Protección · Data Provider
Build with Protección data
Access your customers' banking and energy data — securely, with their explicit consent, over mutual TLS.
Integrate in three steps
Authorise consent
Ask the customer to share, and receive a sender-constrained access token bound to your client certificate.
Manage consent
List, inspect, and revoke the consents a customer has granted you, and stay in sync as they change.
Request data
Call the data endpoints with the right scopes and FAPI headers, and handle results and errors.
Why build on Protección
FAPI 2.0, handled for you
PAR, PKCE, issuer identification, and consent screens are managed by the platform. You drive the flow as a client.
Sender-constrained by default
Access tokens are bound to your mTLS client certificate, so a stolen token is worthless on its own.
Consent you can trust
Least-privilege scopes and a clear lifecycle — customers see and revoke exactly what they've shared.
Start reading
Quickstart
Credentials to your first consented data call in about 15 minutes.
Set up mTLS
Register your client certificate and bind your access tokens.
Integration guide
The full journey: introduction, consent, and data access.
Consent API reference
Every endpoint, request, and response — with a live playground.