Griffin Open banking API

Open banking allows regulated third-party providers (TPPs) to access your customers' account data or initiate payments on their behalf. Griffin partners with [tell.money](https://tell.money/) to provide the TPP-facing open banking APIs. You handle the consent flow — authenticating your customer and registering the consent with Griffin — and Griffin handles the resource requests from TPPs. For a full walkthrough, see our [open banking integration guide](/docs/guides/open-banking-customer-accounts).

Operations 3

GET /v0/open-banking/tell-consents/{consent-id} Get Tell consent #
POST /v0/open-banking/tell-consents/{consent-id}/actions/revoke Revoke Tell consent #
POST /v0/organizations/{organization-id}/open-banking/tell-consents Register Tell consent #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/griffin-open-banking-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

griffin-open-banking-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Griffin Open banking API
  version: ''
  description: '## Introduction


    The Griffin API is based on REST.'
servers:
- url: https://api.griffin.com/
security:
- api-key-auth: []
tags:
- name: Open Banking
  description: 'Open banking allows regulated third-party providers (TPPs) to access your customers'' account data or initiate payments on their behalf.

    Griffin partners with tell.money to provide the TPP-facing open banking APIs.

    You handle the consent flow — authenticating your customer and registering the consent with Griffin — and Griffin handles the resource requests from TPPs.


    For a full walkthrough, see our open banking integration guide.'
paths:
  /v0/open-banking/tell-consents/{consent-id}:
    get:
      tags:
      - Open Banking
      description: Fetch a registered Tell consent.
      parameters:
      - in: path
        name: consent-id
        required: true
        schema:
          type: string
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                type: object
                properties:
                  tell-consent-expiry:
                    title: tell-consent-expiry
                    format: date-time
                    type: string
                    description: ISO 8601 formatted date-time.
                  tell-gateway-id:
                    type: string
                    format: uuid
                    title: tell-gateway-id
                  created-at:
                    title: created-at
                    format: date-time
                    type: string
                    description: ISO 8601 formatted date-time.
                  tell-consent-id:
                    type: string
                    format: uuid
                    title: tell-consent-id
                  tell-consent-scope:
                    type: string
                    title: tell-consent-scope
                    x-anyOf:
                    - type: string
                      enum:
                      - payments
                      - accounts
                    - type: string
                  tell-consent-consumed-at:
                    title: tell-consent-consumed-at
                    format: date-time
                    type: string
                    description: ISO 8601 formatted date-time.
                  tell-consent-url:
                    type: string
                    x-allOf:
                    - type: string
                    - {}
                    - type: object
                      properties:
                        consent-id:
                          type: string
                          format: uuid
                      required:
                      - consent-id
                    x-anyOf:
                    - type: string
                      x-allOf:
                      - type: string
                      - {}
                      - type: object
                        properties:
                          consent-id:
                            type: string
                            format: uuid
                        required:
                        - consent-id
                    - type: string
                      x-allOf:
                      - type: string
                      - {}
                      - type: object
                        properties:
                          consent-id:
                            type: string
                            format: uuid
                        required:
                        - consent-id
                    title: tell-consent-url
                    example: /v0/open-banking/tell-consents/00000000-0000-0000-0000-000000000000
                  tell-consent-status:
                    type: string
                    title: tell-consent-status
