Great Southern Bank · Authentication Profile
Great Southern Bank Authentication
Authentication
Great Southern Bank secures its APIs with none, oauth2, openIdConnect, and mutualTLS across 4 declared security schemes, as derived from its OpenAPI definitions.
FinancialBanksOpen BankingCDRConsumer BankingAustraliaCustomer OwnedProduct Reference Data
Methods: none, oauth2, openIdConnect, mutualTLS
Schemes: 4
OAuth flows:
API key in:
Security Schemes
PublicProductReferenceData none
CDR-OIDC-FAPI openIdConnect
scheme: fapi-1.0-advanced
CDR-OAuth2 oauth2
· flows: authorizationCode
MutualTLS mutualTLS
Source
Authentication Profile
generated: '2026-07-20'
method: searched
source: https://consumerdatastandardsaustralia.github.io/standards/#security-profile
docs: https://www.greatsouthernbank.com.au/consumer-data-policy
summary:
types:
- none
- oauth2
- openIdConnect
- mutualTLS
note: >-
The only public, self-serve surface at Great Southern Bank is the Consumer
Data Right (CDR) Product Reference Data (PRD) API, which is UNAUTHENTICATED
by standard (no API key, no token). All other CDR banking resource endpoints
(accounts, balances, transactions, direct debits, scheduled payments, payees)
are authenticated under the CDR security profile and are reachable ONLY by
ACCC-accredited data recipients (ADRs). The bank does not issue self-service
API keys and operates no public developer portal.
discovery:
source: https://secure.open-banking.greatsouthernbank.com.au/.well-known/openid-configuration
confirmed: '2026-07-21'
issuer: https://auth.open-banking.greatsouthernbank.com.au
authorization_endpoint: https://secure.open-banking.greatsouthernbank.com.au/as/authorization.oauth2
token_endpoint: https://auth.open-banking.greatsouthernbank.com.au/as/token.oauth2
pushed_authorization_request_endpoint: https://auth.open-banking.greatsouthernbank.com.au/as/par.oauth2
registration_endpoint: https://auth.open-banking.greatsouthernbank.com.au/as/clients.oauth2
backchannel_authentication_endpoint: https://auth.open-banking.greatsouthernbank.com.au/as/bc-auth.ciba
cdr_arrangement_revocation_endpoint: https://auth.open-banking.greatsouthernbank.com.au/data-holder/arrangements/revoke
require_pushed_authorization_requests: true
tls_client_certificate_bound_access_tokens: true
token_endpoint_auth_methods_supported: [client_secret_basic, client_secret_post, private_key_jwt]
code_challenge_methods_supported: [S256]
acr_values_supported: [urn:cds.au:cdr:2]
id_token_signing_alg_values_supported: [ES256, PS256]
grant_types_supported: [authorization_code, client_credentials, refresh_token]
schemes:
- name: PublicProductReferenceData
type: none
applies_to:
- listBankingProducts
- getBankingProductDetail
note: >-
Product Reference Data endpoints are openly accessible with no credential.
Confirmed live: GET https://api.open-banking.greatsouthernbank.com.au/cds-au/v1/banking/products
returns HTTP 200 with no Authorization header.
sources:
- openapi/great-southern-bank-cds-banking-products-openapi.yml
- name: CDR-OIDC-FAPI
type: openIdConnect
scheme: fapi-1.0-advanced
applies_to: authenticated CDR banking resource endpoints (ADR-only)
note: >-
Consumer data sharing follows the CDR security profile: OpenID Connect with
the FAPI 1.0 Advanced profile, Pushed Authorization Requests (PAR), private_key_jwt
client authentication, and the CDR Register's dynamic client registration and
ADR accreditation model. Not available to the general public.
sources:
- review.yml
- name: CDR-OAuth2
type: oauth2
applies_to: authenticated CDR banking resource endpoints (ADR-only)
flows:
- flow: authorizationCode
note: Authorization Code flow with PKCE per the CDR / FAPI security profile; consumer authorises data sharing.
scopes:
- bank:accounts.basic:read
- bank:accounts.detail:read
- bank:transactions:read
- bank:payees:read
- bank:regular_payments:read
sources:
- openapi/great-southern-bank-cds-banking-products-openapi.yml
- name: MutualTLS
type: mutualTLS
applies_to: all authenticated CDR data-holder endpoints
note: >-
CDR data-holder endpoints are served over the MTLS server described in the
spec (servers[].description "MTLS"); ADRs present a CDR-issued client certificate.
sources:
- openapi/great-southern-bank-cds-banking-products-openapi.yml
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/great-southern-bank-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.