Approve a debit
Confirm the customer, device credential, payment, and account details before approving or rejecting one debit.
Approve a customer's debit after confirming the customer, device provisioning, payment, and account details. The issuing institution must verify that the customer approved the payment on a registered device and that the device credential, payment details, and account checks all pass before moving any money.
Before you begin
- Provision the customer's device credential and store the
deviceCredentialProvisionIdplus the customer device public key. - Implement Secure every request and response.
- Follow How to Encrypt and Decrypt Data for the request envelope and message-opening sequence.
- Follow Format identifiers and date-times.
- Read Understand common payment fields.
- Read Understand code values.
- Support idempotent lookup by message, instruction, end-to-end, transaction, and client references.
- Store enough data to validate a later Reversal request.
- Configure the institution member code issued by Blinc and the permitted creditor schemes.
Endpoint
Create an HTTPS POST endpoint and give its complete URL to Blinc.
https://sandbox.examplebank.com/blinc/debit-authorizationsEvery request must contain Content-Type: application/json, Accept: application/json, x-timestamp, and x-signature. Every response, including a business rejection, must contain Content-Type: application/json, x-timestamp, and x-signature. See Secure every request and response for what each header protects and how to validate it.
Request business message
After the request has been opened and its institutional signature verified as described in How to Encrypt and Decrypt Data, the business message looks like this:
{
"GrpHdr": {
"MsgId": "00000120260817101530123000000000001",
"CreDtTm": "2026-08-17T10:15:30.123Z",
"NbOfTxs": 1,
"SttlmInf": {
"SttlmMtd": "CLRG",
"ClrSys": {
"Prtry": "BLINC"
},
"ClrChanl": "RTNS"
}
},
"DbtAuthInf": {
"PmtId": {
"InstrId": "DD-INSTR-0001",
"EndToEndId": "DD-E2E-0001",
"TxId": "DD-TX-0001",
"ClrSysRef": "DD-CLR-0001"
},
"deviceCredentialProvisionId": "7f2c1a9e-3b44-4d21-9c66-0a1b2c3d4e5f",
"PmtTpInf": {
"SvcLvl": {
"Cd": "SLEV"
},
"CtgyPurp": {
"Cd": "GDAS"
},
"LclInstrm": {
"Cd": "BLINC"
},
"SeqTp": "OOFF"
},
"InstdAmt": {
"Amt": 1500.0,
"Ccy": "NGN"
},
"IntrBkSttlmAmt": {
"Amt": 1500.0,
"Ccy": "NGN"
},
"IntrBkSttlmDt": "2026-08-17T00:00:00.000Z",
"ChrgBr": "SLEV",
"Dbtr": {
"Nm": "Ada Okafor",
"Id": {
"Othr": {
"Id": "12345678901",
"SchmeNm": {
"Cd": "BVN"
}
}
}
},
"DbtrAcct": {
"Id": {
"Othr": {
"Id": "0123456789",
"SchmeNm": {
"Cd": "NUBAN"
}
}
}
},
"DbtrAgt": {
"FinInstnId": {
"BICFI": "EXAMPLEBIC",
"Name": "Example Bank",
"ClrSysMmbId": {
"MmbId": "000001"
}
}
},
"CdtrAgt": {
"FinInstnId": {
"BICFI": "CREDITORBIC",
"Name": "Creditor Bank",
"ClrSysMmbId": {
"MmbId": "000002"
}
}
},
"Cdtr": {
"Nm": "Example Store",
"Id": {
"Othr": {
"Id": "CREDITOR-001",
"SchmeNm": {
"Cd": "BLINC"
}
}
}
},
"CdtrAcct": {
"Id": {
"Othr": {
"Id": "0987654321",
"SchmeNm": {
"Cd": "NUBAN"
}
}
}
},
"RmtInf": {
"Ustrd": "Debit authorization for online purchase",
"Strd": null
},
"Chrgs": [
{
"Tp": "FEE",
"Cd": "FEE001",
"Amt": {
"Amt": 50.0,
"Ccy": "NGN"
},
"Rcpt": {
"BICFI": "FEEBICX",
"Name": "Fee Recipient",
"ClrSysMmbId": {
"MmbId": "000001"
}
}
},
{
"Tp": "COMMISSION",
"Cd": "COM001",
"Amt": {
"Amt": 20.0,
"Ccy": "NGN"
},
"Rcpt": {
"BICFI": "COMBICX",
"Name": "Commission Recipient",
"ClrSysMmbId": {
