# AIS Consent Management and Retrieving Account Information and Balances Tutorial
source: https://developer.mastercard.com/open-banking-connect/documentation/tutorials-and-guides/consent-ais-tutorial/index.md

In this tutorial we demonstrate how to provide your customer a view of their accounts, transactions and balances, leveraging Open Banking Connect. We cover how you gain consent from the Payment Service Users (PSUs) to access their account details, and show how you request a variety of details related to the customer's account, such as their balance and transactions.

Examples used in this tutorial are based on the Open Banking Connect sandbox. In some cases there maybe some suitable differences between our Sandbox and Production environments. We have noted these differences where applicable, to assist you in preparing for future live use of the OB Connect APIs.


<br />

Tip: Additionally, we show how to retrieve accounts, account details, balances, transactions, and transaction details, using the Rest API and Java library.

## What is Consent? {#what-is-consent}

With the introduction of PSD2, banks are now required to share customer data with third party providers (TPPs), while also requiring that sensitive customer data is shared securely. In order to ensure that only data which the customer has given explicit consent for is shared with the TPP, the customer must give consent to the ASPSP in a process called consent management. Open Banking Connect provides a consent management service for the TPP developer, described in the following Account Information Service tutorial.


### Consent and Open Banking Connect {#consent-and-open-banking-connect}

Open Banking Connect provides single universal API for the TPP developer so that they can connect to banks using all of the standards available across Europe. Currently supported standards include CMA9, PolishAPI, NextGenPSD2, STET, Czech Open Banking Standard, Slovak Banking API Standard, and Budapest Bank. Before a bank allows accessing any sensitive user information, the consent must be authorized as described in this tutorial.

## Get list of available banks {#get-list-of-available-banks}

The first step is to get a list of available banks that the customer is able to access. This is done through the Get List of ASPSPs endpoint in the API. See also the [Get List of ASPSPs](https://developer.mastercard.com/open-banking-connect/documentation/aisfeatures/ais-get-list-of-aspsps/index.md) documentation.

The following sequence diagram shows the flows used to retrieve the list of available banks.
Diagram list_of_banks

### Code sample {#code-sample}

To get a list of available banks submit the following request. The `returnAdditionalData` field is optional, and is used to return a list of capabilities for each Bank:
* Json
* Java

```json
POST /accounts/aspsp
{
  "requestInfo": {
    "xRequestId": "123e4567-e89b-12d3-a456-426655440000"
  },
  "returnAdditionalData": [
    "capabilities",
    "logo",
    "health"
  ],
  "limit": 100,
  "offset": "018d02c8-9be6-4363-9f3a-9009b2c89768"
}
```

```java
import com.mastercard.openbanking.ApiClient;
import com.mastercard.openbanking.ApiException;
import com.mastercard.openbanking.Configuration;
import com.mastercard.openbanking.models.*;
import com.mastercard.openbanking.api.AspsPsApi;

public class Example {
  public static void main(String[] args) {
    ApiClient defaultClient = Configuration.getDefaultApiClient();
    defaultClient.setBasePath("http://localhost/openbanking/sandbox/connect/api");

    AspsPsApi apiInstance = new AspsPsApi(defaultClient);
    PostAspspsParamsBody body = new PostAspspsParamsBody(); // PostAspspsParamsBody | Request Body
    try {
      PostAspspsOKBody result = apiInstance.accountsAspspsPost(body);
      System.out.println(result);
    } catch (ApiException e) {
      System.err.println("Exception when calling AspsPsApi#accountsAspspsPost");
      System.err.println("Status code: " + e.getCode());
      System.err.println("Reason: " + e.getResponseBody());
      System.err.println("Response headers: " + e.getResponseHeaders());
      e.printStackTrace();
    }
  }
}
```

Note: Do not change `xRequestId`, otherwise the request will not provide the pre-defined response in the Sandbox environment. Note: These JAVA and JSON code samples are for the purpose of example only. Open Banking API may evolve over time, rending these codes examples obsolete. Refer to the latest [Get List of ASPSPs](https://developer.mastercard.com/open-banking-connect/documentation/aisfeatures/ais-get-list-of-aspsps/index.md) documentation for the up-to-date JSON examples.

OB Connect sends the response to retrieve the list of available banks below:
* JSON

```JSON
{
  "originalRequestInfo": {
    "xRequestId": "444e4567-e55b-12d3-a456-426655448888"
  },
  "aspsps": [
    {
      "id": "123e4567-e89b-12d3-a456-426655440000",
      "name": "Wood bank",
      "aspspServices": [
        "AIS",
        "PIS",
        "COF"
      ],
      "profile": "CMA9",
      "country": "UK",
      "capabilities": {
        "retrieve_accounts": true,
        "obtain_ais_consent": true,
        "delete_ais_consent": true
      },
      "logo": {
        "fileType": "png",
        "binaryContent": "GNhcm5hbCBwbGVhc3VyZS4=",
        "logoUrl": "https://openbanking.mastercard.eu/live/imgs/16f0f635-9d94-4976-b49b-584ca231c232.svg"
      },
      "health": {
        "aisStatus": "LIVE",
        "pisStatus": "LIVE",
        "lastUpdatedAt": "2021-05-21T08:30:00.123Z"
      },
      "credentialFields": [
        {
          "id": "iban",
          "displayName": "IBAN"
        }
      ]
    }
  ],
  "offset": "d0868dd0-d070-4ffe-9dde-4f9a278d4761"
}
```

