Approve a debit

Confirm the customer, device credential, payment, and account details before approving or rejecting one debit.

Approve a customer's debit after confirming the customer, device provisioning, payment, and account details. The issuing institution must verify that the customer approved the payment on a registered device and that the device credential, payment details, and account checks all pass before moving any money.

Before you begin

Endpoint

Create an HTTPS POST endpoint and give its complete URL to Blinc.

https://sandbox.examplebank.com/blinc/debit-authorizations

Every request must contain Content-Type: application/json, Accept: application/json, x-timestamp, and x-signature. Every response, including a business rejection, must contain Content-Type: application/json, x-timestamp, and x-signature. See Secure every request and response for what each header protects and how to validate it.

Request business message

After the request has been opened and its institutional signature verified as described in How to Encrypt and Decrypt Data, the business message looks like this:

{
  "GrpHdr": {
    "MsgId": "00000120260817101530123000000000001",
    "CreDtTm": "2026-08-17T10:15:30.123Z",
    "NbOfTxs": 1,
    "SttlmInf": {
      "SttlmMtd": "CLRG",
      "ClrSys": {
        "Prtry": "BLINC"
      },
      "ClrChanl": "RTNS"
    }
  },
  "DbtAuthInf": {
    "PmtId": {
      "InstrId": "DD-INSTR-0001",
      "EndToEndId": "DD-E2E-0001",
      "TxId": "DD-TX-0001",
      "ClrSysRef": "DD-CLR-0001"
    },
    "deviceCredentialProvisionId": "7f2c1a9e-3b44-4d21-9c66-0a1b2c3d4e5f",
    "PmtTpInf": {
      "SvcLvl": {
        "Cd": "SLEV"
      },
      "CtgyPurp": {
        "Cd": "GDAS"
      },
      "LclInstrm": {
        "Cd": "BLINC"
      },
      "SeqTp": "OOFF"
    },
    "InstdAmt": {
      "Amt": 1500.0,
      "Ccy": "NGN"
    },
    "IntrBkSttlmAmt": {
      "Amt": 1500.0,
      "Ccy": "NGN"
    },
    "IntrBkSttlmDt": "2026-08-17T00:00:00.000Z",
    "ChrgBr": "SLEV",
    "Dbtr": {
      "Nm": "Ada Okafor",
      "Id": {
        "Othr": {
          "Id": "12345678901",
          "SchmeNm": {
            "Cd": "BVN"
          }
        }
      }
    },
    "DbtrAcct": {
      "Id": {
        "Othr": {
          "Id": "0123456789",
          "SchmeNm": {
            "Cd": "NUBAN"
          }
        }
      }
    },
    "DbtrAgt": {
      "FinInstnId": {
        "BICFI": "EXAMPLEBIC",
        "Name": "Example Bank",
        "ClrSysMmbId": {
          "MmbId": "000001"
        }
      }
    },
    "CdtrAgt": {
      "FinInstnId": {
        "BICFI": "CREDITORBIC",
        "Name": "Creditor Bank",
        "ClrSysMmbId": {
          "MmbId": "000002"
        }
      }
    },
    "Cdtr": {
      "Nm": "Example Store",
      "Id": {
        "Othr": {
          "Id": "CREDITOR-001",
          "SchmeNm": {
            "Cd": "BLINC"
          }
        }
      }
    },
    "CdtrAcct": {
      "Id": {
        "Othr": {
          "Id": "0987654321",
          "SchmeNm": {
            "Cd": "NUBAN"
          }
        }
      }
    },
    "RmtInf": {
      "Ustrd": "Debit authorization for online purchase",
      "Strd": null
    },
    "Chrgs": [
      {
        "Tp": "FEE",
        "Cd": "FEE001",
        "Amt": {
          "Amt": 50.0,
          "Ccy": "NGN"
        },
        "Rcpt": {
          "BICFI": "FEEBICX",
          "Name": "Fee Recipient",
          "ClrSysMmbId": {
            "MmbId": "000001"
          }
        }
      },
      {
        "Tp": "COMMISSION",
        "Cd": "COM001",
        "Amt": {
          "Amt": 20.0,
          "Ccy": "NGN"
        },
        "Rcpt": {
          "BICFI": "COMBICX",
          "Name": "Commission Recipient",
          "ClrSysMmbId": {
            "MmbId": "000001"
          }
        }
      }
    ],
    "TtlChrgs": {
      "Amt": 50.0,
      "Ccy": "NGN"
    },
    "NetSttlmAmt": {
      "Amt": 1450.0,
      "Ccy": "NGN"
    },
    "DbtAuth": {
      "AuthntcnCntxt": {
        "AuthntcnTmstmp": "2026-08-17T10:14:30.000Z",
        "ElctrncSgntr": "<BASE64_CUSTOMER_DEVICE_SIGNATURE>",
        "auth_context": "DEVICE_LOCAL_AUTH",
        "auth_type": "DEVICE_BIOMETRIC_STRONG",
        "auth_binding": {
          "hardware": "SECURE_ENCLAVE",
          "key_id": 42
        },
        "auth_actor": "CUSTOMER"
      },
      "CdtrSchmeId": {
        "Id": {
          "PrvtId": {
            "Othr": {
              "Id": "CREDITOR-001",
              "SchmeNm": {
                "Cd": "BLINC"
              }
            }
          }
        }
      }
    }
  },
  "SplmtryData": {
    "PlcAndNm": "AdditionalDetails",
    "Envlp": {
      "Message": {
        "Amount": 1500.0,
        "ClientReference": "CLIENT-REF-0001"
      },
      "CustomerDeviceLocation": "{\"latitude\":6.5244,\"longitude\":3.3792}",
      "TerminalId": null,
      "TerminalTimestamp": null,
      "TerminalLocation": null,
      "TerminalReference": null,
      "DeviceId": "DEVICE-0001",
      "DeviceName": "Ada's registered phone",
      "TransactionHash": "HASH-0001",
      "ClientReference": "CLIENT-REF-0001",
      "PaymentMethod": "P2P"
    }
  }
}

