Create sandbox customer
POST/v1/sandbox/customers
Post new customers. customerNumber should be used as identifier when performing SCA in test. For private customers an agreement is created automatically as a part of the process. Corporate customers needs to add agreements through POST /v1/sandbox/agreements.
Request
Header Parameters
- keyId must be formatted as
keyId="SN=XXX,CA=YYY"
whereXXX
is the serial number of the signing certificate in hexadecimal encoding andYYY
is the ful Distinguished Name of the Certificate Authority having certificate - algorithm must identify the same algorithm for the signature as presented in the signing certificate and should be
rsa-sha256
- headers must contain
date
,digest
,x-request-id
,psu-id
,psu-corporate-id
, andtpp-redirect-uri
when available - signature must be computed as
Base64(RSA-SHA256(signingString))
Advertises what type of data is actually sent.
Advertises which content types, expressed as MIME types, the client is able to understand. Using content negotiation, the server then selects one of the proposals, uses it and informs the client of its choice with the Content-Type response header.
Advertises which character set the client is able to understand. Using content negotiation, the server then selects one of the proposals, uses it and informs the client of its choice within the Content-Type response header.
Advertises which content encoding, usually a compression algorithm, the client is able to understand. Using content negotiation, the server selects one of the proposals, uses it and informs the client of its choice with the Content-Encoding response header.
Advertises which natural languages the client is able to understand, and which locale variant is preferred. Using content negotiation, the server then selects one of the proposals, uses it and informs the client of its choice with the Content-Language response header.
The domain name of the server (for virtual hosting), and (optionally) the TCP port number on which the server is listening.
Request identifier, unique to the call, as determined by the TPP.
Base64 encoded sha256 or sha512 hash of the message body, used with the signature.
The Digest header is defined by RFC3230 and sha256/sha512 si defined by RFC5843.
The certificate used for signing the request in base64 encoding.
HTTP Message Signature as specified by https://tools.ietf.org/html/draft-cavage-http-signatures-10 with requirements imposed by Berlin Group's NextGenPSD2 Framework.
If any values in the Signature header is ISO-8859-1 or UTF-8 encoded you need to URL encode the Signature header according to RFC 2047 which means MIME encoding the signature.
Also the signature must be wrapped using this format: =?charset?encoding?encoded signature?=
Example of this encoding: =?utf-8?B?a2V5QTQsQ0E9Mi41LjQuOTc9IzB........jMTM1MDUzNDQ0ZTRmMmQ0NjUz?=
Java example of how to implement encoding:
if (charset.equals(StandardCharsets.UTF_8)) {
Signature = String.format("=?utf-8?B?%s?=", Base64.getEncoder().encodeToString(signature.getBytes(StandardCharsets.UTF_8)));
}
- application/json
Body
required
Responses
- 201
- application/json
- Schema
- Example (from schema)
- Example
Schema
Possible values: [PRIVATE
, CORPORATE
]
_links
object
required
self
object
required
{
"customerId": "enc!!IZ5FQKfTP6SdoIoD_nyvKlJt1cHv_JOIku7xUgmyui1a18SoQ0YA4nfH7c28PLxf",
"customerNumber": "01085800481",
"customerType": "PRIVATE",
"customerName": "Testodius Test2",
"_links": {
"self": {
"href": "/v1/sandbox/customers/enc!!IZ5FQKfTP6SdoIoD_nyvKlJt1cHv_JOIku7xUgmyui1a18SoQ0YA4nfH7c28PLxf",
"verbs": [
"GET",
"DELETE"
]
}
}
}
{
"customerId": "enc!!IZ5FQKfTP6SdoIoD_nyvKlJt1cHv_JOIku7xUgmyui1a18SoQ0YA4nfH7c28PLxf",
"customerNumber": "01085800481",
"customerType": "PRIVATE",
"customerName": "Testodius Test2",
"_links": {
"self": {
"href": "/v1/sandbox/customers/enc!!IZ5FQKfTP6SdoIoD_nyvKlJt1cHv_JOIku7xUgmyui1a18SoQ0YA4nfH7c28PLxf",
"verbs": [
"GET",
"DELETE"
]
}
}
}