## AIS Submit Consent {#ais-submit-consent}

In this step we demonstrate how to submit account access consent on behalf of the user.
After completing [Step 2](https://developer.mastercard.com/open-banking-connect/documentation/tutorials-and-guides/consent-ais-tutorial/index.md) where you learned how to get a list of available banks, the user must login and authorize account access.
In order to achieve this, we leverage the consent endpoint of the API. See also the [Account Information Consent](https://developer.mastercard.com/open-banking-connect/documentation/aisfeatures/account-information-consent/index.md) documentation.

The following sequence diagram shows the flow used to initiate the creation of consent to access user accounts, transactions, and balance data.
Diagram submit_consent

#### Submit Consent code sample {#submit-consent-code-sample}

To initiate a consent call, submit the following request:
* JSON
* Java

```JSON
POST /accounts/consents

{
  "requestInfo": {
    "xRequestId": "123e4567-e89b-12d3-a456-426655440000",
    "tppRedirectURI": "https://tpp-ob.com/callback",
    "aspspId": "420e5cff-0e2a-4156-991a-f6eeef0478cf",
    "isLivePsuRequest": true,
    "psuTppCustomerId": "420e5cff-0e2a-4156-991a-f6eeef0478cf",
    "psuIPAddress": "192.168.0.1",
    "psuAgent": "PostmanRuntime/7.20.1",
    "merchant": {
      "id": "MerchantId",
      "name": "MerchantName"
    },
    "credentials": {
      "iban": "DE357543513"
    }
  },
  "validUntil": "2031-04-27",
  "validUntilDateTime": "2031-05-21T08:30:00Z",
  "permissions": [
    "allPSD2"
  ],
  "accounts": [
    {
      "accountReference": {
        "currency": "EUR",
        "accountNumber": {
          "identification": "ACCNUMBR1234567",
          "schemeName": "IBAN"
        }
      }
    }
  ]
}
```

```java
import com.mastercard.openbanking.ApiClient;
import com.mastercard.openbanking.ApiException;
import com.mastercard.openbanking.Configuration;
import com.mastercard.openbanking.models.*;
import com.mastercard.openbanking.api.AiConsentsApi;

public class Example {
  public static void main(String[] args) {
    ApiClient defaultClient = Configuration.getDefaultApiClient();
    defaultClient.setBasePath("http://localhost/openbanking/sandbox/connect/api");

    AiConsentsApi apiInstance = new AiConsentsApi(defaultClient);
    PostAccountsConsentsParamsBody body = new PostAccountsConsentsParamsBody(); // PostAccountsConsentsParamsBody | There are 2 types of AI Consents: All - 'allPSD2' and per level - 'accounts', 'balances', 'transactions'
    try {
      PostAccountsConsentsOKBody result = apiInstance.accountsConsentsPost(body);
      System.out.println(result);
    } catch (ApiException e) {
      System.err.println("Exception when calling AiConsentsApi#accountsConsentsPost");
      System.err.println("Status code: " + e.getCode());
      System.err.println("Reason: " + e.getResponseBody());
      System.err.println("Response headers: " + e.getResponseHeaders());
      e.printStackTrace();
    }
  }
}
```

Note: Do not change `aspspId` and `permissions`, otherwise the request will not provide the pre-defined response in the Sandbox environment. Note: These JAVA and JSON code samples are for the purpose of example only. Open Banking API may evolve over time, rending these codes examples obsolete. Refer to the latest [Account Information Consent](https://developer.mastercard.com/open-banking-connect/documentation/aisfeatures/account-information-consent/index.md) and [Exchange the PSU Authorization for Access Consent](https://developer.mastercard.com/open-banking-connect/documentation/aisfeatures/exchange-psu-consent/index.md) documentation for the up-to-date JSON examples.

The following is an example of a received response. The User should be redirected to the link from the `scaRedirect` field, and prompted to authenticate and authorize consent with the Bank.
* JSON

```JSON
{
  "originalRequestInfo": {
    "xRequestId": "444e4567-e55b-12d3-a456-426655448888"
  },
  "aspspSCAApproach": "REDIRECT",
  "consentRequestId": "rq:7JKvT4jY3oc4xxAdSqdYawemSQP:5zKtXEAq",
  "_links": {
    "scaRedirect": "https://bank1.com/sca/login"
  }
}
```

Note: In production environment, your application needs to redirect the User to the URI received in `scaRedirect` to complete the authentication with the Bank and authorization of the consent.