What this request contains

The request identifies the customer account, the merchant payment, the amount, the customer's approval, and the device credential provisioning record that authorizes the debit. The customer's approval is signed inside the protected message. The institution must verify that approval before debiting the account or crediting the payment beneficiary.

Verify the customer-device signature

ElctrncSgntr is not the same as the institutional x-signature header.

  1. Take the exact SplmtryData.Envlp.Message object shown to the customer for approval.
  2. Serialize it as compact JSON with null properties omitted.
  3. Join the request's x-timestamp value and that JSON with no separator.
  4. Convert the joined string to uppercase.
  5. Verify ElctrncSgntr using the device public key stored with deviceCredentialProvisionId during device credential provisioning.

Reject the debit when the signed customer-visible amount/reference differs from the debit fields.

Decide whether to approve the debit

  1. Decrypt and verify the institutional signature headers.
  2. Validate timestamp, replay state, message ID, and transaction identifiers.
  3. Confirm the debtor institution member ID identifies the receiving institution.
  4. Load the device credential provisioning record by deviceCredentialProvisionId and require active status.
  5. Match the customer and debtor account to the stored device credential provisioning record.
  6. Validate the authentication fields as one combination.
  7. Verify the customer-device signature.
  8. Confirm the instructed amount, currency, settlement date, charges, and net settlement arithmetic agree: net settlement amount = instructed amount - TotalFee (the FEE amount).
  9. Perform the institution's balance, risk, limit, sanctions, and account-status checks.
  10. Record one business outcome and preserve every original reference so a later Reversal can identify this debit.
  11. Sign and encrypt the response, then return the required response headers.

If no response reaches Blinc

Blinc does not retry Debit Authorization. If the connection fails after the institution may have completed the debit, Blinc sends a Reversal request using the original debit references.

When the Reversal arrives, find the original debit by those references. If the debit was accepted, return the full amount once. If no accepted debit exists, return RJCT with NOOR. Do not create a new debit while handling a Reversal, and do not wait for Blinc to resend Debit Authorization.

