Read only the customer fields authorized by an online-verified revocable consumer direction and current privacy policy
/open-banking/customer-dataOriginal narrow third_party token required. Online identity checks bracket a current customer privacy policy/election check and actual permitted-field snapshot. Only selected legal name/address/email/phone fields can be returned; no tax IDs. consumer_direction rules must match provider, service subject, purpose and fields. A later privacy opt-out revokes prior directions even if general opt-out is subsequently lifted. Allowed snapshots and privacy refusals retain immutable evidence. Responses are no-store and every reuse repeats authorization.
Headers
Idempotency-KeystringOptionalSend on every write that creates or changes money or state; a replay with the same key returns the original result with 200.
Body parameters
account_idstringOptionalExample acct_2tVh8nqLxq4GbDe0K1F6S9zRcWm
fieldsarray of stringsRequiredfromstring · date-time or nullOptionalpurposestringRequiredthroughstring · date-time or nullOptionalReturns
200 OK
access_idstringRequiredaccount_idstringOptionalExample acct_2tVh8nqLxq4GbDe0K1F6S9zRcWm
captured_atstring · date-timeRequiredconsent_idstringRequiredcustomer_idstringRequiredExample cust_2tVh8nqLxq4GbDe0K1F6S9zRcWm
dataobjectRequiredsha256stringRequiredErrors
Every error is a problem document with a stable code. See Errors.
400401403404409412413422424429500503