# OB-OBS-011 — Forcing a redirect to the bank's website

> The ASPSP may not impose an automatic redirect to its web page at authentication when the dedicated interface does not support all its authentication procedures.

- Article: PSR 44(1)(k)
- Who is bound: ASPSP
- Who it is for: Product, API, Audit and pentest
- Application: 21 months after entry into force, the general application date (Article 112).
- Level 2: No EBA mandate covers this obligation.
- Origin: RTS 2018/389, Art. 32(3); EBA Opinion of 4 June 2020 on obstacles

Provisional numbering of the April 2026 compromise (Council doc. 8221/26). The final numbering will be added when the Official Journal publishes the text, without changing the id.

## STET 1.6.3: To review

STET redirection sends the user to a URL the bank provides, the OAuth2 authorisation endpoint for the AISP and the `consentApproval` link for the PISP. The specification does not describe handing over to the mobile app, which depends on each bank.

- <https://openfinanceguide.com/en/stet/1.6.3/framework/3-prerequisites-and-technical-details>

## Sources

- [Council doc. 8221/26, page 263](https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=263)

Checked on 2026-10-04. https://openfinanceguide.com/en/dsp3/obligations/ob-obs-011
