Skip to main content
Versionv1

IBAN Verification API (1)

Download OpenAPI specification:Download

Use CM's IBAN Verification API to retrieve a person's International Bank Account Number (IBAN) using iDEAL | Wero. This requires a merchant token. If you have not yet received a merchant token, you can request one via this link.

Transaction

Create transaction

Start an IBAN Verification request

Request Body schema: application/json
required

Start

merchant_token
required
string <uuid> (MerchantToken)

a UUID string that is unique and private to you as a merchant. Do not share this key, keep it safe. Example 3c01abeb-b031-4fea-9f2d-c55c283cd78e

entrance_code
required
string [ 1 .. 40 ] characters ^[a-zA-Z0-9]+$

This is a token that will allow you to rejoin the user to his session when he returns. It can be a maximum of 40 characters and should only contain the characters a-z, A-Z and 0-9. It should only be valid once and needs to be random enough (best use a cryptographically secure random generator), to avoid the possibility of replay attacks.

merchant_return_url
required
string <= 512 characters

The place where the bank should redirect the user to at the end of the flow. The bank will append two query parameters to this url when returning the user to you, trxid and ec. The latter will contain the value of entranceCode, trxid is the transaction_id that you will receive in this request.

Responses

Request samples

Content type
application/json
{
  • "merchant_token": "3c01abeb-b031-4fea-9f2d-c55c283cd78e",
  • "entrance_code": "string",
  • "merchant_return_url": "string"
}

Response samples

Content type
application/json
{}

Get transaction status

After the user has returned to you via your merchant_return_url, you retrieve the transaction_id from the trxid parameter. You should check that both the entrance_code and the transaction_id match your expectations for that consumer, before you make this status call.

Request Body schema: application/json
required
merchant_token
required
string <uuid> (MerchantToken)

a UUID string that is unique and private to you as a merchant. Do not share this key, keep it safe. Example 3c01abeb-b031-4fea-9f2d-c55c283cd78e

transaction_id
required
string (TransactionID) = 16 characters ^[0-9]+$

A token for this transaction. You should store this with your session data, so that at any point, you can make a callback to the CM api and retrieve the status and/or results. Note that it is not guaranteed that your user will return to you via your merchant_return_url. A connection might be dropped, a user might accidentally close a window, or they might trigger the back button and return that way. This id is the only way you can retrieve any information in that case.

merchant_reference
required
string <= 35 characters ^[a-zA-Z0-9]+$

The private reference of the transaction

Responses

Request samples

Content type
application/json
{
  • "merchant_token": "3c01abeb-b031-4fea-9f2d-c55c283cd78e",
  • "transaction_id": "stringstringstri",
  • "merchant_reference": "string"
}

Response samples

Content type
application/json
{
  • "transaction_id": "stringstringstri",
  • "status": "success",
  • "issuer_id": "RABONL2U",
  • "name": "A. van Dijk",
  • "iban": "NL45INGB0000012345"
}