Request field reference

Header and settlement

JSON pathType / requiredSimple explanation and sourceValidation and relationship
GrpHdrObject / RequiredHeader for the complete debit message. Blinc creates it.Must contain all fields below.
GrpHdr.MsgIdText / RequiredUnique message ID for duplicate protection and tracing.A new request must use a new ID; an identical request must produce the same business outcome without debiting the account twice.
GrpHdr.CreDtTmUTC date-time / RequiredTime Blinc created the message.Must be valid UTC and not outside the allowed window.
GrpHdr.NbOfTxsInteger / RequiredNumber of debit transactions inside this message.Must be 1 because this contract carries one DbtAuthInf object.
GrpHdr.SttlmInfObject / RequiredDescribes how institutions settle this payment.Must contain method, system, and channel.
GrpHdr.SttlmInf.SttlmMtdText / RequiredBlinc sends the settlement method. CLRG means settlement through the agreed clearing system.The documented Debit Authorization value is CLRG. Validate it; never insert it when missing.
GrpHdr.SttlmInf.ClrSysObject / RequiredIdentifies the clearing system.Must contain Prtry.
GrpHdr.SttlmInf.ClrSys.PrtryText / RequiredProprietary clearing-system name. The example uses BLINC.Must equal the agreed system identifier.
GrpHdr.SttlmInf.ClrChanlText / RequiredBlinc sends the clearing route. RTNS means real-time processing with net settlement.The documented Debit Authorization value is RTNS. Accept another listed route only when onboarding explicitly enables it.
DbtAuthInfObject / Required"debit authorization transaction information": the complete account-authorization instruction.Validate every child before posting.

Identifiers, device credential, and payment classification

JSON pathType / requiredSimple explanation and sourceValidation and relationship
DbtAuthInf.PmtIdObject / RequiredGroups the identifiers used by different systems to trace the same debit.All four values are required. Store them so a Reversal can locate the original debit after a timeout. Blinc does not retry Debit Authorization.
...PmtId.InstrIdText / RequiredIdentifier for this payment instruction. Blinc creates it.Unique within the agreed institution scope.
...PmtId.EndToEndIdText / RequiredMain business trace ID carried from initiation to final outcome.Store it; a Reversal uses it to locate the original debit.
...PmtId.TxIdText / RequiredTransaction ID for this debit in the switching flow.Must not identify another transaction.
...PmtId.ClrSysRefText / RequiredReference used by the clearing/switching system.Store for reconciliation and support searches.
DbtAuthInf.deviceCredentialProvisionIdText / RequiredIdentifier for the customer's provisioned device credential. Blinc sends the value created during device credential provisioning.Must be present, non-empty, and reference an active device credential provisioning record.
DbtAuthInf.PmtTpInfObject / RequiredClassifies the payment.Child codes must be agreed and internally consistent.
...PmtTpInf.SvcLvl.CdText / RequiredService-level code. It describes the service rules applied to the payment.Accept only contracted values; do not infer from other fields.
...PmtTpInf.CtgyPurp.CdText / RequiredCategory-purpose code. GDAS identifies the agreed goods-and-services payment purpose.Validate against the agreed value.
...PmtTpInf.LclInstrm.CdText / RequiredLocal-instrument code identifying the payment product/rule set.Validate against the agreed instrument.
...PmtTpInf.SeqTpText / OptionalCollection-sequence code. OOFF identifies a one-off authorization.Use the agreed one-off value for Debit Authorization.

