first direct website screenshot

first direct

first direct is a telephone- and internet-based retail bank and a division of HSBC UK Bank plc, headquartered in Leeds, England and launched in 1989. It offers personal current accounts, savings, credit cards, loans, mortgages and insurance to UK consumers with a reputation for customer service, operating with no physical branches of its own. As an HSBC brand, first direct participates in the UK Open Banking regime under HSBC UK - one of the nine CMA9 banks mandated by the Competition and Markets Authority - and is regulated by the Financial Conduct Authority (FCA) and Prudential Regulation Authority (PRA). Its Open Banking surfaces conform to the Open Banking Implementation Entity (OBIE / Open Banking Limited) standards - a public, unauthenticated Open Data API (personal current account product reference data, ATM and branch locators, published on the shared HSBC api.hsbc.com host where "first direct" appears as a distinct brand) and the FAPI-secured OBIE Read/Write APIs - Account and Transaction Information (AIS), Payment Initiation (PIS) and Confirmation of Funds (CBPII) - onboarded and documented through HSBC's developer portal at develop.hsbc.com, which serves the HSBC UK, first direct and M&S Bank brands.

first direct publishes 4 APIs on the APIs.io network, including Open Data API, Account and Transaction Information API (AIS), Payment Initiation API (PIS), and 1 more. Tagged areas include Financial Services, Banking, Open Banking, PSD2, and OBIE.

first direct’s developer surface includes authentication, changelog, sandbox, getting-started guide, signup flow, documentation, support, and 28 more developer resources.

53.9/100 developing ▬ flat Agent 69/100 agent native Full breakdown ↓
scored 2026-07-27 · rubric v0.5
AccessSelf serve
4 APIs
Financial ServicesBankingOpen BankingPSD2OBIEUnited KingdomPaymentsAccount InformationOpen DataHSBCFintech

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-27 · rubric v0.5
Composite quality — 53.9/100 · developing
Contract Quality 13.5 / 25
Developer Ergonomics 12.2 / 20
Commercial Clarity 6.8 / 20
Operational Transparency 5.1 / 13
Governance 0.0 / 12
Discoverability 10.0 / 10
Agent readiness — 69/100 · agent native
Machine-Readable Contract 18 / 18
Agentic Access Contract 15 / 15
MCP Server 0 / 12
Machine-Readable Auth 10 / 10
Idempotency 9 / 9
Stable Error Semantics 8 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 0 / 7
Typed Event Surface 0 / 6
Agent Skills 5 / 5
Well-Known Catalog 4 / 4
Consent & Bot Identity 3 / 3
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/first-direct: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 4

Individual APIs this provider publishes, each with its own machine-readable definition.

first direct Open Data API

Public, unauthenticated OBIE Open Data API exposing first direct product reference data - personal current accounts and related read-only reference data - published on the share...

first direct Account and Transaction Information API (AIS)

OBIE Read/Write Account and Transaction Information (AIS) API for first direct accounts, exposed through HSBC's developer platform. FAPI-secured with OAuth2/OIDC, mutual-TLS cli...

first direct Payment Initiation API (PIS)

OBIE Read/Write Payment Initiation (PIS) API for first direct accounts, exposed through HSBC's developer platform. FAPI-secured with OAuth2/OIDC, mutual-TLS and PSD2 strong cust...

first direct Confirmation of Funds API (CBPII)

OBIE Read/Write Confirmation of Funds (CBPII) API for first direct accounts, exposed through HSBC's developer platform. FAPI-secured with OAuth2/OIDC, mutual-TLS and PSD2 strong...

Security Posture 3

Authentication, domain security, vulnerability disclosure, and trust-center signals.

First Direct Authentication

oauth2/openIdConnect/mutualTLS · 2 schemes

SECURITY

First Direct Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

First Direct Vulnerability Disclosure

Bugcrowd · security.txt · contact published

SECURITY

Scopes 1

OAuth scopes governing access to this provider's APIs.

