payout / developers
API reference

Payout OpenBanking PSD2 API

PSD2 like API to interact with Payout account system.

The API accepts and returns JSON only. Send request bodies with Content-Type: application/json.

Every response carries a response-id header with a unique UUID. The optional Correlation-ID and Process-ID request headers are echoed back in the correlation-id and process-id response headers; when a header is missing, a new UUID is generated for it.

Authentication

Every endpoint except enrolment requires an OAuth 2.0 access token (JWT) issued by PayoutID to the TPP's client. Send it in the Authorization header:

Code
Authorization: Bearer <access_token>

The token must be issued to a TPP client registered with Payout and carry the scope required by the endpoint:

Scope Token Endpoints
AISP authorization_code grant, on behalf of the user list accounts, account info, list transactions
PIISP authorization_code grant, on behalf of the user balance check
PISP client_credentials grant standard sba payment, order status
PISPSUBMIT authorization_code grant against the order OAuth2 endpoint submit payment

AIS endpoints only return data for the accounts the user granted to the TPP.

PISP: Create and submit order flow

To create order, TPP must first get PISP token using client_credentials against normal OAuth2 endpoint. With this access token it is possible to create order using API. After that, TPP need to request access token using authorization_code method to get PISPSUBMIT access token for created order. This request is done against order OAuth2 endpoint, which is the authorization URL followed by /{orderId}.

Errors

Authentication failures return 401:

JSON
{
  "status": 401,
  "reason": "Unauthorized"
}

This covers a missing, invalid or expired token, a token without the required scope or user, and a token issued to an unknown client.

Other errors use this shape:

JSON
{
  "errors": {
    "message": "Resource not found"
  }
}
Status Message When
400 Bad request The body is not valid JSON, a required attribute is missing, or the order ID is not a UUID
404 Resource not found The account or order does not exist, or the account was not granted to the TPP
406 Request is not acceptable The Accept header does not allow JSON
500 Internal server error Unexpected error

Enrolment validation errors and refused payment submissions also return 400, with the bodies described at those endpoints.

POST

enrol

/api/psd2/v1/enrol

Enrol new client. This call will return new client credentials, which will be disabled. Client TPP then will be contacted via first contact email and process will be finished manually. The request must contain the TPP's PSD2 certificate.

This endpoint does not require an access token.

Parameters

Correlation-IDheader · string
Match request to response. Echoed back in the correlation-id response header. e.g. 5f0c7b9e-2a41-4d3b-8e6f-1a2b3c4d5e6f
Process-IDheader · string
Group multiple Request-Response pairs to single process. Echoed back in the process-id response header. e.g. 7c1d2e3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f

Request body

licenseNumber requiredstring
PSD2 license number of TPP. Each license number can be enrolled only once. max 255 · e.g. 12345
clientName requiredstring
Client name of TPP · max 255 · e.g. Example TPP, s.r.o.
logoUristring
URL to publicly accessible logo of TPP · max 255 · e.g. https://tpp.example.com/logo.png
scopes requiredstring[]
List of scopes which TPP will require · e.g. ["AISP"]
contacts requiredstring<email>[]
List of emails which can be used to contact TPP, must be at least one · e.g. ["test@example.com"]
redirectUris requiredstring<uri>[]
Redirect URL's which TPP will use. Each must be an absolute HTTPS URL without a fragment. e.g. ["https://tpp.example.com/oauth/callback"]
certificate requiredstring
Base64 encoded PSD2 certificate · e.g. MIIDdzCCAl+gAwIBAgIURXhhbXBsZVBTRDJDZXJ0aWZpY2F0ZQ==

