How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Finicity Authentication API

Generate authentication tokens and manage credentials

Finicity Authentication API is one of 41 APIs that Finicity publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Authentication. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and an API reference.

This API exposes 2 operations across 1 path, and defines 11 schemas. It is described by OpenAPI 3.2.0, at version 1.43.0.

Requests are made against a single base URL, https://api.finicity.com.

2 operations 1 paths 11 schemas 1 POST1 PUT

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
1.43.0
Base URL
https://api.finicity.com
Authentication
API Key, API Key
Resource Areas
1

Authentication & Security 2

Finicity Authentication API declares 2 security schemes for authenticating requests. An API key is passed in the header as Finicity-App-Key (FinicityAppKey). An API key is passed in the header as Finicity-App-Token (FinicityAppToken). By default, every request must be authenticated.

  • FinicityAppKey — The "Finicity-App-Key" from the developer dashboard
  • FinicityAppToken — A token returned by the /authentication API

Paths & Operations 2

Across 1 path, the API surfaces 2 operations — 1 POST, 1 PUT. Each is listed below with its method, path, parameters, and response codes.

Authentication 2

Generate authentication tokens and manage credentials

POST
/aggregation/v2/partners/authentication
Create Access Token
CreateToken body → 200400401404
PUT
/aggregation/v2/partners/authentication
Modify Partner Secret
ModifyPartnerSecret body → 204400401

Schemas 11

The contract defines 11 schemas that model the data the API accepts and returns. The most detailed are ErrorMessage (10 properties), Error (5 properties), PartnerCredentials (2 properties), ErrorWrapper (1 property). Each schema is shown below with its type and property counts.

PartnerCredentials
object
2 properties 2 required
AccessToken
object
A temporary access token to be passed in the Finicity-App-Token HTTP header of all subsequent API requests
1 property 1 required
ErrorMessage
object
10 properties 1 required
AccountId
string
An account ID
ErrorWrapper
object
A top level object for errors.
1 property 1 required
Errors
object
Object that contains the list of errors.
1 property 1 required
Error
object
A single error.
5 properties
PartnerId
string
Your Partner ID displayed in the [Developer Dashboard](https://developer.mastercard.com/account/log-in)
AssetId
string
An asset ID. Generated by Data Connect or by using the Store Customer Pay Statement API.
PartnerCredentialsWithNewSecret
object
3 required
ErrorList
array
The list of errors.

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

finicity-authentication-api-openapi.yml Raw ↑

Other APIs Finicity publishes across the network.

Finicity Connect
Finicity Verification of Assets (VoA) API
Finicity Verification of Income & Employment (VoIE) API
Finicity Transaction Analysis (Cash Flow) API
Finicity Payments (Account Validation) API
Finicity Open Banking Data Access (FDX)
Finicity Account Validation Assistance API
Finicity Accounts API
Finicity Accounts (Simple) API
Finicity App Registration API
Finicity Balance Analytics API
Finicity Bank Statements API
Where this information came from

This is an independent, third-party profile of Finicity Authentication API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.