Information on Handelsbanken Payment API version 2

Update regarding V2 Payments API for Swedish customers

Handelsbanken Relaunches Payment API V2

The PIS API version 2 has now been relaunched. This version is identical to the previously released version, with the addition of a new endpoint.

Our Payment API V2 now supports the SEK Credit Transfer endpoint for the new local domestic payment type in Sweden.

In addition, we have introduced a new endpoint for both corporate and private customers: other-bank-domestic-credit-transfer. This endpoint should be used for payments that need to be debited immediately after successfully passing all internal validation checks. We understand that this functionality is important for some Third-Party Providers (TPPs). For more information, please refer to the FAQ for ‘Payments to other Banks’.

Please note that, due to changes to our account offerings, it will no longer be possible to initiate payments to other banks from the account type Allkortskonto.

Important Timeline

We kindly ask you to review the documentation available on our Developer Portal and test your integration in our Sandbox environment.

Please be aware that we will shortly be deprecating PIS API V1 and is scheduled to be decommissioned on the 15th November 2026.

Previously communicated information about SEK Credit transfer (from March 2026)

FAQ SEK Credit Transfer

 

 

Country specific Card Account rules
Sweden

Country specific information about our Card Account Information API and its implementation rules.

 

Individual customers

SCA Methods

The strong customer authentication (SCA) methods and security solutions applicable for Swedish Individual customers are:

- Redirect: Card reader and log-on card, with / without cable
- Decoupled: Mobile BankID

Short Term Consent

This endpoint supports access via short term consent for individual customers in Sweden. When using short term consent, you may retrieve a user’s available card list and card balances without setting up long-term access tokens.

Card Accounts

We will deliver Charge Card Accounts and Credit Card Accounts for Individual customers. Debit card transactions are not included in this Card Account Information API because they are included in the Account Information API.

KYC (Know Your Customer)

In order to retrieve customer's card accounts, the customer must have a valid KYC (Know Your Customer) at Handelsbanken. If there isn't a valid KYC, you (as the TPP) will receive a 403 error code when trying to retrieve card account information. Please refer the customer to the Bank / their online banking where they will find instructions.

Allkort (Card Account product)

Allkort MasterCard is a combined charge/credit card which has its own account, which is called the Allkort account (Allkortskonto). The customer can deposit money into the account and there is a credit facility linked to the account. The available amount is the sum of the credit facility and the balance on the account, minus any purchases made on the card that have not yet been invoiced or have been invoiced, but not debited.

Note that with this API you will only receive the card-based transactions, not the transactions made on the Allkort account. If you want to retrieve the account transactions, please use the Accounts API. To get a complete picture of the Allkort product, request information using both the Accounts API and Card Accounts API. 

Mobile BankID

Please note that if the SCA method ”Mobile BankID” is selected, and the Mobile BankID wasn't issued by Handelsbanken (i.e. another bank issued it), it needs to be activated before it can be used. This is achieved by the end user (PSU) logging into the Handelsbanken online services (for the first time).

Attributes for the Card Accounts API

In the below document you'll find which attributes are applicable for Swedish Individual customers, as well as other rules for Card Accounts (e.g. the maximum number of transactions).

Card Accounts API Attributes SE Individuals document

 

Corporate customers

SCA Methods

The strong customer authentication (SCA) methods and security solutions applicable for Swedish Corporate customers are:

- Redirect: Card reader and log-on card, with / without cable
- Decoupled: Mobile BankID

Payment Accounts

We will deliver PSD2 Payment Accounts for Corporate customers.

KYC (Know Your Customer)

In order to retrieve customer's accounts, the customer must have a valid KYC (Know Your Customer) at Handelsbanken. If there isn't a valid KYC, you (as the TPP) will receive a 403 error code when trying to retrieve account information. Please refer the customer to the Bank / their online banking where they will find instructions.

PSU-Corporate-ID

For Corporate banking customers, when sending in a request using our Consent API, you need to add a "PSU-Corporate-ID" into the header. For Swedish Corporates, this is their Organisation number or SHB number, and for Sole Traders (Enskild firma), it is their Social Security Number, all of which are 10 digits.

Corporate mandate

For the end user / agent (PSU) to be able to access the Corporate customer's account information or make payments, they need to have the appropriate permissions as per the Corporate mandate, as well as the "Additional service API Corporate". An end user's permissions can be updated by the Corporate customer's administrator in the Handelsbanken online services by going to “Administration” and then “Mandates”, or by contacting their local branch.

For an end user / agent (PSU) to be able to access a Sub-account (underkonto), a mandate from the owner of the Main-account (huvudkonto) is needed.

Mobile BankID

If the SCA method ”Mobile BankID” is selected, and the Mobile BankID wasn't issued by Handelsbanken (i.e. another bank issued it), it needs to be activated before it can be used. This is achieved by the end user (PSU) logging into the Handelsbanken online services (for the first time).

An end user must also have the appropriate permission "Additional service Log in with Mobile BankID" if they wish to log in using Mobile BankID. This can be updated by the Corporate customer's administrator in the Handelsbanken online services by going to “Administration” and then “Mandates”, or by contacting their local branch.

Attributes for the Accounts API

Please refer to the API specification, to find what attributes are applicable for Swedish customers, as well as other rules for Accounts (e.g. the maximum number of transactions).