How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Deutsche Bank Authorization API

The Authorization API from Deutsche Bank — 3 operation(s) for authorization.

Deutsche Bank Authorization API is one of 50 APIs that Deutsche Bank publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Authorization. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, an API reference, a getting-started guide, and authentication docs.

This API exposes 3 operations across 3 paths, and defines 4 schemas. It is described by OpenAPI 3.2.0, at version 1.0.0.

Requests are made against 2 base URLs: https://testmerch.directpos.de/rest-api/security/v1/, https://simulator-api.db.com:443/gw/public/oneid/.

3 operations 3 paths 4 schemas 1 GET2 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
1.0.0
Base URL
https://api.db.com/gw/dbapi
Authentication
HTTP Bearer
Resource Areas
1

Authentication & Security 1

Deutsche Bank Authorization API declares 1 security scheme for authenticating requests. It accepts HTTP bearer tokens (JWT) (bearerAuth).

Paths & Operations 3

Across 3 paths, the API surfaces 3 operations — 1 GET, 2 POST. Each is listed below with its method, path, parameters, and response codes.

Authorization 3
POST
/token
Get token
getToken 2 params body → 200401default
GET
/ciam/entitlements/oneids/{oneIdId}/contexts/{contextId}/business-transactions
Fetch entitlements for a OneID/context
getBusinessTransactionsEntitlements 2 params → 200401403
POST
/ciam/entitlements/oneids/branch-customer-numbers/privileges
Fetch entitlements by branch customer numbers
getBranchCustomerNumberPrivileges body → 200401403

Schemas 4

The contract defines 4 schemas that model the data the API accepts and returns. The most detailed are AccessTokenResponse (5 properties), AccessTokenRequest (4 properties), ErrorResponse (3 properties), AccessTokenError (2 properties). Each schema is shown below with its type and property counts.

AccessTokenError
object
The response object that is received after a failed authorization.
2 properties 1 required
AccessTokenRequest
object
Perform the request to get an authorization token. Make sure to have URL-encoding applied to the parameter values by your HTTP-client or implementation.
4 properties 4 required
AccessTokenResponse
object
The response object that is received after a successful authorization.
5 properties 5 required
ErrorResponse
object
3 properties

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

deutsche-bank-authorization-api-openapi.yml Raw ↑

Other APIs Deutsche Bank publishes across the network.

Deutsche Bank Alias API
Deutsche Bank Apple Pay API
Deutsche Bank Callback API
Deutsche Bank Cancel SEPA Credit Transfers API
Deutsche Bank Cancel SEPA Instant Credit Transfers API
Deutsche Bank Cash account opening status API
Deutsche Bank Cash Account Openings API
Deutsche Bank Cash Accounts API
Deutsche Bank Create SEPA Credit Transfers API
Deutsche Bank Create SEPA Instant Credit Transfers API
Deutsche Bank Employee Share Plan Securities Account Opening API
Deutsche Bank E Score API
Where this information came from

This is an independent, third-party profile of Deutsche Bank Authorization API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.