Investec · Authentication Profile

Investec Authentication

Authentication

Investec secures its APIs with oauth2 across 2 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode and clientCredentials flow(s).

Financial ServicesBankingOpen BankingPSD2OBIEUnited KingdomPaymentsAccount InformationSpecialist BankWealth ManagementFAPIProgrammable Banking
Methods: oauth2 Schemes: 2 OAuth flows: authorizationCode, clientCredentials API key in:

Security Schemes

TPPOAuth2Security oauth2
· flows: clientCredentials
PSUOAuth2Security oauth2
· flows: authorizationCode

Source

Authentication Profile

Raw ↑
generated: '2026-07-23'
method: searched
source: openapi/obie-account-info-openapi.yaml, openapi/obie-confirmation-funds-openapi.yaml, openapi/obie-payment-initiation-openapi.yaml
summary:
  types:
  - oauth2
  oauth2_flows:
  - authorizationCode
  - clientCredentials
schemes:
- name: TPPOAuth2Security
  type: oauth2
  flows:
  - flow: clientCredentials
    tokenUrl: https://authserver.example/token
    scopes: 1
  description: TPP client credential authorisation flow with the ASPSP
  sources:
  - openapi/obie-account-info-openapi.yaml
  - openapi/obie-confirmation-funds-openapi.yaml
  - openapi/obie-payment-initiation-openapi.yaml
- name: PSUOAuth2Security
  type: oauth2
  flows:
  - flow: authorizationCode
    authorizationUrl: https://authserver.example/authorization
    tokenUrl: https://authserver.example/token
    scopes: 1
  description: OAuth flow, it is required when the PSU needs to perform SCA with the ASPSP when a TPP
    wants to access an ASPSP resource owned by the PSU
  sources:
  - openapi/obie-account-info-openapi.yaml
  - openapi/obie-confirmation-funds-openapi.yaml
  - openapi/obie-payment-initiation-openapi.yaml
docs: https://developer.investec.com/
programmable_banking:
  model: OAuth2 client_credentials + x-api-key
  token_endpoint: POST https://openapi.investec.com/identity/v2/oauth2/token
  headers:
  - 'Authorization: Basic base64(client_id:client_secret)'
  - 'x-api-key: <api key>'
  - 'Content-Type: application/x-www-form-urlencoded'
  grant_type: client_credentials
  token_ttl_seconds: 1800
  scopes:
  - accounts
  - transaction
  note: Programmable Banking (South Africa) first-party auth; distinct from the OBIE FAPI/mTLS flows harvested
    from the OpenAPI securitySchemes.