AIS Data
Account data by account access: accounts, balances and transactions the user shares from their own bank
Universe: Umbrella
Status: beta
Credentials on request. Sandbox demo available.
What it answers
The end user logs in to their own bank and gives a one-time, read-only consent. AIS Data reads what is in the account: the accounts the user shares, their balances and their transactions, as returned by the bank. Money is never moved. The login stays at the bank; no bank credentials are stored.
AIS Data reads the account data; it does not confirm the holder. To confirm who holds an account and match the holder name, use AIS Ident.
Flow
Bank selection -> Bank login -> Consent -> SCA -> Data retrieval -> Accounts, balances, transactions -> Result- Bank selection: the user picks their bank in the hosted flow (
countrypre-selects the country). - Bank login: the user logs in at their own bank, on the bank website or in the banking app.
- Consent: one-time, read-only consent to the data in
accessTypes. - SCA: the user confirms the consent with strong customer authentication at the bank.
- Data retrieval: the accounts the user selects are read from the bank.
- Accounts, balances, transactions: per account
name,type,iban,bic,accountHolderName, and, as requested,balanceandtransactions. - Result: via
POST /ais/data/statusand the webhook.
Access types
accessTypes | Returns |
|---|---|
ACCOUNTS | Account name, type (CURRENT, SAVINGS, OTHER), IBAN, BIC and holder name. Always included. |
BALANCES | balance.current and balance.available, each { value, currency }. |
TRANSACTIONS | transactions[]: id, booking date, description, amount { value, currency }. Limit the range with transactionsFrom and transactionsTo. |
Amounts are decimal strings, negative for debits. The holder name is not guaranteed: some banks
return none, and then accountHolderName is null.
Integration in four calls
Base URLs are in Environments.
1. Authenticate
curl -X POST "$UMBRELLA_BASE_URL/auth" \
-H "Api-Key: $UMBRELLA_API_KEY" \
-H "Customer-Id: $UMBRELLA_CUSTOMER_ID" \
-H "Content-Type: application/x-www-form-urlencoded"2. Start a session
curl -X POST "$UMBRELLA_BASE_URL/ais/data/initiate" \
-H "Authorization: Bearer $ACCESS_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"referenceId": "affordability-000123",
"returnUrl": "https://example.com/affordability/return",
"accessTypes": ["ACCOUNTS", "BALANCES", "TRANSACTIONS"],
"transactionsFrom": "2026-07-01",
"webhookUrl": "https://example.com/webhooks/ais-data"
}'3. Redirect the user
Send the user to redirectUrl. The session is valid for 30 minutes (expiresAt). The user returns to
your returnUrl whether they finished, cancelled or failed.
4. Read the data
curl -X POST "$UMBRELLA_BASE_URL/ais/data/status" \
-H "Authorization: Bearer $ACCESS_TOKEN" \
-H "Content-Type: application/json" \
-d '{ "referenceId": "affordability-000123" }'Or receive the same object on your webhookUrl when the session reaches a final status.
Status and reasons
status | Meaning |
|---|---|
PENDING | The user is still in the flow. |
COMPLETED | Account data retrieved; see accounts. |
ABORTED | The user left the flow; see statusReason. |
EXPIRED | The 30-minute session ran out. |
FAILED | Bank or technical failure; see statusReason. |
statusReason: USER_CANCELLED, CONSENT_DENIED, SCA_FAILED, BANK_NOT_SUPPORTED,
BANK_UNAVAILABLE, TIMEOUT. Errors are the same as for AIS Ident.
Try it
Sandbox demo: openbanking.idcanopy.com connects a sandbox bank with a test user and shows the accounts, balances and transactions it returns. Test banks only, no real account data.
Sandbox test users, per bank
KD-Bank (DE)
| psuId | VRK1234567890ALL |
| Password | password |
| PIN | 123456 |
| SCA method | Mobile TAN |
| Success IBAN | DE39499999600000005111 |
| Decline IBAN | DE98499999600000005116 |
DKB (DE)
| psuId | abc |
| Password | 123 |
| PIN | 123456 |
| SCA code | 962: |
| SCA method | SmartTAN plus HHD 1.4 |
Erste Bank (AT)
| Test user | Pick any user from the list, no password |
BBVA (ES)
| Username | user1 |
| Password | 1234 |
| Authentication code | 123456 |
| IBAN | ES2501822200160201933547 |
NatWest (GB)
| Username | 123456789012 |
| Password | Shown on the bank screen |
Alior Bank (PL)
| psuId | 22058375 |
| Password | 12345678 |
Mock in the reference: in the Umbrella API reference,
choose the server Mock. POST /ais/data/status answers with canned data; add ?scenario= to pick
another one:
scenario | Result |
|---|---|
| (none) | COMPLETED, two accounts with balances and transactions |
no-holder-name | COMPLETED, balances only, accountHolderName: null |
pending | PENDING |
aborted | ABORTED, CONSENT_DENIED |