After you redirect the customer to the `scaRedirect`, the customer authenticates with the bank to authorize consent. The above scaRedirect link allows access to a demo bank (ASPSP) application which can be completed to authorize consent as follows:

1. Fill in any username and password, select the required scenario and redirect type, then click "Log in".
   ![AIS Authorization String](https://static.developer.mastercard.com/content/open-banking-connect/img/tutorials/OBC_AIS_AuthString.png)

2. After login, user will be redirected to the tppRedirectURL specified in the Sandbox API call.

3. The callback with authorization string will be received.

Tip: After the User authorizes consent, your application obtains an authorization string from auth query parameter on the URI address specified in the `tppRedirectURI` field in the request.

***The authorization string will timeout after a maximum period of 10 minutes. This may vary by bank but should not exceed 10 minutes.***

You application uses this authorization string (ex. `code=UKaccountR755r433g5fggfdU34ff4grfdr2oUK005&state=795f0eba-d462-42de-a163-c7559162994f`) and consentId is required in all subsequent requests associated with the consent.

In the Sandbox environment, the authorization string and consentId are hardcoded (See the `authorization` and `consentId` fields in the respective request body).

### Obtaining ConsentId to Retrieve Customer Account Data {#obtaining-consentid-to-retrieve-customer-account-data}

Once consent is authorized, OB Connect sends a consentId used in subsequent requests for account data relating to this consent.

#### Obtaining ConsentID Code Sample {#obtaining-consentid-code-sample}

To exchange the PSU authorization for access consent, submit the following request:
* JSON

```JSON
POST /accounts/consents/authorizations
{
  "requestInfo": {
    "xRequestId": "123e4567-e89b-12d3-a456-426655440000",
    "aspspId": "cf7a59be-6ab5-11ea-bc55-0242ac130003",
     "isLivePsuRequest": true,
    "psuIPAddress": "192.168.0.1",
    "psuAgent": "PostmanRuntime/7.20.1",
    "merchant": {
      "id": "MerchantId",
      "name": "MerchantName"
    }
  },
  "authorization": "code=UKaccountR755r433g5fggfdU34ff4grfdr2oUK005&state=7f48868d-d8ac-49ff-8785-9c43e3ad4a07"
}

```

Note: `aspspId` and `authorization` should be provided unchanged in order to match the pre-defined response in the Sandbox environment.

The following is an example of the received response:
* JSON

```JSON
{
   "originalRequestInfo":{
      "xRequestId":"123e4567-e89b-12d3-a456-426655440000"
   },
   "consentId":"u05k4fh:5t578f34r6g",
   "consentRequestId":"23224"
}
```

<br />

Alert: The OBIE, in alignment with the security community, recommends the use of the Hybrid flow. The platform today enforces this by setting the initial response type to **code id_token** in the authorization request to the ASPSP's Authorization Server. The Authorization server is required to return both the access code and id_token in this case, but the manner in which it does this is left to the discretion of the Authorization Server. This could be in either form:  

* TPP_REDIRECT_URL?All_Params
* TPP_REDIRECT_URL#All_Params   
  The current best practice is to return these values as a hash fragment. This allows the User Agent to receive the values and skip redirection (performance enhancement), and not send the access code through a query string parameter where it will be logged by proxies, firewalls, application servers, and other services in the application path. Having the access code logged in plain text would weaken its value.

For this reason, it is suggested the TPP application parse the access code from the hash fragment and POST it to the Client Service (TPP service) in an AJAX request, where the value may be safely ensconced within the POST body.

## Provide a customer with a list of accounts for their selected bank {#provide-a-customer-with-a-list-of-accounts-for-their-selected-bank}

In this section we explain how to get a list of a customer's accounts from a selected bank. Additional actions can be performed on an account from this list and described in subsequent sections. See also the [Get List of Accounts](https://developer.mastercard.com/open-banking-connect/documentation/aisfeatures/get-list-accounts/index.md) documentation.  

Prerequisites: The TPP should perform the following operations before executing the Get List of Accounts call:

* [Submit Consent Request to your Customers'](https://developer.mastercard.com/open-banking-connect/documentation/tutorials-and-guides/consent-ais-tutorial/index.md) Chosen Bank operation to get authorization string.
* [Exchange the Customer Authorization for ConsentId](https://developer.mastercard.com/open-banking-connect/documentation/tutorials-and-guides/consent-ais-tutorial/index.md) operations to get consentId.

The following sequence diagram shows the flow used to retrieve the list of accounts from the bank based on previously obtained consentId.