"MmbId": "000001"
}
}
}
],
"TtlChrgs": {
"Amt": 50.0,
"Ccy": "NGN"
},
"NetSttlmAmt": {
"Amt": 1450.0,
"Ccy": "NGN"
},
"DbtAuth": {
"AuthntcnCntxt": {
"AuthntcnTmstmp": "2026-08-17T10:14:30.000Z",
"ElctrncSgntr": "<BASE64_CUSTOMER_DEVICE_SIGNATURE>",
"auth_context": "DEVICE_LOCAL_AUTH",
"auth_type": "DEVICE_BIOMETRIC_STRONG",
"auth_binding": {
"hardware": "SECURE_ENCLAVE",
"key_id": 42
},
"auth_actor": "CUSTOMER"
},
"CdtrSchmeId": {
"Id": {
"PrvtId": {
"Othr": {
"Id": "CREDITOR-001",
"SchmeNm": {
"Cd": "BLINC"
}
}
}
}
}
}
},
"SplmtryData": {
"PlcAndNm": "AdditionalDetails",
"Envlp": {
"Message": {
"Amount": 1500.0,
"ClientReference": "CLIENT-REF-0001"
},
"CustomerDeviceLocation": "{\"latitude\":6.5244,\"longitude\":3.3792}",
"TerminalId": null,
"TerminalTimestamp": null,
"TerminalLocation": null,
"TerminalReference": null,
"DeviceId": "DEVICE-0001",
"DeviceName": "Ada's registered phone",
"TransactionHash": "HASH-0001",
"ClientReference": "CLIENT-REF-0001",
"PaymentMethod": "P2P"
}
}
}What this request contains
The request identifies the customer account, the merchant payment, the amount, the customer's approval, and the device credential provisioning record that authorizes the debit. The customer's approval is signed inside the protected message. The institution must verify that approval before debiting the account or crediting the payment beneficiary.
Verify the customer-device signature
ElctrncSgntr is not the same as the institutional x-signature header.
- Take the exact
SplmtryData.Envlp.Messageobject shown to the customer for approval. - Serialize it as compact JSON with null properties omitted.
- Join the request's
x-timestampvalue and that JSON with no separator. - Convert the joined string to uppercase.
- Verify
ElctrncSgntrusing the device public key stored withdeviceCredentialProvisionIdduring device credential provisioning.
Reject the debit when the signed customer-visible amount/reference differs from the debit fields.
Decide whether to approve the debit
- Decrypt and verify the institutional signature headers.
- Validate timestamp, replay state, message ID, and transaction identifiers.
- Confirm the debtor institution member ID identifies the receiving institution.
- Load the device credential provisioning record by
deviceCredentialProvisionIdand require active status. - Match the customer and debtor account to the stored device credential provisioning record.
- Validate the authentication fields as one combination.
- Verify the customer-device signature.
- Confirm the instructed amount, currency, settlement date, charges, and net settlement arithmetic agree:
net settlement amount = instructed amount - TotalFee(theFEEamount). - Perform the institution's balance, risk, limit, sanctions, and account-status checks.
- Record one business outcome and preserve every original reference so a later Reversal can identify this debit.
- Sign and encrypt the response, then return the required response headers.
If no response reaches Blinc
Blinc does not retry Debit Authorization. If the connection fails after the institution may have completed the debit, Blinc sends a Reversal request using the original debit references.
When the Reversal arrives, find the original debit by those references. If the debit was accepted, return the full amount once. If no accepted debit exists, return RJCT with NOOR. Do not create a new debit while handling a Reversal, and do not wait for Blinc to resend Debit Authorization.
