Skip to main content

Account Info API

API Docs (Production)

important

For full OpenAPI reference and live testing, see https://api.blikk.tech/accountinfo/docs.

Securely retrieve customer account information and balances with explicit customer consent using Blikk's Account Information API.

Contact​

Questions or API key requests: hello@blikk.tech

Getting Started​

  1. Obtain API key (email support)
  2. Use HTTPS endpoints
  3. Include API key header in every request (example below)
  4. Create a consent request via API
  5. Create account information or balance request referencing the consent via API
  6. Retrieve data after customer authentication
important

Stage uses bank sandbox systems: no real funds move.

Authentication​

Typical HTTP header

API-Key: YOUR_API_KEY
Content-Type: application/json

Public endpoint GET /v1/consent/sca-complete requires no authentication (bank callback only).

Integration Flows​

  1. Create consent — POST /v1/consents with scope and PSU/Corp-PSU reference
  2. Poll consent — GET /v1/consents/{id}
  3. Receive redirect URL — scaRedirectUrl from response
  4. PSU authenticates at their bank via SCA
  5. PSU approves — PSU reviews and confirms consent scope
  6. Get consent — GET /v1/consents/{id}
  7. Use authorized access — Make subsequent requests with confirmed consent

Account Info Flow​

  1. Create request — POST /v1/account-requests with PSU/Corp-PSU consent reference
  2. Bank returns data — GET /v1/account-requests/{id}
  3. Access results — Fetch the authorized account information from the response
important

If you need to fetch transactions older than 90 days, do so immediately when the consent is first used, or within the first 10 minutes after receiving the consent. Some banks only allow transactions older than 90 days to be fetched during this period, in accordance with PSD2 requirements.

Account Balance Flow​

  1. Create request — POST /v1/account-balance-requests with PSU/Corp-PSU consent reference
  2. Bank returns balance — GET /v1/account-balance-requests/{id}
  3. Access results — Fetch the authorized balance information from the response
note

Some banks use back-channel SCA — the customer is notified via push notification in their banking app rather than through a redirect URL. scaRedirectUrl may remain empty even while processing. Only redirect the customer if scaRedirectUrl is non-empty and status is SCA_REQUIRED. Regardless of bank, continue polling.

Core Endpoints​

Account Information Requests​

MethodEndpointDescription
POST/v1/account-requestsCreate new account information request
GET/v1/account-requests/{id}Retrieve request status and data

Account Balance Requests​

MethodEndpointDescription
POST/v1/account-balance-requestsCreate new balance request
GET/v1/account-balance-requests/{id}Retrieve balance data

Consents​

MethodEndpointDescription
POST/v1/consentsCreate new consent for data access
GET/v1/consentsList consents
GET/v1/consents/{id}Retrieve specific consent

SCA Completion​

MethodEndpointDescription
GET/v1/consent/sca-completeBank callback after customer authentication (public endpoint)

Implementation Tips​

  • Treat request id as the canonical key for reconciliation
  • Use exponential backoff if polling (e.g. 1s → 2s → 4s, cap ~15s)
  • Set unique reference IDs when creating requests to link to your internal order/customer IDs

Security & Compliance​

  • Consent-Based: Explicit customer consent required for all data access
important

Never log or store complete bank account numbers or IBAN details unless absolutely necessary. Implement proper data retention policies to minimize PII exposure.

Error Handling​

The API returns standard HTTP status codes:

  • 200 OK — Request successful
  • 400 Bad Request — Invalid request parameters
  • 401 Unauthorized — Missing or invalid API key
  • 403 Forbidden — API key not authorized for this resource
  • 404 Not Found — Resource not found
  • 409 Conflict — Request conflicts with existing data
  • 429 Too Many Requests — Rate limit exceeded
  • 500 Internal Server Error — Server error

Error responses include a detailed error message and error code for troubleshooting.

note

Always check the error response body for specific error codes and messages. Use these to implement appropriate retry logic and user messaging.

Data Available​

When a request is authorized, you can retrieve:

  • Account Information: Account number, type, currency, IBAN, account holder name, account status, opening date
  • Balance Data: Available balance, current balance, credit limit (where applicable)
  • Account Details: Product details, account ownership information

Glossary​

TermMeaning
SCAStrong Customer Authentication (bank-mandated user authentication)
DebtorAccount holder (customer whose data is being accessed)
CreditorRequesting party (merchant or financial institution)
IBANInternational Bank Account Number
BBANDomestic bank account number
PSD2Payment Services Directive 2 (EU regulation)
ConsentExplicit customer authorization to access financial data
Rate LimitMaximum number of API requests allowed per time window
IdempotentRequest that produces the same result if executed multiple times