For third-party payment service providers (TPPs)

ProCredit Bank Open Banking API

ProCredit Bank provides connectivity with authorised payment service providers through standardised Open Banking interfaces in accordance with the requirements of Ukrainian legislation and Open Banking standards.


This solution has been implemented to support the secure exchange of data and payment messages between the Bank and third-party payment service providers (TPPs) based on the customer's consent. The Bank’s dedicated interfaces enable interaction with authorised third-party payment service providers on a non-discriminatory basis in accordance with the requirements of Ukrainian legislation.

Available services

ProCredit Bank provides access through the following dedicated interfaces:

Account Information Service (AIS) – provision of information regarding a customer's accounts with the customer's consent, including:

  • a list of available accounts;
  • account balance information;
  • transaction data;
  • account details within the scope of the granted consent.


List of Dedicated Interfaces (in Ukrainian)


Access to accounts, account information, and the ability to initiate payment transactions are provided exclusively on the basis of a valid payment service user consent and in accordance with the requirements of Ukrainian legislation.

Functionality

The Open Banking API supports:

  • creation and management of customer consents;
  • access to account and transaction information;
  • initiation of credit transfers;
  • confirmation of the availability of funds;
  • verification of payment transaction status;
  • retrieval of request processing results;
  • use of Strong Customer Authentication (SCA) mechanisms.


All operations are carried out strictly within the scope of the permissions granted by the customer.


Dedicated interfaces functionality description (in Ukrainian)

Security and authentication

To ensure data protection and interaction between Open Banking participants, organisational and technical information security measures are applied, including:

  • secure API connections using TLS 1.2 or higher;
  • mutual TLS authentication between the Bank and TPPs;
  • OAuth 2.0 authorisation mechanisms and other protocols required by Open Banking standards;
  • use of qualified certificates (QWAC and other certificates required by Open Banking standards);
  • application of Strong Customer Authentication (SCA) procedures for account access and payment initiation;
  • verification of the validity of customer consent and TPP authorisation before processing requests;
  • access control, monitoring, and security event logging;
  • request validation and protection against unauthorised access;
  • information security incident management in accordance with the Bank’s internal procedures.

Technical specifications and implementation details

Information regarding the implementation specifics of the ProCredit Bank Open Banking API, including supported authentication mechanisms, integration-specific parameters, and other bank-specific requirements, is available via the link.

 

The API specification provides for:

  • REST API architecture;
  • JSON message exchange format;
  • standardised HTTP methods;
  • use of Open Banking authorisation mechanisms;
  • support for both testing and production environments.


Detailed technical specifications, request and response examples, parameter descriptions, and implementation scenarios are available through the technology operator's resources:

Testing environment (Sandbox)

A testing environment is available to support integration preparation and allows users to:

  • verify API functionality prior to production integration;
  • test AIS, PIS, and FCS scenarios;
  • practise authentication and authorisation procedures;
  • review request and response examples;
  • verify compatibility of their own solutions with the Bank’s services.


Information regarding connection to the testing environment is available in the technology operator's documentation:

Developer portal (in Ukrainian)

Sandbox documentation (in Ukrainian)

Testing programme description (in Ukrainian)

Service availability

Information regarding the availability of dedicated interfaces, service performance metrics, planned maintenance activities, and the status of the Open Banking API is published on the technology operator’s portal via the relevant link.

Connecting to the Open Banking API

To begin integration, it is necessary to:

  1. Hold the status of an authorised payment service provider in accordance with legal requirements.
  2. Review the technical documentation.
  3. Configure integration in the testing environment.
  4. Successfully complete the production readiness assessment.
  5. Connect to the production environment in accordance with the established procedure.


For technical questions regarding integration and connection to the Open Banking API, please contact:
ukr.openbanking@procredit-group.com


Requests are processed by the responsible Bank department on business days in accordance with the Bank’s internal procedures.

Interaction with third-party payment service providers (TPPs)

ProCredit Bank ensures interaction with third-party payment service providers in accordance with the requirements of Ukrainian legislation and the Bank’s internal regulations. Within the Open Banking framework, the Bank:

  • verifies TPP authorisation before granting access;
  • provides account access only where valid customer consent exists;
  • uses Strong Customer Authentication (SCA) mechanisms;
  • ensures logging and monitoring of all interactions via the Open Banking API;
  • provides information regarding planned maintenance and changes that may affect service availability;
  • processes enquiries, incidents, and complaints in accordance with the Bank’s internal procedures.


The Bank ensures that third-party payment service providers are informed of significant changes to dedicated interfaces that may affect integration or the use of Open Banking services.

Incident reporting

In the event of technical issues, connection errors, suspected information security incidents, or questions related to the operation of the Open Banking API, please contact: ukr.openbanking@procredit-group.com


The Bank ensures the handling of requests and interaction with third-party payment service providers in accordance with its internal incident management and business continuity procedures.

Service and documentation updates

ProCredit Bank reserves the right to make changes to dedicated interfaces, technical documentation, and interaction procedures in accordance with legal requirements, regulations of the National Bank of Ukraine, and information security requirements.