Request field reference
Header and settlement
| JSON path | Type / required | Simple explanation and source | Validation and relationship |
|---|---|---|---|
GrpHdr | Object / Required | Header for the complete debit message. Blinc creates it. | Must contain all fields below. |
GrpHdr.MsgId | Text / Required | Unique message ID for duplicate protection and tracing. | A new request must use a new ID; an identical request must produce the same business outcome without debiting the account twice. |
GrpHdr.CreDtTm | UTC date-time / Required | Time Blinc created the message. | Must be valid UTC and not outside the allowed window. |
GrpHdr.NbOfTxs | Integer / Required | Number of debit transactions inside this message. | Must be 1 because this contract carries one DbtAuthInf object. |
GrpHdr.SttlmInf | Object / Required | Describes how institutions settle this payment. | Must contain method, system, and channel. |
GrpHdr.SttlmInf.SttlmMtd | Text / Required | Blinc sends the settlement method. CLRG means settlement through the agreed clearing system. | The documented Debit Authorization value is CLRG. Validate it; never insert it when missing. |
GrpHdr.SttlmInf.ClrSys | Object / Required | Identifies the clearing system. | Must contain Prtry. |
GrpHdr.SttlmInf.ClrSys.Prtry | Text / Required | Proprietary clearing-system name. The example uses BLINC. | Must equal the agreed system identifier. |
GrpHdr.SttlmInf.ClrChanl | Text / Required | Blinc sends the clearing route. RTNS means real-time processing with net settlement. | The documented Debit Authorization value is RTNS. Accept another listed route only when onboarding explicitly enables it. |
DbtAuthInf | Object / Required | "debit authorization transaction information": the complete account-authorization instruction. | Validate every child before posting. |
Identifiers, device credential, and payment classification
| JSON path | Type / required | Simple explanation and source | Validation and relationship |
|---|---|---|---|
DbtAuthInf.PmtId | Object / Required | Groups the identifiers used by different systems to trace the same debit. | All four values are required. Store them so a Reversal can locate the original debit after a timeout. Blinc does not retry Debit Authorization. |
...PmtId.InstrId | Text / Required | Identifier for this payment instruction. Blinc creates it. | Unique within the agreed institution scope. |
...PmtId.EndToEndId | Text / Required | Main business trace ID carried from initiation to final outcome. | Store it; a Reversal uses it to locate the original debit. |
...PmtId.TxId | Text / Required | Transaction ID for this debit in the switching flow. | Must not identify another transaction. |
...PmtId.ClrSysRef | Text / Required | Reference used by the clearing/switching system. | Store for reconciliation and support searches. |
DbtAuthInf.deviceCredentialProvisionId | Text / Required | Identifier for the customer's provisioned device credential. Blinc sends the value created during device credential provisioning. | Must be present, non-empty, and reference an active device credential provisioning record. |
DbtAuthInf.PmtTpInf | Object / Required | Classifies the payment. | Child codes must be agreed and internally consistent. |
...PmtTpInf.SvcLvl.Cd | Text / Required | Service-level code. It describes the service rules applied to the payment. | Accept only contracted values; do not infer from other fields. |
...PmtTpInf.CtgyPurp.Cd | Text / Required | Category-purpose code. GDAS identifies the agreed goods-and-services payment purpose. | Validate against the agreed value. |
...PmtTpInf.LclInstrm.Cd | Text / Required | Local-instrument code identifying the payment product/rule set. | Validate against the agreed instrument. |
...PmtTpInf.SeqTp | Text / Optional | Collection-sequence code. OOFF identifies a one-off authorization. | Use the agreed one-off value for Debit Authorization. |
Amount, parties, and accounts
| JSON path | Type / required | Simple explanation and source | Validation and relationship |
|---|---|---|---|