Diagram list_of_accounts

### Code sample {#code-sample-1}

To retrieve (based on the previously obtained consentId) from the bank the list of available accounts, submit the following request:
* JSON
* Java

```JSON
POST /accounts

{
  "requestInfo": {
    "xRequestId": "123e4567-e89b-12d3-a456-426655440000",
    "consentId": "GFiTpF3:EBy5xGqQMatk",
    "isLivePsuRequest": true,
    "psuTppCustomerId": "420e5cff-0e2a-4156-991a-f6eeef0478cf",
    "psuIPAddress": "192.168.0.1",
    "psuAgent": "PostmanRuntime/7.20.1",
    "aspspId": "420e5cff-0e2a-4156-991a-f6eeef0478cf",
    "merchant": {
      "id": "MerchantId",
      "name": "MerchantName"
    }
  }
}
```

```java
import com.mastercard.openbanking.ApiClient;
import com.mastercard.openbanking.ApiException;
import com.mastercard.openbanking.Configuration;
import com.mastercard.openbanking.models.*;
import com.mastercard.openbanking.api.ListOfAccountsApi;

public class Example {
  public static void main(String[] args) {
    ApiClient defaultClient = Configuration.getDefaultApiClient();
    defaultClient.setBasePath("http://localhost/openbanking/sandbox/connect/api");

    ListOfAccountsApi apiInstance = new ListOfAccountsApi(defaultClient);
    PostAccountsParamsBody body = new PostAccountsParamsBody(); // PostAccountsParamsBody | Request Body
    try {
      PostAccountsOKBody result = apiInstance.accountsPost(body);
      System.out.println(result);
    } catch (ApiException e) {
      System.err.println("Exception when calling ListOfAccountsApi#accountsPost");
      System.err.println("Status code: " + e.getCode());
      System.err.println("Reason: " + e.getResponseBody());
      System.err.println("Response headers: " + e.getResponseHeaders());
      e.printStackTrace();
    }
  }
}
```

The following is an example of a received response:

<br />

* JSON

```JSON
{
  "originalRequestInfo": {
    "xRequestId": "444e4567-e55b-12d3-a456-426655448888"
  },
  "accounts": [
    {
      "resourceId": "account1",
      "currency": "USD",
      "accountHolderType": "Personal",
      "holderName": "John Doe",
      "accountType": "ASTC01",
      "nameClient": "Accounts name client",
      "name": "My savings account",
      "accountNumber": "70000170000005",
      "schemeName": "BBAN",
      "accountPsuRelations": [
        {
          "typeOfRelation": "Owner"
        }
      ]
    }
  ]
}
```

Note: Do not change `aspspId` and `consentId`, otherwise the request will not provide the pre-defined response in the Sandbox environment.

<br />

Note: These JAVA and JSON code samples are for the purpose of example only. Open Banking API may evolve over time, rending these codes examples obsolete. Refer to the latest [Get List of Accounts](https://developer.mastercard.com/open-banking-connect/documentation/aisfeatures/get-list-accounts/index.md) documentation for the up-to-date JSON examples.

## Provide customer with account details for their selected account {#provide-customer-with-account-details-for-their-selected-account}

In this step we show how to get account details, such as currency and account type for a specific account. For viewing account balances and transactions, please see subsequent sections. See also the [Get Account Details](https://developer.mastercard.com/open-banking-connect/documentation/aisfeatures/get-account-details/index.md) documentation.

Prerequisites: The TPP should perform the following operations before executing the Get Account Details call:

* [Submit Consent Request to your Customers' Chosen Bank](https://developer.mastercard.com/open-banking-connect/documentation/tutorials-and-guides/consent-ais-tutorial/index.md) operation to get authorization string
* [Exchange the Customer Authorization for ConsentId](https://developer.mastercard.com/open-banking-connect/documentation/tutorials-and-guides/consent-ais-tutorial/index.md) operations to get consentId
* [Provide Customer with a List of Accounts for Their Selected Bank](https://developer.mastercard.com/open-banking-connect/documentation/tutorials-and-guides/consent-ais-tutorial/index.md) operation to get account identifier

The following sequence diagram shows the flow used to retrieve the account details information from the bank based on previously obtained consentId and account identification code.

Diagram account_details

### Code sample {#code-sample-2}

To retrieve account details from the bank, based on the previously obtained consentId and accountId, submit the following request:
* JSON

```JSON
POST /accounts/account
{
  "requestInfo": {
    "xRequestId": "123e4567-e89b-12d3-a456-426655440000",
    "consentId": "GFiTpF3:EBy5xGqQMatk",
    "aspspId": "420e5cff-0e2a-4156-991a-f6eeef0478cf",
    "isLivePsuRequest": true,
    "psuTppCustomerId": "420e5cff-0e2a-4156-991a-f6eeef0478cf",
    "psuIPAddress": "192.168.0.1",
    "psuAgent": "PostmanRuntime/7.20.1",
    "merchant": {
      "id": "MerchantId",
      "name": "MerchantName"
    }
  },
  "accountId": "aa:q648383844dhhfHhTV"
}
```

Note: Do not change `accountId`, `consentId`, `aspspId`, otherwise the request will not provide the pre-defined response in the Sandbox environment. Note: These JAVA and JSON code samples are for the purpose of example only. Open Banking API may evolve over time, rending these codes examples obsolete. Refer to the latest [Get Account Details](https://developer.mastercard.com/open-banking-connect/documentation/aisfeatures/get-account-details/index.md) documentation for the up-to-date JSON examples.

