# Overview

Saafe Account Aggregator's developer documentation for creating the FIU module which connects with the account aggregator for fetching consent based financial information of the user.

### FIU Module Documentation

**Maintainer:** [Saafe](https://saafe.in)\
**Version:** 1.6.1\
**Updated Date:** 14.11.2024

{% hint style="info" %}
To view the latest version try clearing the browser cache. **Ctrl + Shift + R** on Windows and **Cmd + Shift + R** on Mac
{% endhint %}


# Supported FIPs on Saafe

### Summary

<table data-full-width="false"><thead><tr><th width="508">FIP Type</th><th>Count</th></tr></thead><tbody><tr><td>Banks</td><td>17</td></tr><tr><td>RRBs</td><td>10</td></tr><tr><td>NBFCs</td><td>1</td></tr><tr><td>Depositories</td><td><mark style="color:green;">2 (All)</mark></td></tr><tr><td>Registrar and Transfer Agents (RTA) Mutual Funds</td><td><mark style="color:green;">2 (All)</mark></td></tr><tr><td>Central Recordkeeping Agencies (CRAs) NPS</td><td><mark style="color:green;">3 (All)</mark></td></tr><tr><td>Goods and Services Tax Network</td><td><mark style="color:green;">1 (All)</mark></td></tr><tr><td>Insurances</td><td>7</td></tr></tbody></table>

