🇪🇺 Berlin Group v1.3 - Read transaction list of an account
GET https://open-banking-api.paysera.com/xs2a/berlin/1.3/v1/card-accounts/{account-id}/transactions
Reads account data from a given card account addressed by "account-id".
Authorization​
This endpoint requires mTLS (Mutual TLS) authentication using a valid QWAC certificate,
an OAuth 2.0 access token and the Consent-ID of the consent that granted the access.
Requirements:
- Valid QWAC certificate issued by a qualified trust service provider (QTSP)
- Certificate must be registered with Paysera
- Certificate organization identifier must match your TPP registration in the EBA register
X-Request-IDheader with a UUID on every requestAuthorization: Bearer <access_token>header with the access token issued when the PSU authorised the consentConsent-IDheader with the ID of that consent; a request without it is rejected with400 FORMAT_INVALID
Request signing: not used. This API does not read the Digest, x-jws-signature or
TPP-Signature-Certificate headers — see
Security.
Example (cURL):
curl "https://open-banking-api.paysera.com/xs2a/berlin/1.3/v1/card-accounts/$ACCOUNT_ID/transactions?bookingStatus=booked&dateFrom=2026-01-01" \
--cert qwac-cert.pem \
--key qwac-key.pem \
-H "X-Request-ID: $(uuidgen)" \
-H "Authorization: Bearer $ACCESS_TOKEN" \
-H "Consent-ID: $CONSENT_ID"
For detailed authentication guide, see Authentication.
Parameters​
Path Parameters​
| Name | Type | Required | Description |
|---|---|---|---|
account-id | string | ✓ | This identification is denoting the addressed (card) account. |
| The account-id is retrieved by using a "Read Account List" or "Read Card Account list" call. | |||
| The account-id is the "resourceId" attribute of the account structure. | |||
| Its value is constant at least throughout the lifecycle of a given consent. | |||
Query Parameters​
| Name | Type | Required | Description |
|---|---|---|---|
dateFrom | string | Conditional: Starting date (inclusive the date dateFrom) of the transaction list, mandated if no delta access is required | |
| and if bookingStatus does not equal "information". |
For booked transactions, the relevant date is the booking date.
For pending transactions, the relevant date is the entry date, which may not be transparent
neither in this API nor other channels of the ASPSP.
|
| dateTo | string | | End date (inclusive the data dateTo) of the transaction list, default is "now" if not given.
Might be ignored if a delta function is used.
For booked transactions, the relevant date is the booking date.
For pending transactions, the relevant date is the entry date, which may not be transparent
neither in this API nor other channels of the ASPSP.
|
| entryReferenceFrom | string | | This data attribute is indicating that the AISP is in favour to get all transactions after
the transaction with identification entryReferenceFrom alternatively to the above defined period.
This is a implementation of a delta access.
Not supported by Paysera — see the note below the table.
|
| bookingStatus | string | ✓ | Permitted codes are
- "booked",
- "pending" and
- "both"
"both" means to request transaction reports of transactions of bookingStatus either "pending" or "booked".
|
|
deltaList| boolean | | This data attribute is indicating that the AISP is in favour to get all transactions after the last report access for this PSU on the addressed account. This is another implementation of a delta access-report. Not supported by Paysera — see the note below the table. | |offset| integer | | Number of transactions to skip before the returned page. Default 0.
Paysera uses this parameter for pagination: the next link in the response increments it by the page size, which is fixed at 50. Follow the next link as given rather than setting this parameter yourself.
|
entryReferenceFrom and deltaList are defined by the Berlin Group standard but are not
supported. A request containing either is rejected with 400 PARAMETER_NOT_SUPPORTED.
Response format​
The response carries the fields of an account transaction: transactionId, bookingDate,
valueDate, transactionAmount, and the counterparty IBAN in creditorAccount (debits) or
debtorAccount (credits). The card-specific fields the Berlin Group standard defines for card
transactions, such as maskedPAN, cardAcceptorId, merchantCategoryCode and markupFee, are not
populated. The cardAccount and transactionDetails links point at the account endpoints under
/v1/accounts/.
This is the only card account operation available: the card account list, card account details and card account balances are not supported.