The following is an example of a received response:
* JSON

```JSON
{
  "originalRequestInfo": {
    "xRequestId": "444e4567-e55b-12d3-a456-426655448888"
  },
  "account": {
    "resourceId": "account1",
    "currency": "USD",
    "accountHolderType": "Personal",
    "accountType": "ASTC01",
    "nameClient": "Accounts name client",
    "name": "My savings account",
    "holderName": "John Doe",
    "holderAddress": {
      "street": "Street",
      "buildingNumber": "15",
      "city": "City",
      "postalCode": "PostCode",
      "countrySubDivision": "Division",
      "country": "CC"
    },
    "holderNameAddress": [
      "Street Street"
    ],
    "accountPsuRelations": [
      {
        "typeOfRelation": "Owner"
      }
    ],
    "accountNumber": "70000170000005",
    "schemeName": "BBAN",
    "auxData": "{\"additionalProp1\": \"somePropertyValue1\"}"
  }
}
```

## Retrieve account balances for a customer's account {#retrieve-account-balances-for-a-customers-account}

In this section we show how to retrieve a list of account balances for an account based on previously obtained consentId and accountId. See also the [Get Accounts Balance](https://developer.mastercard.com/open-banking-connect/documentation/aisfeatures/get-account-balances/index.md) documentation.

Prerequisites: The TPP performs the following operations before executing the Get Account Balances call:

* [Submit Consent Request to your Customers Chosen Bank](https://developer.mastercard.com/open-banking-connect/documentation/tutorials-and-guides/consent-ais-tutorial/index.md) operation to get authorization string.
* [Exchange the Customer Authorization for ConsentId](https://developer.mastercard.com/open-banking-connect/documentation/tutorials-and-guides/consent-ais-tutorial/index.md) operations to get consentId.
* [Provide Customer with a List of Accounts for Their Selected Bank](https://developer.mastercard.com/open-banking-connect/documentation/tutorials-and-guides/consent-ais-tutorial/index.md) operation to get account identifier.

The following sequence diagram shows the flow used to retrieve the account balance information from the customer's bank.

Diagram account_balances

##### Code sample {#code-sample-3}

To retrieve a list of account balance details from the bank, based on the previously obtained consentId and accountId, submit the following request:
* JSON
* Java

```JSON
POST /accounts/account/balances

{
  "requestInfo": {
    "xRequestId": "123e4567-e89b-12d3-a456-426655440000",
    "consentId": "GFiTpF3:EBy5xGqQMatk",
    "aspspId": "420e5cff-0e2a-4156-991a-f6eeef0478cf",
    "isLivePsuRequest": true,
    "psuTppCustomerId": "420e5cff-0e2a-4156-991a-f6eeef0478cf",
    "psuIPAddress": "192.168.0.1",
    "psuAgent": "PostmanRuntime/7.20.1",
    "merchant": {
      "id": "MerchantId",
      "name": "MerchantName"
    }
  },
  "accountId": "aa:q648383844dhhfHhTV"
}
```

```java
import com.mastercard.openbanking.ApiClient;
import com.mastercard.openbanking.ApiException;
import com.mastercard.openbanking.Configuration;
import com.mastercard.openbanking.models.*;
import com.mastercard.openbanking.api.AccountBalancesApi;

public class Example {
  public static void main(String[] args) {
    ApiClient defaultClient = Configuration.getDefaultApiClient();
    defaultClient.setBasePath("http://localhost/openbanking/sandbox/connect/api");

    AccountBalancesApi apiInstance = new AccountBalancesApi(defaultClient);
    PostAccountsAccountBalancesParamsBody body = new PostAccountsAccountBalancesParamsBody(); // PostAccountsAccountBalancesParamsBody | Request Body
    try {
      PostAccountsAccountBalancesOKBody result = apiInstance.accountsAccountBalancesPost(body);
      System.out.println(result);
    } catch (ApiException e) {
      System.err.println("Exception when calling AccountBalancesApi#accountsAccountBalancesPost");
      System.err.println("Status code: " + e.getCode());
      System.err.println("Reason: " + e.getResponseBody());
      System.err.println("Response headers: " + e.getResponseHeaders());
      e.printStackTrace();
    }
  }
}
```

Note: Do not change `aspspId`, `accountId` and `consentId`, otherwise the request will not provide the pre-defined response in the Sandbox environment. Note: These JAVA and JSON code samples are for the purpose of example only. Open Banking API may evolve over time, rending these codes examples obsolete. Refer to the latest [Get Account Balances](https://developer.mastercard.com/open-banking-connect/documentation/aisfeatures/get-account-balances/index.md) documentation for the up-to-date JSON examples.

The following is an example of the received response:
* JSON

```JSON
{
  "originalRequestInfo": {
    "xRequestId": "444e4567-e55b-12d3-a456-426655448888"
  },
  "account": {
    "resourceId": "AccountReference1",
    "name": "My savings account",
    "balances": [
      {
        "balanceAmount": {
          "currency": "USD",
          "amount": 100.23
        },
        "balanceType": "Current",
        "creditDebitIndicator": "CREDIT",
        "dateTime": "2021-05-21T08:30:00Z"
      }
    ]
  }
}
```

## Get account transactions {#get-account-transactions}

In this section we show how to retrieve a list of account transactions for an account based on previously obtained consentId and accountId. See also the [Get Account Transactions](https://developer.mastercard.com/open-banking-connect/documentation/aisfeatures/get-account-transactions/index.md) documentation.

