Handelsbanken UK · Authentication Profile

Handelsbanken Uk Authentication

Authentication

Handelsbanken UK secures its APIs with oauth2 and mutualTLS across 4 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the clientCredentials, authorizationCode, and decoupled flow(s).

BankingOpen BankingFinancial-ServicesPSD2Berlin GroupNextGenPSD2PaymentsAccount InformationUnited KingdomFintech
Methods: oauth2, mutualTLS Schemes: 4 OAuth flows: clientCredentials, authorizationCode, decoupled API key in:

Security Schemes

TPP client authentication (mTLS) mutualTLS
Client Credentials Grant oauth2
Authorization Code Grant (Redirect Authorization) oauth2
Decoupled Grant (Decoupled Authorization) oauth2

Source

Authentication Profile

handelsbanken-uk-authentication.yml Raw ↑
generated: '2026-07-23'
method: searched
source: https://developer.handelsbanken.com/api/psd2/guidelines
docs: https://developer.handelsbanken.com/api/psd2/guidelines
note: >-
  Handelsbanken publishes no anonymously downloadable OpenAPI (the specs sit
  behind portal login and the api.handelsbanken.com gateway rejects anonymous
  TLS), so this profile is derived from the published PSD2 technical guidelines
  rather than from a securitySchemes block. The APIs implement the Berlin Group
  NextGenPSD2 authentication model.
summary:
  types:
  - oauth2
  - mutualTLS
  transport_security: mutual-TLS (mTLS)
  oauth2_flows:
  - clientCredentials
  - authorizationCode
  - decoupled
  strong_customer_authentication: true
schemes:
- name: TPP client authentication (mTLS)
  type: mutualTLS
  description: >-
    Third-party providers authenticate the transport channel with a qualified
    certificate. Production requires a PSD2 eIDAS QWAC (Qualified Website
    Authentication Certificate) or a UK Open Banking OBWAC certificate issued by
    a Qualified Trust Service Provider (QTSP); QSEALC/OBSEAL is used for message
    signing. Sandbox access is available before certificate enrolment.
  sources:
  - https://developer.handelsbanken.com/api/psd2/live
- name: Client Credentials Grant
  type: oauth2
  flow: clientCredentials
  description: >-
    Initial OAuth2 client-credentials token used for TPP client authentication
    against the gateway before a PSU consent/authorisation is obtained.
  sources:
  - https://developer.handelsbanken.com/api/psd2/guidelines
- name: Authorization Code Grant (Redirect Authorization)
  type: oauth2
  flow: authorizationCode
  description: >-
    Resulting from the Redirect Authorization (SCA) flow; the PSU authenticates
    at Handelsbanken and an authorization code is exchanged for an access token
    scoped to the consent or payment.
  sources:
  - https://developer.handelsbanken.com/api/psd2/guidelines
- name: Decoupled Grant (Decoupled Authorization)
  type: oauth2
  flow: decoupled
  description: >-
    Handelsbanken's non-standard decoupled SCA flow (the documented exception to
    the OAuth2 specification); the PSU approves out-of-band (e.g. banking app /
    BankID) and the TPP polls for the resulting token. Availability varies by
    country and by customer type (Individual vs Corporate).
  sources:
  - https://developer.handelsbanken.com/api/psd2/guidelines
consent_model:
  regulatory_consent: long-term consent applying across all AIS endpoints
  short_term_consent: 15-minute consent (Sweden, individual users only)
  identifiers:
  - Consent-ID (AIS)
  - Payment-ID (PIS)

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/handelsbanken-uk-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.