First Direct Scopes

3 scopes · clientCredentials/authorizationCode

3 scopes

SCOPES

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

First Direct Agentic Access

86 operations · 20 acting

86 operations · 20 acting

AGENTIC

Resources

Get Started 4

Portal, sign-up, and the first successful call

Documentation 1

Reference material describing how the API behaves

Agent Surfaces 4

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 6

Pagination, idempotency, versioning, errors, and events

Build 2

SDKs, sample code, and the tooling you integrate with

Access & Security 6

Authentication, authorization, and security posture

Operate 3

Status, limits, changes, and where to get help

Commercial 2

Pricing, plans, and the legal terms of use

Company 2

The organization behind the API

Other 5

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
aid: first-direct
url: https://raw.githubusercontent.com/api-evangelist/first-direct/refs/heads/main/apis.yml
name: first direct
kind: company
description: first direct is a telephone- and internet-based retail bank and a division of HSBC UK Bank plc, headquartered
  in Leeds, England and launched in 1989. It offers personal current accounts, savings, credit cards, loans, mortgages and
  insurance to UK consumers with a reputation for customer service, operating with no physical branches of its own. As an
  HSBC brand, first direct participates in the UK Open Banking regime under HSBC UK - one of the nine CMA9 banks mandated
  by the Competition and Markets Authority - and is regulated by the Financial Conduct Authority (FCA) and Prudential Regulation
  Authority (PRA). Its Open Banking surfaces conform to the Open Banking Implementation Entity (OBIE / Open Banking Limited)
  standards - a public, unauthenticated Open Data API (personal current account product reference data, ATM and branch locators,
  published on the shared HSBC api.hsbc.com host where "first direct" appears as a distinct brand) and the FAPI-secured OBIE
  Read/Write APIs - Account and Transaction Information (AIS), Payment Initiation (PIS) and Confirmation of Funds (CBPII)
  - onboarded and documented through HSBC's developer portal at develop.hsbc.com, which serves the HSBC UK, first direct and
  M&S Bank brands.
accessModel:
  pricing: unknown
  onboarding: self-serve
  trial: false
  try_now: false
  public: false
  label: Self-serve signup (HSBC developer portal) · public Open Data
  confidence: medium
  source:
  - authentication
  - open-data
  generated: '2026-07-23'
  method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/apis-json-logo.jpg
tags:
- Financial Services
- Banking
- Open Banking
- PSD2
- OBIE
- United Kingdom
- Payments
- Account Information
- Open Data
- HSBC
- Fintech
created: '2026-07-23'
modified: '2026-07-23'
specificationVersion: '0.19'
apis:
- aid: first-direct:first-direct-open-data-api
  name: first direct Open Data API
  description: Public, unauthenticated OBIE Open Data API exposing first direct product reference data - personal current
    accounts and related read-only reference data - published on the shared HSBC Open Data host where "first direct" is listed
    as a distinct brand. Confirmed live (HTTP 200, application/prs.openbanking.opendata.v2.2+json).
  humanURL: https://develop.hsbc.com/knowledge-article/get-started-open-banking-apis
  baseURL: https://api.hsbc.com/open-banking/v2.2
  tags:
  - Open Data
  - Personal Current Accounts
  - Reference Data
  properties:
  - type: OpenAPI
    url: openapi/obie-opendata-openapi.json
  - type: Documentation
    url: https://develop.hsbc.com/knowledge-article/get-started-open-banking-apis
  - type: APIReference
    url: https://api.hsbc.com/open-banking/v2.2/personal-current-accounts
- aid: first-direct:first-direct-account-information-api
  name: first direct Account and Transaction Information API (AIS)
  description: OBIE Read/Write Account and Transaction Information (AIS) API for first direct accounts, exposed through HSBC's
    developer platform. FAPI-secured with OAuth2/OIDC, mutual-TLS client authentication and PSD2 strong customer authentication;
    requires FCA/TPP onboarding and OBIE/eIDAS certificates. OpenAPI pointer is the shared OBIE Read/Write standard the bank
    conforms to, not a first-direct-proprietary contract.
  humanURL: https://develop.hsbc.com/
  baseURL: ''
  tags:
  - Account Information
  - AISP
  - Read/Write
  properties:
  - type: OpenAPI