Response 201

licenseNumberstring
e.g. 12345
clientIdstring
e.g. a1b2c3d4e5f60718293a4b5c6d7e8f90a1b2c3d4e5f60718293a4b5c6d7e8f90
clientSecretstring
e.g. 0f1e2d3c4b5a69788796a5b4c3d2e1f00f1e2d3c4b5a69788796a5b4c3d2e1f0
cleintNamestring
Client name of TPP · e.g. Example TPP, s.r.o.
logoUristring | null
e.g. https://tpp.example.com/logo.png
scopesstring[]
e.g. ["AISP"]
contactsstring[]
e.g. ["test@example.com"]
redirectsUrisstring[]
Redirect URIs of TPP · e.g. ["https://tpp.example.com/oauth/callback"]

Other responses

400
Validation failed (for example, the license number is already enrolled), or a required attribute is missing.
Request
curl -X POST 'https://sandbox.payout.one/api/psd2/v1/enrol' \
  -H "Content-Type: application/json" \
  -d '{
       "licenseNumber": "12345",
       "clientName": "Example TPP, s.r.o.",
       "logoUri": "https://tpp.example.com/logo.png",
       "certificate": "MIIDdzCCAl+gAwIBAgIURXhhbXBsZVBTRDJDZXJ0aWZpY2F0ZQ==",
       "scopes": [
         "AISP"
       ],
       "contacts": [
         "test@example.com"
       ],
       "redirectUris": [
         "https://tpp.example.com/oauth/callback"
       ]
     }'
Response 201
{
  "licenseNumber": "12345",
  "clientId": "a1b2c3d4e5f60718293a4b5c6d7e8f90a1b2c3d4e5f60718293a4b5c6d7e8f90",
  "clientSecret": "0f1e2d3c4b5a69788796a5b4c3d2e1f00f1e2d3c4b5a69788796a5b4c3d2e1f0",
  "cleintName": "Example TPP, s.r.o.",
  "logoUri": "https://tpp.example.com/logo.png",
  "scopes": [
    "AISP"
  ],
  "contacts": [
    "test@example.com"
  ],
  "redirectsUris": [
    "https://tpp.example.com/oauth/callback"
  ]
}
GET

list accounts

/api/psd2/v1/accounts

List all accounts of current user that the user granted to the TPP.

Parameters

Correlation-IDheader · string
Match request to response. Echoed back in the correlation-id response header. e.g. 5f0c7b9e-2a41-4d3b-8e6f-1a2b3c4d5e6f
Process-IDheader · string
Group multiple Request-Response pairs to single process. Echoed back in the process-id response header. e.g. 7c1d2e3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f

Response 200

creationDateTimestring<date-time>
Date and time in RFC 3339 format when the list was created · e.g. 2026-10-06T08:15:30.123456+00:00
accountsobject[]
identificationobject
identifierstring
Unique identification · e.g. Q7v_K2mNp4Xs
namestring
Name of account · e.g. Example Shop, s.r.o.
productNamestring
Name of product which is represented by this account, statically "Payout Account" e.g. Payout Account
typestring
Type of account, statically "CACC" e.g. CACC
baseCurrencystring
Currency code of account according to ISO 4217 - 3 capital letters, statically "EUR" e.g. EUR
servicerobject
Service responsible for this account
financialInstitutionIdentificationstring
Name of service responsible for this account · e.g. Payout, s.r.o.
consentstring[]
Scopes acquired for this account · e.g. ["AISP"]

Other responses

401
Missing or invalid bearer token, or the token lacks the required scope.
Request
curl -X GET 'https://sandbox.payout.one/api/psd2/v1/accounts' \
  -H "Authorization: Bearer $TOKEN"
Response 200
{
  "creationDateTime": "2026-10-06T08:15:30.123456+00:00",
  "accounts": [
    {
      "identification": {
        "identifier": "Q7v_K2mNp4Xs"
      },
      "name": "Example Shop, s.r.o.",
      "productName": "Payout Account",
      "type": "CACC",
      "baseCurrency": "EUR",
      "servicer": {
        "financialInstitutionIdentification": "Payout, s.r.o."
      },
      "consent": [
        "AISP"
      ]
    }
  ]
}
POST

account info

/api/psd2/v1/accounts/information

Retrieve detailed info about user account

Parameters

Correlation-IDheader · string
Match request to response. Echoed back in the correlation-id response header. e.g. 5f0c7b9e-2a41-4d3b-8e6f-1a2b3c4d5e6f
Process-IDheader · string
Group multiple Request-Response pairs to single process. Echoed back in the process-id response header. e.g. 7c1d2e3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f