Transaction collections​
Inside cardTransactions, the collections are decided by the bookingStatus you ask for, not
by whether anything was found. For the three bookingStatus values listed above, a requested
collection is always present, and is an empty array when the account has no transactions of that
kind in the requested period:
bookingStatus | Collections returned |
|---|---|
booked | booked |
pending | pending |
both | booked and pending, both always present |
Pagination​
Transactions are returned in pages of up to 50. The page size is fixed — no parameter changes it.
When further transactions exist in the requested period, the response carries a _links.next entry
pointing at the following page:
"_links": {
"first": { "href": "/xs2a/berlin/1.3/v1/card-accounts/{account-id}/transactions?dateFrom=2026-03-01&bookingStatus=both" },
"next": { "href": "/xs2a/berlin/1.3/v1/card-accounts/{account-id}/transactions?dateFrom=2026-03-01&bookingStatus=both&offset=50" }
}
These links sit at the root of the response, next to cardAccount and cardTransactions —
not inside cardTransactions._links, which carries only the cardAccount link.
Follow _links.next until it is no longer present. A response without it is the last page.
_links.first is present on every transaction list response, including a single-page one. Reading
only the first response returns an incomplete list — this is normal paginated behaviour, not an
error. Both hrefs are paths on the host you called, so treat each as opaque and request it as given
rather than constructing it yourself.
The Berlin Group standard also admits a download link alongside them, for reports of a huge size.
Paysera does not return one.
Errors​
This endpoint may return the following errors. The list is shared by every endpoint of this API, so not every code applies to every endpoint.
Every error listed below is returned with a tppMessages array. Each message has a category and a code, and may add a path (the header or field at fault) and a text.
400 - Bad Request​
The request could not be understood by the server due to malformed syntax or invalid parameters.
Common error codes:
CONSENT_UNKNOWN- The consent in theConsent-IDheader is unknown or cannot be used by this TPPFORMAT_ERROR- Invalid request format or syntax, for example a malformed body field or anX-Request-IDthat is not a UUIDFORMAT_INVALID- The mandatoryConsent-IDheader is missingPARAMETER_NOT_SUPPORTED- Request contains unsupported parametersPERIOD_INVALID- The requested consent validity period is outside the allowed rangeSERVICE_INVALID- The addressed service is not valid for the addressed resourcesSESSIONS_NOT_SUPPORTED- Combined AIS and PIS sessions (combinedServiceIndicator) are not supported
Example response:
{
"tppMessages": [
{
"category": "ERROR",
"code": "FORMAT_ERROR",
"path": "X-Request-ID",
"text": "Request ID must be a valid UUID string."
}
]
}
401 - Unauthorized​
The certificate, the access token or the consent could not be used to authenticate the request.
Common error codes:
CERTIFICATE_INVALID- The TPP certificate is not valid or is not registered with PayseraCERTIFICATE_MISSING- The TPP certificate is missing in the requestCONSENT_EXPIRED- The consent has expired and can no longer be usedCONSENT_INVALID- The consent is invalid for this operationROLE_INVALID- The TPP certificate does not have the role this endpoint requires (AIS or PIS)TOKEN_INVALID- The access token does not carry the scope this endpoint requiresTOKEN_EXPIRED- The access token has expired, has been revoked or could not be verifiedTOKEN_UNKNOWN- The access token is unknown or invalid
Example response:
{
"tppMessages": [
{
"category": "ERROR",
"code": "CERTIFICATE_INVALID"
}
]
}
403 - Forbidden​
The TPP does not have the necessary permissions or the resource access is forbidden.
Common error codes:
CONSENT_UNKNOWN- The addressed consent is unknown to this TPP, or the TPP may not perform this consent operationRESOURCE_UNKNOWN- The addressed resource is unknown to this TPP
Example response:
{
"tppMessages": [
{
"category": "ERROR",
"code": "CONSENT_UNKNOWN"
}
]
}
404 - Not Found​
The requested resource could not be found.
Common error codes:
RESOURCE_UNKNOWN- The addressed resource is not found or does not existSERVICE_INVALID- The request path does not match any endpoint of this API
Example response:
{
"tppMessages": [
{
"category": "ERROR",
"code": "RESOURCE_UNKNOWN"
}
]
}
405 - Method Not Allowed​
The HTTP method used is not allowed for this endpoint.
