v1

latestOpenAPI 3.0.1Creative Commons Attribution 4.0 International Public License2026-07-1334289536.7 KB
Payment Initiation Service (PIS)
Common Services

Update PSU data for payment initiation cancellation

This method updates PSU data on the cancellation authorisation resource if needed. It may authorise a cancellation of the payment within the Embedded SCA Approach where needed.

Independently from the SCA Approach it supports e.g. the selection of the authentication method and a non-SCA PSU authentication.

There are several possible update PSU data requests in the context of a cancellation authorisation within the payment initiation services needed, which depends on the SCA approach:

  • Redirect SCA Approach: A specific Update PSU data request is applicable for
    • the selection of authentication methods, before choosing the actual SCA approach.
  • Decoupled SCA Approach: A specific Update PSU data request is only applicable for
    • adding the PSU Identification, if not provided yet in the payment initiation request or the Account Information Consent Request, or if no OAuth2 access token is used, or
    • the selection of authentication methods.
  • Embedded SCA Approach: The Update PSU data request might be used
    • to add credentials as a first factor authentication data of the PSU and
    • to select the authentication method and
    • transaction authorisation.

The SCA approach might depend on the chosen SCA method. For that reason, the following possible update PSU data request can apply to all SCA approaches:

  • Select an SCA method in case of several SCA methods are available for the customer.

There are the following request types on this access path:

  • Update PSU identification
  • Update PSU authentication
  • Select PSU autorization method WARNING: This method needs a reduced header, therefore many optional elements are not present. Maybe in a later version the access path will change.
  • Transaction Authorisation WARNING: This method needs a reduced header, therefore many optional elements are not present. Maybe in a later version the access path will change.
put/v1/{payment-service}/{payment-product}/{paymentId}/cancellation-authorisations/{authorisationId}

Path parameters

payment-service'payments' | 'bulk-payments' | 'periodic-payments' required

Payment service:

Possible values are:

  • payments
  • bulk-payments
  • periodic-payments
payment-product'domestic-swiss-credit-transfers-isr' | 'domestic-swiss-credit-transfers' | 'domestic-swiss-credit-transfers-qr' | 'domestic-swiss-foreign-credit-transfers' | 'swiss-sepa-credit-transfers' | 'swiss-cross-border-credit-transfers' | 'pain.001-sepa-credit-transfers' | 'pain.001-cross-border-credit-transfers' | 'pain.001-swiss-six-credit-transfers' required

The addressed payment product endpoint, e.g. for SEPA Credit Transfers (SCT). The ASPSP will publish which of the payment products/endpoints will be supported.

The following payment products are supported:

  • domestic-swiss-credit-transfers-isr
  • domestic-swiss-credit-transfers
  • domestic-swiss-credit-transfers-qr
  • domestic-swiss-foreign-credit-transfers
  • swiss-sepa-credit-transfers
  • swiss-cross-border-credit-transfers
  • pain.001-sepa-credit-transfers
  • pain.001-cross-border-credit-transfers
  • pain.001-swiss-six-credit-transfers

Remark: For all SEPA Credit Transfer based endpoints which accept XML encoding, the XML pain.001 schemes provided by EPC are supported by the ASPSP as a minimum for the body content. Further XML schemes might be supported by some communities.

Remark: For cross-border and TARGET-2 payments only community wide pain.001 schemes do exist. There are plenty of country specificic scheme variants.

paymentIdstring required

Resource identification of the generated payment initiation resource.

Example:1234-wertiq-983

Resource identification of the generated payment initiation resource.

authorisationIdstring required

Resource identification of the related SCA.

Example:123auth456

Resource identification of the related SCA.

Headers

X-Request-IDstring required

ID of the request, unique to the call, as determined by the initiating party.

Digeststring

Is contained if and only if the "Signature" element is contained in the header of the request.

Signaturestring

A signature of the request by the TPP on application level. This might be mandated by ASPSP.