Request body

identifier requiredstring
Identificator of account (identification.identifier from list accounts) · e.g. Q7v_K2mNp4Xs

Response 200

accountobject
namestring
Name of account · e.g. Example Shop, s.r.o.
productNamestring
Name of product of which instance is this account · e.g. Payout Account
baseCurrencystring
Basic currency of this account in ISO 4217 · e.g. EUR
typestring
ISO 20022 - Cash Account Type Code · e.g. CACC
balancesobject[]
One balance per currency
namestring
Name of account · e.g. Example Shop, s.r.o.
typeCodeOrProprietarystring
Statically "ITAV" e.g. ITAV
amountobject
Represent value with currency
valuestring
Decimal amount of money, serialized as a string · e.g. 3055.8500
currencystring
Currency code according to ISO 4217 - 3 capital letters · e.g. EUR
creditDebitIndicatorstring
"CRDT" when incoming funds exceed outgoing funds, otherwise "DBIT" one of CRDT, DBIT · e.g. CRDT
dateTimestring<date-time>
Date and time in RFC 3339 format when the balance was read · e.g. 2026-10-06T08:15:30.123456+00:00

Other responses

400
The body is not valid JSON, a required attribute is missing, or a path parameter has the wrong format.
401
Missing or invalid bearer token, or the token lacks the required scope.
404
The account or order does not exist, or the account was not granted to the TPP.
Request
curl -X POST 'https://sandbox.payout.one/api/psd2/v1/accounts/information' \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
       "identifier": "Q7v_K2mNp4Xs"
     }'
Response 200
{
  "account": {
    "name": "Example Shop, s.r.o.",
    "productName": "Payout Account",
    "baseCurrency": "EUR",
    "type": "CACC"
  },
  "balances": [
    {
      "name": "Example Shop, s.r.o.",
      "typeCodeOrProprietary": "ITAV",
      "amount": {
        "value": "3055.8500",
        "currency": "EUR"
      },
      "creditDebitIndicator": "CRDT",
      "dateTime": "2026-10-06T08:15:30.123456+00:00"
    }
  ]
}
POST

list transactions

/api/psd2/v1/accounts/transactions

List all transactions for user or account. Only accounts the user granted to the TPP are included. Transactions are returned newest first.

Parameters

Correlation-IDheader · string
Match request to response. Echoed back in the correlation-id response header. e.g. 5f0c7b9e-2a41-4d3b-8e6f-1a2b3c4d5e6f
Process-IDheader · string
Group multiple Request-Response pairs to single process. Echoed back in the process-id response header. e.g. 7c1d2e3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f

Request body

identifierstring
Identifier of account for which to return transactions · e.g. Q7v_K2mNp4Xs
dateFromstring<date>
Limit results to be newer than specified date (YYYY-MM-DD) · e.g. 2026-09-01
dateTostring<date>
Limit results to be older than specified date (YYYY-MM-DD) · e.g. 2026-09-30
statusstring
Filter transactions by their state · one of BOOKED, INFO · e.g. BOOKED
pageSizeinteger
Number of results to return · default 50 · e.g. 20
pageinteger
Current page in pagination, starting at 0 · default 0 · e.g. 4