                    x-anyOf:
                    - type: string
                      enum:
                      - revoked
                      - consumed
                      - authorised
                    - type: string
                  tell-consent-permissions:
                    type: array
                    items:
                      type: string
                      title: tell-consent-permission
                      x-anyOf:
                      - type: string
                        enum:
                        - ReadPartyPSU
                        - ReadTransactionsDetail
                        - ReadProducts
                        - ReadStatementsDetail
                        - ReadDirectDebits
                        - ReadTransactionsDebits
                        - ReadTransactionsCredits
                        - ReadBeneficiariesDetail
                        - ReadBalances
                        - ReadPAN
                        - ReadScheduledPaymentsDetail
                        - ReadAccountsDetail
                        - ReadAccountsBasic
                        - ReadOffers
                        - ReadBeneficiariesBasic
                        - ReadStandingOrdersBasic
                        - ReadStandingOrdersDetail
                        - ReadTransactionsBasic
                        - ReadParty
                        - ReadStatementsBasic
                        - ReadScheduledPaymentsBasic
                      - type: string
                  bank-account-urls:
                    type: array
                    items:
                      type: string
                      x-allOf:
                      - type: string
                      - {}
                      - type: object
                        properties:
                          bank-account-id:
                            type: string
                            format: ''
                            title: bank-account-id
                            required: true
                            name: bank-account-id
                        required:
                        - bank-account-id
                      x-anyOf:
                      - type: string
                        x-allOf:
                        - type: string
                        - {}
                        - type: object
                          properties:
                            bank-account-id:
                              type: string
                              format: ''
                              title: bank-account-id
                              required: true
                              name: bank-account-id
                          required:
                          - bank-account-id
                      - type: string
                        x-allOf:
                        - type: string
                        - {}
                        - type: object
                          properties:
                            bank-account-id:
                              type: string
                              format: ''
                              title: bank-account-id
                              required: true
                              name: bank-account-id
                          required:
                          - bank-account-id
                      title: account-url
                      example: /v0/bank/accounts/ba.IGJhbmstYWNjb3VudC1pZA
                      description: Link to the bank account resource.
                  tell-consent-revoked-at:
                    title: tell-consent-revoked-at
                    format: date-time
                    type: string
                    description: ISO 8601 formatted date-time.
                required:
                - tell-consent-url
                - tell-consent-id
                - tell-gateway-id
                - bank-account-urls
                - tell-consent-scope
                - tell-consent-permissions
                - tell-consent-status
                - created-at
                title: tell-consent-response
                description: A registered Tell consent.
        '401':
          description: Requires an API key to continue
          headers:
            www-authenticate:
              description: Returns `GriffinSession` if no valid authentication is found.
              schema:
                type: string
        '404':
          description: ''
      summary: Get Tell consent
      operationId: getV0OpenBankingTellConsentsByConsentId
      x-operation-id-source: derived
  /v0/open-banking/tell-consents/{consent-id}/actions/revoke:
    post:
      tags:
      - Open Banking
      description: 'Revoke a registered Tell consent.