Prerequisites: The TPP performs the following operations before executing the Get Account Transactions call:

* [Submit Consent Request to your Customers Chosen Bank](https://developer.mastercard.com/open-banking-connect/documentation/tutorials-and-guides/consent-ais-tutorial/index.md) operation to get authorization string
* [Exchange the Customer Authorization for ConsentId](https://developer.mastercard.com/open-banking-connect/documentation/tutorials-and-guides/consent-ais-tutorial/index.md) operation to get consentId
* [Provide Customer with a List of Accounts for Their Selected Bank](https://developer.mastercard.com/open-banking-connect/documentation/tutorials-and-guides/consent-ais-tutorial/index.md) operation to get account identifier

The following sequence diagram shows the flows used to retrieve the list of account transactions from the bank based on previously obtained consentId and account identification code.

Diagram account_transactions

### Code sample {#code-sample-4}

To retrieve a list of transactions from the bank, based on the previously obtained consentId and accountId, submit the following request:
* JSON
* Java

```JSON
POST /accounts/account/transactions

{
  "requestInfo": {
    "xRequestId": "123e4567-e89b-12d3-a456-426655440000",
    "consentId": "GFiTpF3:EBy5xGqQMatk",
    "aspspId": "420e5cff-0e2a-4156-991a-f6eeef0478cf",
    "isLivePsuRequest": true,
    "psuTppCustomerId": "420e5cff-0e2a-4156-991a-f6eeef0478cf",
    "psuIPAddress": "192.168.0.1",
    "psuAgent": "PostmanRuntime/7.20.1",
    "merchant": {
      "id": "MerchantId",
      "name": "MerchantName"
    }
  },
  "accountId": "aa:q648383844dhhfHhTV",
  "limit": 20,
  "offset": "ofset4prev$earch12345",
  "bookingDateFrom": "2018-11-21",
  "bookingDateTo": "2018-11-23"
}
```

```java
import com.mastercard.openbanking.ApiClient;
import com.mastercard.openbanking.ApiException;
import com.mastercard.openbanking.Configuration;
import com.mastercard.openbanking.models.*;
import com.mastercard.openbanking.api.TransactionsApi;

public class Example {
  public static void main(String[] args) {
    ApiClient defaultClient = Configuration.getDefaultApiClient();
    defaultClient.setBasePath("http://localhost/openbanking/sandbox/connect/api");

    TransactionsApi apiInstance = new TransactionsApi(defaultClient);
    PostAccountsAccountTransactionsParamsBody body = new PostAccountsAccountTransactionsParamsBody(); // PostAccountsAccountTransactionsParamsBody | Request Body
    try {
      PostAccountsAccountTransactionsOKBody result = apiInstance.accountsAccountTransactionsPost(body);
      System.out.println(result);
    } catch (ApiException e) {
      System.err.println("Exception when calling TransactionsApi#accountsAccountTransactionsPost");
      System.err.println("Status code: " + e.getCode());
      System.err.println("Reason: " + e.getResponseBody());
      System.err.println("Response headers: " + e.getResponseHeaders());
      e.printStackTrace();
    }
  }
}
```

Note: Do not change `aspspId`, `accountId` and `consentId` , otherwise the request will not provide the pre-defined response in the Sandbox environment. Note: These JAVA and JSON code samples are for the purpose of example only. Open Banking API may evolve over time, rending these codes examples obsolete. Refer to the latest [Get Account Transactions](https://developer.mastercard.com/open-banking-connect/documentation/aisfeatures/get-account-transactions/index.md) documentation for the up-to-date JSON examples.

