API archive entry · source-reported

Swiss NextGen Banking API-Framework

# Summary The **Swiss NextGen API** is based on the NextGenPSD2 *Framework Version 1.3.4* of the Berlin Group which offers a modern, open, harmonised and interoperable set of Application Programming Interfaces (APIs) as the safest and most efficient way to provide data securely. The NextGen Framework reduces XS2A complexity and costs, addresses the problem of multiple competing standards in Europe and, aligned with the goals of the Euro Retail Payments Board, enables European banking customers to benefit from innovative products and services ('Banking as a Service') by granting TPPs safe and secure (authenticated and authorised) access to their bank accounts and financial data. The Swiss edtion refines the message formats specific to Switzerland and defines some matching examples. The possible Approaches are: * Redirect SCA Approach * *(Not recommended by obp.ch community) OAuth SCA Approach* * *(Not recommended by obp.ch community) Decoupled SCA Approach* * *(Not recommended by obp.ch community) Embedded SCA Approach without SCA method* * *(Not recommended by obp.ch community) Embedded SCA Approach with only one SCA method available* * *(Not recommended by obp.ch community) Embedd

Provider / source website

Plan the first integration safely

The access fields below come from the connected directory. Their likely implementation impact is explained without assuming provider-specific behavior.

Authentication

OAuth is reported. Confirm flows, scopes, consent, token lifetime, and refresh rules.

Transport

HTTPS is not confirmed. Do not send credentials or production data until secure transport is verified.

Browser access

CORS is unknown. Treat direct browser access as unconfirmed and test before choosing a client-only architecture.

First-request sequence

  1. Identify the current base URL, version, and endpoint for the use case.
  2. Confirm how credentials are issued and where they may be stored.
  3. Test success, invalid input, throttling, unavailable data, and timeouts.
  4. Record response fields, pagination, caching, and error shapes.
  5. Add monitoring, retries with backoff, and an appropriate fallback.

Questions to resolve before production

Pricing and quotas

Confirm current plans, free-tier limits, overages, and request ceilings.

Endpoint coverage

Check that the operations and response fields match the intended workload.

Reliability

Look for uptime history, a status page, support routes, and service commitments.

Data and privacy

Review retention, licensing, regional processing, and compliance requirements.

Versioning

Confirm the active version, change policy, deprecation window, and migration guidance.

Developer experience

Validate SDKs, examples, error formats, pagination, and test environments.

Source reference

APIs.guru OpenAPI Directory

This page separates source-reported facts from questions that need live provider verification.