        After revoking a consent with Tell Money, also revoke it with Griffin

        so that Griffin rejects any further resource requests for this consent.'
      parameters:
      - in: path
        name: consent-id
        required: true
        schema:
          type: string
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                type: object
                properties:
                  tell-consent-expiry:
                    title: tell-consent-expiry
                    format: date-time
                    type: string
                    description: ISO 8601 formatted date-time.
                  tell-gateway-id:
                    type: string
                    format: uuid
                    title: tell-gateway-id
                  created-at:
                    title: created-at
                    format: date-time
                    type: string
                    description: ISO 8601 formatted date-time.
                  tell-consent-id:
                    type: string
                    format: uuid
                    title: tell-consent-id
                  tell-consent-scope:
                    type: string
                    title: tell-consent-scope
                    x-anyOf:
                    - type: string
                      enum:
                      - payments
                      - accounts
                    - type: string
                  tell-consent-consumed-at:
                    title: tell-consent-consumed-at
                    format: date-time
                    type: string
                    description: ISO 8601 formatted date-time.
                  tell-consent-url:
                    type: string
                    x-allOf:
                    - type: string
                    - {}
                    - type: object
                      properties:
                        consent-id:
                          type: string
                          format: uuid
                      required:
                      - consent-id
                    x-anyOf:
                    - type: string
                      x-allOf:
                      - type: string
                      - {}
                      - type: object
                        properties:
                          consent-id:
                            type: string
                            format: uuid
                        required:
                        - consent-id
                    - type: string
                      x-allOf:
                      - type: string
                      - {}
                      - type: object
                        properties:
                          consent-id:
                            type: string
                            format: uuid
                        required:
                        - consent-id
                    title: tell-consent-url
                    example: /v0/open-banking/tell-consents/00000000-0000-0000-0000-000000000000
                  tell-consent-status:
                    type: string
                    title: tell-consent-status
                    x-anyOf:
                    - type: string
                      enum:
                      - revoked
                      - consumed
                      - authorised
                    - type: string
                  tell-consent-permissions:
                    type: array
                    items:
                      type: string
                      title: tell-consent-permission
                      x-anyOf:
                      - type: string
                        enum:
                        - ReadPartyPSU
                        - ReadTransactionsDetail
                        - ReadProducts
                        - ReadStatementsDetail
                        - ReadDirectDebits
                        - ReadTransactionsDebits
                        - ReadTransactionsCredits
                        - ReadBeneficiariesDetail
                        - ReadBalances
                        - ReadPAN
                        - ReadScheduledPaymentsDetail
                        - ReadAccountsDetail
                        - ReadAccountsBasic
                        - ReadOffers
                        - ReadBeneficiariesBasic
                        - ReadStandingOrdersBasic
                        - ReadStandingOrdersDetail
                        - ReadTransactionsBasic
                        - ReadParty
                        - ReadStatementsBasic
                        - ReadScheduledPaymentsBasic
                      - type: string
                  bank-account-urls:
                    type: array
                    items:
                      type: string
                      x-allOf:
                      - type: string
                      - {}
                      - type: object
                        properties:
                          bank-account-id:
                            type: string
                            format: ''
                            title: bank-account-id
                            required: true
                            name: bank-account-id
                        required:
                        - bank-account-id
                      x-anyOf:
                      - type: string
                        x-allOf:
                        - type: string
                        - {}
                        - type: object
                          properties:
                            bank-account-id:
                              type: string
                              format: ''
                              title: bank-account-id
                              required: true
                              name: bank-account-id
                          required:
                          - bank-account-id
                      - type: string
                        x-allOf:
                        - type: string
                        - {}
                        - type: object
                          properties:
                            bank-account-id:
                              type: string
                              format: ''
                              title: bank-account-id
                              required: true
                              name: bank-account-id
                          required:
                          - bank-account-id
                      title: account-url
                      example: /v0/bank/accounts/ba.IGJhbmstYWNjb3VudC1pZA
                      description: Link to the bank account resource.
                  tell-consent-revoked-at:
                    title: tell-consent-revoked-at
                    format: date-time
                    type: string
                    description: ISO 8601 formatted date-time.
                required:
                - tell-consent-url
                - tell-consent-id
                - tell-gateway-id
                - bank-account-urls
                - tell-consent-scope
                - tell-consent-permissions
                - tell-consent-status
                - created-at
                title: tell-consent-response
                description: A registered Tell consent.
        '401':
          description: Requires an API key to continue
          headers:
            www-authenticate:
              description: Returns `GriffinSession` if no valid authentication is found.
              schema:
                type: string
        '404':
          description: Consent not found.
        '422':
          description: Consent is already revoked.
      summary: Revoke Tell consent
      operationId: postV0OpenBankingTellConsentsByConsentIdActionsRevoke
      x-operation-id-source: derived
  /v0/organizations/{organization-id}/open-banking/tell-consents:
    post:
      tags:
      - Open Banking
      description: 'Register a Tell consent for open banking on your customers'' accounts.


        After granting a consent with Tell Money, register it with Griffin so

        that Griffin can validate Tell''s subsequent resource requests.


        `tell-consent-permissions` behaviour depends on `tell-consent-scope`:

        - `accounts` scope requires at least one permission; this controls which

        AISP operations the TPP can perform (e.g. reading balances or

        transactions).

        - `payments` scope does not use permissions — Tell Money returns them

        empty and Griffin authorises payment operations from the scope alone.

