How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

first direct Direct Debits API

The Direct Debits API from first direct — 2 operation(s) for direct debits.

first direct Direct Debits API is one of 34 APIs that first direct publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Direct Debits. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and an API reference.

This API exposes 2 operations across 2 paths, and defines 22 schemas. It is described by OpenAPI 3.2.0, at version 4.0.1.

Requests are made against a single base URL, /open-banking/v4.0/aisp.

2 operations 2 paths 22 schemas 2 GET

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
4.0.1
Base URL
https://api.hsbc.com/open-banking/v2.2
Authentication
OAuth 2.0, OAuth 2.0
Terms of Service
Resource Areas
1

Authentication & Security 2

first direct Direct Debits API declares 2 security schemes for authenticating requests. It supports OAuth 2.0 (TPPOAuth2Security) using the clientCredentials flow, exposing 1 scope. It supports OAuth 2.0 (PSUOAuth2Security) using the authorizationCode flow, exposing 1 scope.

  • TPPOAuth2Security — TPP client credential authorisation flow with the ASPSP
  • PSUOAuth2Security — OAuth flow, it is required when the PSU needs to perform SCA with the ASPSP when a TPP wants to access an ASPSP resource owned by the PSU

Paths & Operations 2

Across 2 paths, the API surfaces 2 operations — 2 GET. Each is listed below with its method, path, parameters, and response codes.

Direct Debits 2
GET
/accounts/{AccountId}/direct-debits
Get Direct Debits for an AccountId
GetAccountsAccountIdDirectDebits 7 params → 200400401403404405406429
GET
/direct-debits
Get Direct Debits
GetDirectDebits 6 params → 200400401403404405406429

Schemas 22

The contract defines 22 schemas that model the data the API accepts and returns. The most detailed are OBMandateRelatedInformation1 (8 properties), Links (5 properties), OBError1 (4 properties), OBErrorResponse1 (4 properties). Each schema is shown below with its type and property counts.

OBError1
object
4 properties 1 required
Links
object
Links relevant to the payload
5 properties 1 required
OBMandateRelatedInformation1
object
Provides further details of the mandate signed between the creditor and the debtor.
8 properties 1 required
ExternalCategoryPurpose1Code
string
Enumeration of codes that outlines the type of purpose behind a transaction, payment or risk. For all enum values see ExternalCategoryPurpose1Code in ISOExtern…
OBActiveOrHistoricCurrencyAndAmount_0
object
The amount of the most recent direct debit collection.
2 properties 2 required
OBErrorResponse1
object
An array of detail error codes, and messages, and URLs to documentation to help remediation.
4 properties 1 required
OBExternalMandateClassification1Code
string
Type of mandate instruction. For a full list of values see OBExternalClassification1Code in OBInternalCodeSet [here](https://github.com/OpenBankingUK/ExternalI…
ActiveOrHistoricCurrencyCode_1
string
A code allocated to a currency by a Maintenance Agency under an international identification scheme, as described in the latest edition of the international st…
OBFrequency6Code
string
For a full list of values see OBFrequency6Code in OBInternalCodeSet [here](https://github.com/OpenBankingUK/ExternalInternalCodeSets)
ExternalMandateStatus1Code
string
Specifies the status of the standing order in code form. For a full list of enumeration values refer to 'ExternalMandateStatus1Code' in ISOExternalCodeset [her…
ISODateTime
string
All dates in the JSON payloads are represented in ISO 8601 date-time format. All date-time fields in responses must include the timezone. An example is below:…
AccountId
string
A unique and immutable identifier used to identify the account resource. This identifier has no meaning to the account owner.
DirectDebitId
string
A unique and immutable identifier used to identify the direct debit resource. This identifier has no meaning to the account owner.
PointInTime
string
Exact2NumericText - Further information on the exact point in time the event should take place. Specifies a frequency in terms of an exact point in time or mom…
Meta
object
Meta Data relevant to the payload
3 properties
OBActiveCurrencyAndAmount_SimpleType
string
A number of monetary units specified in an active currency where the unit of currency is explicit and compliant with ISO 4217.
Frequency_1
string
Individual Definitions: NotKnown - Not Known EvryDay - Every day EvryWorkgDay - Every working day IntrvlDay - An interval specified in number of calendar days…
Name_2
string
Name of Service User.
OBFrequency6
object
Regularity with which credit transfer instructions are to be created and processed
3 properties 1 required
OBReadDirectDebit2
object
3 properties 1 required
OBExternalStatusReason1Code
string
Low level textual error code, for all enum values see OBExternalStatusReason1Code in OBInternalCodeSet [here](https://github.com/OpenBankingUK/ExternalInternal…
PreviousPaymentDateTime
string
Date of most recent direct debit collection. All dates in the JSON payloads are represented in ISO 8601 date-time format. All date-time fields in responses mus…

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

first-direct-direct-debits-api-openapi.yml Raw ↑

Other APIs first direct publishes across the network.

first direct Account Access Consents API
first direct Accounts API
first direct ATM API
first direct Balances API
first direct BCA API
first direct Beneficiaries API
first direct Branch API
first direct CCC API
first direct Domestic Payment Consents API
first direct Domestic Payments API
first direct Domestic Scheduled Payment Consents API
first direct Domestic Scheduled Payments API
Where this information came from

This is an independent, third-party profile of first direct Direct Debits API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.