Amount, parties, and accounts

JSON pathType / requiredSimple explanation and sourceValidation and relationship
DbtAuthInf.InstdAmtObject / RequiredThe gross amount the customer authorized. Blinc instructs the issuing institution to debit this amount from the customer's account associated with the device credential.Contains numeric amount and currency.
...InstdAmt.AmtDecimal / RequiredAmount in normal currency units. 2500.00 means NGN 2,500.00, not kobo.Must be positive, within limits, and equal the customer-approved Message.Amount.
...InstdAmt.CcyText / RequiredISO currency code.Must be supported and match settlement and charge rules.
DbtAuthInf.IntrBkSttlmAmtObject / Deprecated, still sentLegacy interbank settlement amount, kept for backward compatibility. The amount that actually settles is DbtAuthInf.NetSttlmAmt, derived from InstdAmt minus TtlChrgs.Not consumed for posting; do not treat it as the settlement amount.
...IntrBkSttlmAmt.AmtDecimal / Deprecated, still sentNumeric value of the legacy interbank settlement amount.Informational only.
...IntrBkSttlmAmt.CcyText / Deprecated, still sentCurrency of the legacy interbank settlement amount.Informational only.
DbtAuthInf.IntrBkSttlmDtUTC date-time / RequiredDate on which interbank settlement applies.Must satisfy the agreed settlement-date rule.
DbtAuthInf.ChrgBrText / RequiredBlinc sends who bears charges. SLEV means the service-level agreement decides the charge treatment.The documented Debit Authorization value is SLEV. Validate it against Chrgs; do not invent it when missing.
DbtAuthInf.DbtrObject / RequiredCustomer whose account is debited.Must match the stored device credential provisioning record.
...Dbtr.NmText / RequiredCustomer's human-readable name.Use for audit/display; identity matching uses the ID.
...Dbtr.Id.Othr.IdText / RequiredCustomer identity value, shown as BVN.Sensitive; must match the account owner associated with the provisioned device credential.
...Dbtr.Id.Othr.SchmeNm.CdText / RequiredScheme that explains the customer ID.Validate ID format for the named scheme.
DbtAuthInf.DbtrAcctObject / RequiredCustomer account to debit.Must be active, debit-enabled, and owned by the debtor.
...DbtrAcct.Id.Othr.IdText / RequiredCustomer account number.Sensitive; match the account associated with the provisioned device credential.
...DbtrAcct.Id.Othr.SchmeNm.CdText / RequiredAccount-number scheme, for example NUBAN.Must match the supplied account format.
DbtAuthInf.DbtrAgtObject / RequiredContainer for the customer's issuing institution.Must contain FinInstnId.
...DbtrAgt.FinInstnIdObject / RequiredIdentifies the debtor's issuing institution.Its member ID must identify the receiving institution.
...DbtrAgt.FinInstnId.BICFIText / ConditionalBank Identifier Code when used.Validate format if present.
...DbtrAgt.FinInstnId.NameText / RequiredHuman-readable issuing-institution name.Display/audit only; route using the member ID.
...DbtrAgt.FinInstnId.ClrSysMmbId.MmbIdText / RequiredDebtor institution member code.Must equal the code configured for the endpoint.
DbtAuthInf.CdtrAgtObject / RequiredContainer for the creditor's financial institution.Must contain FinInstnId.
...CdtrAgt.FinInstnId.BICFIText / ConditionalCreditor institution's BIC when used.Validate format if present.
...CdtrAgt.FinInstnId.NameText / RequiredHuman-readable creditor-institution name.Store for reconciliation.
...CdtrAgt.FinInstnId.ClrSysMmbId.MmbIdText / RequiredCreditor institution member code.Must be a recognised routing member.
DbtAuthInf.CdtrObject / RequiredCreditor receiving the payment.Must match the creditor and transaction details supplied by Blinc.
...Cdtr.NmText / RequiredHuman-readable creditor name.Use for display/audit.
...Cdtr.Id.Othr.IdText / RequiredStable creditor ID.Must match DbtAuthInf.DbtAuth.CdtrSchmeId...Id.
...Cdtr.Id.Othr.SchmeNm.CdText / RequiredScheme explaining the creditor ID.Validate against agreed code.
DbtAuthInf.CdtrAcctObject / RequiredCreditor account related to this collection.Must be permitted for the creditor.
...CdtrAcct.Id.Othr.IdText / RequiredCreditor account number.Sensitive; validate format and creditor relationship.
...CdtrAcct.Id.Othr.SchmeNm.CdText / RequiredScheme for the creditor account number.Must match the account format.