DbtAuthInf.InstdAmt | Object / Required | The gross amount the customer authorized. Blinc instructs the issuing institution to debit this amount from the customer's account associated with the device credential. | Contains numeric amount and currency. |
...InstdAmt.Amt | Decimal / Required | Amount in normal currency units. 2500.00 means NGN 2,500.00, not kobo. | Must be positive, within limits, and equal the customer-approved Message.Amount. |
...InstdAmt.Ccy | Text / Required | ISO currency code. | Must be supported and match settlement and charge rules. |
DbtAuthInf.IntrBkSttlmAmt | Object / Deprecated, still sent | Legacy interbank settlement amount, kept for backward compatibility. The amount that actually settles is DbtAuthInf.NetSttlmAmt, derived from InstdAmt minus TtlChrgs. | Not consumed for posting; do not treat it as the settlement amount. |
...IntrBkSttlmAmt.Amt | Decimal / Deprecated, still sent | Numeric value of the legacy interbank settlement amount. | Informational only. |
...IntrBkSttlmAmt.Ccy | Text / Deprecated, still sent | Currency of the legacy interbank settlement amount. | Informational only. |
DbtAuthInf.IntrBkSttlmDt | UTC date-time / Required | Date on which interbank settlement applies. | Must satisfy the agreed settlement-date rule. |
DbtAuthInf.ChrgBr | Text / Required | Blinc sends who bears charges. SLEV means the service-level agreement decides the charge treatment. | The documented Debit Authorization value is SLEV. Validate it against Chrgs; do not invent it when missing. |
DbtAuthInf.Dbtr | Object / Required | Customer whose account is debited. | Must match the stored device credential provisioning record. |
...Dbtr.Nm | Text / Required | Customer's human-readable name. | Use for audit/display; identity matching uses the ID. |
...Dbtr.Id.Othr.Id | Text / Required | Customer identity value, shown as BVN. | Sensitive; must match the account owner associated with the provisioned device credential. |
...Dbtr.Id.Othr.SchmeNm.Cd | Text / Required | Scheme that explains the customer ID. | Validate ID format for the named scheme. |
DbtAuthInf.DbtrAcct | Object / Required | Customer account to debit. | Must be active, debit-enabled, and owned by the debtor. |
...DbtrAcct.Id.Othr.Id | Text / Required | Customer account number. | Sensitive; match the account associated with the provisioned device credential. |
...DbtrAcct.Id.Othr.SchmeNm.Cd | Text / Required | Account-number scheme, for example NUBAN. | Must match the supplied account format. |
DbtAuthInf.DbtrAgt | Object / Required | Container for the customer's issuing institution. | Must contain FinInstnId. |
...DbtrAgt.FinInstnId | Object / Required | Identifies the debtor's issuing institution. | Its member ID must identify the receiving institution. |
...DbtrAgt.FinInstnId.BICFI | Text / Conditional | Bank Identifier Code when used. | Validate format if present. |
...DbtrAgt.FinInstnId.Name | Text / Required | Human-readable issuing-institution name. | Display/audit only; route using the member ID. |
...DbtrAgt.FinInstnId.ClrSysMmbId.MmbId | Text / Required | Debtor institution member code. | Must equal the code configured for the endpoint. |
DbtAuthInf.CdtrAgt | Object / Required | Container for the creditor's financial institution. | Must contain FinInstnId. |
...CdtrAgt.FinInstnId.BICFI | Text / Conditional | Creditor institution's BIC when used. | Validate format if present. |
...CdtrAgt.FinInstnId.Name | Text / Required | Human-readable creditor-institution name. | Store for reconciliation. |
...CdtrAgt.FinInstnId.ClrSysMmbId.MmbId | Text / Required | Creditor institution member code. | Must be a recognised routing member. |
DbtAuthInf.Cdtr | Object / Required | Creditor receiving the payment. | Must match the creditor and transaction details supplied by Blinc. |
...Cdtr.Nm | Text / Required | Human-readable creditor name. | Use for display/audit. |
...Cdtr.Id.Othr.Id | Text / Required | Stable creditor ID. | Must match DbtAuthInf.DbtAuth.CdtrSchmeId...Id. |
...Cdtr.Id.Othr.SchmeNm.Cd | Text / Required | Scheme explaining the creditor ID. | Validate against agreed code. |
DbtAuthInf.CdtrAcct | Object / Required | Creditor account related to this collection. | Must be permitted for the creditor. |
