Work is underway internally on what TPP support will be available. We will update this page when more information is available.
POST-BREXIT Certificate Implementation Status (updated by OBIE IES team
SCA-RTS
Which date are you planning on implementing the SCA reauthentication exemption?
27 September 2022
27 September 2022
What is your approach to token management to enable application of the reauthentication exemption?(see link to FCA guidance)
We will implement the exemption by issuing refresh tokens with no expiry date.
We will implement the exemption by issuing refresh tokens with no expiry date.
Existing consents
The first time that the 90 day refresh token is exchanged for an access token following our change, the new refresh token issued will have an unlimited expiry. Subsequent refresh tokens issued for the consent will continue to have unlimited expiry. The TPP can then go on to access exempt data for the consent on an ongoing basis, subject to consent expiry or revocation.
As long as the ‘old’ refresh token is exchanged before its original 90 day expiry, the customer will not need to re-authenticate with us. If it has been more than 90 days since the customer authenticated for the consent, we will not allow the refresh token to be exchanged for a new non-expiring one.
We will continue to ask for SCA when accessing non-exempt data under the consent, if it has not been done within 5 minutes.
New consents
Consents set up and authorised after our change goes live will use non-expiring refresh tokens for their lifetime. We will still require customers to complete SCA with us at authorisation, but customers will no longer need to come back to us every 90 days to re-authenticate.
We will ask for SCA when accessing non-exempt data under the consent, if it has not been done within 5 minutes.
We will continue to request SCA for non-exempt data requests.
Article 10A - Endpoints exempt of SCA-RTS
Accounts
Transactions (90days)
Balances
Standing orders
Direct debits
Beneficiaries
Products
Offers
Parties
Scheduled Payments
Statements
Article 10A - Endpoints not exempt of SCA-RTS
Transactions (more than 90days)
Standing orders
Direct debits
Beneficiaries
Products
Offers
Parties
Scheduled Payments
Statements
Article 10A - Maximum time period after authentication
Please specify the time period in minutes
SCA-RTS implementation status(updated by OBL PS team only)
Status
colour
Green
title
READY
Implemented
Panel
titleColor
Black
borderStyle
dashed
title
ImplementationSecurity Profile
Page Properties
id
TCID-IMP
Directory?
Open Banking
Location of Well Known Endpoints?
OB Technical Directory and OB Implementation Guide
API Standard Implemented?
Open Banking
Name of Account Holder Implementation Date?
Completed -
Name of account holder is returned via the party endpoint
Date of Current eIDAS Implementation?
MTLS
Current Certificates used for Identification?
Current Certificates used for Transport?
OB Transport (non-eIDAS-like)
Current Certificates used for Signing?
OB Signing (non-eIDAS-like)
Date of Future eIDAS Implementation?
No future update currently planned.
Future Certificates used for Identification?
No future update currently planned.
Future Certificates used for Transport?
No future update currently planned.
Future Certificates used for Signing?
No future update currently planned.
Major Milestones
SCA is already in place at log in for the existing Online and Mobile channels and was in place pre-PSD2.
Production date for SCA in the Open Banking channel to be provided.