The PSR (PSD3) for API teams
The PSR sets a functional baseline for the dedicated interface, and STET 1.6.3, unchanged since October 2022, does not cover all of it. The largest gap is consents. The TPP must send the bank the purpose and validity period of every consent, the bank must tell the TPP about every withdrawal, and STET has neither the fields nor a notification. A PISP must be able to read the account, its holders and its currencies before initiation, which the STET PISP role cannot do, and to know which status counts as confirmation of execution.
Start by filtering the list on the STET statuses Missing, then Partial. Then look at refresh token lifetimes, because the bank may now require SCA only on an AISP's first access, unless it suspects fraud, and it is the AISP that repeats it every 180 days. The notice period before an API change drops from three months to two.
By Tancrède Simonin, October 4, 2026
Where to start
The five obligations that change the most for this role.
- OB-DB-007PSR 43(3b)Partial
The TPP sends each consent to the ASPSP
The TPP tells the ASPSP without undue delay about each new consent, with its name, the account, the purpose, the validity and the data categories, and the ASPSP shows only what the TPP sent it.
STET 1.6.3
PUT /consentssends the accounts and data types, with no purpose, validity or date. Nothing exists for recurring PIS consents. - OB-DB-008PSR 43(4)Partial
The ASPSP tells the TPP about every change
The ASPSP tells the TPP without undue delay about any change the user makes in the dashboard, withdrawal included.
STET 1.6.3 STET has neither a consent status to query nor a notification. A withdrawal revokes the refresh token, and the AISP only finds out from the
invalid_granterror on its next refresh. - OB-PIS-009PSR 36(4)(hc)Missing
Account, holders and currencies visible before initiation
Before initiation, the PISP sees the account identifier, the holders' names and the currencies, where the user has access to them.
STET 1.6.3 The PISP can only propose a
debtorAccountin its request. It reads nothing about the account before initiation. - OB-PIS-011PSR 36(5)(b)Partial
Confirmation that the payment will be executed
The ASPSP confirms to the PISP as soon as possible that the payment has been or will be executed, taking pending orders into account, without sharing those orders with it.
STET 1.6.3 The PISP reads ISO 20022 statuses (
ACSP,ACSC,RJCT…) by polling, and the specification, which predates the text, does not say which one counts as confirmation of execution. - OB-SCA-002PSR 86(3)To review
ASPSP SCA on the AISP's first access only
For a given AISP, the ASPSP applies SCA only on the first access to the account data and not afterwards, unless it has reasonable grounds to suspect fraud.
STET 1.6.3 The Framework has the AISP's refresh token revoked when the regulatory delay between two SCAs expires, which sends the user back to an SCA at the bank. After the first access the bank can no longer impose it, and renewing SCA is the AISP's job (OB-SCA-003).
Every obligation for this role
46 obligations in the register concern this role. Obligations checked on October 4, 2026.