        Pass `[]` (matching Tell''s response) or any value; the field is still

        required in the request.'
      parameters:
      - required: true
        name: organization-id
        in: path
        schema:
          type: string
      responses:
        '201':
          description: ''
          content:
            application/json:
              schema:
                type: object
                properties:
                  tell-consent-expiry:
                    title: tell-consent-expiry
                    format: date-time
                    type: string
                    description: ISO 8601 formatted date-time.
                  tell-gateway-id:
                    type: string
                    format: uuid
                    title: tell-gateway-id
                  created-at:
                    title: created-at
                    format: date-time
                    type: string
                    description: ISO 8601 formatted date-time.
                  tell-consent-id:
                    type: string
                    format: uuid
                    title: tell-consent-id
                  tell-consent-scope:
                    type: string
                    title: tell-consent-scope
                    x-anyOf:
                    - type: string
                      enum:
                      - payments
                      - accounts
                    - type: string
                  tell-consent-consumed-at:
                    title: tell-consent-consumed-at
                    format: date-time
                    type: string
                    description: ISO 8601 formatted date-time.
                  tell-consent-url:
                    type: string
                    x-allOf:
                    - type: string
                    - {}
                    - type: object
                      properties:
                        consent-id:
                          type: string
                          format: uuid
                      required:
                      - consent-id
                    x-anyOf:
                    - type: string
                      x-allOf:
                      - type: string
                      - {}
                      - type: object
                        properties:
                          consent-id:
                            type: string
                            format: uuid
                        required:
                        - consent-id
                    - type: string
                      x-allOf:
                      - type: string
                      - {}
                      - type: object
                        properties:
                          consent-id:
                            type: string
                            format: uuid
                        required:
                        - consent-id
                    title: tell-consent-url
                    example: /v0/open-banking/tell-consents/00000000-0000-0000-0000-000000000000
                  tell-consent-status:
                    type: string
                    title: tell-consent-status
                    x-anyOf:
                    - type: string
                      enum:
                      - revoked
                      - consumed
                      - authorised
                    - type: string
                  tell-consent-permissions:
                    type: array
                    items:
                      type: string
                      title: tell-consent-permission
                      x-anyOf:
                      - type: string
                        enum:
                        - ReadPartyPSU
                        - ReadTransactionsDetail
                        - ReadProducts
                        - ReadStatementsDetail
                        - ReadDirectDebits
                        - ReadTransactionsDebits
                        - ReadTransactionsCredits
                        - ReadBeneficiariesDetail
                        - ReadBalances
                        - ReadPAN
                        - ReadScheduledPaymentsDetail
                        - ReadAccountsDetail
                        - ReadAccountsBasic
                        - ReadOffers
                        - ReadBeneficiariesBasic
                        - ReadStandingOrdersBasic
                        - ReadStandingOrdersDetail
                        - ReadTransactionsBasic
                        - ReadParty
                        - ReadStatementsBasic
                        - ReadScheduledPaymentsBasic
                      - type: string
                  bank-account-urls:
                    type: array
                    items:
                      type: string
                      x-allOf:
                      - type: string
                      - {}
                      - type: object
                        properties:
                          bank-account-id:
                            type: string
                            format: ''
                            title: bank-account-id
                            required: true
                            name: bank-account-id
                        required:
                        - bank-account-id
                      x-anyOf:
                      - type: string
                        x-allOf:
                        - type: string
                        - {}
                        - type: object
                          properties:
                            bank-account-id:
                              type: string
                              format: ''
                              title: bank-account-id
                              required: true
                              name: bank-account-id
                          required:
                          - bank-account-id
                      - type: string
                        x-allOf:
                        - type: string
                        - {}
                        - type: object
                          properties:
                            bank-account-id:
                              type: string
                              format: ''
                              title: bank-account-id
                              required: true
                              name: bank-account-id
                          required:
                          - bank-account-id
                      title: account-url