The following is an example of a received response:
* JSON

```JSON
{
  "originalRequestInfo": {
    "xRequestId": "444e4567-e55b-12d3-a456-426655448888"
  },
  "offset": "ofset4prev$earch12345",
  "transactions": [
    {
      "transactionId": "transactionreference",
      "bookingDateTime": "2021-05-21T08:30:00Z",
      "tradeDate": "2021-05-21T08:30:00Z",
      "transactionAmount": {
        "currency": "USD",
        "amount": 100.23
      },
      "remittanceInformationUnstructured": "Payment for fruits",
      "status": "ACSC",
      "creditDebitIndicator": "CREDIT",
      "initiatorNameAddress": [
        "Street Street"
      ],
      "senderNameAddress": [
        "Street Street"
      ],
      "senderAccountNumber": "ACCNUMBR1234567",
      "recipientNameAddress": [
        "Street Street"
      ],
      "recipientAccountNumber": "ACCNUMBR1234567",
      "recipientAccountMassPayment": "RecipientMass1",
      "recipientBankBicOrSwift": "SBICCOD1",
      "recipientBankName": "Recipient Bank Name 1",
      "recipientBankCode": "88457329",
      "recipientBankCountryCode": "PL",
      "recipientBankAddress": [
        "Street Street"
      ],
      "senderName": "John Doe",
      "recipientName": "John Doe",
      "senderAccountNumberScheme": "IBAN",
      "recipientAccountNumberScheme": "IBAN",
      "senderAccountMassPayment": "SenderMass1",
      "senderBankBicOrSwift": "SBICCOD1",
      "senderBankName": "Sender Bank Name 1",
      "senderBankCode": "10901014",
      "senderBankCountryCode": "PL",
      "senderBankAddress": [
        "Street Street"
      ],
      "transactionType": "Transaction Type 1",
      "auxData": "{\"additionalProp1\": \"somePropertyValue1\"}",
      "postTransactionBalance": 100.23,
      "mcc": "MCC1",
      "rejectionReason": "Rejection Reason 1",
      "rejectionDate": "2021-05-21T08:30:00Z",
      "holdExpirationDate": "2021-05-21T08:30:00Z",
      "bankTransactionCode": {
        "domain": {
          "code": "ACMT",
          "familyCode": "MCOP",
          "subFamilyCode": "CHRG"
        },
        "proprietary": {
          "code": "FWBC",
          "issuer": "BAI"
        }
      }
    }
  ],
  "messages": [
    {
      "code": "IGNORED_DATE_FILTERS",
      "description": "Date filters may be ignored for ASPSPs using current API Profile. Please refer to the API specification for details."
    }
  ]
}
```

## Get account transaction details {#get-account-transaction-details}

In this section we show how to retrieve details of a transaction for an account, based on a previously obtained consentId, accountId and transactionId. See also the [Get Account Transactions Details](https://developer.mastercard.com/open-banking-connect/documentation/aisfeatures/get-account-transactions-details/index.md) documentation.

Prerequisites: The TPP performs the following operations before executing Get Account Transaction Details call:

* [Submit Consent Request to your Customers Chosen Bank](https://developer.mastercard.com/open-banking-connect/documentation/tutorials-and-guides/consent-ais-tutorial/index.md) operation to get authorization string.
* [Exchange the Customer Authorization for ConsentId](https://developer.mastercard.com/open-banking-connect/documentation/tutorials-and-guides/consent-ais-tutorial/index.md) operation to get consentId.
* [Provide Customer with a List of Accounts for Their Selected Bank](https://developer.mastercard.com/open-banking-connect/documentation/tutorials-and-guides/consent-ais-tutorial/index.md) operation to get account identifier.
* [Get Account Transactions](https://developer.mastercard.com/open-banking-connect/documentation/tutorials-and-guides/consent-ais-tutorial/index.md) operation to get transaction identifier.

The following sequence diagram shows the flow used to retrieve account transaction details from the Bank, based on previously obtained consentId, accountId and transaction identification code.

Diagram account_transaction_details

### Code sample {#code-sample-5}

To retrieve details for a given transaction from the bank, previously obtained consentId, accountId and transactionId, submit the following request:
* JSON
* Java

```JSON
POST /accounts/account/transactions/transaction

{
  "requestInfo": {
    "xRequestId": "123e4567-e89b-12d3-a456-426655440000",
    "consentId": "MatkBJbqtZ8sPNznYtfV:5g",
    "aspspId": "b806ae68-a45b-49d6-b25a-69fdb81dede6",
    "isLivePsuRequest": false,
    "psuTppCustomerId": "420e5cff-0e2a-4156-991a-f6eeef0478cf",
    "psuIPAddress": "192.168.0.1",
    "psuAgent": "PostmanRuntime/7.20.1",
    "merchant": {
      "id": "MerchantId",
      "name": "MerchantName"
    }
  },
  "accountId": "qqCfw:XwAa:665hs5:r55dM",
  "transactionId": "7ccs6s5:r55a:4MctP"
}
```

```java
import com.mastercard.openbanking.ApiClient;
import com.mastercard.openbanking.ApiException;
import com.mastercard.openbanking.Configuration;
import com.mastercard.openbanking.models.*;
import com.mastercard.openbanking.api.TransactionDetailsApi;

public class Example {
  public static void main(String[] args) {
    ApiClient defaultClient = Configuration.getDefaultApiClient();
    defaultClient.setBasePath("http://localhost/openbanking/sandbox/connect/api");

    TransactionDetailsApi apiInstance = new TransactionDetailsApi(defaultClient);
    PostAccountsAccountTransactionsTransactionParamsBody body = new PostAccountsAccountTransactionsTransactionParamsBody(); // PostAccountsAccountTransactionsTransactionParamsBody | Request Body
    try {
      PostAccountsAccountTransactionsTransactionOKBody result = apiInstance.accountsAccountTransactionsTransactionPost(body);
      System.out.println(result);
    } catch (ApiException e) {
      System.err.println("Exception when calling TransactionDetailsApi#accountsAccountTransactionsTransactionPost");
      System.err.println("Status code: " + e.getCode());
      System.err.println("Reason: " + e.getResponseBody());
      System.err.println("Response headers: " + e.getResponseHeaders());
      e.printStackTrace();
    }
  }
}
```

Note: Do not change `aspspId`, `accountId`, `consentId` and `transactionId`, otherwise the request will not provide the pre-defined response in the Sandbox environment. Note: These JAVA and JSON code samples are for the purpose of example only. Open Banking API may evolve over time, rending these codes examples obsolete. Refer to the latest [Get Account Transactions Details](https://developer.mastercard.com/open-banking-connect/documentation/aisfeatures/get-account-transactions-details/index.md) documentation for the up-to-date JSON examples.

