v1

latestOpenAPI 3.0.1Creative Commons Attribution 4.0 International Public License2026-07-1334289536.7 KB
Payment Initiation Service (PIS)
Common Services

Read the SCA status of the payment cancellation's authorisation

This method returns the SCA status of a payment initiation's authorisation sub-resource.

get/v1/{payment-service}/{payment-product}/{paymentId}/cancellation-authorisations/{authorisationId}

Path parameters

payment-service'payments' | 'bulk-payments' | 'periodic-payments' required

Payment service:

Possible values are:

  • payments
  • bulk-payments
  • periodic-payments
payment-product'domestic-swiss-credit-transfers-isr' | 'domestic-swiss-credit-transfers' | 'domestic-swiss-credit-transfers-qr' | 'domestic-swiss-foreign-credit-transfers' | 'swiss-sepa-credit-transfers' | 'swiss-cross-border-credit-transfers' | 'pain.001-sepa-credit-transfers' | 'pain.001-cross-border-credit-transfers' | 'pain.001-swiss-six-credit-transfers' required

The addressed payment product endpoint, e.g. for SEPA Credit Transfers (SCT). The ASPSP will publish which of the payment products/endpoints will be supported.

The following payment products are supported:

  • domestic-swiss-credit-transfers-isr
  • domestic-swiss-credit-transfers
  • domestic-swiss-credit-transfers-qr
  • domestic-swiss-foreign-credit-transfers
  • swiss-sepa-credit-transfers
  • swiss-cross-border-credit-transfers
  • pain.001-sepa-credit-transfers
  • pain.001-cross-border-credit-transfers
  • pain.001-swiss-six-credit-transfers

Remark: For all SEPA Credit Transfer based endpoints which accept XML encoding, the XML pain.001 schemes provided by EPC are supported by the ASPSP as a minimum for the body content. Further XML schemes might be supported by some communities.

Remark: For cross-border and TARGET-2 payments only community wide pain.001 schemes do exist. There are plenty of country specificic scheme variants.

paymentIdstring required

Resource identification of the generated payment initiation resource.

Example:1234-wertiq-983

Resource identification of the generated payment initiation resource.

authorisationIdstring required

Resource identification of the related SCA.

Example:123auth456

Resource identification of the related SCA.

Headers

X-Request-IDstring required

ID of the request, unique to the call, as determined by the initiating party.

Digeststring

Is contained if and only if the "Signature" element is contained in the header of the request.

Signaturestring

A signature of the request by the TPP on application level. This might be mandated by ASPSP.

TPP-Signature-Certificatestring byte

The certificate used for signing the request, in base64 encoding. Must be contained if a signature is contained.

PSU-IP-Addressstring ipv4

The forwarded IP Address header field consists of the corresponding http request IP Address field between PSU and TPP.

PSU-IP-Portstring

The forwarded IP Port header field consists of the corresponding HTTP request IP Port field between PSU and TPP, if available.

PSU-Acceptstring

The forwarded IP Accept header fields consist of the corresponding HTTP request Accept header fields between PSU and TPP, if available.

PSU-Accept-Charsetstring

The forwarded IP Accept header fields consist of the corresponding HTTP request Accept header fields between PSU and TPP, if available.

PSU-Accept-Encodingstring

The forwarded IP Accept header fields consist of the corresponding HTTP request Accept header fields between PSU and TPP, if available.

PSU-Accept-Languagestring

The forwarded IP Accept header fields consist of the corresponding HTTP request Accept header fields between PSU and TPP, if available.

PSU-User-Agentstring

The forwarded Agent header field of the HTTP request between PSU and TPP, if available.

PSU-Http-Method'GET' | 'POST' | 'PUT' | 'PATCH' | 'DELETE'

HTTP method used at the PSU ? TPP interface, if available. Valid values are:

  • GET
  • POST
  • PUT
  • PATCH
  • DELETE
PSU-Device-IDstring

UUID (Universally Unique Identifier) for a device, which is used by the PSU, if available. UUID identifies either a device or a device dependant application installation. In case of an installation identification this ID needs to be unaltered until removal from device.

PSU-Geo-Locationstring

The forwarded Geo Location of the corresponding http request between PSU and TPP if available.

Response

OK

scaStatus'received' | 'psuIdentified' | 'psuAuthenticated' | 'scaMethodSelected' | 'started' | 'unconfirmed' | 'finalised' | 'failed' | 'exempted' required

This data element is containing information about the status of the SCA method applied.

The following codes are defined for this data type.

  • 'received': An authorisation or cancellation-authorisation resource has been created successfully.
  • 'psuIdentified': The PSU related to the authorisation or cancellation-authorisation resource has been identified.
  • 'psuAuthenticated': The PSU related to the authorisation or cancellation-authorisation resource has been identified and authenticated e.g. by a password or by an access token.
  • 'scaMethodSelected': The PSU/TPP has selected the related SCA routine. If the SCA method is chosen implicitly since only one SCA method is available, then this is the first status to be reported instead of 'received'.
  • 'unconfirmed': SCA is technically successfully finalised by the PSU, but the authorisation resource needs a confirmation command by the TPP yet.
  • 'started': The addressed SCA routine has been started.
  • 'finalised': The SCA routine has been finalised successfully (including a potential confirmation command). This is a final status of the authorisation resource.
  • 'failed': The SCA routine failed. This is a final status of the authorisation resource.
  • 'exempted': SCA was exempted for the related transaction, the related authorisation is successful. This is a final status of the authorisation resource.
psuMessagestring

Text to be displayed to the PSU.

trustedBeneficiaryFlagboolean

Additional Service: Trusted Benificiaries Within this data element, the ASPSP might optionally communicate towards the TPP whether the creditor was part of the related trusted beneficiary list. This attribute is only contained in case of a final scaStatus.

Example response

{
  "scaStatus": "psuAuthenticated"
}