ASPSP restricting access for TPPs who embeds the redirect
- Regulation
- Directive 2015/2366/EU (PSD2)
- Article
- 68, para. 5
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Submitted by
- Other
- Submitted
- 2021-10-19
- Answered
- 2022-04-13
- Answer provided by
- ESAs (EBA, ESMA, EIOPA)
Question
Background
Answer
Original source: European Banking Authority, Q&A ID 2021_6245
This Q&A is published by European Banking Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.
Similar Q&As
Re-engineering by TPP of the ASPSP’s redirect API and PSU customer journey
Answered 2022-04-13
Authentication procedures that ASPSPs’ interfaces are required to support (using re-direction)
Answered 2023-01-27
Proxy matrices
Answered 2025-08-29
Authentication process of the PSU with the ASPSP in a combined AIS and PIS journey in a redirection approach
Answered 2025-10-03
PSU support in dedicated and redirected interfaces.
Answered 2026-06-12
More Q&As on this topic
Definition of "equivalent authentication procedure" for journeys initiated from a mobile application
Answered 2026-06-12
Obstacle assessment of a mandatory client segment selection screen in a redirection journey
Answered 2026-06-12
Clarification of the scope of the term "authentication procedures" in the context of the RTS and the EBA Opinion on obstacles
Answered 2026-06-12
SCA exception for Contactless only terminals (SoftPOS) in case of emergency
Answered 2025-10-03
the use of strong and widely recognized encryption techniques
Answered 2025-10-03
📋 Track EU financial regulation continuously
Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.
14-day free trial. No credit card required.