Dedicated interface(9)
- CoveredOB-IF-001PSR 35(1)T + 21 months
At least one dedicated interface per ASPSP
ASPSP
- CoveredOB-IF-003PSR 35(3)T + 21 months
Recognised communication standards
ASPSP
- Out of specOB-IF-004PSR 35(3)T + 21 months
Free technical documentation and public summary
ASPSP
- Out of specOB-IF-005PSR 35(4)T + 21 months
Two months' notice before any change
ASPSP
- Out of specOB-IF-007PSR 35(6)T + 21 months
Testing facility with support
ASPSP
- CoveredOB-IF-008PSR 35(7)T + 21 months
Error messages that explain the cause
ASPSP
- CoveredOB-IF-009PSR 36(2)(b)T + 21 months
Authentication started by the TPP, protected session
ASPSP
- Out of specOB-IF-015PSR 45(1)T + 21 months
TPP access through the dedicated interface only
AISP · PISP
- CoveredOB-IF-017PSR 36(2)(a)T + 21 months
TPP identification towards the ASPSP
ASPSP · AISP · PISP
Account information(5)
- CoveredOB-AIS-002PSR 36(3)T + 21 months
Minimum data for the AISP
ASPSP
- PartialOB-AIS-003PSR 37(2)T + 21 months
Data parity with the customer interface
ASPSP
- To reviewOB-AIS-004PSR 41(2)T + 21 months
AIS access with or without the user
ASPSP
- Out of specOB-AIS-006PSR 36(5a)T + 21 months
Holder name and identifier are not sensitive
ASPSP · AISP · PISP
- CoveredOB-AIS-007PSR 47(1)(d)T + 21 months
The AISP accesses designated accounts only
AISP
Payment initiation(12)
- CoveredOB-PIS-001PSR 36(4)(a)T + 21 months
Standing order, set-up and revocation
ASPSP
- CoveredOB-PIS-002PSR 36(4)(b)T + 21 months
Single payment
ASPSP
- CoveredOB-PIS-003PSR 36(4)(c)T + 21 months
Future-dated payment, initiation and revocation
ASPSP
- CoveredOB-PIS-004PSR 36(4)(d)T + 21 months
Payments to multiple beneficiaries
ASPSP
- CoveredOB-PIS-005PSR 36(4)(e)T + 21 months
Payee outside the payer's beneficiary list
ASPSP
- PartialOB-PIS-006PSR 37(3)T + 21 months
Execution information and status until the end
ASPSP
- MissingOB-PIS-007PSR 36(4)(g)T + 21 months
Account holder name check before initiation
ASPSP
- PartialOB-PIS-008PSR 36(4)(ha)T + 21 months
The PISP chooses the authentication procedure
ASPSP
- MissingOB-PIS-009PSR 36(4)(hc)T + 21 months
Account, holders and currencies visible before initiation
ASPSP
- PartialOB-PIS-010PSR 36(5)(a)T + 21 months
Yes or no answer on funds
ASPSP
- PartialOB-PIS-011PSR 36(5)(b)T + 21 months
Confirmation that the payment will be executed
ASPSP
- PartialOB-PIS-012PSR 65(1)T + 21 months
Refusal over suspected fraud, reasons to the PISP
ASPSP
Consent dashboard(4)
- PartialOB-DB-002PSR 43(2)(a)T + 21 months
What the dashboard shows
ASPSP
- MissingOB-DB-004PSR 43(2)(c)T + 21 months
Re-establishment possible for 48 hours
ASPSP
- PartialOB-DB-007PSR 43(3b)T + 21 months
The TPP sends each consent to the ASPSP
AISP · PISP · ASPSP
- PartialOB-DB-008PSR 43(4)T + 21 months
The ASPSP tells the TPP about every change
ASPSP
Prohibited obstacles(11)
- CoveredOB-OBS-001PSR 44(1)(a)T + 21 months
Blocking the use of the bank's credentials
ASPSP
- CoveredOB-OBS-002PSR 44(1)(b)T + 21 months
Making the user type the account identifier at the bank
ASPSP
- To reviewOB-OBS-003PSR 44(1)(c)T + 21 months
Checking the consent given to the TPP
ASPSP
- To reviewOB-OBS-004PSR 44(1)(d)T + 21 months
Requiring additional registrations
ASPSP
- To reviewOB-OBS-005PSR 44(1)(e)T + 21 months
Requiring contact details to be pre-registered
ASPSP
- CoveredOB-OBS-006PSR 44(1)(f)T + 21 months
Limiting payments to the payer's beneficiary list
ASPSP
- CoveredOB-OBS-007PSR 44(1)(g)T + 21 months
Limiting to domestic account identifiers
ASPSP
- To reviewOB-OBS-008PSR 44(1)(h)T + 21 months
More SCA than in the direct channel
ASPSP
- CoveredOB-OBS-009PSR 44(1)(i)T + 21 months
Not supporting every authentication procedure
ASPSP
- To reviewOB-OBS-011PSR 44(1)(k)T + 21 months
Forcing a redirect to the bank's website
ASPSP
- CoveredOB-OBS-012PSR 44(1)(l)T + 21 months
Two SCAs in a payment-initiation-only journey
ASPSP
Strong customer authentication(4)
- CoveredOB-SCA-001PSR 86(2)T + 21 months
TPPs rely on the ASPSP's authentication
ASPSP
- To reviewOB-SCA-002PSR 86(3)T + 21 months
ASPSP SCA on the AISP's first access only
ASPSP
- To reviewOB-SCA-003PSR 86(4)T + 21 months
AISP SCA every 180 days
AISP
- Out of specOB-SCA-005PSR 89(1)(e)From entry into force
RTS on open communication standards
EBA
Authorities and sanctions(1)
STET 1.6.3 handbook pages to read
The pages these obligations cite, most cited first.
