Information on Handelsbanken Payment API version 2

Update regarding V2 Payments API for Swedish customers

Handelsbanken Relaunches Payment API V2

The PIS API version 2 has now been relaunched. This version is identical to the previously released version, with the addition of a new endpoint.

Our Payment API V2 now supports the SEK Credit Transfer endpoint for the new local domestic payment type in Sweden.

In addition, we have introduced a new endpoint for both corporate and private customers: other-bank-domestic-credit-transfer. This endpoint should be used for payments that need to be debited immediately after successfully passing all internal validation checks. We understand that this functionality is important for some Third-Party Providers (TPPs). For more information, please refer to the FAQ for ‘Payments to other Banks’.

Please note that, due to changes to our account offerings, it will no longer be possible to initiate payments to other banks from the account type Allkortskonto.

Important Timeline

We kindly ask you to review the documentation available on our Developer Portal and test your integration in our Sandbox environment.

Please be aware that we will shortly be deprecating PIS API V1 and is scheduled to be decommissioned on the 15th November 2026.

Previously communicated information about SEK Credit transfer (from March 2026)

FAQ SEK Credit Transfer

 

 

Country specific Account and Card rules
Great Britain

Here you will find country specific information about our Account and Card Information API and its implementation rules.

 

Individual Accounts

SCA Methods

The strong customer authentication (SCA) methods and security solutions applicable for British Individual customers are:

- Redirect: Digital ID
- Redirect: Card reader and log-on card, with / without cable

Payment Accounts

We will deliver PSD2 Payment Accounts for Individual customers.

Attributes for the Accounts API

In the below document you'll find which attributes are applicable for British customers, as well as other rules for Accounts (e.g. the maximum number of transactions).

General Accounts API (that supports multiple countries): Accounts API - GB Attributes document

NEW country specific Accounts & Cards API GB: Accounts and Cards API GB - Attributes document

 

Individual Cards

SCA Methods

The strong customer authentication (SCA) methods and security solutions applicable for British Individual customers are:

- Redirect: Digital ID, card reader and log-on card, with / without cable

Card Accounts

We will deliver Charge Card Accounts for Individual customers. Debit card transactions are not included in this Card Account Information API because they are included in the Account Information API.

Attributes for the Card Accounts API (British Individual customers only)

In the below document you'll find which attributes are applicable for British Individual customers, as well as other rules for Card Accounts (e.g. the maximum number of transactions).

General Card Accounts API (that supports multiple countries): Card Accounts API - GB Attributes document

NEW country specific Accounts & Cards API GB: Accounts and Cards API GB - Attributes document

 

Corporate Accounts

SCA Methods

The strong customer authentication (SCA) methods and security solutions applicable for British Corporate customers are:

- Redirect: Digital ID
- Redirect: Card reader and log-on card, with / without cable

Consent flow

To make the Consent flow easier for accessing GB Corporate accounts, we have removed the requirement for TPPs to enter a customer number in the PSU-Corporate-ID field (in the header). Instead, TPPs who want to access GB Corporate accounts should input the value UNKNOWN into the PSU-Corporate-ID field. As a result of the TPP entering UNKNOWN, after the customer has authenticated themselves in the SCA flow, they will be presented with a list where they can either select Individual (if they have access to Individual accounts) or the name of the Corporate(s) that they have access to. The customer can only make one selection per Consent.

It's important to note that if PSU-Corporate-ID is left blank, we will assume it is an Individual customer and if they aren't (because they only have access to Corporate accounts), then the signing will return an error.

Payment Accounts

We will deliver PSD2 Payment Accounts for Corporate customers.

Permission to view accounts

For the end user / agent (PSU) to be able to access the Corporate customer's account information, they need to have the appropriate permissions as per the Corporate mandate.

An end user's permissions can be updated by the Corporate customer's administrator in the Handelsbanken Online Banking services (e.g. under "Profile", then "Permission administration"). They then need to select "Permission by person" and select the name of the user. For our Account Information API, the user needs to have the "View account information" permission.

Providing the user has the correct permission, they will be able to view the account in the Handelsbanken Online Banking services, as well as the Third Party Provider's services. If a PSU is unsure about their permissions, they need to contact their local branch.

Attributes for the Accounts API

In the below document you'll find which attributes are applicable for British customers, as well as other rules for Accounts (e.g. the maximum number of transactions).

General Accounts API (that supports multiple countries): Accounts API - GB Attributes document

NEW country specific Accounts & Cards API GB: Accounts and Cards API GB - Attributes document