Tesco 403 Forbidden From /transactions

Description

Hello, we are getting a HTTP403 response when requesting the /transactions endpoint. We successfully used a refresh_token in our /token endpoint and received a bearer token in the response. We can also get the account's balances successfully.

Request
GET https://ob.api.tescobank.com/open-banking/v3.1/aisp/accounts/778bdb20e5104db7a19ba82025d41f1a/transactions?fromBookingDateTime=2019-10-22T00%3A00%3A00&toBookingDateTime=2019-10-29T23%3A59%3A59 HTTP/1.1
Authorization: Bearer jrpgGW8ggShuQztcdF7xaWKrNRXt
x-fapi-financial-id: 0015800001041RXAAY
accept: application/json

Response
HTTP/1.1 403 Forbidden
date: Tue, 29 Oct 2019 09:53:50 GMT
content-length: 142
connection: keep-alive
via: 1.1 lon1-bit15

{"Code":"UK.OBIE.Reauthenticate","Id":"ac615b0f-0c5b-4429-a0df-e98427c944f6","Message":"Reauthentication required for request"}

Please investigate and advise. Thank you.

This is the response when requesting the token that is used in the above request
HTTP/1.1 200 OK
cache-control: no-cache, no-store
content-type: application/json;charset=utf-8
date: Tue, 29 Oct 2019 09:53:47 GMT
expires: Thu, 01 Jan 1970 00:00:00 GMT
pragma: no-cache
referrer-policy: origin
set-cookie: PF=FLh8UOWGWIdAJ6ClnUwqFm;Path=/;Secure;HttpOnly,TS01d8e832=013005f00141b55b2fe9feab1878f45ea272ca1a02e062ff6fd247f97fcb7e8740486697c5d346211bb9807e4354ad019cab947fef97a0fdfc7a5848cad007f82646b090dc; Path=/; Secure; HTTPOnly
x-frame-options: SAMEORIGIN
content-length: 147
connection: keep-alive
via: 1.1 lon1-bit19

{"access_token":"jrpgGW8ggShuQztcdF7xaWKrNRXt","refresh_token":"iLF9vRCWtcg7l61QhJRIHoUY1OZRkHRwl9LaQ6ebHR","token_type":"Bearer","expires_in":299}

Technical Impact

Tesco integration does not work when using refresh_token

Workaround

None

Resolution Notes

None

Impact Assessment

Tesco integration does not work when using refresh_token

Status

Assignee

Unassigned

Reporter

Service Desk

Reference

None

Service Desk Reference

OBSD-11992

ASPSP

Query Type

None

Created (Original)

Nov 06, 2019, 7:16 PM

TPP Impact

None

OB Environment

None

Business Impact Severity

Level 3

Share

Yes
Configure