curl --request POST \
--url https://api.app.lastaccountingcompany.com/portal/payment-settings/bank-connection \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"customer_id": "<string>",
"expected_row_version": 2,
"evidence_ref": "<string>",
"evidence_document_id": "<string>",
"evidence_sha256": "<string>",
"letter_account_iban": "<string>",
"agreement_id": "<string>"
}
'import requests
url = "https://api.app.lastaccountingcompany.com/portal/payment-settings/bank-connection"
payload = {
"customer_id": "<string>",
"expected_row_version": 2,
"evidence_ref": "<string>",
"evidence_document_id": "<string>",
"evidence_sha256": "<string>",
"letter_account_iban": "<string>",
"agreement_id": "<string>"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
customer_id: '<string>',
expected_row_version: 2,
evidence_ref: '<string>',
evidence_document_id: '<string>',
evidence_sha256: '<string>',
letter_account_iban: '<string>',
agreement_id: '<string>'
})
};
fetch('https://api.app.lastaccountingcompany.com/portal/payment-settings/bank-connection', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.app.lastaccountingcompany.com/portal/payment-settings/bank-connection",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'customer_id' => '<string>',
'expected_row_version' => 2,
'evidence_ref' => '<string>',
'evidence_document_id' => '<string>',
'evidence_sha256' => '<string>',
'letter_account_iban' => '<string>',
'agreement_id' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.app.lastaccountingcompany.com/portal/payment-settings/bank-connection"
payload := strings.NewReader("{\n \"customer_id\": \"<string>\",\n \"expected_row_version\": 2,\n \"evidence_ref\": \"<string>\",\n \"evidence_document_id\": \"<string>\",\n \"evidence_sha256\": \"<string>\",\n \"letter_account_iban\": \"<string>\",\n \"agreement_id\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.app.lastaccountingcompany.com/portal/payment-settings/bank-connection")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"customer_id\": \"<string>\",\n \"expected_row_version\": 2,\n \"evidence_ref\": \"<string>\",\n \"evidence_document_id\": \"<string>\",\n \"evidence_sha256\": \"<string>\",\n \"letter_account_iban\": \"<string>\",\n \"agreement_id\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.app.lastaccountingcompany.com/portal/payment-settings/bank-connection")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"customer_id\": \"<string>\",\n \"expected_row_version\": 2,\n \"evidence_ref\": \"<string>\",\n \"evidence_document_id\": \"<string>\",\n \"evidence_sha256\": \"<string>\",\n \"letter_account_iban\": \"<string>\",\n \"agreement_id\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"can_change": true,
"can_verify": true,
"banks": [
{
"bic": "<string>",
"name": "<string>",
"route": "iso_corporate",
"readiness": "live",
"activation": "bank_letter_or_provider_read",
"guide": "<string>"
}
],
"terms": {
"version": "<string>",
"url": "<string>",
"accepted": true
},
"verification": {
"state": "clear"
},
"setup": {
"iban": "<string>",
"bic": "<string>",
"bank_name": "<string>",
"delivery": "unavailable",
"bank_route_readiness": "live",
"row_version": 123,
"can_change": true,
"bank_connection": {
"state": "not_started",
"can_submit": true,
"can_activate": true,
"can_check": true,
"checks_enabled": true,
"submitted_at": "2023-11-07T05:31:56Z",
"activated_at": "2023-11-07T05:31:56Z",
"last_checked_at": "2023-11-07T05:31:56Z",
"provider_enriched_at": "2023-11-07T05:31:56Z"
},
"bank_route": "iso_corporate",
"bank_route_guide": "<string>"
}
}{
"error": "<string>",
"detail": "<string>"
}Move the paying account's Nordea Business connection forward
Open Payments reaches a Nordea Business account only after the company has applied for Corporate Access Lite inside Nordea Business and Nordea has activated it. A signed-in company admin declares the application (application_submitted). A company admin or LAC staff asks Open Payments about the paying account now (observe): the provider lists the company’s accounts with their statement-enrichment time, LAC records the observation, and current evidence about the current paying account (listed, enabled, a statement enrichment dated after the declaration and at most 14 days old) activates the connection with a machine-verifiable evidence reference; evidence from before the current declaration never activates, so a reset connection cannot re-activate from old statements; LAC also runs this read once a day on a settings read while the application is pending. A signed-in LAC staff member, under the staff customer-write confirmation headers, may record Nordea’s activation from the customer’s forwarded activation letter (active): the letter is one of the customer’s retained uploads (evidence_document_id with its evidence_sha256, a PDF or an image under an approved archive prefix), letter_account_iban is the payment account it names and must be the paying account, and agreement_id is the bank’s agreement identifier printed on it. The recorded evidence names the document and its digest; a typed note (evidence_ref) is refused. The same record is reachable for agents as the operation payments.bank_connection.activate@1. Only an active connection lets the database derive delivery_enabled; every release still proves live provider readiness. expected_row_version pins the paying account version the caller saw. A changed paying IBAN returns the connection to not_started.
