W007
Description | The OBIE R/W API specification (in v3.0, 3.1, 3.1.1, 3.1.2 and 3.1.3) require both TPPs and ASPSPs to sign all payment messages (JSON Web Signatures JWS). Non-repudiation requirements are met through the use of a number of extensions including RFC 7797. The OBIE specification makes use of the "b64" header parameter and currently enforces the following:
The |
---|---|
Risk assessment |
|
Mitigating controls | Immediate action
In the longer term
OBIE will work with ASPSPs, TPPs and vendors to ensure that this is effectively communicated. |
Impact if refused |
|
Financial cost (if any) £ | Not known |
Resource cost (if any) £ | Not known |
© Open Banking Limited 2019 | https://www.openbanking.org.uk/open-licence | https://www.openbanking.org.uk