Implementation Guide: Vanquis Bank

Implementation Guide: Vanquis Bank

Announcements

Improvement

Delivery date

 

Improvement

Delivery date

 

Production API available for integration. For more information on how to integrate with our API or to access test accounts please raise a ticket to Vanquis Bank via the Open Banking Service Desk here

 

Sep 14, 2019 

eIDAS certificates are now supported in our Test facility

May 18, 2020 

 

eIDAS certificates are now supported in Production

May 29, 2020 

 

Implemented Payment Initiation APIs v3.1.7 Deprecated June 2026

Feb 24, 2021 

 

Implemented Account Information Service APIs v3.1.8

Jan 20, 2022

 

Implemented SCA-RTC v3.1.10

Nov 8, 2022

 

Switching off Vanquis online banking so PSUs will have to complete a consent journey via the Vanquis Bank app.

Summer 2026

 

Change to Production:

Improvement

Delivery date

Improvement

Delivery date

Production API available for integration. For more information on how to integrate with our API or to access test accounts please raise a ticket to Vanquis Bank via the Open Banking Service Desk here

Sep 14, 2019 

New internally-hosted test facility available which provides closer alignment to production interface

Nov 4, 2019 

Allowed AISP to send expiration date in the account access consent call. 

Jan 20, 2022

  • As part of v3.1.10 Implementation, Vanquis will introduced a long lived refresh token of 60 years.

  • Consent will not be expire and if the consent is revoked then need to create new consent.

  • AISP/CBPII/PISP consents created after implementation of v3.1.10 will no longer require re-authentication every 90 days. The new rules in place will ask for customer reconfirmation with the TPP not ASPSP.

  • Consents issued and authorised before v3.1.10 implementation will remain valid for 90 days.

  • There are no changes to Vanquis current implementation of Access Tokens. Third parties should continue to pass OAuth credentials in a Get Access Token call.  In response, the Vanquis authorisation server issues an access token, reuse the access token until it expires. When it expires, you can get a new token.

Nov 8, 2022

Added Pagination to Transactions endpoint.

Jun 23, 2026

Production and Test facility Full interface Specifications

General guidance notes:

  • For guidance on detailed documentation of the Read/Write Data API specifications please visit the appropriate section on the Open Banking Developer Zone

  • We are currently supporting version 3.1.10 for AISP, CBPII specifications of the Open Banking Standard

  • App-to-app redirection is only supported in Production not in the test facility.

  • For all related implementation support please raise a ticket to Vanquis Bank via the Open Banking Service Desk here

  • Dynamic Client Registration is enabled and is mandatory

  • Supported endpoint token methods: private_key_jwt

  • Supported grant types: client_credentials & authorisation_code

  • Display of data IDs (e.g. transactionid & statementid) in REST responses is enabled

  • The Open API test facility should not be used for load testing

 

This page has been created and maintained by the relevant ASPSP, and OBIE takes no liability for the completeness nor accuracy of this data.

Note to ASPSP: Please indicate which brands this applies to and/or duplicate this page per brand if relevant.

 

ASPSP

Vanquis Bank

 

Brand

Vanquis Bank

 

Date

13/09/2019

 

Developer portal (s)

https://www.vanquis.co.uk/developer-portal

 


On-boarding

Supports dynamic client registration (Y/N)

Yes

Instructions for manual onboarding

Manual on-boarding is not supported.

OIDC .well-known endpoint

Production: https://auth.openbanking.vanquis.co.uk/.well-known/openid-configuration

Test facility: https://sandbox.auth.openbanking.vanquis.co.uk/.well-known/openid-configuration

Notes on testing

Please raise a ticket to Vanquis Bank via the Open Banking Service Desk here to request Test accounts

Other on-boarding notes

TPP's can on-board with us directly using Open Banking UK Eco-system issued certificates. Please follow the details below:

On-boarding via Open Banking U.K. Eco-system

  1. Register/Enroll with Open Banking

  2. Submit Software Statement Assertion to Client Registration endpoint:

    1. Productionhttps://mtls.auth.openbanking.vanquis.co.uk/connect/register

    2. Test facilityhttps://sandbox.mtls.auth.openbanking.vanquis.co.uk/connect/register

  3. Follow the instructions on https://www.vanquis.co.uk/developer-portal for help to get started.  

 

Documentation URL

 

Implementation Guide: Vanquis Bank

Tips/Notes for TPP's

Based on the recent TPP queries the following section should help third parties to connect with Vanquis Bank Open banking system.

  • For client registration we only support PS256 algorithm and NOT RS256.

  • The "aud" value varies depending on the call during the dynamic client registration and Consent flows as given in the table below.

  • "ReadAccountsBasic" is a Mandatory permission to access the accounts data even when the "ReadAccountsDetail" permission is requested.

  • "ReadTransactionsBasic" is a Mandatory permission to access the transaction data even when the "ReadTransactionsDetail" permission is requested.

  • "ReadStatementsBasic" is a Mandatory permission to access the statement data even when the "ReadStatementsDetail" permission is requested.

  • "ReadProducts" permission is NOT supported. API calls will fail if this is included in the request.

  • Transaction date range CAN NOT be in the future to access the transactions data. We only expose the last 6 months worth of transactions data.

  • Clients requesting data via MTLS end points for Sandbox (i.e. Test facility) environment should pass Client Certificates issued by Open banking Pre-production Issuer and CA.

  • Clients requesting data via MTLS end points for Production environment should pass Client Certificates issued by Open banking Production Issuer and CA.

