# OB-SCA-001 — TPPs rely on the ASPSP's authentication

> The ASPSP lets PISPs and AISPs rely on the authentication procedures it provides to its customers.

- Article: PSR 86(2)
- Who is bound: ASPSP
- Who it is for: API
- Application: 21 months after entry into force, the general application date (Article 112).
- Level 2: RTS under Article PSR 89(1)(a), draft due at T + 12 months.
- Origin: PSD2, Art. 97(5)

Provisional numbering of the April 2026 compromise (Council doc. 8221/26). The final numbering will be added when the Official Journal publishes the text, without changing the id.

## STET 1.6.3: Covered

STET's three approaches, redirect, decoupled and one-factor embedded, all rely on the bank's authentication.

- <https://openfinanceguide.com/en/stet/1.6.3/framework/3-prerequisites-and-technical-details>

## Sources

- [Council doc. 8221/26, page 362](https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=362)

Checked on 2026-10-04. https://openfinanceguide.com/en/dsp3/obligations/ob-sca-001