    url: openapi/obie-account-info-openapi.yaml
  - type: Documentation
    url: https://develop.hsbc.com/knowledge-article/get-started-open-banking-apis
  - type: APIReference
    url: https://develop.hsbc.com/
- aid: first-direct:first-direct-payment-initiation-api
  name: first direct Payment Initiation API (PIS)
  description: OBIE Read/Write Payment Initiation (PIS) API for first direct accounts, exposed through HSBC's developer platform.
    FAPI-secured with OAuth2/OIDC, mutual-TLS and PSD2 strong customer authentication; requires FCA/TPP onboarding and OBIE/eIDAS
    certificates. OpenAPI pointer is the shared OBIE Read/Write standard, not a first-direct-proprietary contract.
  humanURL: https://develop.hsbc.com/
  baseURL: ''
  tags:
  - Payment Initiation
  - PISP
  - Read/Write
  properties:
  - type: OpenAPI
    url: openapi/obie-payment-initiation-openapi.yaml
  - type: Documentation
    url: https://develop.hsbc.com/knowledge-article/get-started-open-banking-apis
  - type: APIReference
    url: https://develop.hsbc.com/
- aid: first-direct:first-direct-confirmation-of-funds-api
  name: first direct Confirmation of Funds API (CBPII)
  description: OBIE Read/Write Confirmation of Funds (CBPII) API for first direct accounts, exposed through HSBC's developer
    platform. FAPI-secured with OAuth2/OIDC, mutual-TLS and PSD2 strong customer authentication; requires FCA/TPP onboarding
    and OBIE/eIDAS certificates. OpenAPI pointer is the shared OBIE Read/Write standard, not a first-direct-proprietary contract.
  humanURL: https://develop.hsbc.com/
  baseURL: ''
  tags:
  - Confirmation of Funds
  - CBPII
  - Read/Write
  properties:
  - type: OpenAPI
    url: openapi/obie-confirmation-funds-openapi.yaml
  - type: Documentation
    url: https://develop.hsbc.com/knowledge-article/get-started-open-banking-apis
  - type: APIReference
    url: https://develop.hsbc.com/
common:
- type: AgenticAccess
  url: agentic-access/first-direct-agentic-access.yml
- type: DomainSecurity
  url: security/first-direct-domain-security.yml
- type: OAuthScopes
  url: scopes/first-direct-scopes.yml
- type: Authentication
  url: authentication/first-direct-authentication.yml
- type: Conventions
  url: conventions/first-direct-conventions.yml
- type: Idempotency
  url: conventions/first-direct-conventions.yml
- type: ErrorCatalog
  url: errors/first-direct-problem-types.yml
- type: Conformance
  url: conformance/first-direct-conformance.yml
- type: Lifecycle
  url: lifecycle/first-direct-lifecycle.yml
- type: Deprecation
  url: https://standards.openbanking.org.uk/operational-guidelines/change-and-communication-management/
- type: ChangeLog
  url: changelog/first-direct-changelog.yml
- type: DataModel
  url: data-model/first-direct-data-model.yml
- type: Sandbox
  url: sandbox/first-direct-sandbox.yml
- type: Postman
  url: https://develop.hsbc.com/knowledge-article/get-started-open-banking-apis
- type: WellKnown
  url: well-known/first-direct-well-known.yml
- type: SecurityTxt
  url: well-known/first-direct-security.txt
- type: VulnerabilityDisclosure
  url: security/first-direct-vulnerability-disclosure.yml
- type: Security
  url: https://www.hsbc.com/.well-known/security.txt
- type: AgentSkill
  url: skills/_index.yml
- type: LLMsTxt
  url: llms/first-direct-llms.txt
- type: Overlay
  url: overlays/first-direct-obie-account-info-overlay.yaml
- type: Overlay
  url: overlays/first-direct-obie-payment-initiation-overlay.yaml
- type: Overlay
  url: overlays/first-direct-obie-confirmation-funds-overlay.yaml
- type: Overlay
  url: overlays/first-direct-obie-opendata-overlay.yaml
- type: GettingStarted
  url: https://develop.hsbc.com/knowledge-article/get-started-open-banking-apis
- type: SignUp
  url: https://develop.hsbc.com/
- type: Website
  url: https://www.firstdirect.com/
- type: DeveloperPortal
  url: https://develop.hsbc.com/
- type: Documentation
  url: https://develop.hsbc.com/knowledge-article/get-started-open-banking-apis
- type: OpenBanking
  url: https://www.firstdirect.com/ways-to-bank/open-banking/
- type: GitHubOrganization
  url: https://github.com/hsbc
- type: LinkedIn
  url: https://www.linkedin.com/company/first-direct
- type: Support
  url: https://www.firstdirect.com/help/
- type: TermsOfService
  url: https://www.firstdirect.com/legals/terms-and-conditions/
- type: PrivacyPolicy
  url: https://www.firstdirect.com/privacy/
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com