Bank Australia · Authentication Profile

Bank Australia Authentication

Authentication

Bank Australia secures its APIs with none, oauth2, and openIdConnect across 2 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode flow(s).

FinancialBanksOpen BankingCDRConsumer Data RightConsumer BankingAustraliaMutual Bank
Methods: none, oauth2, openIdConnect Schemes: 2 OAuth flows: authorizationCode API key in:

Security Schemes

public-no-auth none
cdr-oauth2-fapi oauth2
scheme: authorizationCode

Source

Authentication Profile

Raw ↑
generated: '2026-07-20'
method: searched
source: >-
  https://www.bankaust.com.au/support/open-banking/developer/ +
  Consumer Data Standards (Consumer Data Right) security profile
summary:
  types: [none, oauth2, openIdConnect]
  api_key_in: []
  oauth2_flows: [authorizationCode]
  note: >-
    Two distinct surfaces. The public Product Reference Data (PRD) API requires
    NO authentication and NO API key - only the mandatory CDS `x-v` version
    header. The authenticated Consumer Data Sharing surface (account and
    transaction data for consenting customers) is governed by the CDR security
    profile: OAuth2 authorization-code flow with OpenID Connect, mutual-TLS
    sender-constrained tokens, PKCE, and the Financial-grade API (FAPI 1.0
    Advanced) profile, brokered through the ACCC CDR Register rather than a
    bank-proprietary authorization server.
schemes:
- name: public-no-auth
  type: none
  applies_to: Product Reference Data API (GET /banking/products, /banking/products/{productId})
  description: >-
    Unauthenticated public endpoints. No credential is issued or required; the
    only mandatory request header is `x-v` (CDS API version).
  sources: [apis.yml]
- name: cdr-oauth2-fapi
  type: oauth2
  scheme: authorizationCode
  fapi_profile: FAPI 1.0 Advanced
  mtls: true
  pkce: true
  applies_to: Consumer Data Sharing (accredited data recipients, consenting customers)
  description: >-
    OAuth2 authorization-code + OIDC with mutual-TLS-bound tokens under the CDR
    security profile. Accreditation and dynamic client registration are handled
    via the CDR Register; not exercised by the public PRD API captured here.
  docs: https://consumerdatastandardsaustralia.github.io/standards/#security-profile
  sources: [Consumer Data Standards security profile]

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/bank-australia-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.