### List of FIPs supported on Saafe

<table data-full-width="true"><thead><tr><th width="69">No</th><th width="306">Entity Name</th><th width="200">FIP ID (PROD)</th><th width="170">Category</th><th>Supported Data Types</th></tr></thead><tbody><tr><td>1</td><td>AU Small Finance Bank</td><td>AUBank-FIP</td><td>Bank</td><td>DEPOSIT</td></tr><tr><td>2</td><td>Axis Bank</td><td>AXIS001</td><td>Bank</td><td>DEPOSIT</td></tr><tr><td>3</td><td>Bank of Maharashtra</td><td>BOM_FIP</td><td>Bank</td><td>DEPOSIT</td></tr><tr><td>4</td><td>City Union Bank</td><td>CUBFIP</td><td>Bank</td><td>DEPOSIT</td></tr><tr><td>5</td><td>Federal Bank</td><td>FDRLFIPPROD</td><td>Bank</td><td>DEPOSIT</td></tr><tr><td>6</td><td>Fincare Small Finance Bank</td><td>fiplive@fincarebank</td><td>Bank</td><td>DEPOSIT</td></tr><tr><td>7</td><td>HDFC Bank</td><td>HDFC-FIP</td><td>Bank</td><td>DEPOSIT</td></tr><tr><td>8</td><td>ICICI Bank</td><td>ICICI-FIP</td><td>Bank</td><td>DEPOSIT</td></tr><tr><td>9</td><td>IDBI Bank</td><td>idbibank-fip</td><td>Bank</td><td>DEPOSIT, RECURRING_DEPOSIT, TERM_DEPOSIT</td></tr><tr><td>10</td><td>IDFC First Bank</td><td>IDFCFirstBank-FIP</td><td>Bank</td><td>DEPOSIT</td></tr><tr><td>11</td><td>Indian Bank</td><td>IBFIP</td><td>Bank</td><td>DEPOSIT, RECURRING_DEPOSIT, TERM_DEPOSIT</td></tr><tr><td>12</td><td>Karur Vysya Bank</td><td>KarurVysyaBank-FIP</td><td>Bank</td><td>DEPOSIT</td></tr><tr><td>13</td><td>Kotak Mahindra Bank</td><td>KotakMahindraBank-FIP</td><td>Bank</td><td>DEPOSIT</td></tr><tr><td>14</td><td>Punjab National Bank</td><td>PNB-FIP</td><td>Bank</td><td>DEPOSIT</td></tr><tr><td>15</td><td>UCO Bank</td><td>UCOB-FIP</td><td>Bank</td><td>DEPOSIT</td></tr><tr><td>16</td><td>Union Bank of India</td><td>UBI-FIP</td><td>Bank</td><td>DEPOSIT</td></tr><tr><td>17</td><td>Yes Bank</td><td>YESB-FIP</td><td>Bank</td><td>DEPOSIT</td></tr><tr><td>18</td><td>Assam Gramin Vikash Bank</td><td>AGVB-FIP</td><td>RRB</td><td>DEPOSIT</td></tr><tr><td>19</td><td>Bangiya Gramin Vikash Bank</td><td>BGVB-FIP</td><td>RRB</td><td>DEPOSIT</td></tr><tr><td>20</td><td>Chaitanya Godavari Grameena Bank</td><td>CGGBFIP0001</td><td>RRB</td><td>DEPOSIT</td></tr><tr><td>21</td><td>Dakshin Bihar Gramin Bank</td><td>DBGB-FIP</td><td>RRB</td><td>DEPOSIT</td></tr><tr><td>22</td><td>Himachal Pradesh Gramin Bank</td><td>HPGB-FIP</td><td>RRB</td><td>DEPOSIT</td></tr><tr><td>23</td><td>Manipur Rural Bank</td><td>MRB-FIP</td><td>RRB</td><td>DEPOSIT</td></tr><tr><td>24</td><td>Prathama UP Gramin Bank</td><td>PUPGB-FIP</td><td>RRB</td><td>DEPOSIT</td></tr><tr><td>25</td><td>Punjab Gramin Bank</td><td>PGB-FIP</td><td>RRB</td><td>DEPOSIT</td></tr><tr><td>26</td><td>Sarva Haryana Gramin Bank</td><td>SHGB-FIP</td><td>RRB</td><td>DEPOSIT</td></tr><tr><td>27</td><td>Tripura Gramin Bank</td><td>TGB-FIP</td><td>RRB</td><td>DEPOSIT</td></tr><tr><td>28</td><td>Mahindra &#x26; Mahindra Financial Services Limited</td><td>MMFSL_FIP_PROD</td><td>NBFC</td><td>TERM_DEPOSIT</td></tr><tr><td>29</td><td>Goods and Services Tax Network</td><td>GSTN-FIP</td><td>GSTN</td><td>GSTR1_3B</td></tr><tr><td>30</td><td>CDSL</td><td>CDSLFIP</td><td>Depository</td><td>EQUITIES, MUTUAL_FUNDS, IDR, REIT, CIS, INVIT, AIF, ETF</td></tr><tr><td>31</td><td>NSDL</td><td>fip@nsdl</td><td>Depository</td><td>EQUITIES, MUTUAL_FUNDS, IDR, REIT, CIS, INVIT, AIF, ETF</td></tr><tr><td>32</td><td>CAMS (RTA)</td><td>CAMSRTAFIP</td><td>RTA</td><td>MUTUAL_FUNDS, SIP</td></tr><tr><td>33</td><td>KFin Technologies Limited (RTA)</td><td>kfinmf-fip</td><td>RTA</td><td>MUTUAL_FUNDS</td></tr><tr><td>34</td><td>CAMS (NPS)</td><td>CAMSCRAFIP</td><td>CRA</td><td>NPS</td></tr><tr><td>35</td><td>KFin Technologies Limited (NPS)</td><td>kfinnps-fip</td><td>CRA</td><td>NPS</td></tr><tr><td>36</td><td>Protean eGov Technologies Private Limited (NPS)</td><td>NPS_PROD</td><td>CRA</td><td>NPS</td></tr><tr><td>37</td><td>HDFC Life Insurance</td><td>fiplive@hdfclife</td><td>Life Insurance</td><td>INSURANCE_POLICIES</td></tr><tr><td>38</td><td>ICICI Prudential Life Insurance</td><td>iciciprudential-fip</td><td>Life Insurance</td><td>INSURANCE_POLICIES</td></tr><tr><td>39</td><td>Max Life Insurance</td><td>maxlifeinsurance-fip</td><td>Life Insurance</td><td>INSURANCE_POLICIES, LIFE_INSURANCE</td></tr><tr><td>40</td><td>SBI Life Insurance</td><td>sbilife-fip</td><td>Life Insurance</td><td>INSURANCE_POLICIES</td></tr><tr><td>41</td><td>Shriram General Insurance</td><td>SHRIRAMGI_LIVE</td><td>General Insurance</td><td>INSURANCE_POLICIES</td></tr><tr><td>42</td><td>Shriram Life Insurance</td><td>SHRIRAM_LIFE_INSURANCE_FIP_PROD</td><td>Life Insurance</td><td>INSURANCE_POLICIES</td></tr><tr><td>43</td><td>Tata AIA Life Insurance</td><td>talic-fip</td><td>Life Insurance</td><td>INSURANCE_POLICIES</td></tr></tbody></table>

