Salt Edge Open Banking API now supports eIDAS PSD2 certificates

Friday 17 May 2019 13:48 CET | News

Salt Edge has added the support of eIDAS PSD2 certificates in its system for TPP identification when they access ASPSPs’ channels.

Now, the company’s clients that act as payment service providers (AISP, PISP, PIISP, ASPSP) and that use Salt Edge as a technical service provider (TSP) are able to generate certificate requests and upload signed eIDAS certificates into the client dashboard.

The PSD2 Regulatory Technical Standards (RTS) specify that TPPs should be able to use a certificate issued by any eIDAS Qualified Trust Service Provider (QTSP) in order to identify and authenticate themselves when accessing ASPSP channels. And, Salt Edge is the first Open Banking TSP that has implemented a self-service generation of Certificate Signing Request (CSR) for test and live usage in its system. The platform supports the generation of both QWAC and QSEAL eIDAS certificates signature requests. This implementation meets the strict PSD2 requirements and helps with maintaining the highest level of security in the new Open Banking era.

In its Opinion on the use of eIDAS certificates under the RTS on SCA and CSC, European Banking Authority (EBA) advises the TPPs that use TSPs to create and use a separate eIDAS certificate for each TSP. This should ensure business continuity and better risk management, because the legitimacy of one certificate would not be affected by the expiration/revocation of any other.

The whole process of eIDAS certificate generation requires the following steps:

  • Generate a CSR in the Salt Edge client dashboard (separate CSRs are generated for each type of certificates, i.e. QWAC and QSEAL);

  • Send the generated CSR file to QTSP for issuing the eIDAS certificate;

  • Upload the signed eIDAS certificate in the client dashboard for the corresponding CSR.

Salt Edge is a global fintech company offering solutions to financial institutions, banks, finapps, and other fintech companies. The company is registered as Account Information Service Provider by the UK’s FCA, under PSD2. Among its services are financial data aggregation API, open banking and PSD2 solutions, white label retail banking, and data enrichment.

Free Headlines in your E-mail

Every day we send out a free e-mail with the most important headlines of the last 24 hours.

Subscribe now

Keywords: Salt Edge, Open Banking, API, eIDAS, PSD2, TPP, fintech, banking, RTS
Countries: World