from the earliest available transaction.All dates in the JSON payloads are represented in ISO 8601 date-time format.
                        All date-time fields in responses must include the timezone. An example is below:
                        2017-04-05T10:43:07+00:00
                      type: string
                      format: date-time
                    TransactionToDateTime:
                      description: |-
                        Specified end date and time for the transaction query period.
                        If this is not populated, the end date will be open ended, and data will be returned to the latest available transaction.All dates in the JSON payloads are represented in ISO 8601 date-time format.
                        All date-time fields in responses must include the timezone. An example is below:
                        2017-04-05T10:43:07+00:00
                      type: string
                      format: date-time
                Risk:
                  description: The Risk section is sent by the initiating party to the ASPSP. It is used to specify additional details for risk scoring for Account Info.
                  type: object
                  properties: {}
                  additionalProperties: false
              additionalProperties: false
        description: Default
        required: true
      responses:
        '201':
          description: Account Access Consents Created
          headers:
            x-fapi-interaction-id:
              description: An RFC4122 UID used as a correlation id.
              required: true
              schema:
                type: string
          content:
            application/json; charset=utf-8:
              schema:
                type: object
                required:
                  - Data
                  - Risk
                properties:
                  Data:
                    type: object
                    required:
                      - ConsentId
                      - CreationDateTime
                      - Status
                      - StatusUpdateDateTime
                      - Permissions
                    properties:
                      ConsentId:
                        description: Unique identification as assigned to identify the account access consent resource.
                        type: string
                        minLength: 1
                        maxLength: 128
                      CreationDateTime:
                        description: |-
                          Date and time at which the resource was created.All dates in the JSON payloads are represented in ISO 8601 date-time format.
                          All date-time fields in responses must include the timezone. An example is below:
                          2017-04-05T10:43:07+00:00
                        type: string
                        format: date-time
                      Status:
                        description: Specifies the status of consent resource in code form.
                        type: string
                        enum:
                          - Authorised
                          - AwaitingAuthorisation
                          - Rejected
                          - Revoked
                      StatusUpdateDateTime:
                        description: |-
                          Date and time at which the resource status was updated.All dates in the JSON payloads are represented in ISO 8601 date-time format.
                          All date-time fields in responses must include the timezone. An example is below:
                          2017-04-05T10:43:07+00:00
                        type: string
                        format: date-time
                      Permissions:
                        type: array
                        items:
                          description: Specifies the Open Banking account access data types. This is a list of the data clusters being consented by the PSU, and requested for authorisation with the ASPSP.
                          type: string
                          enum:
                            - ReadAccountsBasic
                            - ReadAccountsDetail
                            - ReadBalances
                            - ReadBeneficiariesBasic
                            - ReadBeneficiariesDetail
                            - ReadDirectDebits
                            - ReadOffers
                            - ReadPAN
                            - ReadParty
                            - ReadPartyPSU
                            - ReadProducts
                            - ReadScheduledPaymentsBasic
                            - ReadScheduledPaymentsDetail
                            - ReadStandingOrdersBasic
                            - ReadStandingOrdersDetail
                            - ReadStatementsBasic
                            - ReadStatementsDetail
                            - ReadTransactionsBasic
                            - ReadTransactionsCredits
                            - ReadTransactionsDebits
                            - ReadTransactionsDetail
                        minItems: 1
                      ExpirationDateTime:
                        description: |-
                          Specified date and time the permissions will expire.
                          If this is not populated, the permissions will be open ended.All dates in the JSON payloads are represented in ISO 8601 date-time format.
                          All date-time fields in responses must include the timezone. An example is below:
                          2017-04-05T10:43:07+00:00
                        type: string
                        format: date-time
                      TransactionFromDateTime:
                        description: |-
                          Specified start date and time for the transaction query period.
                          If this is not populated, the start date will be open ended, and data will be returned from the earliest available transaction.All dates in the JSON payloads are represented in ISO 8601 date-time format.
                          All date-time fields in responses must include the timezone. An example is below:
                          2017-04-05T10:43:07+00:00
                        type: string
                        format: date-time
                      TransactionToDateTime:
                        description: |-
                          Specified end date and time for the transaction query period.
                          If this is not populated, the end date will be open ended, and data will be returned to the latest available transaction.All dates in the JSON payloads are represented in ISO 8601 date-time format.
                          All date-time fields in responses must include the timezone. An example is below:
                          2017-04-05T10:43:07+00:00
                        type: string
                        format: date-time
                  Risk:
                    description: The Risk section is sent by the initiating party to the ASPSP. It is used to specify additional details for risk scoring for Account Info.
                    type: object
                    properties: {}
                    additionalProperties: false
                  Links:
                    type: object
                    description: Links relevant to the payload
                    properties:
                      Self:
                        type: string
                        format: uri
                      First:
                        type: string
                        format: uri
                      Prev:
                        type: string
                        format: uri
                      Next:
                        type: string
                        format: uri
                      Last:
                        type: string
                        format: uri
                    additionalProperties: false
                    required:
                      - Self
                  Meta:
                    title: MetaData
                    type: object
                    description: Meta Data relevant to the payload
                    properties:
                      TotalPages:
                        type: integer
                        format: int32
                      FirstAvailableDateTime:
                        description: |-
                          All dates in the JSON payloads are represented in ISO 8601 date-time format.
                          All date-time fields in responses must include the timezone. An example is below:
                          2017-04-05T10:43:07+00:00
                        type: string
                        format: date-time
                      LastAvailableDateTime:
                        description: |-
                          All dates in the JSON payloads are represented in ISO 8601 date-time format.