The following is an example of the received response:
* JSON

```JSON
{
  "originalRequestInfo": {
    "xRequestId": "444e4567-e55b-12d3-a456-426655448888"
  },
  "transactionId": "transactionreference",
  "bookingDateTime": "2021-05-21T08:30:00Z",
  "transactionAmount": {
    "currency": "USD",
    "amount": 100.23
  },
  "remittanceInformationUnstructured": "Payment for fruits",
  "status": "ACSC",
  "creditDebitIndicator": "CREDIT",
  "initiatorNameAddress": [
    "Street Street"
  ],
  "senderNameAddress": [
    "Street Street"
  ],
  "recipientNameAddress": [
    "Street Street"
  ],
  "tradeDate": "2021-05-21T08:30:00Z",
  "senderAccountNumber": "ACCNUMBR123456",
  "recipientAccountNumber": "ACCNUMBR1234567",
  "recipientAccountMassPayment": "RecipientMass1",
  "recipientBankBicOrSwift": "RBICCOD1",
  "recipientBankName": "Recipient Bank Name 1",
  "recipientBankCode": "88457329",
  "recipientBankCountryCode": "PL",
  "recipientBankAddress": [
    "Street Street"
  ],
  "senderAccountMassPayment": "SenderMass1",
  "senderBankBicOrSwift": "SBICCOD1",
  "senderBankName": "Sender Bank Name 1",
  "senderBankCode": "10901014",
  "senderBankCountryCode": "PL",
  "senderBankAddress": [
    "Street Street"
  ],
  "transactionType": "Transaction Type 1",
  "auxData": "{\"additionalProp1\": \"somePropertyValue1\"}",
  "postTransactionBalance": 100.23,
  "mcc": "MCC1",
  "rejectionReason": "Rejection Reason 1",
  "rejectionDate": "2021-05-21T08:30:00Z",
  "holdExpirationDate": "2021-05-21T08:30:00Z",
  "senderName": "John Doe",
  "recipientName": "John Doe",
  "senderAccountNumberScheme": "IBAN",
  "recipientAccountNumberScheme": "IBAN",
  "bankTransactionCode": {
    "domain": {
      "code": "ACMT",
      "familyCode": "MCOP",
      "subFamilyCode": "CHRG"
    },
    "proprietary": {
      "code": "FWBC",
      "issuer": "BAI"
    }
  }
}
```

## Account Information Consent Deletion {#account-information-consent-deletion}

In this step we demonstrate how to delete an account access consent on behalf of the user. To achieve this, we leverage the delete consent endpoint of the API. See also the [Account Information Consent Deletion](https://developer.mastercard.com/open-banking-connect/documentation/aisfeatures/delete-ais-consent/index.md) documentation.

Prerequisites: The TPP performs the following operations before executing Account Information Consent Deletion call:

* [Submit Consent Request to your Customers Chosen Bank](https://developer.mastercard.com/open-banking-connect/documentation/tutorials-and-guides/consent-ais-tutorial/index.md) operation to get authorization string.
* [Exchange the Customer Authorization for ConsentId](https://developer.mastercard.com/open-banking-connect/documentation/tutorials-and-guides/consent-ais-tutorial/index.md) operation to get consentId.

The following sequence diagram shows the flow used to delete account consent from the Bank, based on previously obtained consentId.

Diagram delete_ais_consent

### Code sample {#code-sample-6}

To delete a previously obtained consentId from the bank submit the following request:
* JSON

```JSON
POST /accounts/consents/delete

{
  "requestInfo": {
    "xRequestId": "123e4567-e89b-12d3-a456-426655440000",
    "aspspId": "420e5cff-0e2a-4156-991a-f6eeef0478cf",
    "psuTppCustomerId": "420e5cff-0e2a-4156-991a-f6eeef0478cf",
    "merchant": {
      "id": "MerchantId",
      "name": "MerchantName"
    }
  },
  "consentId": "GFiTpF3:EBy5xGqQMatk"
}
```

Note: Do not change `consentId`, otherwise the request will not provide the pre-defined response in the Sandbox environment. Note: These JAVA and JSON code samples are for the purpose of example only. Open Banking API may evolve over time, rending these codes examples obsolete. Refer to the latest [Get Account Transactions Details](https://developer.mastercard.com/open-banking-connect/documentation/aisfeatures/get-account-transactions-details/index.md) documentation for the up-to-date JSON examples.

The following is an example of the received response:
* JSON

```JSON
{
  "originalRequestInfo": {
    "xRequestId": "444e4567-e55b-12d3-a456-426655448888"
  }
}
```