- 3. Prerequisites and technical detailsCited by OB-IF-003, OB-IF-008, OB-IF-009, OB-IF-017, OB-AIS-004, OB-DB-004, OB-DB-008, OB-OBS-001, OB-OBS-004, OB-OBS-005, OB-OBS-008, OB-OBS-009, OB-OBS-011, OB-SCA-001, OB-SCA-002, OB-SCA-003, OB-ENF-007
- POST /payment-requestsCited by OB-IF-009, OB-PIS-002, OB-PIS-004, OB-PIS-005, OB-PIS-008, OB-PIS-009, OB-OBS-002, OB-OBS-006, OB-OBS-007
- PUT /consentsCited by OB-AIS-006, OB-AIS-007, OB-DB-002, OB-DB-004, OB-DB-007, OB-DB-008, OB-OBS-003
- GET /payment-requests/{paymentRequestResourceId}Cited by OB-PIS-006, OB-PIS-010, OB-PIS-011, OB-PIS-012
- 6.1. PSU Context RetrievalCited by OB-IF-009, OB-SCA-002, OB-SCA-003
- AISP endpointsCited by OB-IF-001, OB-AIS-003
- PISP endpointsCited by OB-IF-001, OB-PIS-007
- GET /accounts/{accountResourceId}/ownersCited by OB-AIS-002, OB-AIS-006
- 6.2. Consent ForwardingCited by OB-AIS-007, OB-DB-007
- PUT /payment-requests/{paymentRequestResourceId}Cited by OB-PIS-001, OB-PIS-003
- 8.2. Payment Request with multiple instructions having different beneficiariesCited by OB-PIS-004, OB-OBS-012
- BeneficiaryCited by OB-PIS-005, OB-OBS-006
- AuthenticationApproachCited by OB-OBS-001, OB-OBS-009
- CBPII endpointsCited by OB-IF-001
- ErrorModelCited by OB-IF-008
- GET /accountsCited by OB-AIS-002
- GET /accounts/{accountResourceId}/balancesCited by OB-AIS-002
- GET /accounts/{accountResourceId}/transactionsCited by OB-AIS-002
- 8.3. Standing Orders RequestCited by OB-PIS-001
- StandingOrderCharacteristicsCited by OB-PIS-001
- 8.1. Payment Request with multiple instructions having differentCited by OB-PIS-003
- GET /payment-requests/{paymentRequestResourceId}/transactionsCited by OB-PIS-006
- SupplementaryDataCited by OB-PIS-008
- FundsAvailabilityInformationCited by OB-PIS-010
- POST /funds-confirmationsCited by OB-PIS-010
- PaymentInformationStatusCodeCited by OB-PIS-011
- StatusReasonInformationCited by OB-PIS-012
- AccessCited by OB-DB-002
- PaymentRequestResourceCited by OB-OBS-002
- POST /registerCited by OB-OBS-004
- AccountIdentificationCited by OB-OBS-007
- POST /payment-requests/{paymentRequestResourceId}/confirmationCited by OB-OBS-012