OB-OBS-011PSR 44(1)(k)Prohibited obstacles
Forcing a redirect to the bank's website
What the text fixes
The ASPSP may not impose an automatic redirect to its web page at authentication when the dedicated interface does not support all its authentication procedures.
- Article
- PSR 44(1)(k)Provisional numbering of the April 2026 compromise (Council doc. 8221/26). The final numbering will be added when the Official Journal publishes the text, without changing the id.
- Who is bound
- ASPSP
- Who it is for
- Product, API, Audit and pentest
- Application
- 21 months after entry into force, the general application date (Article 112).
- Level 2
- No EBA mandate covers this obligation.
- Origin
- RTS 2018/389, Art. 32(3); EBA Opinion of 4 June 2020 on obstacles
STET 1.6.3
To reviewSTET redirection sends the user to a URL the bank provides, the OAuth2 authorisation endpoint for the AISP and the consentApproval link for the PISP. The specification does not describe handing over to the mobile app, which depends on each bank.
Handbook pages
Sources
Checked on October 4, 2026
The entry as JSON
{
"id": "OB-OBS-011",
"article": "PSR 44(1)(k)",
"alsoIn": [],
"articleFinal": null,
"actors": [
"aspsp"
],
"roles": [
"product",
"api",
"pentest"
],
"appliesAt": "T+21",
"title": {
"fr": "Rediriger d'office vers le site de la banque",
"en": "Forcing a redirect to the bank's website",
"es": "Redirigir de oficio a la web del banco",
"pt-br": "Redirecionar de ofício para o site do banco"
},
"level1": {
"fr": "L'ASPSP ne peut pas imposer une redirection automatique vers son site web au moment de l'authentification quand l'interface dédiée ne supporte pas toutes ses procédures d'authentification.",
"en": "The ASPSP may not impose an automatic redirect to its web page at authentication when the dedicated interface does not support all its authentication procedures.",
"es": "El ASPSP no puede imponer una redirección automática a su página web en el momento de la autenticación cuando la interfaz dedicada no admite todos sus procedimientos de autenticación.",
"pt-br": "O ASPSP não pode impor um redirecionamento automático para sua página web no momento da autenticação quando a interface dedicada não suporta todos os seus procedimentos de autenticação."
},
"level2": null,
"origin": [
{
"act": "rts-2018-389",
"articles": "32(3)"
},
{
"act": "eba-opinion-2020"
}
],
"stet": {
"1.6.3": {
"status": "review",
"note": {
"fr": "La redirection STET envoie l'utilisateur vers une URL fournie par la banque, l'autorisation OAuth2 pour l'AISP et le lien `consentApproval` pour le PISP. La spécification ne décrit pas le passage vers l'application mobile, qui dépend de chaque banque.",
"en": "STET redirection sends the user to a URL the bank provides, the OAuth2 authorisation endpoint for the AISP and the `consentApproval` link for the PISP. The specification does not describe handing over to the mobile app, which depends on each bank.",
"es": "La redirección STET lleva al usuario a una URL que facilita el banco, la autorización OAuth2 para el AISP y el enlace `consentApproval` para el PISP. La especificación no describe el paso a la aplicación móvil, que depende de cada banco.",
"pt-br": "O redirecionamento STET leva o usuário a uma URL fornecida pelo banco, a autorização OAuth2 para o AISP e o link `consentApproval` para o PISP. A especificação não descreve a passagem para o aplicativo móvel, que depende de cada banco."
},
"pages": [
"framework/3-prerequisites-and-technical-details"
]
}
},
"verification": null,
"sources": [
{
"document": "8221/26",
"page": 263
}
],
"verifiedAt": "2026-10-04"
}