1. Introduction
Framnex for Developers
  • Introduction
    • Overview
    • Quick Start
    • Authentication
  • ClientIntegrationAccounts
    • Returns an account by its identifier
      GET
    • Returns the paged list of accounts
      GET
  • ClientIntegrationAuth
    • Obtain an access token using client credentials.
      POST
  • ClientIntegrationExchangeRates
    • Returns the exchange rate between the sell and buy accounts
      GET
  • ClientIntegrationTransfers
    • Creates a new outgoing transfer
      POST
    • Returns the paged list of transfers, filtered by the provided filter
      GET
    • Returns a transfer by its identifier
      GET
  • ClientIntegrationWebhooks
    • Registers (or replaces) the URL webhooks are delivered to for the integrator
      POST
    • Returns the currently registered webhook URL for the integrator
      GET
    • Returns the paged list of webhook deliveries, filtered by the provided filter
      GET
    • Returns a webhook delivery by its identifier
      GET
    • Re-queues a failed webhook delivery for another attempt
      POST
  • ClientIntegrationTransferDocuments
    • Downloads a document by its file name.
      GET
    • Gets all documents
      GET
    • Uploads multiple documents.
      POST
  • Schemas
    • BankClientAPI
      • Account
      • AccountCredentials
      • AccountState
      • AccountType
      • AchCredentials
      • Address
      • BankDetails
      • BusinessEntity
      • ClientIntegrationAuthRequest
      • ClientIntegrationAuthResponse
      • ClientIntegrationErrorResponse
      • CreateExchangeTransferRequest
      • CreateOutgoingTransferRequest
      • CreateTransferRequest
      • CreateTransferType
      • CreatedResponse
      • Credentials
      • CredentialsState
      • CryptoCredentials
      • CustomerTransferStateDto
      • CryptoTransferDetails
      • ExchangeRate
      • DocumentDto
      • FasterUkCredentials
      • ExchangeTransferCancelledWebhookPayload
      • ExchangeTransfer
      • FedWireCredentials
      • IndividualEntity
      • ExchangeTransferExecutedWebhookPayload
      • InternalCredentials
      • InternalServerError
      • IError
      • LegalEntity
      • GasPaymentWebhookPayload
      • IReason
      • LegalEntityType
      • ISuccess
      • LocalAEDCredentials
      • LocalXafCredentials
      • IncomingTransferReceivedWebhookPayload
      • IncomingTransfer
      • NeftCredentials
      • OperationTypeDto
      • PageInfoDto
      • Participant
      • PixCredentials
      • SepaCredentials
      • SortOrderDto
      • SwiftCredentials
      • OutgoingTransferCancelledWebhookPayload
      • OutgoingTransfer
      • TedPayCredentials
      • OutgoingTransferExecutedWebhookPayload
      • PagedFilterDto
      • TransferGas
      • TransferPagedDataDto
      • TransferState
      • TransferType
      • PaymentMethod
      • TransferTypeDto
      • PaymentSystem
      • UaeFtsCredentials
      • RegisterWebhookRequest
      • UaeIppCredentials
      • Result
      • ValidationProblemDetails
      • ProblemDetails
      • YeePayNgnLocalCredentials
      • Transfer
      • TransferDetails
      • TransferDetailsType
      • WebhookDelivery
      • WebhookDeliveryPagedDataDto
      • WebhookPayload
      • WebhookState
      • WebhookSubscription
      • WebhookType
      • YeePayKesLocalCredentials
      • YeePayMxnLocalCredentials
GuidesBaaS API ReferenceBank Client API Reference
GuidesBaaS API ReferenceBank Client API Reference
  1. Introduction

Authentication

Use an access token to authenticate every protected Bank Client API request. Framnex provides a separate username and secret for each environment.

Keep credentials secure#

Store the username and secret in a server-side secret store. Do not include them in browser code, mobile applications, source control, logs, or URLs.
Use separate credentials for each environment. A token is valid only for the environment that issued it.

Request an access token#

The Bank Client API base URL includes the Merchant service path:
https://<host>/api/merchant
Exchange the username and secret at POST /integration/auth/token:
The response contains the token type, access token, and lifetime in seconds:
{
  "accessToken": "<token>",
  "tokenType": "Bearer",
  "expiresIn": 3600
}
The expiresIn value is an example. Always use the value returned by the API.

Authenticate a request#

Send the access token in the Authorization header:
For example:
Do not send the username or secret to protected resource endpoints.

Renew an access token#

The API does not return a refresh token. Request a new access token with the same credentials before the current token expires. Use expiresIn to calculate the renewal time, and allow a small safety margin for network and clock differences.
If a protected request returns 401 Unauthorized, discard the current token, obtain a new token, and retry the request once. Do not retry authentication failures without a limit.

Troubleshooting#

400 Bad Request means that the request body is invalid or a required field is missing.
401 Unauthorized from the token endpoint means that the username or secret is invalid.
401 Unauthorized from a protected endpoint means that the bearer token is missing, invalid, or expired.
Continue with the Bank Client API Quick Start for the complete first-request flow.
Modified at 2026-09-22 08:48:34
Previous
Quick Start
Next
Returns an account by its identifier
Built with