Common error codes:
SERVICE_INVALID- The HTTP method is not supported for this service
Example response:
{
"tppMessages": [
{
"category": "ERROR",
"code": "SERVICE_INVALID"
}
]
}
429 - Too Many Requests​
The TPP has used up the account data accesses its consent allows.
Each consent allows its agreed frequencyPerDay accesses (4 by default, or a higher value agreed with Paysera) to each account data resource per 24 hours. Requests sent with the PSU-IP-Address header under a recurring consent do not count towards the limit.
Common error codes:
ACCESS_EXCEEDED- The consent'sfrequencyPerDaylimit for this resource has been reached
Example response:
{
"tppMessages": [
{
"category": "ERROR",
"code": "ACCESS_EXCEEDED"
}
]
}
500 - Internal Server Error​
An unexpected error occurred on the server side. This indicates a problem with the ASPSP's system. Please try again later or contact Paysera support if the issue persists.
Common error codes:
INTERNAL_SERVER_ERROR- The request could not be completed; try again laterINVALID_TPP_CONFIGURATION- The TPP's configuration at Paysera is invalid; contact Paysera support
Example response:
{
"tppMessages": [
{
"category": "ERROR",
"code": "INTERNAL_SERVER_ERROR"
}
]
}
Example​
Request​
GET https://open-banking-api.paysera.com/xs2a/berlin/1.3/v1/card-accounts/{account-id}/transactions?dateFrom=value&dateTo=value&bookingStatus=value&offset=value
X-Request-ID: 99391c7e-ad88-49ec-a2ad-99ddcb1f7721
Authorization: Bearer <access_token>
Consent-ID: 7f5eb2a1-4c3d-4f2b-9a6e-1d8c0b5a3e94
# plus the QWAC certificate presented during the TLS handshake
Response​
{
"cardAccount": {
"iban": "DE87200500001234567890"
},
"cardTransactions": {
"booked": [
{
"transactionId": "88213401",
"bookingDate": "2026-06-17",
"valueDate": "2026-06-17",
"transactionAmount": {
"currency": "EUR",
"amount": "42.90"
},
"creditorAccount": {
"iban": "LT601010012345678901"
},
"_links": {
"transactionDetails": {
"href": "/xs2a/berlin/1.3/v1/accounts/e1c0aaef-0cbe-42ef-b520-54a2f04d391f/transactions/88213401"
}
}
}
],
"pending": [],
"_links": {
"cardAccount": {
"href": "/xs2a/berlin/1.3/v1/accounts/e1c0aaef-0cbe-42ef-b520-54a2f04d391f"
}
}
},
"_links": {
"first": {
"href": "/xs2a/berlin/1.3/v1/card-accounts/e1c0aaef-0cbe-42ef-b520-54a2f04d391f/transactions?dateFrom=2026-06-01&dateTo=2026-06-30&bookingStatus=both"
}
}
}
AUTHORIZATION: HTTP
REQUEST
RESPONSE
{
"cardAccount": {
"iban": "DE87200500001234567890"
},
"cardTransactions": {
"booked": [
{
"transactionId": "88213401",
"bookingDate": "2026-06-17",
"valueDate": "2026-06-17",
"transactionAmount": {
"currency": "EUR",
"amount": "42.90"
},
"creditorAccount": {
"iban": "LT601010012345678901"
},
"_links": {
"transactionDetails": {
"href": "/xs2a/berlin/1.3/v1/accounts/e1c0aaef-0cbe-42ef-b520-54a2f04d391f/transactions/88213401"
}
}
}
],
"pending": [],
"_links": {
"cardAccount": {
"href": "/xs2a/berlin/1.3/v1/accounts/e1c0aaef-0cbe-42ef-b520-54a2f04d391f"
}
}
},
"_links": {
"first": {
"href": "/xs2a/berlin/1.3/v1/card-accounts/e1c0aaef-0cbe-42ef-b520-54a2f04d391f/transactions?dateFrom=2026-06-01&dateTo=2026-06-30&bookingStatus=both"
}
}
}