                      example: /v0/bank/accounts/ba.IGJhbmstYWNjb3VudC1pZA
                      description: Link to the bank account resource.
                  tell-consent-revoked-at:
                    title: tell-consent-revoked-at
                    format: date-time
                    type: string
                    description: ISO 8601 formatted date-time.
                required:
                - tell-consent-url
                - tell-consent-id
                - tell-gateway-id
                - bank-account-urls
                - tell-consent-scope
                - tell-consent-permissions
                - tell-consent-status
                - created-at
                title: tell-consent-response
                description: A registered Tell consent.
        '401':
          description: Requires an API key to continue
          headers:
            www-authenticate:
              description: Returns `GriffinSession` if no valid authentication is found.
              schema:
                type: string
        '404':
          description: Gateway not found.
        '409':
          description: Consent with this ID already exists.
        '422':
          description: At least one of the supplied bank accounts doesn't exist.
      summary: Register Tell consent
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                tell-consent-id:
                  type: string
                  format: uuid
                tell-gateway-id:
                  type: string
                  format: uuid
                tell-consent-scope:
                  type: string
                  enum:
                  - payments
                  - accounts
                tell-consent-permissions:
                  type: array
                  items:
                    type: string
                    enum:
                    - ReadPartyPSU
                    - ReadTransactionsDetail
                    - ReadProducts
                    - ReadStatementsDetail
                    - ReadDirectDebits
                    - ReadTransactionsDebits
                    - ReadTransactionsCredits
                    - ReadBeneficiariesDetail
                    - ReadBalances
                    - ReadPAN
                    - ReadScheduledPaymentsDetail
                    - ReadAccountsDetail
                    - ReadAccountsBasic
                    - ReadOffers
                    - ReadBeneficiariesBasic
                    - ReadStandingOrdersBasic
                    - ReadStandingOrdersDetail
                    - ReadTransactionsBasic
                    - ReadParty
                    - ReadStatementsBasic
                    - ReadScheduledPaymentsBasic
                  uniqueItems: true
                  description: Permissions granted by the consent. For `accounts` scope, must list at least one permission. For `payments` scope, pass `[]` — Tell Money returns no permissions and Griffin authorises payments from the scope alone.
                bank-account-urls:
                  type: array
                  items:
                    type: string
                    x-allOf:
                    - type: string
                    - {}
                    - type: object
                      properties:
                        bank-account-id:
                          type: string
                          format: ''
                          title: bank-account-id
                          required: true
                          name: bank-account-id
                      required:
                      - bank-account-id
                    x-anyOf:
                    - type: string
                      x-allOf:
                      - type: string
                      - {}
                      - type: object
                        properties:
                          bank-account-id:
                            type: string
                            format: ''
                            title: bank-account-id
                            required: true
                            name: bank-account-id
                        required:
                        - bank-account-id
                    - type: string
                      x-allOf:
                      - type: string
                      - {}
                      - type: object
                        properties:
                          bank-account-id:
                            type: string
                            format: ''
                            title: bank-account-id
                            required: true
                            name: bank-account-id
                        required:
                        - bank-account-id
                    title: account-url
                    example: /v0/bank/accounts/ba.IGJhbmstYWNjb3VudC1pZA
                    description: Link to the bank account resource.
                tell-consent-expiry:
                  title: inst
                  format: date-time
                  type: string
                  description: ISO 8601 formatted date-time.
              required:
              - tell-consent-id
              - tell-gateway-id
              - tell-consent-scope
              - tell-consent-permissions
              - bank-account-urls
              x-allOf:
              - type: object
                properties: {}
                required: []
              - {}
              title: request-register-tell-consent
        required: true
      operationId: postV0OrganizationsByOrganizationIdOpenBankingTellConsents
      x-operation-id-source: derived
components:
  securitySchemes:
    api-key-auth:
      type: apiKey
      in: header
      name: Authorization
      description: 'API token authentication.

        It should follow the format: `GriffinAPIKey g-test-MyKey-XXXXXXX`'
x-tagGroups:
- name: Getting started
  tags:
  - API keys
  - Connectivity
  - Navigation
  - Events
  - Webhooks
  - Message Signatures
- name: Customer verifications
  tags:
  - Legal persons
  - Legal person history
  - Claims
  - Workflows
  - Verifications
  - Decisions
  - Companies House
  - Reliance onboarding
- name: Banking
  tags:
  - Bank accounts
  - Bank account events
  - Bank account restrictions
  - Bank account holds
  - Pooled account membership
  - Payments
  - Transactions
  - Payees
  - Confirmation of payee
  - Open banking
- name: Team management
  tags:
  - Organizations
  - Users
  - Roles
  - Memberships
  - Invitations
x-id:
- default