...CdtrAcct.Id.Othr.Id | Text / Required | Creditor account number. | Sensitive; validate format and creditor relationship. |
...CdtrAcct.Id.Othr.SchmeNm.Cd | Text / Required | Scheme for the creditor account number. | Must match the account format. |
Narration, charges, and net settlement
| JSON path | Type / required | Simple explanation and source | Validation and relationship |
|---|---|---|---|
DbtAuthInf.RmtInf | Object / Required | Remittance information shown in records/statements. | Contains plain narration and optional structured invoice data. |
...RmtInf.Ustrd | Text / Required | Human-readable narration, for example Monthly subscription. | Apply length/content rules and store for statements. |
...RmtInf.Strd | Object or null / Optional | Structured invoice/remittance details. | When non-null, validate its complete schema; null means only Ustrd is used. |
DbtAuthInf.Chrgs | Array / Required | The itemized fees applied to this authorization. Each item states its type, code, amount, currency, and the institution that receives it. | Must contain at least one item; each item's Tp must be FEE or COMMISSION. The FEE item amount is the complete transaction TotalFee. The COMMISSION item amount is the issuer IssuerShare contained within TotalFee, not an additional charge. A zero COMMISSION amount is valid when no issuer share applies. All charge item currencies must match InstdAmt.Ccy. |
...Chrgs[].Tp | Text / Required | FEE is the complete transaction TotalFee; COMMISSION is the issuer IssuerShare contained within TotalFee, not an additional charge. | Must equal FEE or COMMISSION; no other value is accepted. |
...Chrgs[].Cd | Text / Required | Opaque code identifying the specific charge. | Must be present and non-empty. |
...Chrgs[].Amt.Amt | Decimal / Required | Charge amount in normal currency units. | Must be zero or greater. A zero value is valid when the corresponding charge does not apply. |
...Chrgs[].Amt.Ccy | Text / Required | Currency of this charge item. | Must match InstdAmt.Ccy. |
...Chrgs[].Rcpt | Object / Required | The institution that receives this charge item. | Must contain Name and ClrSysMmbId; BICFI may be null. |
...Chrgs[].Rcpt.BICFI | Text / Optional | Recipient's Bank Identifier Code. | May be null. |
...Chrgs[].Rcpt.Name | Text / Required | Recipient's human-readable institution name. | Must be present and non-empty. |
...Chrgs[].Rcpt.ClrSysMmbId.MmbId | Text / Required | Recipient's clearing system member identifier. | Must be present and non-empty. |
DbtAuthInf.TtlChrgs | Object / Required | The complete transaction TotalFee, equal to the FEE charge item amount, expressed as an Amt/Ccy pair. | Amt must equal the FEE item amount (TotalFee), not FEE plus COMMISSION; Ccy must match InstdAmt.Ccy. |
...TtlChrgs.Amt | Decimal / Required | Numeric value of TotalFee, equal to the FEE charge item amount. | Must equal the FEE item amount, not the sum of FEE and COMMISSION. |
...TtlChrgs.Ccy | Text / Required | Currency of TotalFee. | Must match InstdAmt.Ccy. |
DbtAuthInf.NetSttlmAmt | Object / Required | The amount that actually settles to the creditor after the TotalFee (FEE amount) is deducted once from the gross instructed amount. | Amt must equal InstdAmt.Amt minus TtlChrgs.Amt, and must not be negative; Ccy must match InstdAmt.Ccy. This field drives settlement/posting, not IntrBkSttlmAmt. |
...NetSttlmAmt.Amt | Decimal / Required | Numeric net settlement value: InstdAmt.Amt - TtlChrgs.Amt. | Must not be negative. |
...NetSttlmAmt.Ccy | Text / Required | Currency of the net settlement amount. | Must match InstdAmt.Ccy. |
DbtAuthInf.DbtAuth | Object / Required | Customer authentication context and creditor-scheme facts for this authorization. | Both children are required. |
...DbtAuth.AuthntcnCntxt | Object / Required | Proves the account holder approved this authorization and how the authentication event took place. | Must contain AuthntcnTmstmp, ElctrncSgntr, auth_context, auth_type, auth_binding, and auth_actor. |
...AuthntcnCntxt.AuthntcnTmstmp | UTC date-time / Required | Time the customer approved this authorization. | Cannot be in the future. |