### Upcoming FIPs on Saafe

<table><thead><tr><th width="80" data-type="number">No</th><th width="319">Entity Name</th><th width="132">Category</th><th>Supported Data Types</th></tr></thead><tbody><tr><td>1</td><td>Suryoday Small Finance Bank</td><td>Bank</td><td>DEPOSIT</td></tr><tr><td>2</td><td>Bank of Baroda</td><td>Bank</td><td>DEPOSIT</td></tr><tr><td>3</td><td>Bank of India</td><td>Bank</td><td>DEPOSIT</td></tr><tr><td>4</td><td>Punjab &#x26; Sind Bank</td><td>Bank</td><td>DEPOSIT</td></tr><tr><td>5</td><td>Canara Bank</td><td>Bank</td><td>DEPOSIT</td></tr><tr><td>6</td><td>South Indian Bank</td><td>Bank</td><td>DEPOSIT</td></tr><tr><td>7</td><td>DBS Bank</td><td>Bank</td><td>DEPOSIT</td></tr><tr><td>8</td><td>Kotak Mahindra Life Insurance</td><td>Insurance</td><td>INSURANCE_POLICIES</td></tr><tr><td>9</td><td>Aditya Birla Sun Life Insurance</td><td>Insurance</td><td>INSURANCE_POLICIES</td></tr><tr><td>10</td><td>Star Health Insurance</td><td>Insurance</td><td>INSURANCE_POLICIES</td></tr><tr><td>11</td><td>United India Insurance</td><td>Insurance</td><td>INSURANCE_POLICIES</td></tr></tbody></table>


# Become an FIU

### Steps to become an FIU

* **Get registered and regulated** by at least one of the Financial Service Regulators (FSR), namely - RBI, SEBI, IRDAI, PFRDA.
* **Implement the FIU Module**
  * <https://api.rebit.org.in/spec/fiu> - This has the notification endpoints that you will need to create for an AA to send notifications to your FIU Module
  * <https://api.rebit.org.in/spec/aa> - This has the APIs of AA that you need to integrate for the process flow.
* **Test your module**\
  Saafe will provide you the credentials to raise a consent and test your module. This will be shared via an email once confirming step 1.
* **Enrol your module** \
  We will need to enroll your module in the UAT Central Registry which Saafe will guide you through it.
* **Get Certified** \
  Get your certification showing adherence to Technical Standards prescribed by ReBIT by a Sahamati empanelled auditor <https://sahamati.org.in/empaneled-certifiers/> \
  \
  The certifier will provide you with a testing kit that you can use it test your module. We recommend start using the testing kit from the initial stage of development so that you can test the endpoints in parallel to the development.
* **Get your details publicised**\
  After getting the certification from one of the certifiers, you will have to do a bi-lateral agreement with Saafe and we will onboard you on the Live environment.
* **Go Live** \
  You can start testing with the prod data after this with your beta testers and go live after that.&#x20;


