IDCanopy Developers
Umbrella APIAIS Data

AIS Data

Account data by account access: accounts, balances and transactions the user shares from their own bank

Universe: Umbrella
Status: beta

Credentials on request. Sandbox demo available.

What it answers

The end user logs in to their own bank and gives a one-time, read-only consent. AIS Data reads what is in the account: the accounts the user shares, their balances and their transactions, as returned by the bank. Money is never moved. The login stays at the bank; no bank credentials are stored.

AIS Data reads the account data; it does not confirm the holder. To confirm who holds an account and match the holder name, use AIS Ident.

Flow

Bank selection -> Bank login -> Consent -> SCA -> Data retrieval -> Accounts, balances, transactions -> Result
  1. Bank selection: the user picks their bank in the hosted flow (country pre-selects the country).
  2. Bank login: the user logs in at their own bank, on the bank website or in the banking app.
  3. Consent: one-time, read-only consent to the data in accessTypes.
  4. SCA: the user confirms the consent with strong customer authentication at the bank.
  5. Data retrieval: the accounts the user selects are read from the bank.
  6. Accounts, balances, transactions: per account name, type, iban, bic, accountHolderName, and, as requested, balance and transactions.
  7. Result: via POST /ais/data/status and the webhook.

Access types

accessTypesReturns
ACCOUNTSAccount name, type (CURRENT, SAVINGS, OTHER), IBAN, BIC and holder name. Always included.
BALANCESbalance.current and balance.available, each { value, currency }.
TRANSACTIONStransactions[]: id, booking date, description, amount { value, currency }. Limit the range with transactionsFrom and transactionsTo.

Amounts are decimal strings, negative for debits. The holder name is not guaranteed: some banks return none, and then accountHolderName is null.

Integration in four calls

Base URLs are in Environments.

1. Authenticate

curl -X POST "$UMBRELLA_BASE_URL/auth" \
  -H "Api-Key: $UMBRELLA_API_KEY" \
  -H "Customer-Id: $UMBRELLA_CUSTOMER_ID" \
  -H "Content-Type: application/x-www-form-urlencoded"

2. Start a session

curl -X POST "$UMBRELLA_BASE_URL/ais/data/initiate" \
  -H "Authorization: Bearer $ACCESS_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "referenceId": "affordability-000123",
    "returnUrl": "https://example.com/affordability/return",
    "accessTypes": ["ACCOUNTS", "BALANCES", "TRANSACTIONS"],
    "transactionsFrom": "2026-07-01",
    "webhookUrl": "https://example.com/webhooks/ais-data"
  }'

3. Redirect the user

Send the user to redirectUrl. The session is valid for 30 minutes (expiresAt). The user returns to your returnUrl whether they finished, cancelled or failed.

4. Read the data

curl -X POST "$UMBRELLA_BASE_URL/ais/data/status" \
  -H "Authorization: Bearer $ACCESS_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{ "referenceId": "affordability-000123" }'

Or receive the same object on your webhookUrl when the session reaches a final status.

Status and reasons

statusMeaning
PENDINGThe user is still in the flow.
COMPLETEDAccount data retrieved; see accounts.
ABORTEDThe user left the flow; see statusReason.
EXPIREDThe 30-minute session ran out.
FAILEDBank or technical failure; see statusReason.

statusReason: USER_CANCELLED, CONSENT_DENIED, SCA_FAILED, BANK_NOT_SUPPORTED, BANK_UNAVAILABLE, TIMEOUT. Errors are the same as for AIS Ident.

Try it

Sandbox demo: openbanking.idcanopy.com connects a sandbox bank with a test user and shows the accounts, balances and transactions it returns. Test banks only, no real account data.

Sandbox test users, per bank
KD-Bank (DE)
psuIdVRK1234567890ALL
Passwordpassword
PIN123456
SCA methodMobile TAN
Success IBANDE39499999600000005111
Decline IBANDE98499999600000005116
DKB (DE)
psuIdabc
Password123
PIN123456
SCA code962:
SCA methodSmartTAN plus HHD 1.4
Erste Bank (AT)
Test userPick any user from the list, no password
BBVA (ES)
Usernameuser1
Password1234
Authentication code123456
IBANES2501822200160201933547
NatWest (GB)
Username123456789012
PasswordShown on the bank screen
Alior Bank (PL)
psuId22058375
Password12345678

Mock in the reference: in the Umbrella API reference, choose the server Mock. POST /ais/data/status answers with canned data; add ?scenario= to pick another one:

scenarioResult
(none)COMPLETED, two accounts with balances and transactions
no-holder-nameCOMPLETED, balances only, accountHolderName: null
pendingPENDING
abortedABORTED, CONSENT_DENIED

On this page