...AuthntcnCntxt.ElctrncSgntr | Base64 text / Required | Customer-device signature of x-timestamp + compact Message, uppercased. | Verify with the device public key stored for deviceCredentialProvisionId. Never log it. |
...AuthntcnCntxt.auth_context | Text / Required | Where the authentication decision happened. DEVICE_LOCAL_AUTH means the registered customer device authenticated locally. | Initial contract accepts device-local only. Reject unknown, proximity, or delegated contexts. |
...AuthntcnCntxt.auth_type | Text / Required | Blinc sends the method actually performed: DEVICE_BIOMETRIC_STRONG for a strong device biometric or DEVICE_PIN for the registered device PIN flow. | The standard conformance value is DEVICE_BIOMETRIC_STRONG. Validate it against the registered authenticator; never infer it. |
...AuthntcnCntxt.auth_binding | Object / Required | Binds the authentication claim to one registered authenticator and hardware security boundary. | Must contain hardware and key_id. |
...AuthntcnCntxt.auth_binding.hardware | Text / Required | Blinc sends where the authenticator private key is protected: Apple-style secure enclave, Android StrongBox, or another trusted execution environment. | The example uses SECURE_ENCLAVE; the actual value must match the registered key. There is no fallback hardware value. |
...AuthntcnCntxt.auth_binding.key_id | 64-bit integer / Required | Numeric database ID of the active authenticator used for approval. | Must be greater than zero. It is not a device ID, GUID, key text, or quoted number. Use for traceability without logging sensitive key material. |
...AuthntcnCntxt.auth_actor | Text / Required | Who performed the authentication. CUSTOMER means the account owner/customer approved it. | Must be CUSTOMER for device-local authentication. Reject contradictory actors. |
...DbtAuth.CdtrSchmeId | Object / Required | Structured creditor identifier used to validate the creditor. | Final ID must match the transaction's creditor. |
...CdtrSchmeId.Id.PrvtId.Othr.Id | Text / Required | Creditor scheme ID. | Must match Cdtr.Id.Othr.Id. |
Additional transaction details
| JSON path | Type / required | Simple explanation and source | Validation and relationship |
|---|---|---|---|
SplmtryData | Object / Required | Extra payment, device, and terminal details. Authentication is not carried here; it is inside DbtAuthInf.DbtAuth.AuthntcnCntxt. | Must contain PlcAndNm and Envlp. |
SplmtryData.PlcAndNm | Text / Required | Label for the extra-data block. | Use the contracted value AdditionalDetails. |
SplmtryData.Envlp | Object / Required | Contains customer-approved details, device context, and terminal context. | Validate every required child. |
...Envlp.Message | Object / Required | Small customer-visible transaction object covered by the customer-device signature. | Its amount/reference must match the corresponding outer debit fields. Preserve exact serialization for signature verification. |
...Envlp.Message.Amount | Decimal / Required | Amount shown to and approved by the customer. | Must equal DbtAuthInf.InstdAmt.Amt. |
...Envlp.Message.ClientReference | Text / Required | Client reference shown to/approved by the customer. | Must equal Envlp.ClientReference. |
...Envlp.CustomerDeviceLocation | JSON text / Required | String containing the device's location evidence, such as latitude/longitude JSON. | Parse as valid JSON, apply consent/privacy rules, and do not log it. |
...Envlp.TerminalId | Text or null / Conditional | Identifier of a physical/payment terminal. null for flows without a terminal. | Required when the selected payment method uses a terminal. |
...Envlp.TerminalTimestamp | UTC date-time text or null / Conditional | Time the terminal observed the payment. | Required and validated when a terminal is used. |
...Envlp.TerminalLocation | JSON/location text or null / Conditional | Location associated with the terminal. | Required when institution or payment-method rules need terminal location. |
...Envlp.TerminalReference | Text or null / Conditional | Terminal's own transaction reference. | Required for terminal-based flows. Store it for reconciliation and for matching the original debit after a timeout. |
