Groupe BPCE · OAuth Scopes

Groupe BPCE OAuth Scopes

OAuth 2.0 searched

Groupe BPCE publishes 12 OAuth 2.0 scopes via the authorizationCode and clientCredentials flows. Scopes are the fine-grained permissions an application requests at authorization time to act against the Groupe BPCE API on a user’s behalf.

Tokens are issued from /stet/psd2/oauth/token.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

CompanyBankingFinancial ServicesOpen BankingPSD2PaymentsInsuranceFrance
Scopes: 12 Flows: authorizationCode, clientCredentials Method: searched

OAuth endpoints

Authorization URL
/stet/psd2/oauth/authorize /api/oauth/authorize /psd2/oauth/authorize
Token URL
/stet/psd2/oauth/token /api/oauth/token
Flows
authorizationCodeclientCredentials

Scopes (12)

ScopeDescriptionFlows
aisp Access by an AISP to one given PSU's account authorizationCode
cbpii Access by a CBPII to one given PSU's account to check payment coverage authorizationCode, clientCredentials
extended_transaction_history Access by an AISP to a transaction history over more than the 90 last days authorizationCode
moneyTransfer.externalAccounts:READ Scope for read External accounts authorizationCode
moneyTransfer.externalAccounts:WRITE Scope for write External accounts authorizationCode
moneyTransfer.internalAccounts:READ Scope for read Internal accounts authorizationCode
moneyTransfer.transferRequests.confirmations:WRITE Scope for transfer requests confirmations. authorizationCode
moneyTransfer.transferRequests:DELETE Scope to delete transfer requests. authorizationCode
moneyTransfer.transferRequests:READ Minimal scope for consultation of transfer requests authorizationCode
moneyTransfer.transferRequests:WRITE Scope to create or modify transfer requests authorizationCode
pisp Access by a PISP for posting a confirmation after authentication of the PSU through OAUTH2 Authorization Code authorizationCode, clientCredentials
manageRegistration Client-credentials scope for the PSD2 Registration API token (POST /token with generic client_id "PSD2_TPPRegister", mutual TLS with QWAC). Not declared in the registration spec.

Source

OAuth Scopes

Raw ↑
generated: '2026-10-09'
method: searched
source: openapi/groupe-bpce-natixis-psd2-accounts-openapi.yml, openapi/groupe-bpce-natixis-wealth-management-psd2-accounts-openapi.yml,
  openapi/groupe-bpce-open-finance-transfer-openapi.yml, openapi/groupe-bpce-psd2-accounts-openapi.yml, openapi/groupe-bpce-psd2-funds-availability-openapi.yml,
  openapi/groupe-bpce-psd2-payments-openapi.yml, https://apistore.groupebpce.com/api/psd2-registration, https://apistore.groupebpce.com/api/account-information-services-3
schemes:
- name: accessCode
  source: openapi/groupe-bpce-natixis-psd2-accounts-openapi.yml
  flows:
  - flow: authorizationCode
    authorizationUrl: /stet/psd2/oauth/authorize
    tokenUrl: /stet/psd2/oauth/token
  description: 'In order to access the PSU''s account information, the AISP needs to get either an authorization
    code grant or a Client Initiated Backchannel Authentication token.

    In order to post a funds confirmation request, the CBPII needs to get either an authorization code grant or
    a Client Initiated Backchannel Authentication token when registration of the account has not been previously
    processed.

    In order to confirm a Payment or Transfer Request, the PISP needs to get either an authorization code grant
    or a Client Initiated Backchannel Authentication token.

    The client_id field within the token request must be filled with the value of the organization identifier attribute
    that was set in the distinguished name of eIDAS certificate of the TPP, according to ETSI recommandations.

    (cf §5.2.1 of [ETSI specfication](https://www.etsi.org/standards-search#page=1&search=TS119495))'
- name: accessCode
  source: openapi/groupe-bpce-natixis-wealth-management-psd2-accounts-openapi.yml
  flows:
  - flow: authorizationCode
    authorizationUrl: /stet/psd2/oauth/authorize
    tokenUrl: /stet/psd2/oauth/token
  description: 'In order to access the PSU''s account information, the AISP needs to get either an authorization
    code grant or a Client Initiated Backchannel Authentication token.

    In order to post a funds confirmation request, the CBPII needs to get either an authorization code grant or
    a Client Initiated Backchannel Authentication token when registration of the account has not been previously
    processed.

    In order to confirm a Payment or Transfer Request, the PISP needs to get either an authorization code grant
    or a Client Initiated Backchannel Authentication token.