# Environment

<table data-full-width="false"><thead><tr><th>Variables</th><th>Hackathon</th><th>Sandbox</th></tr></thead><tbody><tr><td>CR Environment</td><td>Sandbox</td><td>UAT</td></tr><tr><td>AA Entity ID</td><td>saafe-sandbox</td><td>dashboard-aa-preprod</td></tr><tr><td>Web App URL</td><td><a href="https://test.saafe.in/">https://test.saafe.in/</a></td><td><a href="https://sandbox.saafe.in/">https://sandbox.saafe.in/</a></td></tr><tr><td>Central Registry (CR) Base URL</td><td>https://api.sandbox.sahamati.org.in/cr</td><td>https://uatcr.sahamati.org.in</td></tr><tr><td>IAM Base URL</td><td>https://api.sandbox.sahamati.org.in/iam</td><td>https://api.uat.sahamati.org.in/iam</td></tr><tr><td>Token Service (OLD) Base URL "Deprecated"</td><td>https://tokens.sandbox.sahamati.org.in</td><td>https://uattokens.sahamati.org.in</td></tr><tr><td>CR Token Public Key</td><td>https://tokens.sandbox.sahamati.org.in/auth/realms/sahamati/protocol/openid-connect/certs</td><td>https://uattokens.sahamati.org.in/auth/realms/sahamati/protocol/openid-connect/certs</td></tr></tbody></table>

### AA Entity JSON

{% tabs %}
{% tab title="Hackathon Env" %}
{% code overflow="wrap" %}

```json
{
  "name": "Saafe Sandbox",
  "id": "saafe-sandbox",
  "code": "saafe-sandbox",
  "entityhandle": "@saafe-sandbox",
  "baseurl": "v2:https://test.saafe.in/api/v2",
  "webviewurl": "https://test.saafe.in/webview",
  "certificate": {
    "alg": "RS256",
    "e": "AQAB",
    "kid": "8f53656e-9b5d-4afd-8208-86f1859d84e5",
    "kty": "RSA",
    "n": "kZtbglKhedm2VSGpQhHugdrwC-sAcJtHyOCXUHeGc1c9tGLGfwSNZ2qVJu6HyYXhaJ11M2-noNVFKFK1PB-pVJAL53jHDa2rMyGHGebb3I8rs1fXoDA3uc-t0E9P6qDlH_BJs2cNEpGyM1NNEG-rIUF1bWKmo8IaifuGu17S8QVeUJ3a2BvzeugHfxgF0RAhW9JziBpX7H-Do-6prwiOcNipRTME7eXhcZuHgGAmOYkkFmRnBSjt90EmfH_cZKGyCDRu0XuEXZXvcTauDbHIJSe4PGDQCEYMeqFt-9MziJZeWUen6CJMxTHxYudGQSbZgPm0q953Zs-o4I_-pBoeXw",
    "use": "sig"
  },
  "inboundports": [
    "443",
    "80"
  ],
  "outboundports": null,
  "ips": [
    "3.108.179.208"
  ]
}
```

