API archive entry · source-reported

bunq API

***UPDATE:*** *We have released a beta version of the new bunq API documentation.* ***NOTICE:*** *We have updated the sandbox base url to `https://public-api.sandbox.bunq.com/v1/`. Please update your applications accordingly. Check here: for more info.* ***PSD2 NOTICE:*** *The second Payment Services Directive (PSD2) may affect your current or planned usage of our public API, as some of the API services are now subject to a permit. Please be aware that using our public API without the required PSD2 permit is at your own risk and take notice of our updated API Terms and Conditions on for more information.* # Introduction Welcome to bunq! - The bunq API is organised around REST. JSON will be returned in almost all responses from the API, including errors but excluding binary (image) files. - Please configure your implementation to send its API requests to `https://public-api.sandbox.bunq.com/v1/` - There is a version of the Android app that connects to the bunq Sandbox environment. To create accounts for the Sandbox app, please follow the steps in the Android Emulator section. ## Getting started Before you start sending API requests, you need to get an API key and activate it. API ac

Provider / source website

Plan the first integration safely

The access fields below come from the connected directory. Their likely implementation impact is explained without assuming provider-specific behavior.

Authentication

OAuth is reported. Confirm flows, scopes, consent, token lifetime, and refresh rules.

Transport

HTTPS is not confirmed. Do not send credentials or production data until secure transport is verified.

Browser access

CORS is unknown. Treat direct browser access as unconfirmed and test before choosing a client-only architecture.

First-request sequence

  1. Identify the current base URL, version, and endpoint for the use case.
  2. Confirm how credentials are issued and where they may be stored.
  3. Test success, invalid input, throttling, unavailable data, and timeouts.
  4. Record response fields, pagination, caching, and error shapes.
  5. Add monitoring, retries with backoff, and an appropriate fallback.

Questions to resolve before production

Pricing and quotas

Confirm current plans, free-tier limits, overages, and request ceilings.

Endpoint coverage

Check that the operations and response fields match the intended workload.

Reliability

Look for uptime history, a status page, support routes, and service commitments.

Data and privacy

Review retention, licensing, regional processing, and compliance requirements.

Versioning

Confirm the active version, change policy, deprecation window, and migration guidance.

Developer experience

Validate SDKs, examples, error formats, pagination, and test environments.

Source reference

APIs.guru OpenAPI Directory

This page separates source-reported facts from questions that need live provider verification.