    The client_id field within the token request must be filled with the value of the organization identifier attribute
    that was set in the distinguished name of eIDAS certificate of the TPP, according to ETSI recommandations.

    (cf §5.2.1 of [ETSI specfication](https://www.etsi.org/standards-search#page=1&search=TS119495))'
- name: oauth2-authorizationCodePKCE-moneyTransfer
  source: openapi/groupe-bpce-open-finance-transfer-openapi.yml
  flows:
  - flow: authorizationCode
    authorizationUrl: /api/oauth/authorize
    tokenUrl: /api/oauth/token
- name: accessCode
  source: openapi/groupe-bpce-psd2-accounts-openapi.yml
  flows:
  - flow: authorizationCode
    authorizationUrl: /stet/psd2/oauth/authorize
    tokenUrl: /stet/psd2/oauth/token
  description: 'In order to access the PSU''s account information, the AISP needs to get either an authorization
    code grant or a Client Initiated Backchannel Authentication token.

    In order to post a funds confirmation request, the CBPII needs to get either an authorization code grant or
    a Client Initiated Backchannel Authentication token when registration of the account has not been previously
    processed.

    In order to confirm a Payment or Transfer Request, the PISP needs to get either an authorization code grant
    or a Client Initiated Backchannel Authentication token.

    The client_id field within the token request must be filled with the value of the organization identifier attribute
    that was set in the distinguished name of eIDAS certificate of the TPP, according to ETSI recommandations.

    (cf §5.2.1 of [ETSI specfication](https://www.etsi.org/standards-search#page=1&search=TS119495))'
- name: accessCode
  source: openapi/groupe-bpce-psd2-funds-availability-openapi.yml
  flows:
  - flow: authorizationCode
    authorizationUrl: /stet/psd2/oauth/authorize
    tokenUrl: /stet/psd2/oauth/token
  description: 'In order to access the PSU''s account information, the AISP needs to get either an authorization
    code grant or a Client Initiated Backchannel Authentication token.

    In order to post a funds confirmation request, the CBPII needs to get either an authorization code grant or
    a Client Initiated Backchannel Authentication token when registration of the account has not been previously
    processed.

    In order to confirm a Payment or Transfer Request, the PISP needs to get either an authorization code grant
    or a Client Initiated Backchannel Authentication token.

    The client_id field within the token request must be filled with the value of the organization identifier attribute
    that was set in the distinguished name of eIDAS certificate of the TPP, according to ETSI recommandations.

    (cf §5.2.1 of [ETSI specfication](https://www.etsi.org/standards-search#page=1&search=TS119495))'
- name: clientCredentials
  source: openapi/groupe-bpce-psd2-funds-availability-openapi.yml
  flows:
  - flow: clientCredentials
    tokenUrl: /stet/psd2/oauth/token
  description: 'In order to post, get or cancel a Payment or Transfer Request, the PISP needs to get a client credential
    OAUTH2 token.

    In order to confirm a Payment or Transfer Request, the PISP needs to get either an authorization code grant
    or a client credential OAUTH2 token.

    In order to post a funds confirmation request, the CBPII needs to get a client credential OAUTH2 token when
    registration of the account has already been previously processed.

    The client_id field within the token request must be filled with the value of the organization identifier attribute
    that was set in the distinguished name of eIDAS certificate of the TPP, according to ETSI recommandations.

    (cf §5.2.1 of [ETSI specfication](https://www.etsi.org/standards-search#page=1&search=TS119495))'
- name: accessCode
  source: openapi/groupe-bpce-psd2-payments-openapi.yml
  flows:
  - flow: authorizationCode
    authorizationUrl: /psd2/oauth/authorize
    tokenUrl: /stet/psd2/oauth/token
  description: 'In order to access the PSU''s account information, the AISP needs to get either an authorization
    code grant or a Client Initiated Backchannel Authentication token.

    In order to post a funds confirmation request, the CBPII needs to get either an authorization code grant or
    a Client Initiated Backchannel Authentication token when registration of the account has not been previously
    processed.

    In order to confirm a Payment or Transfer Request, the PISP needs to get either an authorization code grant
    or a Client Initiated Backchannel Authentication token.

    The client_id field within the token request must be filled with the value of the organization identifier attribute
    that was set in the distinguished name of eIDAS certificate of the TPP, according to ETSI recommandations.