{% endcode %}
{% endtab %}

{% tab title="Sandbox Env" %}
{% code overflow="wrap" %}

```json
{
  "name": "Dashboard AA PREPROD",
  "id": "dashboard-aa-preprod",
  "code": "dashboard-aa-preprod",
  "entityhandle": "@dashboard-aa-preprod",
  "baseurl": "v2:https://sandbox.saafe.in/api/v2",
  "webviewurl": "https://sandbox.saafe.in/webview",
  "certificate": {
    "alg": "RS256",
    "e": "AQAB",
    "kid": "b5a1468b-1bd4-4be6-b505-bf2c8d4df056",
    "kty": "RSA",
    "n": "p6DCZYiVNsq3WRgzCWuFvXTGUs3BeDJydPMQMjyzXoXb-s_tvkquED0IeMcj30oic-W7xAkqAm579b9epk0aB5bkWmfSy1tlnzCnNmIsHxA0QEXI9PuohSHLfNFHIk921ymPNji5mlRpoKHzt4029MZvRAxytTcNNGxA3GvicHZFuHLio7AENfhEAmVSURuZPNQeolTcLjYjiArypLV_vtXdTI9sz0OhHOh8whC82efpfxz69LMm86WkISFSSCGG_gMvjtGonxRnKE-iqvkOv4ol6ksZs8xnbzFT-Cmlt13n6DbHJ7s4ZVmwlX8H8GEFBuiUb9I-YSt8sbA-KUi76w",
    "use": "sig"
  },
  "inboundports": [
    "443",
    "80"
  ],
  "outboundports": null,
  "ips": [
    "65.0.34.190"
  ]
}
```

{% endcode %}
{% endtab %}
{% endtabs %}


# Overview


# Create FIU Entity

Sahamati have created sandbox UAT portal where you can create an FIU entity and get the central registry API credentials.

Steps to create FIU Entity in central registry to get the API credentials.

1. Open [https://aacommons.sahamati.org.in](https://aacommons.sahamati.org.in/) and create an account.
2. After login Create New -> FIU
3. **Entity Info Name =** Your Company Name Eg: Acme Bank
4. **Entity Info Id =** Your unique entity id Eg: acme-bank-fiu
5. **Entity Info Code =** Code issued by the regulator Eg: acme-bank-fiu **Note: You can use same as Entity Info Id**
6. **Certificate =** Public Key that is shared with other entities to verify your API calls. Ref [How to create Certificate](/fiu-module/jws-signature)
7. **Base URL =** Your FIU Module's base url Eg: `v2:https://fiu.matrixbank.com/api/v2`
8. Get the client id and client secret after creating the FIU entity and share it with your developer.

Share the created FIU entity id with Saafe to get access to the AA Sandbox.


# IAM User Endpoints


# Generate IAM User Token

### Environment

<table><thead><tr><th width="218">Environment</th><th>IAM Base URL</th></tr></thead><tbody><tr><td>Saafe Hackathon</td><td><code>https://api.sandbox.sahamati.org.in/iam</code></td></tr><tr><td>Saafe Sandbox</td><td><code>https://api.uat.sahamati.org.in/iam</code></td></tr></tbody></table>

### API Request

<mark style="color:green;">`POST`</mark> `{{IAM Base URL}}/v1/user/token/generate`

User Token is used to access the IAM user APIs

**Headers**

| Name         | Value                               |
| ------------ | ----------------------------------- |
| Content-Type | `application/x-www-form-urlencoded` |

**Body**

| Key      | Value  | Description        |
| -------- | ------ | ------------------ |
| username | string | IAM admin username |
| password | string | IAM admin password |

**Response**

{% tabs %}
{% tab title="200" %}
{% code overflow="wrap" %}

```json
{
    "ver": "1.0.0",
    "timestamp": "2024-10-10T10:33:56.177646614Z",
    "txnId": "a3229d47-c50c-4ce5-8aa2-9325dcdfe1b8",
    "accessToken": "JWT TOKEN",
    "expiresIn": 86400,
    "refreshExpiresIn": 0,
    "tokenType": "Bearer",
    "notBeforePolicy": 0,
    "scope": "email secret-expiry-ts profile entityMetadata"
}
```

{% endcode %}
{% endtab %}
{% endtabs %}


# Secret Management


# Entity Secret Read

### Environment

<table><thead><tr><th width="218">Environment</th><th>IAM Base URL</th></tr></thead><tbody><tr><td>Saafe Hackathon</td><td><code>https://api.sandbox.sahamati.org.in/iam</code></td></tr><tr><td>Saafe Sandbox</td><td><code>https://api.uat.sahamati.org.in/iam</code></td></tr></tbody></table>

### API Request

<mark style="color:green;">`POST`</mark> `{{IAM Base URL}}/v1/entity/secret/read`

Lets the FIU fetch the entity id's secret key.

