OB-IF-009PSR 36(2)(b)Dedicated interface
Authentication started by the TPP, protected session
What the text fixes
The interface lets the TPP ask the ASPSP to start authentication based on the user's consent, keeps the session between the parties open throughout authentication, and protects the integrity and confidentiality of credentials and authentication codes.
- Article
- PSR 36(2)(b) · See also PSR 36(1)(a), PSR 36(1)(b)Provisional numbering of the April 2026 compromise (Council doc. 8221/26). The final numbering will be added when the Official Journal publishes the text, without changing the id.
- Who is bound
- ASPSP
- Who it is for
- API, Audit and pentest
- Application
- 21 months after entry into force, the general application date (Article 112).
- Level 2
- RTS under Article PSR 89(1)(e), draft due at T + 12 months.The mandate names this article.
- Origin
- RTS 2018/389, Art. 30(2)
STET 1.6.3
CoveredIn redirect or decoupled mode, the TPP triggers authentication at the bank, through the OAuth2 authorisation for the AISP and through the payment request for the PISP, over a mutually authenticated TLS connection.
Handbook pages
Sources
Checked on October 4, 2026
The entry as JSON
{
"id": "OB-IF-009",
"article": "PSR 36(2)(b)",
"alsoIn": [
"PSR 36(1)(a)",
"PSR 36(1)(b)"
],
"articleFinal": null,
"actors": [
"aspsp"
],
"roles": [
"api",
"pentest"
],
"appliesAt": "T+21",
"title": {
"fr": "Authentification lancée par le TPP, session protégée",
"en": "Authentication started by the TPP, protected session",
"es": "Autenticación iniciada por el TPP, sesión protegida",
"pt-br": "Autenticação iniciada pelo TPP, sessão protegida"
},
"level1": {
"fr": "L'interface permet au TPP de demander à l'ASPSP de lancer l'authentification sur la base du consentement de l'utilisateur, maintient la session entre les parties pendant toute l'authentification et protège l'intégrité et la confidentialité des identifiants et des codes d'authentification.",
"en": "The interface lets the TPP ask the ASPSP to start authentication based on the user's consent, keeps the session between the parties open throughout authentication, and protects the integrity and confidentiality of credentials and authentication codes.",
"es": "La interfaz permite al TPP pedir al ASPSP que inicie la autenticación sobre la base del consentimiento del usuario, mantiene la sesión entre las partes durante toda la autenticación y protege la integridad y la confidencialidad de las credenciales y de los códigos de autenticación.",
"pt-br": "A interface permite ao TPP pedir ao ASPSP que inicie a autenticação com base no consentimento do usuário, mantém a sessão entre as partes durante toda a autenticação e protege a integridade e a confidencialidade das credenciais e dos códigos de autenticação."
},
"level2": {
"mandate": "PSR 89(1)(e)",
"instrument": "rts",
"deadline": "T+12",
"link": "named"
},
"origin": [
{
"act": "rts-2018-389",
"articles": "30(2)"
}
],
"stet": {
"1.6.3": {
"status": "present",
"note": {
"fr": "En redirection ou en découplé, le TPP déclenche l'authentification chez la banque, par l'autorisation OAuth2 pour l'AISP et par la requête de paiement pour le PISP, sur une connexion TLS à authentification mutuelle.",
"en": "In redirect or decoupled mode, the TPP triggers authentication at the bank, through the OAuth2 authorisation for the AISP and through the payment request for the PISP, over a mutually authenticated TLS connection.",
"es": "En redirección o en desacoplado, el TPP desencadena la autenticación en el banco, mediante la autorización OAuth2 en el caso del AISP y mediante la solicitud de pago en el del PISP, sobre una conexión TLS con autenticación mutua.",
"pt-br": "Em redirecionamento ou desacoplado, o TPP dispara a autenticação no banco, pela autorização OAuth2 no caso do AISP e pela solicitação de pagamento no caso do PISP, sobre uma conexão TLS com autenticação mútua."
},
"pages": [
"framework/3-prerequisites-and-technical-details",
"flows/6-1-psu-context-retrieval",
"endpoints/pisp/payment-requests-post"
]
}
},
"verification": null,
"sources": [
{
"document": "8221/26",
"page": 242
},
{
"document": "8221/26",
"page": 243
}
],
"verifiedAt": "2026-10-04"
}