Open Banking Consent & SCA

Consent grant, strong customer authentication, scoped access, and revocation

Open Banking Consent & SCA Consent grant, strong customer authentication, scoped access, and revocation create consent consentId redirect to bank authenticate SCA challenge approve scope mark authorised code + token GET accounts validate scope account data revoke consent Grant Authenticate (SCA) Access & revoke PSU · account holder · Sequence participant PSU account holder TPP · third party · Sequence participant TPP third party ASPSP Auth · SCA + tokens · Sequence participant ASPSP Auth SCA + tokens Consent Svc · state machine · Sequence participant Consent Svc state machine AIS / PIS API · resource edge · Sequence participant AIS / PIS API resource edge Legend request return security async trace

Consent as a Resource

  • • Durable id and state machine, not a token scope
  • • Minted before SCA so approval is itemised
  • • Revocation and expiry enforced as a unit

SCA & Exemptions

  • • Two independent factors across the three classes
  • • Exemptions evaluated before any challenge
  • • Each exemption logged as a revocable claim

Scope Boundary

  • • AIS is read-only; PIS authorises one payment
  • • Checked against the consent, not a broad claim
  • • Live tokens die the moment consent ends