Great Southern Bank · Authentication Profile

Great Southern Bank Authentication

Authentication

Great Southern Bank secures its APIs with none, oauth2, openIdConnect, and mutualTLS across 4 declared security schemes, as derived from its OpenAPI definitions.

FinancialBanksOpen BankingCDRConsumer BankingAustraliaCustomer OwnedProduct Reference Data
Methods: none, oauth2, openIdConnect, mutualTLS Schemes: 4 OAuth flows: API key in:

Security Schemes

PublicProductReferenceData none
CDR-OIDC-FAPI openIdConnect
scheme: fapi-1.0-advanced
CDR-OAuth2 oauth2
· flows: authorizationCode
MutualTLS mutualTLS

Source

Authentication Profile

Raw ↑
generated: '2026-07-20'
method: searched
source: https://consumerdatastandardsaustralia.github.io/standards/#security-profile
docs: https://www.greatsouthernbank.com.au/consumer-data-policy
summary:
  types:
  - none
  - oauth2
  - openIdConnect
  - mutualTLS
  note: >-
    The only public, self-serve surface at Great Southern Bank is the Consumer
    Data Right (CDR) Product Reference Data (PRD) API, which is UNAUTHENTICATED
    by standard (no API key, no token). All other CDR banking resource endpoints
    (accounts, balances, transactions, direct debits, scheduled payments, payees)
    are authenticated under the CDR security profile and are reachable ONLY by
    ACCC-accredited data recipients (ADRs). The bank does not issue self-service
    API keys and operates no public developer portal.
discovery:
  source: https://secure.open-banking.greatsouthernbank.com.au/.well-known/openid-configuration
  confirmed: '2026-07-21'
  issuer: https://auth.open-banking.greatsouthernbank.com.au
  authorization_endpoint: https://secure.open-banking.greatsouthernbank.com.au/as/authorization.oauth2
  token_endpoint: https://auth.open-banking.greatsouthernbank.com.au/as/token.oauth2
  pushed_authorization_request_endpoint: https://auth.open-banking.greatsouthernbank.com.au/as/par.oauth2
  registration_endpoint: https://auth.open-banking.greatsouthernbank.com.au/as/clients.oauth2
  backchannel_authentication_endpoint: https://auth.open-banking.greatsouthernbank.com.au/as/bc-auth.ciba
  cdr_arrangement_revocation_endpoint: https://auth.open-banking.greatsouthernbank.com.au/data-holder/arrangements/revoke
  require_pushed_authorization_requests: true
  tls_client_certificate_bound_access_tokens: true
  token_endpoint_auth_methods_supported: [client_secret_basic, client_secret_post, private_key_jwt]
  code_challenge_methods_supported: [S256]
  acr_values_supported: [urn:cds.au:cdr:2]
  id_token_signing_alg_values_supported: [ES256, PS256]
  grant_types_supported: [authorization_code, client_credentials, refresh_token]
schemes:
- name: PublicProductReferenceData
  type: none
  applies_to:
  - listBankingProducts
  - getBankingProductDetail
  note: >-
    Product Reference Data endpoints are openly accessible with no credential.
    Confirmed live: GET https://api.open-banking.greatsouthernbank.com.au/cds-au/v1/banking/products
    returns HTTP 200 with no Authorization header.
  sources:
  - openapi/great-southern-bank-cds-banking-products-openapi.yml
- name: CDR-OIDC-FAPI
  type: openIdConnect
  scheme: fapi-1.0-advanced
  applies_to: authenticated CDR banking resource endpoints (ADR-only)
  note: >-
    Consumer data sharing follows the CDR security profile: OpenID Connect with
    the FAPI 1.0 Advanced profile, Pushed Authorization Requests (PAR), private_key_jwt
    client authentication, and the CDR Register's dynamic client registration and
    ADR accreditation model. Not available to the general public.
  sources:
  - review.yml
- name: CDR-OAuth2
  type: oauth2
  applies_to: authenticated CDR banking resource endpoints (ADR-only)
  flows:
  - flow: authorizationCode
    note: Authorization Code flow with PKCE per the CDR / FAPI security profile; consumer authorises data sharing.
  scopes:
  - bank:accounts.basic:read
  - bank:accounts.detail:read
  - bank:transactions:read
  - bank:payees:read
  - bank:regular_payments:read
  sources:
  - openapi/great-southern-bank-cds-banking-products-openapi.yml
- name: MutualTLS
  type: mutualTLS
  applies_to: all authenticated CDR data-holder endpoints
  note: >-
    CDR data-holder endpoints are served over the MTLS server described in the
    spec (servers[].description "MTLS"); ADRs present a CDR-issued client certificate.
  sources:
  - openapi/great-southern-bank-cds-banking-products-openapi.yml

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/great-southern-bank-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.