Account Info API
For full OpenAPI reference and live testing, see https://api.blikk.tech/accountinfo/docs.
Securely retrieve customer account information and balances with explicit customer consent using Blikk's Account Information API.
Contact
Questions or API key requests: hello@blikk.tech
Getting Started
- Obtain API key (email support)
- Use HTTPS endpoints
- Include API key header in every request (example below)
- Create a consent request via API
- Create account information or balance request referencing the consent via API
- Retrieve data after customer authentication
Stage uses bank sandbox systems: no real funds move.
Authentication
Typical HTTP header
API-Key: YOUR_API_KEY
Content-Type: application/json
Public endpoint GET /v1/consent/sca-complete requires no authentication (bank callback only).
Integration Flows
Consent Management Flow
- Create consent —
POST /v1/consentswith scope and PSU/Corp-PSU reference - Poll consent —
GET /v1/consents/{id} - Receive redirect URL —
scaRedirectUrlfrom response - PSU authenticates at their bank via SCA
- PSU approves — PSU reviews and confirms consent scope
- Get consent —
GET /v1/consents/{id} - Use authorized access — Make subsequent requests with confirmed consent
Account Info Flow
- Create request —
POST /v1/account-requestswith PSU/Corp-PSU consent reference - Bank returns data —
GET /v1/account-requests/{id} - Access results — Fetch the authorized account information from the response
If you need to fetch transactions older than 90 days, do so immediately when the consent is first used, or within the first 10 minutes after receiving the consent. Some banks only allow transactions older than 90 days to be fetched during this period, in accordance with PSD2 requirements.
Account Balance Flow
- Create request —
POST /v1/account-balance-requestswith PSU/Corp-PSU consent reference - Bank returns balance —
GET /v1/account-balance-requests/{id} - Access results — Fetch the authorized balance information from the response
Some banks use back-channel SCA — the customer is notified via push notification in their banking app rather than through a redirect URL. scaRedirectUrl may remain empty even while processing. Only redirect the customer if scaRedirectUrl is non-empty and status is SCA_REQUIRED. Regardless of bank, continue polling.
Core Endpoints
Account Information Requests
| Method | Endpoint | Description |
|---|---|---|
POST | /v1/account-requests | Create new account information request |
GET | /v1/account-requests/{id} | Retrieve request status and data |
Account Balance Requests
| Method | Endpoint | Description |
|---|---|---|
POST | /v1/account-balance-requests | Create new balance request |
GET | /v1/account-balance-requests/{id} | Retrieve balance data |
Consents
| Method | Endpoint | Description |
|---|---|---|
POST | /v1/consents | Create new consent for data access |
GET | /v1/consents | List consents |
GET | /v1/consents/{id} | Retrieve specific consent |
SCA Completion
| Method | Endpoint | Description |
|---|---|---|
GET | /v1/consent/sca-complete | Bank callback after customer authentication (public endpoint) |
Implementation Tips
- Treat request
idas the canonical key for reconciliation - Use exponential backoff if polling (e.g. 1s → 2s → 4s, cap ~15s)
- Set unique reference IDs when creating requests to link to your internal order/customer IDs
Security & Compliance
- Consent-Based: Explicit customer consent required for all data access
Never log or store complete bank account numbers or IBAN details unless absolutely necessary. Implement proper data retention policies to minimize PII exposure.
Error Handling
The API returns standard HTTP status codes:
200 OK— Request successful400 Bad Request— Invalid request parameters401 Unauthorized— Missing or invalid API key403 Forbidden— API key not authorized for this resource404 Not Found— Resource not found409 Conflict— Request conflicts with existing data429 Too Many Requests— Rate limit exceeded500 Internal Server Error— Server error
Error responses include a detailed error message and error code for troubleshooting.
Always check the error response body for specific error codes and messages. Use these to implement appropriate retry logic and user messaging.
Data Available
When a request is authorized, you can retrieve:
- Account Information: Account number, type, currency, IBAN, account holder name, account status, opening date
- Balance Data: Available balance, current balance, credit limit (where applicable)
- Account Details: Product details, account ownership information
Glossary
| Term | Meaning |
|---|---|
| SCA | Strong Customer Authentication (bank-mandated user authentication) |
| Debtor | Account holder (customer whose data is being accessed) |
| Creditor | Requesting party (merchant or financial institution) |
| IBAN | International Bank Account Number |
| BBAN | Domestic bank account number |
| PSD2 | Payment Services Directive 2 (EU regulation) |
| Consent | Explicit customer authorization to access financial data |
| Rate Limit | Maximum number of API requests allowed per time window |
| Idempotent | Request that produces the same result if executed multiple times |