**Headers**

| Name          | Value                     |
| ------------- | ------------------------- |
| Content-Type  | `application/json`        |
| Authorization | `Bearer <IAM User Token>` |

**Body**

```json
{
    "ver": "1.0.0",
    "timestamp": "2024-10-10T10:48:45.030353256Z", //Current timestamp
    "txnId": "79ecd03d-867a-491d-8f5d-ec521a31c159", //unique UUID
    "entityId": "your entity id" //Entity ID under the user
}
```

**Response**

{% tabs %}
{% tab title="200" %}

```json
{
    "ver": "1.0.0",
    "timestamp": "2024-10-10T10:48:45.030353256Z",
    "txnId": "79ecd03d-867a-491d-8f5d-ec521a31c159",
    "entityId": "your entity id",
    "secret": "string", //Your Entity ID's secret key
    "expiresOn": 1733226041466
}
```

{% endtab %}
{% endtabs %}


# Entity Secret Reset

### Environment

<table><thead><tr><th width="218">Environment</th><th>IAM Base URL</th></tr></thead><tbody><tr><td>Saafe Hackathon</td><td><code>https://api.sandbox.sahamati.org.in/iam</code></td></tr><tr><td>Saafe Sandbox</td><td><code>https://api.uat.sahamati.org.in/iam</code></td></tr></tbody></table>

### API Request

<mark style="color:green;">`POST`</mark> `{{IAM Base URL}}/v1/entity/secret/reset`

Lets the FIU reset the entity id's secret on a specific interval.&#x20;

Note:&#x20;

1. If you fail to reset the secret before the expiry token generation will fail
2. Old Secret will not working immediately after the new secret is generated
3. Token generated using the old token will be still active as long as the token is not expired.

**Headers**

| Name          | Value                     |
| ------------- | ------------------------- |
| Content-Type  | `application/json`        |
| Authorization | `Bearer <IAM User Token>` |

**Body**

```json
{
    "ver": "1.0.0",
    "timestamp": "2024-10-10T10:48:45.030353256Z", //Current timestamp
    "txnId": "79ecd03d-867a-491d-8f5d-ec521a31c159", //unique UUID
    "entityId": "your entity id" //Entity ID under the user
}
```

**Response**

{% tabs %}
{% tab title="200" %}

```json
{
    "ver": "1.0.0",
    "timestamp": "2024-10-10T10:48:45.030353256Z",
    "txnId": "79ecd03d-867a-491d-8f5d-ec521a31c159",
    "entityId": "your entity id",
    "secret": "string", //Your Entity ID's secret key
    "expiresOn": 1733226041466
}
```

{% endtab %}
{% endtabs %}


# Entity Auth Token

### Environment

<table><thead><tr><th width="218">Environment</th><th>IAM Base URL</th></tr></thead><tbody><tr><td>Saafe Hackathon</td><td><code>https://api.sandbox.sahamati.org.in/iam</code></td></tr><tr><td>Saafe Sandbox</td><td><code>https://api.uat.sahamati.org.in/iam</code></td></tr></tbody></table>

### API Request

<mark style="color:green;">`POST`</mark> `{{IAM Base URL}}/v1/entity/token/generate`

User Token is used to access the IAM user APIs

**Headers**

| Name         | Value                               |
| ------------ | ----------------------------------- |
| Content-Type | `application/x-www-form-urlencoded` |

**Body**

| Key    | Value  | Description       |
| ------ | ------ | ----------------- |
| id     | string | FIU Entity ID     |
| secret | string | FIU Entity Secret |