Narration, charges, and net settlement

JSON pathType / requiredSimple explanation and sourceValidation and relationship
DbtAuthInf.RmtInfObject / RequiredRemittance information shown in records/statements.Contains plain narration and optional structured invoice data.
...RmtInf.UstrdText / RequiredHuman-readable narration, for example Monthly subscription.Apply length/content rules and store for statements.
...RmtInf.StrdObject or null / OptionalStructured invoice/remittance details.When non-null, validate its complete schema; null means only Ustrd is used.
DbtAuthInf.ChrgsArray / RequiredThe itemized fees applied to this authorization. Each item states its type, code, amount, currency, and the institution that receives it.Must contain at least one item; each item's Tp must be FEE or COMMISSION. The FEE item amount is the complete transaction TotalFee. The COMMISSION item amount is the issuer IssuerShare contained within TotalFee, not an additional charge. A zero COMMISSION amount is valid when no issuer share applies. All charge item currencies must match InstdAmt.Ccy.
...Chrgs[].TpText / RequiredFEE is the complete transaction TotalFee; COMMISSION is the issuer IssuerShare contained within TotalFee, not an additional charge.Must equal FEE or COMMISSION; no other value is accepted.
...Chrgs[].CdText / RequiredOpaque code identifying the specific charge.Must be present and non-empty.
...Chrgs[].Amt.AmtDecimal / RequiredCharge amount in normal currency units.Must be zero or greater. A zero value is valid when the corresponding charge does not apply.
...Chrgs[].Amt.CcyText / RequiredCurrency of this charge item.Must match InstdAmt.Ccy.
...Chrgs[].RcptObject / RequiredThe institution that receives this charge item.Must contain Name and ClrSysMmbId; BICFI may be null.
...Chrgs[].Rcpt.BICFIText / OptionalRecipient's Bank Identifier Code.May be null.
...Chrgs[].Rcpt.NameText / RequiredRecipient's human-readable institution name.Must be present and non-empty.
...Chrgs[].Rcpt.ClrSysMmbId.MmbIdText / RequiredRecipient's clearing system member identifier.Must be present and non-empty.
DbtAuthInf.TtlChrgsObject / RequiredThe complete transaction TotalFee, equal to the FEE charge item amount, expressed as an Amt/Ccy pair.Amt must equal the FEE item amount (TotalFee), not FEE plus COMMISSION; Ccy must match InstdAmt.Ccy.
...TtlChrgs.AmtDecimal / RequiredNumeric value of TotalFee, equal to the FEE charge item amount.Must equal the FEE item amount, not the sum of FEE and COMMISSION.
...TtlChrgs.CcyText / RequiredCurrency of TotalFee.Must match InstdAmt.Ccy.
DbtAuthInf.NetSttlmAmtObject / RequiredThe amount that actually settles to the creditor after the TotalFee (FEE amount) is deducted once from the gross instructed amount.Amt must equal InstdAmt.Amt minus TtlChrgs.Amt, and must not be negative; Ccy must match InstdAmt.Ccy. This field drives settlement/posting, not IntrBkSttlmAmt.
...NetSttlmAmt.AmtDecimal / RequiredNumeric net settlement value: InstdAmt.Amt - TtlChrgs.Amt.Must not be negative.
...NetSttlmAmt.CcyText / RequiredCurrency of the net settlement amount.Must match InstdAmt.Ccy.
DbtAuthInf.DbtAuthObject / RequiredCustomer authentication context and creditor-scheme facts for this authorization.Both children are required.
...DbtAuth.AuthntcnCntxtObject / RequiredProves the account holder approved this authorization and how the authentication event took place.Must contain AuthntcnTmstmp, ElctrncSgntr, auth_context, auth_type, auth_binding, and auth_actor.
...AuthntcnCntxt.AuthntcnTmstmpUTC date-time / RequiredTime the customer approved this authorization.Cannot be in the future.
...AuthntcnCntxt.ElctrncSgntrBase64 text / RequiredCustomer-device signature of x-timestamp + compact Message, uppercased.Verify with the device public key stored for deviceCredentialProvisionId. Never log it.
...AuthntcnCntxt.auth_contextText / RequiredWhere the authentication decision happened. DEVICE_LOCAL_AUTH means the registered customer device authenticated locally.Initial contract accepts device-local only. Reject unknown, proximity, or delegated contexts.
...AuthntcnCntxt.auth_typeText / RequiredBlinc sends the method actually performed: DEVICE_BIOMETRIC_STRONG for a strong device biometric or DEVICE_PIN for the registered device PIN flow.The standard conformance value is DEVICE_BIOMETRIC_STRONG. Validate it against the registered authenticator; never infer it.
...AuthntcnCntxt.auth_bindingObject / RequiredBinds the authentication claim to one registered authenticator and hardware security boundary.Must contain hardware and key_id.
...AuthntcnCntxt.auth_binding.hardwareText / RequiredBlinc sends where the authenticator private key is protected: Apple-style secure enclave, Android StrongBox, or another trusted execution environment.The example uses SECURE_ENCLAVE; the actual value must match the registered key. There is no fallback hardware value.
...AuthntcnCntxt.auth_binding.key_id64-bit integer / RequiredNumeric database ID of the active authenticator used for approval.Must be greater than zero. It is not a device ID, GUID, key text, or quoted number. Use for traceability without logging sensitive key material.
...AuthntcnCntxt.auth_actorText / RequiredWho performed the authentication. CUSTOMER means the account owner/customer approved it.Must be CUSTOMER for device-local authentication. Reject contradictory actors.
...DbtAuth.CdtrSchmeIdObject / RequiredStructured creditor identifier used to validate the creditor.Final ID must match the transaction's creditor.
...CdtrSchmeId.Id.PrvtId.Othr.IdText / RequiredCreditor scheme ID.Must match Cdtr.Id.Othr.Id.

