How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

TSB Bank Authorization Server APIs API

The Authorization Server APIs API from TSB Bank — 9 operation(s) for authorization server apis.

TSB Bank Authorization Server APIs API is one of 12 APIs that TSB Bank publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Authorization Server APIs. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and an API reference.

This API exposes 14 operations across 9 paths, and defines 5 schemas. It is described by OpenAPI 3.2.0, at version 4.3.1.

Requests are made against a single base URL, https://apis.tsb.co.uk:443/.

14 operations 9 paths 5 schemas 6 GET4 OPTIONS4 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
4.3.1
Base URL
https://apis.tsb.co.uk
Authentication
OAuth 2.0
Resource Areas
1

Authentication & Security 1

TSB Bank Authorization Server APIs API declares 1 security scheme for authenticating requests. It supports OAuth 2.0 (OAuth2) using the implicit flow, exposing 5 scopes.

Paths & Operations 14

Across 9 paths, the API surfaces 14 operations — 6 GET, 4 OPTIONS, 4 POST. Each is listed below with its method, path, parameters, and response codes.

Authorization Server APIs 14
GET
/auth/oauth/v2/authorize
Initializes an OAuth 2.0 flow using a responsetype. See RFC 6749 (https://tools.ietf.org/html/rfc6749) for more details.
Get_request_authorization 15 params → 200302400401403405500
GET
/auth/oauth/health
An endpoint that can be used to verify your OAuth authentication flow is working correctly. Is only usable if the context variable otk.health.apikey is defined inside the corresponding service policy.
Get_request_health_check 1 param → 200500503
GET
/auth/oauth/v2/authorize/login
Receives a request as the result of a redirect from the /auth/oauth/v2/authorize endpoint. Creates a login page or forwards a request to the consent screen.
Get_request_authorize_login 3 params → 200400403405500
POST
/auth/oauth/v2/authorize/login
Authenticates a user during the OAuth 2.0 responsetype flow OR Authenticates a user during the OAuth 2.0 responsetype using a social platform.
Post_request_authorize_login 10 params → 200302400401403405500
POST
/auth/oauth/v2/authorize/consent
Handles the 'deny' and 'grant' result of a resource owner's decision at the consent page when 'action' is: 'consent', the API returns an HTML page for the user to grant or deny the request. 'grant',…
Post_request_authorize_consent 1 param body → 200302400401403405500
POST
/connect/session/logout
The resource owner deletes his active session on the OAuth server.
Create_resource_owner_logout_ 5 params → 200204400401403405500
OPTIONS
/.well-known/openid-configuration
OpenID Connect Discovery endpoint
Options_getOpenIDDiscovery 3 params → 204400
GET
/.well-known/openid-configuration
OpenID Connect Discovery endpoint
Get_OpenIDDiscovery → 200403405500
OPTIONS
/openid/connect/register
OpenID Connect Dynamic Registration Configuration endpoint
Options_oidc_register 3 params → 204400
POST
/openid/connect/register
OpenID Connect Dynamic Registration endpoint
Post_oidc_register body → 201400403405429500
OPTIONS
/openid/connect/register/{client_id}
OpenID Connect Dynamic Registration Configuration endpoint
Options_oidc_register_config 4 params → 204400
GET
/openid/connect/register/{client_id}
OpenID Connect Dynamic Registration Configuration endpoint
Get_oidc_register_config 2 params → 200400401403405500
OPTIONS
/openid/connect/jwks.json
OpenID Connect jwks endpoint
Options_jwk_set_ 3 params → 204400
GET
/openid/connect/jwks.json
OpenID Connect jwks endpoint
Get_jwk_set_ → 200403405500

Schemas 5

The contract defines 5 schemas that model the data the API accepts and returns. The most detailed are OpenIDDiscovery (18 properties), SessionObject (10 properties), RequestParametersObject (7 properties), SessionData (3 properties). Each schema is shown below with its type and property counts.

SessionData
object
3 properties 3 required
RequestParametersObject
object
7 properties
SessionObject
object
10 properties
OpenIDDiscovery
object
The OpenID configuration document as defined by the specification: http://openid.net/specs/openid-connect-discovery-10.htmlProviderMetadata
18 properties 7 required
RequestConsentObject
object
2 properties

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

tsb-bank-authorization-server-apis-api-openapi.yml Raw ↑

Other APIs TSB Bank publishes across the network.

TSB Account and Transaction Information API (AIS)
TSB Payment Initiation API (PIS)
TSB Confirmation of Funds API (CBPII)
TSB Bank ATM API
TSB Bank BCA API
TSB Bank Branch API
TSB Bank CCC API
TSB Bank PCA API
TSB Bank Resource Server APIs API
TSB Bank SME API
TSB Bank Token Server APIs API
Where this information came from

This is an independent, third-party profile of TSB Bank Authorization Server APIs API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.