v1

latestOpenAPI 3.0.0Apache 2.02026-07-134807111.3 MB
challenge-request

Endpoint for apps to fetch a challenge request.

get/user/{userID}/challenge-request/{itemId}

Path parameters

userIDinteger required
itemIdinteger required

Headers

Cache-Controlstring

The standard HTTP Cache-Control header is required for all signed requests.

User-Agentstring required

The User-Agent header field should contain information about the user agent originating the request. There are no restrictions on the value of this header.

X-Bunq-Languagestring

The X-Bunq-Language header must contain a preferred language indication. The value of this header is formatted as a ISO 639-1 language code plus a ISO 3166-1 alpha-2 country code, separated by an underscore. Currently only the languages en_US and nl_NL are supported. Anything else will default to en_US.

X-Bunq-Regionstring

The X-Bunq-Region header must contain the region (country) of the client device. The value of this header is formatted as a ISO 639-1 language code plus a ISO 3166-1 alpha-2 country code, separated by an underscore.

X-Bunq-Client-Request-Idstring

This header must specify an ID with each request that is unique for the logged in user. There are no restrictions for the format of this ID. However, the server will respond with an error when the same ID is used again on the same DeviceServer.

X-Bunq-Geolocationstring

This header must specify the geolocation of the device. The format of this value is longitude latitude altitude radius country. The country is expected to be formatted of an ISO 3166-1 alpha-2 country code. When no geolocation is available or known the header must still be included but can be zero valued.

X-Bunq-Client-Authenticationstring required

The authentication token is used to authenticate the source of the API call. It is required by all API calls except for POST /v1/installation. It is important to note that the device and session calls are using the token from the response of the installation call, while all the other calls use the token from the response of the session-server call

Response

Endpoint for apps to fetch a challenge request.

amountstring

The transaction amount.

expiry_timestring

When the identity check expires.

descriptionstring

The description of the purchase. NULL if no description is given.

statusstring

The status of the secure code. Can be PENDING, ACCEPTED, REJECTED, EXPIRED.

decision_descriptionstring

Textual explanation of the decision.

decision_description_translatedstring

Textual explanation of the decision in user's language.

url_merchant_appstring

The return url for the merchant app after the challenge is accepted or rejected.

event_idinteger

The ID of the latest event for the identity check.

card_idinteger

The ID of the card used for the authentication request of the identity check.