Please note that we are continuously improving API's based on feedback, For feedback or further information please raise a ticket to Vanquis Bank via the Open Banking Service Desk here

Our Certifications

Title

Description

Title

Description

Open ID (Security Conformance)

https://openid.net/certification/#FAPI_OPs 

Open Banking UK (Functional Conformance)

Functional Conformance

Test Account details

 

  • Test accounts for both the test facility and production are available on request, please raise a ticket to Vanquis Bank via the Open Banking Service Desk here

Account and Transaction API

Note to ASPSP: Please add a column per brand if relevant

Swagger version

We currently support version 3.1

See JSON version: https://raw.githubusercontent.com/OpenBankingUK/read-write-api-specs/v3.1.0/dist/account-info-swagger.json

See YAML version: https://raw.githubusercontent.com/OpenBankingUK/read-write-api-specs/v3.1.0/dist/account-info-swagger.yaml

Base URI

Production: https://mtls.data.openbanking.vanquis.co.uk/open-banking/v3.1/aisp/

Test facility: https://sandbox.mtls.data.openbanking.vanquis.co.uk/open-banking/v3.1/aisp/

General variances to specification 

Please see above "Tips/Notes for TPP's" section

Non-functional limitations

  • Live environment hence unsuitable for load testing

  • Transaction History - We support 6 months transaction history

  • Pagination - supported in our transactions endpoints

  • Re-authentication/Authorization - Access token lifetime is 10 minutes

  • Refresh tokens are supported, lifetime is 60years

 

The following endpoints are implemented and will return data where applicable

Ref

Resource

Endpoints

Notes

Ref

Resource

Endpoints

Notes

1

Account Access Consents

  • POST /account-access-consents

  • GET /account-access-consents/{ConsentId}

  • DELETE /account-access-consents/{ConsentId}

Supported permissions are:

  • ReadAccountsBasic

  • ReadAccountsDetail

  • ReadBalances

  • ReadOffers

  • ReadStatementsBasic

  • ReadStatementsDetail

  • ReadTransactionsBasic

  • ReadTransactionsCredits

  • ReadTransactionsDebits

  • ReadTransactionsDetail

If requests are made, including non-supported permissions, the request will fail

2

Accounts

  • GET /accounts

  • GET /accounts/{AccountId}

Example

Production: GET https://mtls.data.openbanking.vanquis.co.uk/open-banking/v3.1/aisp/accounts

Test facility: GET https://sandbox.mtls.data.openbanking.vanquis.co.uk/open-banking/v3.1/aisp/accounts

  • GET/accounts command is always required as first call to generate AccountId

3

Balances

  • GET /accounts/{AccountId}/balances

  • GET /balances

 

 4

Transactions

  • GET /accounts/{AccountId}/transactions

  • GET /transactions

 

 5

Offers

  • GET /accounts/{AccountId}/offers

  • GET /offers

 

 6

Statements

  • GET /accounts/{AccountId}/statements

  • GET /accounts/{AccountId}/statements/{StatementId}

  • GET /accounts/{AccountId}/statements/{StatementId}/transactions

  • GET /statements

 

 

The following table highlights endpoints which will return '404 resource not found'

Ref

 Resource

Endpoints

Notes 

Ref

 Resource

Endpoints

Notes 

1

Products

  • GET /accounts/{AccountId}/product

  • GET /products

 

2

Party

  • GET /accounts/{AccountId}/party

  • GET /party

 

3

Beneficiaries

  • GET /accounts/{AccountId}/beneficiaries

  • GET /beneficiaries

 

4

Direct Debits

  • GET /accounts/{AccountId}/direct-debits

  • GET /direct-debits

 

5

Standing-orders

  • GET /accounts/{AccountId}/standing-orders

  • GET /standing-orders

 

6

Scheduled payments

  • GET /accounts/{AccountId}/scheduled-payments

  • GET /scheduled-payments

 

7

Statements

  • GET /accounts/{AccountId}/statements/{StatementId}/file

  • All other statements endpoints are implemented, only statement/file is not implemented.

Confirmation of Availability of Funds

The following endpoints are implemented and will return data where applicable

Ref

Resource

Endpoints

Notes

Ref

Resource

Endpoints

Notes

1

Funds Confirmation Consent

  • POST /funds-confirmation-consents

  • GET /funds-confirmation-consents/{ConsentId}

  • DELETE /funds-confirmation-consents/{ConsentId}

Example

Production: POST https://mtls.data.openbanking.vanquis.co.uk/open-banking/v3.1/cbpii/funds-confirmation-consents

Test facility: POST https://sandbox.mtls.data.openbanking.vanquis.co.uk/open-banking/v3.1/cbpii/funds-confirmation-consents

  • Please note full 16 Digits PAN will be required to gain the consent successfully.

 2

Funds Confirmation

 POST /funds-confirmations

 

 

Payment Initiation API

Swagger version

Deprecated June 2026

Base URI

 

General variances to specification 

 

Non-functional limitations

 

 

The following table highlights endpoints which will return '404 resource not found'

Ref

 Resource

Endpoints

Notes 

Ref

 Resource

Endpoints

Notes 

1

Domestic Scheduled Payments

  • POST /domestic-scheduled-payment-consents

  • GET /domestic-scheduled-payment-consents/{ConsentId}

  • POST /domestic-scheduled-payments

  • GET /domestic-scheduled-payments/{DomesticScheduledPaymentId}

 

2

Domestic Standing Orders

  • POST /domestic-standing-order-consents

  • GET /domestic-standing-order-consents/{ConsentId}

  • POST /domestic-standing-orders

  • GET /domestic-standing-orders/{DomesticStandingOrderId}

 

3

International Payments

  • POST /international-payment-consents