curl --request POST \
--url https://api.app.lastaccountingcompany.com/portal/payment-settings/bank-connection \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"customer_id": "<string>",
"expected_row_version": 2,
"evidence_ref": "<string>",
"evidence_document_id": "<string>",
"evidence_sha256": "<string>",
"letter_account_iban": "<string>",
"agreement_id": "<string>"
}
'import requests
url = "https://api.app.lastaccountingcompany.com/portal/payment-settings/bank-connection"
payload = {
"customer_id": "<string>",
"expected_row_version": 2,
"evidence_ref": "<string>",
"evidence_document_id": "<string>",
"evidence_sha256": "<string>",
"letter_account_iban": "<string>",
"agreement_id": "<string>"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
customer_id: '<string>',
expected_row_version: 2,
evidence_ref: '<string>',
evidence_document_id: '<string>',
evidence_sha256: '<string>',
letter_account_iban: '<string>',
agreement_id: '<string>'
})
};
fetch('https://api.app.lastaccountingcompany.com/portal/payment-settings/bank-connection', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.app.lastaccountingcompany.com/portal/payment-settings/bank-connection",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'customer_id' => '<string>',
'expected_row_version' => 2,
'evidence_ref' => '<string>',
'evidence_document_id' => '<string>',
'evidence_sha256' => '<string>',
'letter_account_iban' => '<string>',
'agreement_id' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.app.lastaccountingcompany.com/portal/payment-settings/bank-connection"
payload := strings.NewReader("{\n \"customer_id\": \"<string>\",\n \"expected_row_version\": 2,\n \"evidence_ref\": \"<string>\",\n \"evidence_document_id\": \"<string>\",\n \"evidence_sha256\": \"<string>\",\n \"letter_account_iban\": \"<string>\",\n \"agreement_id\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.app.lastaccountingcompany.com/portal/payment-settings/bank-connection")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"customer_id\": \"<string>\",\n \"expected_row_version\": 2,\n \"evidence_ref\": \"<string>\",\n \"evidence_document_id\": \"<string>\",\n \"evidence_sha256\": \"<string>\",\n \"letter_account_iban\": \"<string>\",\n \"agreement_id\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.app.lastaccountingcompany.com/portal/payment-settings/bank-connection")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"customer_id\": \"<string>\",\n \"expected_row_version\": 2,\n \"evidence_ref\": \"<string>\",\n \"evidence_document_id\": \"<string>\",\n \"evidence_sha256\": \"<string>\",\n \"letter_account_iban\": \"<string>\",\n \"agreement_id\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"can_change": true,
"can_verify": true,
"banks": [
{
"bic": "<string>",
"name": "<string>",
"route": "iso_corporate",
"readiness": "live",
"activation": "bank_letter_or_provider_read",
"guide": "<string>"
}
],
"terms": {
"version": "<string>",
"url": "<string>",
"accepted": true
},
"verification": {
"state": "clear"
},
"setup": {
"iban": "<string>",
"bic": "<string>",
"bank_name": "<string>",
"delivery": "unavailable",
"bank_route_readiness": "live",
"row_version": 123,
"can_change": true,
"bank_connection": {
"state": "not_started",
"can_submit": true,
"can_activate": true,
"can_check": true,
"checks_enabled": true,
"submitted_at": "2023-11-07T05:31:56Z",
"activated_at": "2023-11-07T05:31:56Z",
"last_checked_at": "2023-11-07T05:31:56Z",
"provider_enriched_at": "2023-11-07T05:31:56Z"
},
"bank_route": "iso_corporate",
"bank_route_guide": "<string>"
}
}{
"error": "<string>",
"detail": "<string>"
}Authorizations
Firebase ID token from an interactive portal session. Required for interactive operations (payroll, company settings, API-key management) and invoice decisions allowed by the member's review permissions.
Body
x >= 1application_submitted, observe, active Retired free-text note; refused for active.
500Required for active. The customer's retained activation letter (an evidence.document of this tenant, PDF or image).
128Required for active. The digest of the letter as the uploads list shows it; the server activates exactly those retained bytes or answers 409.
^[0-9a-f]{64}$Required for active. The payment account the letter names; must be the current paying account.
The bank's agreement identifier printed on the letter (Nordea "Sopimustunnus").
64Response
Current payment settings.
The banks a company admin may choose as the paying bank: the provider lists them for the market and LAC has a route policy for them. route is how a payment reaches the bank (iso_corporate: a bank-side corporate agreement and the customer confirms the uploaded file in the bank; psd2_pis: payment initiation the customer authorises at release). readiness is live when LAC has proven the route end to end and releases money on it, provider_listed when the provider lists the bank but LAC has not verified the route yet: the account can be saved and the customer-side steps started, but nothing is released. activation names what marks the bank connection active and guide the setup guidance the portal renders for the bank. Live routes sort first.
Show child attributes
Show child attributes
Show child attributes
Show child attributes
Authoritative KYC UI state derived from LAC's hosted-flow attempt record and the provider's live status. started means LAC returned a hosted URL that remains the one actionable flow for 24 hours; retry means that URL expired or Open Payments answered Invalid; pending means a start has no recorded outcome and must not be repeated before the same 24-hour boundary. Only clear represents current provider validity.
- Option 1
- Option 2
Show child attributes
Show child attributes
Show child attributes
Show child attributes