Additional transaction details

JSON pathType / requiredSimple explanation and sourceValidation and relationship
SplmtryDataObject / RequiredExtra payment, device, and terminal details. Authentication is not carried here; it is inside DbtAuthInf.DbtAuth.AuthntcnCntxt.Must contain PlcAndNm and Envlp.
SplmtryData.PlcAndNmText / RequiredLabel for the extra-data block.Use the contracted value AdditionalDetails.
SplmtryData.EnvlpObject / RequiredContains customer-approved details, device context, and terminal context.Validate every required child.
...Envlp.MessageObject / RequiredSmall customer-visible transaction object covered by the customer-device signature.Its amount/reference must match the corresponding outer debit fields. Preserve exact serialization for signature verification.
...Envlp.Message.AmountDecimal / RequiredAmount shown to and approved by the customer.Must equal DbtAuthInf.InstdAmt.Amt.
...Envlp.Message.ClientReferenceText / RequiredClient reference shown to/approved by the customer.Must equal Envlp.ClientReference.
...Envlp.CustomerDeviceLocationJSON text / RequiredString containing the device's location evidence, such as latitude/longitude JSON.Parse as valid JSON, apply consent/privacy rules, and do not log it.
...Envlp.TerminalIdText or null / ConditionalIdentifier of a physical/payment terminal. null for flows without a terminal.Required when the selected payment method uses a terminal.
...Envlp.TerminalTimestampUTC date-time text or null / ConditionalTime the terminal observed the payment.Required and validated when a terminal is used.
...Envlp.TerminalLocationJSON/location text or null / ConditionalLocation associated with the terminal.Required when institution or payment-method rules need terminal location.
...Envlp.TerminalReferenceText or null / ConditionalTerminal's own transaction reference.Required for terminal-based flows. Store it for reconciliation and for matching the original debit after a timeout.
...Envlp.DeviceIdText / RequiredIdentifier for the customer device used in the payment flow.Match the registered-device context according to institution policy; do not confuse with numeric key_id.
...Envlp.DeviceNameText / RequiredHuman-readable device label.Display/audit only; do not use it as a security key.
...Envlp.TransactionHashText / RequiredHash/proof created for the transaction by the trusted flow.Validate format and relationship to the transaction when that contract is enabled.
...Envlp.ClientReferenceText / RequiredClient-generated business reference for this payment.Must be unique and equal Message.ClientReference.
...Envlp.PaymentMethodText / RequiredBlinc sends how the debit started. P2P is direct person/account initiation; TAP2PAY, STATICQR, and DYNAMICQR identify the corresponding terminal or QR flow.The documented Debit Authorization value is P2P. Validate consistency with terminal fields and reject a missing, numeric, or unknown value.

