import { Callout } from "zudoku/ui/Callout";

# Bank connection via PSD2/XS2A (finAPI)

This page describes the PSD2/XS2A connection via finAPI in 365 business Banking: how it works, what it requires and which accounts and payments it supports.

The connection to your bank is established by [finAPI GmbH](https://www.finapi.io/), a PSD2-compliant open banking provider. As a BaFin-licensed account information service (AIS) and payment initiation service (PIS), finAPI retrieves your transactions and initiates your payments. For this, your online banking credentials are used, which you enter only in your bank's web form.

## At a glance

| | |
|---|---|
| Value on the bank account card | *SEPA Bank Account* in the **Account Information Service** field, the **Payment Initiation Service** field or both |
| Requirement | online banking at a bank reachable via finAPI ([Supported banks](../../supported-banks.mdx)), company bank access |
| Setup | a few minutes in your bank's web form |
| Payment approval | per payment run by TAN in the web form; not in the background |
| Consent | expires regularly under PSD2 rules and is renewed ([Renew consent](renew-consent.mdx)) |

## How the connection works

### Account information (AIS)

finAPI accesses your payment accounts through the PSD2-compliant **XS2A** interface (Access to Account), the European open banking standard. finAPI also supports the German **FinTS** protocol (formerly HBCI), which reaches accounts that are usually not offered via XS2A, such as savings accounts, building savings accounts, credit card accounts and securities accounts. If neither XS2A nor FinTS is available, finAPI uses **web scraping** as a fallback.

Which routes are used for an account is shown on the bank account card on the **Banking Interfaces** FastTab under **Statements read over**. finAPI decides which route a single request uses.

### Payment initiation (PIS)

finAPI initiates payments through the XS2A interface. You approve every payment or every payment run in your bank's web form with a TAN. Therefore, payments via PSD2 never run in the background.

## Supported accounts and payments

Depending on bank, country and available interface:

| Accounts | Payments |
|---|---|
| bank accounts (current, savings and business accounts) | SEPA credit transfers |
| securities accounts | SEPA instant credit transfers |
| loan accounts | future-dated transfers |
| credit cards | standing orders |
| building savings accounts | SEPA collective credit transfers |
| cooperative shares (for example at Volksbanken and Raiffeisenbanken) | SEPA direct debits and SEPA collective direct debits |

The functions that your bank allows for a given account are shown after connecting under [Bank account capabilities](../../bank-accounts/capabilities.mdx).

## Pros and cons

| Pros | Cons |
|---|---|
| Set up in a few minutes, without a contract with the bank | Payments only with a TAN, not in the background |
| Automatic bank statements at no extra cost from the bank | Your online banking daily limit applies here too |
| Standing orders and instant transfers, if the bank offers them | Consent must be renewed regularly |
| Also accounts reachable only via FinTS | Not every bank is reachable |

<Callout type="tip" title="Daily limit exceeded: combination with EBICS">
If your payment runs exceed the daily limit, continue to retrieve the accounts via finAPI and pay via EBICS. See [Combine banking services](../mixed-operation.mdx).
</Callout>

## See also

- [Connect a bank account via PSD2/XS2A](connect.mdx)
- [Use with my own bank login](personal-bank-access.mdx)
- [Supported banks](../../supported-banks.mdx)
- [Security and data protection](../../concepts/security.mdx)
