BCU Bank · Authentication Profile

Bcu Bank Authentication

Authentication

BCU Bank secures its APIs with none, oauth2, openIdConnect, and mutualTLS across 0 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode flow(s).

FinancialBanksOpen BankingCDRConsumer Data RightConsumer BankingMutual BankAustralia
Methods: none, oauth2, openIdConnect, mutualTLS Schemes: 0 OAuth flows: authorizationCode API key in:

Security Schemes

Source

Authentication Profile

Raw ↑
generated: '2026-07-20'
method: searched
source: openapi/bcu-bank-cds-banking-products-openapi.yml + DSB Consumer Data Standards (FAPI/OIDC security profile)
docs: https://consumerdatastandardsaustralia.github.io/standards/#security-profile
summary:
  types:
  - none
  - oauth2
  - openIdConnect
  - mutualTLS
  oauth2_flows:
  - authorizationCode
  notes: >-
    The CDS Banking OpenAPI does not declare formal components.securitySchemes;
    the CDR security model is defined normatively by the DSB Consumer Data
    Standards Security Profile rather than inline in each Data Holder spec.
    Authentication is captured here from the standard plus the per-operation
    x-scopes present in the spec.
surfaces:
- surface: Product Reference Data (PRD)
  authenticated: false
  scheme: none
  detail: >-
    GET /banking/products and /banking/products/{productId} are public and
    unauthenticated. Callers still send CDS protocol headers (x-v version
    negotiation, optional x-min-v). Confirmed live and public at
    https://public.cdr-api.bcu.com.au/cds-au/v1/banking/products (HTTP 200).
- surface: Consumer data sharing (authenticated banking resources)
  authenticated: true
  schemes:
  - type: oauth2
    flow: authorizationCode
    detail: >-
      CDR authorization-code flow with PKCE (S256) under the OIDC Hybrid/
      authorization-code profile; access tokens are bearer tokens scoped to the
      CDR banking scopes below. Consent is captured through the CDR consent
      (Authorisation) flow; access is restricted to Accredited Data Recipients.
  - type: openIdConnect
    detail: >-
      OpenID Connect for identity and consent, per the CDR/FAPI profile
      (request objects, ID tokens).
  - type: mutualTLS
    detail: >-
      Mutual TLS is required on the resource server (the spec's only declared
      server is described "MTLS": https://mtls.dh.example.com/cds-au/v1) and for
      client authentication (tls_client_auth / private_key_jwt) per FAPI 1.0
      Advanced.
  fapi: FAPI 1.0 Advanced
  request_headers:
  - x-fapi-interaction-id
  - x-fapi-auth-date
  - x-fapi-customer-ip-address
  - x-cds-client-headers
scopes_ref: scopes/bcu-bank-scopes.yml

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/bcu-bank-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.