Response 200

pageCountinteger
Total number of pages after filtering · e.g. 3
transactionsobject[]
List of returned transactions
amountobject
Represent value with currency
valuestring
Decimal amount of money, serialized as a string · e.g. 3055.8500
currencystring
Currency code according to ISO 4217 - 3 capital letters · e.g. EUR
creditDebitIndicatorstring
Indicates if this transaction is credit or debit transaction · one of CRDT, DBIT · e.g. CRDT
reversalIndicatorboolean
Indicates if this transaction is rollback of some previous transaction · e.g. false
statusstring
Indicates whatever transaction was executed ("INFO") or is pending ("BOOKED") · one of INFO, BOOKED · e.g. INFO
bookingDatestring<date>
e.g. 2026-09-15
valueDatestring<date>
e.g. 2026-09-15
bankTransactionCodestring
"GHC" for fee transactions, "PM" for all other transactions · one of PM, GHC · e.g. PM
transactionDetailsobject
referencesobject
Attribute that identify transaction
accountServicerReferencestring
Internal service provider transaction reference · e.g. 184512
endToEndIdentificationstring | null
Transaction reference in the form /VS{variable symbol}/SS/KS, or null when the transaction has none · e.g. /VS20260915/SS/KS
relatedPartiesobject
Parties between which transaction is executed
debtorobject
namestring
Name of the party · e.g. Example Customer
debtorAccountobject
identificationstring
Globaly identifies party, can be internal identificator, IBAN, etc. e.g. CZ6508000000192000145399
creditorobject
namestring
Name of the party · e.g. Example Shop, s.r.o.
creditorAccountobject
identificationstring
Globaly identifies party, can be internal identificator, IBAN, etc. e.g. Q7v_K2mNp4Xs
relatedDatesobject
Important dates from transaction processing
acceptanceDateTimestring<date>
e.g. 2026-09-15

Other responses

401
Missing or invalid bearer token, or the token lacks the required scope.
Request
curl -X POST 'https://sandbox.payout.one/api/psd2/v1/accounts/transactions' \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
       "page": 2,
       "identifier": "Q7v_K2mNp4Xs"
     }'
Response 200
{
  "pageCount": 3,
  "transactions": [
    {
      "amount": {
        "value": "25.0000",
        "currency": "EUR"
      },
      "creditDebitIndicator": "CRDT",
      "reversalIndicator": false,
      "status": "INFO",
      "bookingDate": "2026-09-15",
      "valueDate": "2026-09-15",
      "bankTransactionCode": "PM",
      "transactionDetails": {
        "references": {
          "accountServicerReference": "184512",
          "endToEndIdentification": "/VS20260915/SS/KS"
        },
        "relatedParties": {
          "debtor": {
            "name": "Example Customer"
          },
          "debtorAccount": {
            "identification": "CZ6508000000192000145399"
          },
          "creditor": {
            "name": "Example Shop, s.r.o."
          },
          "creditorAccount": {
            "identification": "Q7v_K2mNp4Xs"
          }
        },
        "relatedDates": {
          "acceptanceDateTime": "2026-09-15"
        }
      }
    }
  ]
}
POST

standard sba payment

/api/psd2/v1/payments/standard/sba

Initialize payment using json format. The order is created in status PDNG and is executed only after it is submitted with submit payment.

Parameters

Correlation-IDheader · string
Match request to response. Echoed back in the correlation-id response header. e.g. 5f0c7b9e-2a41-4d3b-8e6f-1a2b3c4d5e6f
Process-IDheader · string
Group multiple Request-Response pairs to single process. Echoed back in the process-id response header. e.g. 7c1d2e3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f