TPP-Signature-Certificatestring byte

The certificate used for signing the request, in base64 encoding. Must be contained if a signature is contained.

PSU-IDstring

Client ID of the PSU in the ASPSP client interface.

Might be mandated in the ASPSP's documentation.

It might be contained even if an OAuth2 based authentication was performed in a pre-step or an OAuth2 based SCA was performed in an preceding AIS service in the same session. In this case the ASPSP might check whether PSU-ID and token match, according to ASPSP documentation.

PSU-ID-Typestring

Type of the PSU-ID, needed in scenarios where PSUs have several PSU-IDs as access possibility.

In this case, the mean and use are then defined in the ASPSP's documentation.

PSU-Corporate-IDstring

Might be mandated in the ASPSP's documentation. Only used in a corporate context.

PSU-Corporate-ID-Typestring

Might be mandated in the ASPSP's documentation. Only used in a corporate context.

PSU-IP-Addressstring ipv4

The forwarded IP Address header field consists of the corresponding http request IP Address field between PSU and TPP.

PSU-IP-Portstring

The forwarded IP Port header field consists of the corresponding HTTP request IP Port field between PSU and TPP, if available.

PSU-Acceptstring

The forwarded IP Accept header fields consist of the corresponding HTTP request Accept header fields between PSU and TPP, if available.

PSU-Accept-Charsetstring

The forwarded IP Accept header fields consist of the corresponding HTTP request Accept header fields between PSU and TPP, if available.

PSU-Accept-Encodingstring

The forwarded IP Accept header fields consist of the corresponding HTTP request Accept header fields between PSU and TPP, if available.

PSU-Accept-Languagestring

The forwarded IP Accept header fields consist of the corresponding HTTP request Accept header fields between PSU and TPP, if available.

PSU-User-Agentstring

The forwarded Agent header field of the HTTP request between PSU and TPP, if available.

PSU-Http-Method'GET' | 'POST' | 'PUT' | 'PATCH' | 'DELETE'

HTTP method used at the PSU ? TPP interface, if available. Valid values are:

  • GET
  • POST
  • PUT
  • PATCH
  • DELETE
PSU-Device-IDstring

UUID (Universally Unique Identifier) for a device, which is used by the PSU, if available. UUID identifies either a device or a device dependant application installation. In case of an installation identification this ID needs to be unaltered until removal from device.

PSU-Geo-Locationstring

The forwarded Geo Location of the corresponding http request between PSU and TPP if available.

Request body

{"stackTrail":"paths:/v1/{payment-service}/{payment-product}/{paymentId}/cancellation-authorisations/{authorisationId}:put:requestBody:content:application/json:schema:oneOf:0","oasType":"schema","type":"unknown"}
OR
OR
OR
OR

Example request

{
  "authenticationMethodId": "myAuthenticationID"
}

Response

OK

OR
OR
OR
OR

Example response

{
  "transactionFees": {
    "currency": "EUR",
    "amount": "123"
  },
  "currencyConversionFees": {
    "currency": "EUR",
    "amount": "123"
  },
  "estimatedTotalAmount": {
    "currency": "EUR",
    "amount": "123"
  },
  "estimatedInterbankSettlementAmount": {
    "currency": "EUR",
    "amount": "123"
  },
  "scaMethods": [
    {
      "authenticationMethodId": "myAuthenticationID",
      "name": "SMS OTP on phone +49160 xxxxx 28",
      "explanation": "Detailed information about the SCA method for the PSU."
    }
  ],
  "_links": {
    "scaStatus": {
      "href": "/v1/payments/swiss-sepa-credit-transfers/1234-wertiq-983"
    },
    "selectAuthenticationMethod": {
      "href": "/v1/payments/swiss-sepa-credit-transfers/1234-wertiq-983"
    }
  },
  "scaStatus": "psuAuthenticated"
}