                          All date-time fields in responses must include the timezone. An example is below:
                          2017-04-05T10:43:07+00:00
                        type: string
                        format: date-time
                    additionalProperties: false
                additionalProperties: false
            application/json:
              schema:
                type: object
                required:
                  - Data
                  - Risk
                properties:
                  Data:
                    type: object
                    required:
                      - ConsentId
                      - CreationDateTime
                      - Status
                      - StatusUpdateDateTime
                      - Permissions
                    properties:
                      ConsentId:
                        description: Unique identification as assigned to identify the account access consent resource.
                        type: string
                        minLength: 1
                        maxLength: 128
                      CreationDateTime:
                        description: |-
                          Date and time at which the resource was created.All dates in the JSON payloads are represented in ISO 8601 date-time format.
                          All date-time fields in responses must include the timezone. An example is below:
                          2017-04-05T10:43:07+00:00
                        type: string
                        format: date-time
                      Status:
                        description: Specifies the status of consent resource in code form.
                        type: string
                        enum:
                          - Authorised
                          - AwaitingAuthorisation
                          - Rejected
                          - Revoked
                      StatusUpdateDateTime:
                        description: |-
                          Date and time at which the resource status was updated.All dates in the JSON payloads are represented in ISO 8601 date-time format.
                          All date-time fields in responses must include the timezone. An example is below:
                          2017-04-05T10:43:07+00:00
                        type: string
                        format: date-time
                      Permissions:
                        type: array
                        items:
                          description: Specifies the Open Banking account access data types. This is a list of the data clusters being consented by the PSU, and requested for authorisation with the ASPSP.
                          type: string
                          enum:
                            - ReadAccountsBasic
                            - ReadAccountsDetail
                            - ReadBalances
                            - ReadBeneficiariesBasic
                            - ReadBeneficiariesDetail
                            - ReadDirectDebits
                            - ReadOffers
                            - ReadPAN
                            - ReadParty
                            - ReadPartyPSU
                            - ReadProducts
                            - ReadScheduledPaymentsBasic
                            - ReadScheduledPaymentsDetail
                            - ReadStandingOrdersBasic
                            - ReadStandingOrdersDetail
                            - ReadStatementsBasic
                            - ReadStatementsDetail
                            - ReadTransactionsBasic
                            - ReadTransactionsCredits
                            - ReadTransactionsDebits
                            - ReadTransactionsDetail
                        minItems: 1
                      ExpirationDateTime:
                        description: |-
                          Specified date and time the permissions will expire.
                          If this is not populated, the permissions will be open ended.All dates in the JSON payloads are represented in ISO 8601 date-time format.
                          All date-time fields in responses must include the timezone. An example is below:
                          2017-04-05T10:43:07+00:00
                        type: string
                        format: date-time
                      TransactionFromDateTime:
                        description: |-
                          Specified start date and time for the transaction query period.
                          If this is not populated, the start date will be open ended, and data will be returned from the earliest available transaction.All dates in the JSON payloads are represented in ISO 8601 date-time format.
                          All date-time fields in responses must include the timezone. An example is below:
                          2017-04-05T10:43:07+00:00
                        type: string
                        format: date-time
                      TransactionToDateTime:
                        description: |-
                          Specified end date and time for the transaction query period.
                          If this is not populated, the end date will be open ended, and data will be returned to the latest available transaction.All dates in the JSON payloads are represented in ISO 8601 date-time format.
                          All date-time fields in responses must include the timezone. An example is below:
                          2017-04-05T10:43:07+00:00
                        type: string
                        format: date-time
                  Risk:
                    description: The Risk section is sent by the initiating party to the ASPSP. It is used to specify additional details for risk scoring for Account Info.
                    type: object
                    properties: {}
                    additionalProperties: false
                  Links:
                    type: object
                    description: Links relevant to the payload
                    properties:
                      Self:
                        type: string
                        format: uri
                      First:
                        type: string
                        format: uri
                      Prev:
                        type: string
                        format: uri
                      Next:
                        type: string
                        format: uri
                      Last:
                        type: string
                        format: uri
                    additionalProperties: false
                    required:
                      - Self
                  Meta:
                    title: MetaData
                    type: object
                    description: Meta Data relevant to the payload
                    properties:
                      TotalPages:
                        type: integer
                        format: int32
                      FirstAvailableDateTime:
                        description: |-
                          All dates in the JSON payloads are represented in ISO 8601 date-time format.
                          All date-time fields in responses must include the timezone. An example is below:
                          2017-04-05T10:43:07+00:00
                        type: string
                        format: date-time
                      LastAvailableDateTime:
                        description: |-
                          All dates in the JSON payloads are represented in ISO 8601 date-time format.
                          All date-time fields in responses must include the timezone. An example is below:
                          2017-04-05T10:43:07+00:00
                        type: string
                        format: date-time
                    additionalProperties: false
                additionalProperties: false
            application/jose+jwe:
              schema:
                type: object
                required:
                  - Data
                  - Risk
                properties:
                  Data:
                    type: object
                    required:
                      - ConsentId
                      - CreationDateTime
                      - Status
                      - StatusUpdateDateTime
                      - Permissions
                    properties:
                      ConsentId:
                        description: Unique identification as assigned to identify the account access consent resource.
                        type: string
                        minLength: 1
                        maxLength: 12

# --- truncated at 32 KB (7655 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/allica-bank/refs/heads/main/openapi/allica-bank-account-information-openapi.yaml