How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Finicity Third Party Access API

Generate and manage access keys for other partners

Finicity Third Party Access API is one of 41 APIs that Finicity publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Third Party Access. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and an API reference.

This API exposes 3 operations across 2 paths, and defines 17 schemas. It is described by OpenAPI 3.2.0, at version 1.43.0.

Requests are made against a single base URL, https://api.finicity.com.

3 operations 2 paths 17 schemas 1 DELETE1 POST1 PUT

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
1.43.0
Base URL
https://api.finicity.com
Authentication
API Key, API Key
Resource Areas
1

Authentication & Security 2

Finicity Third Party Access API declares 2 security schemes for authenticating requests. An API key is passed in the header as Finicity-App-Key (FinicityAppKey). An API key is passed in the header as Finicity-App-Token (FinicityAppToken). By default, every request must be authenticated.

  • FinicityAppKey — The "Finicity-App-Key" from the developer dashboard
  • FinicityAppToken — A token returned by the /authentication API

Paths & Operations 3

Across 2 paths, the API surfaces 3 operations — 1 DELETE, 1 POST, 1 PUT. Each is listed below with its method, path, parameters, and response codes.

Third Party Access 3

Generate and manage access keys for other partners

POST
/aggregation/v1/partners/accessKey
Generate Third Party Access Key
GenerateThirdPartyAccessKey body → 200400401404
PUT
/aggregation/v1/partners/accessKey/{consentReceiptId}
Update Third Party Access
UpdateThirdPartyAccessKey 1 param body → 200400401404
DELETE
/aggregation/v1/partners/accessKey/{consentReceiptId}
Revoke Third Party Access
RevokeThirdPartyAccessKey 1 param → 204400401404

Schemas 17

The contract defines 17 schemas that model the data the API accepts and returns. The most detailed are ErrorMessage (10 properties), ThirdPartyAccessReceipt (8 properties), ThirdPartyAccessProduct (5 properties), ThirdPartyAccessKeyData (5 properties). Each schema is shown below with its type and property counts.

ThirdPartyAccessProvenance
object
Provenance regarding the calling client like clientFingerprint, ipAddress and token.
3 properties
ErrorMessage
object
10 properties 1 required
ThirdPartyAccessKeyReceiptData
object
An object representing the third party access key receipt customerId: This is recipient's customerId represented as a pseudo identifier. accountId: This is the…
1 property
AccountId
string
An account ID
ThirdPartyAccessPeriod
object
Object which describes access validity
3 properties 3 required
ThirdPartyAccessPeriodTypes
string
Multiple types will be supported. Presently below types are supported. "timeframe": Specifies a timeframe bounded by a startTime and endTime. The startTime is…
ThirdPartyAccessProductTypes
string
Third party access token can be generated for the following product types: "moneyTransferDetails": Retrieve account details for money transfer "availableBalanc…
ThirdPartyAccessProof
object
An object representing a digital signature of the access key
3 properties
ThirdPartyAccessReceipt
object
An object representing consent receipt
8 properties
AssetId
string
An asset ID. Generated by Data Connect or by using the Store Customer Pay Statement API.
PartnerId
string
Your Partner ID displayed in the [Developer Dashboard](https://developer.mastercard.com/account/log-in)
ThirdPartyAccessReceiptData
object
An object representing consent access data
2 properties
ThirdPartyAccessKeyData
object
An object representing the third party access key request customerId: This is recipient's customer identifier partnerId: This is recipient partner identifier t…
5 properties 4 required
DateTimeWithZone
string
A date-time with time zone
CustomerId
string
A customer ID. See Add Customer API for how to create a customer ID.
ThirdPartyAccessProduct
object
Product for which access token to be generated
5 properties 3 required
ConsentReceiptId
string
Third party access key receipt ID. Generated by generate third party access key API.

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

finicity-third-party-access-api-openapi.yml Raw ↑

Other APIs Finicity publishes across the network.

Finicity Connect
Finicity Verification of Assets (VoA) API
Finicity Verification of Income & Employment (VoIE) API
Finicity Transaction Analysis (Cash Flow) API
Finicity Payments (Account Validation) API
Finicity Open Banking Data Access (FDX)
Finicity Account Validation Assistance API
Finicity Accounts API
Finicity Accounts (Simple) API
Finicity App Registration API
Finicity Authentication API
Finicity Balance Analytics API
Where this information came from

This is an independent, third-party profile of Finicity Third Party Access API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.