# OB-IF-009 — Authentication started by the TPP, protected session

> The interface lets the TPP ask the ASPSP to start authentication based on the user's consent, keeps the session between the parties open throughout authentication, and protects the integrity and confidentiality of credentials and authentication codes.

- Article: PSR 36(2)(b) (See also PSR 36(1)(a), PSR 36(1)(b))
- Who is bound: ASPSP
- Who it is for: API, Audit and pentest
- Application: 21 months after entry into force, the general application date (Article 112).
- Level 2: RTS under Article PSR 89(1)(e), draft due at T + 12 months.
- Origin: RTS 2018/389, Art. 30(2)

Provisional numbering of the April 2026 compromise (Council doc. 8221/26). The final numbering will be added when the Official Journal publishes the text, without changing the id.

## STET 1.6.3: Covered

In redirect or decoupled mode, the TPP triggers authentication at the bank, through the OAuth2 authorisation for the AISP and through the payment request for the PISP, over a mutually authenticated TLS connection.

- <https://openfinanceguide.com/en/stet/1.6.3/framework/3-prerequisites-and-technical-details>
- <https://openfinanceguide.com/en/stet/1.6.3/flows/6-1-psu-context-retrieval>
- <https://openfinanceguide.com/en/stet/1.6.3/endpoints/pisp/payment-requests-post>

## Sources

- [Council doc. 8221/26, page 242](https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=242)
- [Council doc. 8221/26, page 243](https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=243)

Checked on 2026-10-04. https://openfinanceguide.com/en/dsp3/obligations/ob-if-009