...Envlp.DeviceId | Text / Required | Identifier for the customer device used in the payment flow. | Match the registered-device context according to institution policy; do not confuse with numeric key_id. |
...Envlp.DeviceName | Text / Required | Human-readable device label. | Display/audit only; do not use it as a security key. |
...Envlp.TransactionHash | Text / Required | Hash/proof created for the transaction by the trusted flow. | Validate format and relationship to the transaction when that contract is enabled. |
...Envlp.ClientReference | Text / Required | Client-generated business reference for this payment. | Must be unique and equal Message.ClientReference. |
...Envlp.PaymentMethod | Text / Required | Blinc sends how the debit started. P2P is direct person/account initiation; TAP2PAY, STATICQR, and DYNAMICQR identify the corresponding terminal or QR flow. | The documented Debit Authorization value is P2P. Validate consistency with terminal fields and reject a missing, numeric, or unknown value. |
Successful response
Return a signed and encrypted payment response. The readable response is:
{
"GrpHdr": {
"MsgId": "00000120260816102501000000000000102",
"CreDtTm": "2026-08-16T10:25:01.000Z",
"OrgnlMsgId": "12345620260816102500000000000000003",
"OrgnlMsgNmId": "pacs.003.001.11"
},
"TxInfAndSts": {
"OrgnlInstrId": "DD-INSTR-0001",
"OrgnlEndToEndId": "DD-E2E-0001",
"OrgnlTxId": "DD-TX-0001",
"TxSts": "ACSC",
"StsRsnInf": null,
"SplmtryData": {
"PlcAndNm": "AdditionalDetails",
"Envlp": { "CustomParam": { "PostingReference": "INST-POST-0001" } }
}
}
}| Response path | Explanation |
|---|---|
GrpHdr | Response header created by the institution. |
GrpHdr.MsgId | New unique ID for the response. |
GrpHdr.CreDtTm | UTC time the response was created. |
GrpHdr.OrgnlMsgId | Copy of the request's GrpHdr.MsgId. |
GrpHdr.OrgnlMsgNmId | Original message family, pacs.003.001.11 for Debit Authorization. |
TxInfAndSts | Business result for the transaction. |
TxInfAndSts.OrgnlInstrId | Copy of request PmtId.InstrId. |
TxInfAndSts.OrgnlEndToEndId | Copy of request PmtId.EndToEndId. |
TxInfAndSts.OrgnlTxId | Copy of request PmtId.TxId. |
TxInfAndSts.TxSts | ACSC when accepted and recorded; RJCT when rejected. HTTP status does not replace this field. |
TxInfAndSts.StsRsnInf | null on success; on rejection, contains originator, machine reason, and plain corrective explanation. |
TxInfAndSts.SplmtryData | Extra response data. |
...SplmtryData.PlcAndNm | Label for the extra-data block. |
...SplmtryData.Envlp.CustomParam | Object for agreed institution-specific response references. Do not place undocumented secrets here. |
...CustomParam.PostingReference | Institution-generated posting/reference ID used for reconciliation and support. |
Rejection response
Use TxSts: "RJCT" and populate:
| Field | Meaning |
|---|---|
StsRsnInf.Orgtr.Nm | Institution or component that made the rejection decision. |
StsRsnInf.Rsn.Cd | Stable reason code that identifies why the institution rejected the debit. |
StsRsnInf.AddtlInf | Simple sentence explaining the problem and what Blinc should correct. |
Test before certification
- A valid customer request with an active device credential returns
ACSConce. - Fee-only, full-issuer-share, and partial-issuer-share requests all reconcile as
net settlement amount = instructed amount - TotalFee(theFEEamount), withCOMMISSIONas the containedIssuerShareand not an additional deduction. - After a simulated timeout, Blinc does not resend Debit Authorization; it sends a Reversal with the original debit references.
- Reversal returns the accepted debit once, or returns
RJCTwithNOORwhen no accepted debit exists. - Missing, inactive, unknown, or mismatched
deviceCredentialProvisionIdreturnsRJCT. - Institutional signature or customer signature failure rejects before posting.
- Changed
Message.Amountor client reference fails the customer signature or consistency check. - Missing, zero, string-valued, or wrong
key_idrejects. - Unsupported or contradictory authentication context/type/hardware/actor rejects.
- HTTP
200containingRJCTis handled as a business rejection.
Next
Learn how to return clear errors and handle repeated deliveries.
Updated 3 days ago