Skip to main content

Open Banking API - Berlin Group Reference

Version: Berlin Group v1.3

The Paysera Open Banking API provides PSD2-compliant access to account information and payment initiation services through standardized Berlin Group NextGenPSD2 interfaces for EU-wide operations.

Base URL​

  • Production: https://open-banking-api.paysera.com/xs2a/berlin/1.3/v1
Looking for Georgia Standard?

For Georgian market integration, visit Open Banking for Georgia documentation.

Authentication​

All Open Banking API endpoints are protected by mTLS using a valid QWAC certificate. For the consent and payment endpoints the certificate is the only credential needed — creating a consent or a payment, reading it, reading its status and listing its authorisations all work with the certificate alone. Payment cancellation is not supported.

Reading account data additionally requires an OAuth 2.0 access token, obtained after the PSU has completed SCA, together with the Consent-ID of the consent that granted the access. This covers the account list, account details, balances, transactions and transaction details (and card account transactions).

Consent and payment endpoints — certificate only:

curl https://open-banking-api.paysera.com/xs2a/berlin/1.3/v1/payments/sepa-credit-transfers/{paymentId} \
--cert qwac-cert.pem \
--key qwac-key.pem \
-H "X-Request-ID: $(uuidgen)"

Account data endpoints — certificate, access token and consent:

curl https://open-banking-api.paysera.com/xs2a/berlin/1.3/v1/accounts \
--cert qwac-cert.pem \
--key qwac-key.pem \
-H "Authorization: Bearer <access_token>" \
-H "Consent-ID: <consent_id>" \
-H "X-Request-ID: $(uuidgen)"

This API has no request-signing step — a QSealC certificate is not used and signature headers are not read. See Security.

For more details, please refer to the Open Banking API Authentication Documentation.

API Features​

Payment Initiation Services (PIS)​

Initiate SEPA credit transfers, instant SEPA, TARGET2 payments, and domestic RON transfers. Payments are authorised with Strong Customer Authentication and their status can be tracked. Payment cancellation is not supported.

Account Information Services (AIS)​

Access account lists, details, real-time balances, and transaction history. Multi-currency account support with secure consent-based access.

Create and manage account access consents. The PSU authorises each consent through the redirect SCA approach over OAuth 2.0.

Card Accounts​

Read the transaction history of payment card accounts.

Strong Customer Authentication (SCA)​

One SCA approach is supported: redirect over OAuth 2.0. Payment and consent creation responses carry ASPSP-SCA-Approach: REDIRECT and a scaOAuth link that points at the OAuth 2.0 authorisation server metadata document. Read it, then send the PSU through its authorization_endpoint. The embedded and decoupled approaches are not supported, and Paysera does not return a scaRedirect link.

Pagination​

Only the transaction list endpoints are paginated. They return up to 50 transactions per page; the page size is fixed and no parameter changes it. When more transactions exist in the requested period, the response carries a _links.next entry at its root pointing at the following page. Follow it until it is no longer present — a response without it is the last page.

Example:

GET /xs2a/berlin/1.3/v1/accounts/{account-id}/transactions?dateFrom=2026-03-01&bookingStatus=both&offset=50

Every other list endpoint returns its full result set in one response.

Rate Limits​

The API implements rate limiting to ensure service stability. If you exceed the rate limit, you will receive a 429 Too Many Requests response.

Contact​

Paysera Support: tech_support@paysera.com Website: https://www.paysera.com