Police Bank · Authentication Profile

Police Bank Authentication

Authentication

Police Bank declares 0 security scheme(s) across its OpenAPI definitions.

FinancialBanksOpen BankingCDRConsumer BankingAustraliaMutual BankProduct Reference Data
Methods: Schemes: 0 OAuth flows: API key in:

Security Schemes

Source

Authentication Profile

Raw ↑
generated: '2026-07-20'
method: searched
source: openapi/police-bank-cds-banking-products-openapi.yml
docs: https://consumerdatastandardsaustralia.github.io/standards/#security-profile
# Police Bank publicly exposes only the unauthenticated Product Reference Data
# (PRD) surface of the CDR Banking API. The PRD endpoints (/banking/products,
# /banking/products/{productId}) require NO authentication - they are open,
# machine-readable product data as mandated for every Australian ADI under the
# Consumer Data Right. The OpenAPI declares no securitySchemes for these ops.
summary:
  types: []
  public_unauthenticated: true
  api_key_in: []
  oauth2_flows: []
prd_surface:
  authenticated: false
  note: >-
    No API key, token, or client credential is required to call the Product
    Reference Data endpoints. A mandatory x-v request header selects the API
    version but is not an auth credential.
consumer_data_sharing:
  # The broader (authenticated) CDR data-sharing flows are governed by the CDS
  # security profile, not by a Police Bank-proprietary scheme. Police Bank
  # participates as a data holder; members authenticate via the CDR consent
  # flow with ACCC-accredited data recipients. These flows are NOT exposed on
  # Police Bank's public surface.
  standard: Consumer Data Standards security profile (FAPI 1.0 Advanced)
  mechanisms: [OAuth2 authorization code + PKCE, OpenID Connect, PAR, MTLS-bound tokens]
  applies_to: authenticated banking data sharing (accounts, transactions, etc.)
  exposed_publicly: false
  scopes: scopes/police-bank-scopes.yml  # 5 CDR banking scopes carried as x-scopes in the spec

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/police-bank-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.