WeLab Bank Open API

WeLab Bank's Open API programme, published under the Hong Kong Monetary Authority Open API Framework and linked as "Open API" from the welab.bank site footer. The developer portal at portal-sandbox.welab.bank carries the API catalogue (account information APIs including account balance, account status and account transaction) and a help centre, and requires registration with WeLab Bank as a third-party service provider. The API gateways themselves are dedicated hosts in AWS ap-east-1 (Hong Kong): api.welab.bank for production and api-sandbox.welab.bank for the sandbox. Both enforce mutual TLS — an anonymous request to the sandbox gateway is answered with HTTP 400 "No required SSL certificate was sent" — so no operation, schema or specification is reachable without a WeLab-issued client certificate.

API entry from apis.yml

apis.yml Raw ↑
name: WeLab Bank Open API
description: 'WeLab Bank''s Open API programme, published under the Hong Kong Monetary Authority Open
  API Framework and linked as "Open API" from the welab.bank site footer. The developer portal at portal-sandbox.welab.bank
  carries the API catalogue (account information APIs including account balance, account status and account
  transaction) and a help centre, and requires registration with WeLab Bank as a third-party service provider.
  The API gateways themselves are dedicated hosts in AWS ap-east-1 (Hong Kong): api.welab.bank for production
  and api-sandbox.welab.bank for the sandbox. Both enforce mutual TLS — an anonymous request to the sandbox
  gateway is answered with HTTP 400 "No required SSL certificate was sent" — so no operation, schema or
  specification is reachable without a WeLab-issued client certificate.'
humanURL: https://portal-sandbox.welab.bank/
baseURL: https://api.welab.bank
tags:
- open-banking
- hkma-open-api
- account-information
- digital-banking
- hong-kong
properties:
- type: DeveloperPortal
  url: https://portal-sandbox.welab.bank/
- type: Authentication
  url: authentication/welab-authentication.yml
- type: Conformance
  url: conformance/welab-conformance.yml
x-evidence:
  checked: '2026-08-05'
  probes:
  - url: https://api-sandbox.welab.bank/
    status: 400
    note: nginx — "No required SSL certificate was sent" (mutual TLS required)
  - url: https://api.welab.bank/
    status: 0
    note: TCP connect timeout from a US network; DNS resolves to prod-opa-gw-public-nlb (AWS ap-east-1)
  - url: https://portal-sandbox.welab.bank/
    status: 403
    note: Cloudflare block page returned to every non-interactive client