Request body

instructionIdentification requiredstring
Client assigned instruction identification · max 255 · e.g. aff52ratg5ageh53
debtor requiredobject
identifier requiredstring
Debtor identifier, the account identifier (identification.identifier from list accounts) · max 255 · e.g. Q7v_K2mNp4Xs
creditor requiredobject
name requiredstring
Full name or company name of creditor · max 255 · e.g. Example Supplier, s.r.o.
iban requiredstring
max 255 · e.g. SK3112000000198742637541
email requiredstring
max 255 · e.g. billing@example.com
instructedAmount requiredobject
value requirednumber
Number with two decimals representing money amount · e.g. 12.5
currency requiredstring
Currency code according to ISO 4217 · max 255 · e.g. EUR
endToEndIdentificationstring
Client assigned transaction reference. In the form /VS{variable symbol}/SS{specific symbol}/KS{constant symbol} the variable symbol becomes the payment reference; it must be numeric with at most 10 digits, otherwise the submission is refused. max 255 · e.g. /VS20261006/SS/KS
remittanceInformationstring
max 255 · e.g. Invoice 2026-104

Response 201

orderIdstring<uuid>
e.g. 3b0f6c2e-8d41-4a7b-9c55-1e2f3a4b5c6d
statusstring
"PDNG" - created, not submitted yet; "ACSC" - submitted, payment created; "RJCT" - submission refused (returned only by submit payment) · one of PDNG, ACSC, RJCT · e.g. PDNG
statusDatetimestring<date-time>
Date and time when status was read · e.g. 2026-10-06T08:15:30.123456Z

Other responses

400
The body is not valid JSON, a required attribute is missing, or a path parameter has the wrong format.
401
Missing or invalid bearer token, or the token lacks the required scope.
404
No account with the debtor identifier exists.
Request
curl -X POST 'https://sandbox.payout.one/api/psd2/v1/payments/standard/sba' \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
       "instructionIdentification": "aff52ratg5ageh53",
       "debtor": {
         "identifier": "Q7v_K2mNp4Xs"
       },
       "creditor": {
         "name": "Example Supplier, s.r.o.",
         "iban": "SK3112000000198742637541",
         "email": "billing@example.com"
       },
       "instructedAmount": {
         "value": 12.5,
         "currency": "EUR"
       },
       "endToEndIdentification": "/VS20261006/SS/KS",
       "remittanceInformation": "Invoice 2026-104"
     }'
Response 201
{
  "orderId": "3b0f6c2e-8d41-4a7b-9c55-1e2f3a4b5c6d",
  "status": "PDNG",
  "statusDatetime": "2026-10-06T08:15:30.123456Z"
}
POST

submit payment

/api/psd2/v1/payments/submission

Submit initialized payment for processing. This request is done only with access token that can be retrieved using authorization_code oauth2 method against the order OAuth2 endpoint (the authorization URL followed by /{orderId}) and requires scope PISPSUBMIT.

The order is identified by the access token; the request has no body. Submitting an order that was already submitted returns it unchanged with 200.

Parameters

Correlation-IDheader · string
Match request to response. Echoed back in the correlation-id response header. e.g. 5f0c7b9e-2a41-4d3b-8e6f-1a2b3c4d5e6f
Process-IDheader · string
Group multiple Request-Response pairs to single process. Echoed back in the process-id response header. e.g. 7c1d2e3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f

Response 201

orderIdstring<uuid>
e.g. 3b0f6c2e-8d41-4a7b-9c55-1e2f3a4b5c6d
statusstring
"PDNG" - created, not submitted yet; "ACSC" - submitted, payment created; "RJCT" - submission refused (returned only by submit payment) · one of PDNG, ACSC, RJCT · e.g. PDNG
statusDatetimestring<date-time>
Date and time when status was read · e.g. 2026-10-06T08:15:30.123456Z