    (cf §5.2.1 of [ETSI specfication](https://www.etsi.org/standards-search#page=1&search=TS119495))'
- name: clientCredentials
  source: openapi/groupe-bpce-psd2-payments-openapi.yml
  flows:
  - flow: clientCredentials
    tokenUrl: /stet/psd2/oauth/token
  description: 'In order to post, get or cancel a Payment or Transfer Request, the PISP needs to get a client credential
    OAUTH2 token.

    In order to confirm a Payment or Transfer Request, the PISP needs to get either an authorization code grant
    or a client credential OAUTH2 token.

    In order to post a funds confirmation request, the CBPII needs to get a client credential OAUTH2 token when
    registration of the account has already been previously processed.

    The client_id field within the token request must be filled with the value of the organization identifier attribute
    that was set in the distinguished name of eIDAS certificate of the TPP, according to ETSI recommandations.

    (cf §5.2.1 of [ETSI specfication](https://www.etsi.org/standards-search#page=1&search=TS119495))'
scopes:
- scope: aisp
  description: Access by an AISP to one given PSU's account
  flows:
  - authorizationCode
  sources:
  - openapi/groupe-bpce-natixis-psd2-accounts-openapi.yml
  - openapi/groupe-bpce-natixis-wealth-management-psd2-accounts-openapi.yml
  - openapi/groupe-bpce-psd2-accounts-openapi.yml
- scope: cbpii
  description: Access by a CBPII to one given PSU's account to check payment coverage
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/groupe-bpce-psd2-funds-availability-openapi.yml
- scope: extended_transaction_history
  description: Access by an AISP to a transaction history over more than the 90 last days
  flows:
  - authorizationCode
  sources:
  - openapi/groupe-bpce-natixis-psd2-accounts-openapi.yml
  - openapi/groupe-bpce-natixis-wealth-management-psd2-accounts-openapi.yml
  - openapi/groupe-bpce-psd2-accounts-openapi.yml
- scope: moneyTransfer.externalAccounts:READ
  description: Scope for read External accounts
  flows:
  - authorizationCode
  sources:
  - openapi/groupe-bpce-open-finance-transfer-openapi.yml
- scope: moneyTransfer.externalAccounts:WRITE
  description: Scope for write External accounts
  flows:
  - authorizationCode
  sources:
  - openapi/groupe-bpce-open-finance-transfer-openapi.yml
- scope: moneyTransfer.internalAccounts:READ
  description: Scope for read Internal accounts
  flows:
  - authorizationCode
  sources:
  - openapi/groupe-bpce-open-finance-transfer-openapi.yml
- scope: moneyTransfer.transferRequests.confirmations:WRITE
  description: Scope for transfer requests confirmations.
  flows:
  - authorizationCode
  sources:
  - openapi/groupe-bpce-open-finance-transfer-openapi.yml
- scope: moneyTransfer.transferRequests:DELETE
  description: Scope to delete transfer requests.
  flows:
  - authorizationCode
  sources:
  - openapi/groupe-bpce-open-finance-transfer-openapi.yml
- scope: moneyTransfer.transferRequests:READ
  description: Minimal scope for consultation of transfer requests
  flows:
  - authorizationCode
  sources:
  - openapi/groupe-bpce-open-finance-transfer-openapi.yml
- scope: moneyTransfer.transferRequests:WRITE
  description: Scope to create or modify transfer requests
  flows:
  - authorizationCode
  sources:
  - openapi/groupe-bpce-open-finance-transfer-openapi.yml
- scope: pisp
  description: Access by a PISP for posting a confirmation after authentication of the PSU through OAUTH2 Authorization
    Code
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/groupe-bpce-psd2-payments-openapi.yml
- name: manageRegistration
  description: Client-credentials scope for the PSD2 Registration API token (POST /token with generic client_id
    "PSD2_TPPRegister", mutual TLS with QWAC). Not declared in the registration spec.
  source: https://apistore.groupebpce.com/api/psd2-registration
docs: https://apistore.groupebpce.com/api/psd2-registration
notes: 'Registration payload field "scope": "TPP scopes are comma separated, and possible values are : “aisp” and/or
  “pisp” and/or “cbpii”". AIS docs: Authorization Code /token requests "shall be sent WITHOUT the « scope » parameter";
  client_credentials uses scope=aisp.'

Work with this as data

Every scope set here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for oauth scopes

4 MCP tools reach this
  • find_scopesBrowse and filter every scope set in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This scope set
curl "https://apis.io/api/v1/scopes/groupe-bpce-scopes"
All oauth scopes
curl "https://apis.io/api/v1/scopes?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.