Rabobank Australia · Authentication Profile

Rabobank Australia Authentication

Authentication

Rabobank Australia secures its APIs with none, oauth2, and openIdConnect across 2 declared security schemes, as derived from its OpenAPI definitions.

FinancialBanksOpen BankingCDRConsumer BankingAustraliaAgribusinessProduct Reference Data
Methods: none, oauth2, openIdConnect Schemes: 2 OAuth flows: API key in:

Security Schemes

public-prd none
cdr-adr-oauth2-oidc-fapi oauth2

Source

Authentication Profile

Raw ↑
generated: '2026-07-20'
method: searched
source: >-
  Rabobank Australia Open Banking pages + CDR regime + live probe (no auth
  required on GET /banking/products). The harvested CDS OpenAPI declares no
  securitySchemes for the public PRD paths.
summary:
  types: [none, oauth2, openIdConnect]
  public_surface_auth: none
  authenticated_surface_auth: [oauth2, openIdConnect]
schemes:
- name: public-prd
  type: none
  applies_to:
  - openapi/rabobank-australia-cds-banking-products-openapi.yml#listBankingProducts
  - openapi/rabobank-australia-cds-banking-products-openapi.yml#getBankingProductDetail
  detail: >-
    Product Reference Data endpoints are public and unauthenticated by CDR
    design. Confirmed live: GET /banking/products succeeds with only the
    mandatory x-v header and no credentials.
- name: cdr-adr-oauth2-oidc-fapi
  type: oauth2
  scheme_detail: OpenID Connect Hybrid flow with FAPI 1.0 Advanced security profile, PAR, PKCE and mTLS-bound tokens.
  applies_to: authenticated CDR consumer data sharing (accounts, balances, transactions, payees, direct debits)
  detail: >-
    Not a self-serve public API. Authenticated CDR data sharing is available
    only to accredited data recipients (ADRs) under the Consumer Data Right,
    with Rabobank Australia acting as a registered data holder. Consent is
    obtained through the CDR OAuth2 / OpenID Connect (FAPI) authorization flow;
    access tokens are scoped to CDR banking scopes (bank:accounts.basic:read,
    bank:transactions:read, common:customer.basic:read, etc.).
docs: https://www.rabobank.com.au/support/open-banking

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/rabobank-australia-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.