Other responses

200
The order was already submitted.
400
The payment was refused (for example, insufficient available balance). The body has status RJCT; its orderId is a newly generated UUID, not the ID of the submitted order.
401
Missing or invalid bearer token, or the token lacks the required scope.
Request
curl -X POST 'https://sandbox.payout.one/api/psd2/v1/payments/submission' \
  -H "Authorization: Bearer $TOKEN"
Response 201
{
  "orderId": "3b0f6c2e-8d41-4a7b-9c55-1e2f3a4b5c6d",
  "status": "ACSC",
  "statusDatetime": "2026-10-06T08:16:02.481530Z"
}
GET

order status

/api/psd2/v1/payments/{order_id}/status

Return actual status of the order

Parameters

order_id requiredpath · string<uuid>
Order ID returned as orderId by standard sba payment · e.g. 3b0f6c2e-8d41-4a7b-9c55-1e2f3a4b5c6d
Correlation-IDheader · string
Match request to response. Echoed back in the correlation-id response header. e.g. 5f0c7b9e-2a41-4d3b-8e6f-1a2b3c4d5e6f
Process-IDheader · string
Group multiple Request-Response pairs to single process. Echoed back in the process-id response header. e.g. 7c1d2e3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f

Response 200

orderIdstring<uuid>
e.g. 3b0f6c2e-8d41-4a7b-9c55-1e2f3a4b5c6d
statusstring
"PDNG" - created, not submitted yet; "ACSC" - submitted, payment created; "RJCT" - submission refused (returned only by submit payment) · one of PDNG, ACSC, RJCT · e.g. PDNG
statusDatetimestring<date-time>
Date and time when status was read · e.g. 2026-10-06T08:15:30.123456Z

Other responses

400
The body is not valid JSON, a required attribute is missing, or a path parameter has the wrong format.
401
Missing or invalid bearer token, or the token lacks the required scope.
404
The account or order does not exist, or the account was not granted to the TPP.
Request
curl -X GET 'https://sandbox.payout.one/api/psd2/v1/payments/{order_id}/status' \
  -H "Authorization: Bearer $TOKEN"
Response 200
{
  "orderId": "3b0f6c2e-8d41-4a7b-9c55-1e2f3a4b5c6d",
  "status": "PDNG",
  "statusDatetime": "2026-10-06T08:15:30.123456Z"
}
POST

balance check

/api/psd2/v1/accounts/balanceCheck

Check if account has enough resources to fulfill specified request. The response is APPR when the available balance in the requested currency is greater than amount, otherwise DECL.

Parameters

Correlation-IDheader · string
Match request to response. Echoed back in the correlation-id response header. e.g. 5f0c7b9e-2a41-4d3b-8e6f-1a2b3c4d5e6f
Process-IDheader · string
Group multiple Request-Response pairs to single process. Echoed back in the process-id response header. e.g. 7c1d2e3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f

Request body

instructionIdentificationstring
Technical payment identificator generated by PIISP. Accepted but not evaluated. e.g. piisp-20261006-0001
creationDateTimestring<date-time>
The date and time in RFC3339 format at which a particular action has been requested or executed. Accepted but not evaluated. e.g. 2026-10-06T08:15:30+00:00
identifier requiredstring
Payout account unique identificator · e.g. Q7v_K2mNp4Xs
amount requiredobject
amount requiredinteger | string
Numeric value of the amount, as an integer or a decimal string such as "60.50". Fractional JSON numbers are not accepted. e.g. 6000
currency requiredstring
Alphabetic codes from ISO 4217. e.g. EUR

Response 200

responsestring
Either "APPR" or "DECL" one of APPR, DECL · e.g. APPR
dateTimestring<date-time>
The date and time in RFC3339 format at which a particular action has been requested or executed. e.g. 2026-10-06T08:15:30.123456+00:00

Other responses

400
The body is not valid JSON, a required attribute is missing, or a path parameter has the wrong format.
401
Missing or invalid bearer token, or the token lacks the required scope.
Request
curl -X POST 'https://sandbox.payout.one/api/psd2/v1/accounts/balanceCheck' \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
       "instructionIdentification": "piisp-20261006-0001",
       "identifier": "Q7v_K2mNp4Xs",
       "amount": {
         "amount": 6000,
         "currency": "EUR"
       }
     }'
Response 200
{
  "response": "APPR",
  "dateTime": "2026-10-06T08:15:30.123456+00:00"
}

Was this page helpful?