How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Finicity Data Sharing Consent API

Manage data sharing consents

Finicity Data Sharing Consent API is one of 41 APIs that Finicity publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Data Sharing Consent. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and an API reference.

This API exposes 4 operations across 3 paths, and defines 18 schemas. It is described by OpenAPI 3.2.0, at version 1.43.0.

Requests are made against a single base URL, https://api.finicity.com.

4 operations 3 paths 18 schemas 2 DELETE2 GET

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
1.43.0
Base URL
https://api.finicity.com
Authentication
API Key, API Key
Resource Areas
1

Authentication & Security 2

Finicity Data Sharing Consent API declares 2 security schemes for authenticating requests. An API key is passed in the header as Finicity-App-Key (FinicityAppKey). An API key is passed in the header as Finicity-App-Token (FinicityAppToken). By default, every request must be authenticated.

  • FinicityAppKey — The "Finicity-App-Key" from the developer dashboard
  • FinicityAppToken — A token returned by the /authentication API

Paths & Operations 4

Across 3 paths, the API surfaces 4 operations — 2 DELETE, 2 GET. Each is listed below with its method, path, parameters, and response codes.

Data Sharing Consent 4

Manage data sharing consents

GET
/data-sharing-consents
Get Customer Data Sharing Consents By Customer ID
GetDataSharingConsentsByCustomerId 7 params → 200400404401
GET
/data-sharing-consents/{consent_receipt_id}
Get Customer Data Sharing Consent By ID
GetDataSharingConsentsByID 1 param → 200404401
DELETE
/data-sharing-consents/{consent_receipt_id}
Revoke Data Sharing Consent by ID
RevokeDataSharingConsentById 2 params → 204404401
DELETE
/data-sharing-consents/{consent_receipt_id}/institutionLogins/{institution_login_id}
Revoke Data Sharing Consent for an Institution by Institution Login ID
RevokeDataSharingConsentByInstitutionLoginID 3 params → 204404401

Schemas 18

The contract defines 18 schemas that model the data the API accepts and returns. The most detailed are DataSharingConsentReceipt (15 properties), InstitutionInfo (12 properties), ConsentErrorMessage (8 properties), ConsentAccountDetails (5 properties). Each schema is shown below with its type and property counts.

DataHandling
object
2 properties 2 required
InstitutionInfo
object
Represents the institution which has data that the user consents to share
12 properties 8 required
ConsentAccountDetails
object
5 properties 2 required
ConsentAccountId
string
A unique identifier of an account within the Mastercard Open Banking system.
DataScopes
array
List of data scopes requested or granted for this operation.
DataSharingConsentReceipt
object
The consent receipt
15 properties 9 required
ConsentAccessPeriod
object
A period of time allowed for accessing the customer’s data granted by this consent. If the consent contains more than one institution arrangement, then this pe…
2 properties 2 required
ConsentErrorMessage
object
8 properties 1 required
DisclosureDetails
object
2 properties 2 required
ConsentInstitutionLoginId
string
A unique identifier of the authentication session with the Financial Institution within the Mastercard Open Banking system.
InstitutionArrangementStatusDetails
object
Details of the Institution status.
2 properties 2 required
DataSharingConsentReceipts
object
List of consent receipts
4 properties 4 required
ISODateTime
string
A date and time in ISO 8601 format (YYYY-MM-DDThh:mm:ssTZD). See also: [How do I handle Dates and Times?](https://developer.mastercard.com/open-finance-us/docu…
ConsentStatusDetails
object
Details on the status of the consent.
2 properties 2 required
AssetId
string
An asset ID. Generated by Data Connect or by using the Store Customer Pay Statement API.
ConsentCustomerId
string
A Mastercard Open Finance customer ID. See also: "Add Customer".
DataSharingConsentContext
string
Represents the context in which consent receipt was created. Possible values are 1. partner - User grants consent to access account data 2. crossPartner - User…
InstitutionArrangementAccessPeriod
object
A period of time allowed for accessing the customer’s data for the particular institution. This information must be displayed to the customers in the consent a…
2 properties 2 required

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

finicity-data-sharing-consent-api-openapi.yml Raw ↑

Other APIs Finicity publishes across the network.

Finicity Connect
Finicity Verification of Assets (VoA) API
Finicity Verification of Income & Employment (VoIE) API
Finicity Transaction Analysis (Cash Flow) API
Finicity Payments (Account Validation) API
Finicity Open Banking Data Access (FDX)
Finicity Account Validation Assistance API
Finicity Accounts API
Finicity Accounts (Simple) API
Finicity App Registration API
Finicity Authentication API
Finicity Balance Analytics API
Where this information came from

This is an independent, third-party profile of Finicity Data Sharing Consent API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.