Successful response

Return a signed and encrypted payment response. The readable response is:

{
  "GrpHdr": {
    "MsgId": "00000120260816102501000000000000102",
    "CreDtTm": "2026-08-16T10:25:01.000Z",
    "OrgnlMsgId": "12345620260816102500000000000000003",
    "OrgnlMsgNmId": "pacs.003.001.11"
  },
  "TxInfAndSts": {
    "OrgnlInstrId": "DD-INSTR-0001",
    "OrgnlEndToEndId": "DD-E2E-0001",
    "OrgnlTxId": "DD-TX-0001",
    "TxSts": "ACSC",
    "StsRsnInf": null,
    "SplmtryData": {
      "PlcAndNm": "AdditionalDetails",
      "Envlp": { "CustomParam": { "PostingReference": "INST-POST-0001" } }
    }
  }
}
Response pathExplanation
GrpHdrResponse header created by the institution.
GrpHdr.MsgIdNew unique ID for the response.
GrpHdr.CreDtTmUTC time the response was created.
GrpHdr.OrgnlMsgIdCopy of the request's GrpHdr.MsgId.
GrpHdr.OrgnlMsgNmIdOriginal message family, pacs.003.001.11 for Debit Authorization.
TxInfAndStsBusiness result for the transaction.
TxInfAndSts.OrgnlInstrIdCopy of request PmtId.InstrId.
TxInfAndSts.OrgnlEndToEndIdCopy of request PmtId.EndToEndId.
TxInfAndSts.OrgnlTxIdCopy of request PmtId.TxId.
TxInfAndSts.TxStsACSC when accepted and recorded; RJCT when rejected. HTTP status does not replace this field.
TxInfAndSts.StsRsnInfnull on success; on rejection, contains originator, machine reason, and plain corrective explanation.
TxInfAndSts.SplmtryDataExtra response data.
...SplmtryData.PlcAndNmLabel for the extra-data block.
...SplmtryData.Envlp.CustomParamObject for agreed institution-specific response references. Do not place undocumented secrets here.
...CustomParam.PostingReferenceInstitution-generated posting/reference ID used for reconciliation and support.

Rejection response

Use TxSts: "RJCT" and populate:

FieldMeaning
StsRsnInf.Orgtr.NmInstitution or component that made the rejection decision.
StsRsnInf.Rsn.CdStable reason code that identifies why the institution rejected the debit.
StsRsnInf.AddtlInfSimple sentence explaining the problem and what Blinc should correct.

Test before certification

  • A valid customer request with an active device credential returns ACSC once.
  • Fee-only, full-issuer-share, and partial-issuer-share requests all reconcile as net settlement amount = instructed amount - TotalFee (the FEE amount), with COMMISSION as the contained IssuerShare and not an additional deduction.
  • After a simulated timeout, Blinc does not resend Debit Authorization; it sends a Reversal with the original debit references.
  • Reversal returns the accepted debit once, or returns RJCT with NOOR when no accepted debit exists.
  • Missing, inactive, unknown, or mismatched deviceCredentialProvisionId returns RJCT.
  • Institutional signature or customer signature failure rejects before posting.
  • Changed Message.Amount or client reference fails the customer signature or consistency check.
  • Missing, zero, string-valued, or wrong key_id rejects.
  • Unsupported or contradictory authentication context/type/hardware/actor rejects.
  • HTTP 200 containing RJCT is handled as a business rejection.

Next

Learn how to return clear errors and handle repeated deliveries.


Did this page help you?