**Response**

{% tabs %}
{% tab title="200" %}
{% code overflow="wrap" %}

```json
{
    "ver": "1.0.0",
    "timestamp": "2024-10-10T11:11:45.096203206Z",
    "txnId": "6dc871b0-cc81-4437-9286-28e317f0afaa",
    "accessToken": "JWT Token",
    "expiresIn": 86400,
    "refreshExpiresIn": 0,
    "tokenType": "Bearer",
    "notBeforePolicy": 0,
    "scope": "email microprofile-jwt profile address phone offline_access"
}
```

{% endcode %}
{% endtab %}
{% endtabs %}


# Entity Auth Token (Deprecated)

Generate Entity Auth Token or client\_api\_key

### Environment

<table><thead><tr><th width="218">Environment</th><th>Token Service (OLD) Base URL</th></tr></thead><tbody><tr><td>Saafe Hackathon</td><td><code>https://tokens.sandbox.sahamati.org.in</code></td></tr><tr><td>Saafe Sandbox</td><td><code>https://uattokens.sahamati.org.in</code></td></tr></tbody></table>

### API Request

<mark style="color:green;">`POST`</mark> `{{Token Service Base URL}}/auth/realms/sahamati/protocol/openid-connect/token`

#### Request <a href="#request" id="request"></a>

**Authorization Basic Auth**

<table data-header-hidden><thead><tr><th width="254"></th><th></th></tr></thead><tbody><tr><td>Username</td><td>client id - Obtained in <a href="/pages/P8RZNuk6Kz2oSMi8iHkN">Create FIU Entity</a></td></tr><tr><td>Password</td><td>client secret - Obtained in <a href="/pages/P8RZNuk6Kz2oSMi8iHkN">Create FIU Entity</a></td></tr></tbody></table>

**Body**

| **Key**     | **Value**           |
| ----------- | ------------------- |
| grant\_type | client\_credentials |
| scope       | openid              |

#### Response <a href="#response" id="response"></a>

```json
{
    "access_token": "string",
    "expires_in": 86400,
    "refresh_expires_in": 0,
    "token_type": "Bearer",
    "id_token": "string",
    "not-before-policy": 0,
    "scope": "openid email microprofile-jwt profile address phone offline_access"
}
```

**Note:** **access\_token** in the above response needs to be used as **client\_api\_key** in the header of the API calls made to the AA


# Central Registry APIs

You would need to access CR APIs to get list of AAs and FIPs. The API document can be found here in this [AA Commons Documentation](< https://sahamati.gitbook.io/aa-common-service/central-registry/cr-api-details>)

You can download the [postman collection here](https://drive.google.com/drive/folders/1NmtiaL-Dv5fsEzGR79iWXr5Tlt__U6YZ?usp=sharing).

### Collection Variables Values for UAT

| Variable          | Value                                                                                   |
| ----------------- | --------------------------------------------------------------------------------------- |
| CR\_API           | <https://uatcr.sahamati.org.in/v2>                                                      |
| auth.token-url    | <https://uattokens.sahamati.org.in/auth/realms/sahamati/protocol/openid-connect/token>  |
| auth.clientId     | Client ID obtained after [creating FIU entity](/central-registry/create-fiu-entity)     |
| auth.clientSecret | Client secret obtained after [creating FIU entity](/central-registry/create-fiu-entity) |

<https://uattokens.sahamati.org.in/auth/realms/sahamati/protocol/openid-connect/token>


# GET AA List

### Environment

<table><thead><tr><th width="218">Environment</th><th>CR API BASE URL</th></tr></thead><tbody><tr><td>Saafe Hackathon</td><td><code>https://api.sandbox.sahamati.org.in/cr</code></td></tr><tr><td>Saafe Sandbox</td><td><code>https://uatcr.sahamati.org.in</code></td></tr></tbody></table>

### API Request

<mark style="color:green;">`POST`</mark> `{{CR API BASE URL}}/v2/entityInfo/AA`

Gets the list of AAs registered in the central registry

**Headers**

| Name          | Value                        |
| ------------- | ---------------------------- |
| Content-Type  | `application/json`           |
| Authorization | `Bearer <Entity Auth Token>` |

**Response**

{% tabs %}
{% tab title="200" %}
{% code overflow="wrap" %}

```json
[
  {
    "ver": "1.0",
    "timestamp": "2024-10-04 09:48:13.11",
    "txnid": "ef9cebd9-a11d-411a-9950-94e911cca8ed",
    "requester": {
      "name": "Saafe Sandbox",
      "id": "saafe-sandbox"
    },
    "entityinfo": {
      "name": "Saafe Sandbox",
      "id": "saafe-sandbox",
      "code": "saafe-sandbox",
      "entityhandle": "@saafe-sandbox",
      "Identifiers": [],
      "baseurl": "v2:https://test.saafe.in/api/v2",
      "webviewurl": "https://test.saafe.in/webview",
      "fitypes": [],
      "certificate": {
        "alg": "RS256",
        "e": "AQAB",
        "kid": "8f53656e-9b5d-4afd-8208-86f1859d84e5",
        "kty": "RSA",
        "n": "kZtbglKhedm2VSGpQhHugdrwC-sAcJtHyOCXUHeGc1c9tGLGfwSNZ2qVJu6HyYXhaJ11M2-noNVFKFK1PB-pVJAL53jHDa2rMyGHGebb3I8rs1fXoDA3uc-t0E9P6qDlH_BJs2cNEpGyM1NNEG-rIUF1bWKmo8IaifuGu17S8QVeUJ3a2BvzeugHfxgF0RAhW9JziBpX7H-Do-6prwiOcNipRTME7eXhcZuHgGAmOYkkFmRnBSjt90EmfH_cZKGyCDRu0XuEXZXvcTauDbHIJSe4PGDQCEYMeqFt-9MziJZeWUen6CJMxTHxYudGQSbZgPm0q953Zs-o4I_-pBoeXw",
        "use": "sig"
      },
      "tokeninfo": {
        "url": "",
        "desc": ""
      },
      "gsp": null,
      "signature": {},
      "type": null,
      "tags": null,
      "inboundports": [
        "443",
        "80"
      ],
      "outboundports": null,
      "ips": [
        "3.108.179.208"
      ],
      "credentialsPk": null,
      "oldEntityId": null
    }
  },
  {
    "ver": "1.0",
    "timestamp": "2024-09-20 12:49:08.909",
    "txnid": "29ae-11e8-a8d7-0290",
    "requester": {
      "name": "AA-SIMULATOR",
      "id": "AA-SIMULATOR"
    },
    "entityinfo": {
      "name": "AA-SIMULATOR",
      "id": "AA-SIMULATOR",
      "code": "AA-SIMULATOR",
      "entityhandle": "@AA-SIMULATOR",
      "Identifiers": [
        {
          "category": "STRONG",
          "type": "MOBILE"
        }
      ],
      "baseurl": "v2:https://api.sandbox.sahamati.org.in/simulate/v2/",
      "webviewurl": "",
      "fitypes": [
        "DEPOSIT"
      ],
      "certificate": {
        "alg": "RS256",
        "e": "AQAB",
        "kid": "f676b688-07a2-450b-ddacb5-ss52fcb98dcobs",
        "kty": "RSA",
        "n": "pOFhy12KFAcIwG-vKqkMWCc8oxAbEmB7_sakwxBYN1NudI1mddWdzUhUU38M1B3McDs-actIRDxisNvFMLOwqzQCojQiuao8fh9z8roxEEZx_LR5zG-S6xNbcsMl76FoYpYofKWfNf5Nxnc_FRcS2Yi38XaGXez5Z3JO_NvNtzZtvVjGSRlXUjEBN8q2o4c-o_fA5RVsKX57duOXLWeO6jMzhulrnSEWSv0dTvH1OeJGjtF4csXro0NWa8C9F9MUwP7juH90gmrAKacFkLPaU_uyBZzwu3w14Sa4jru2g7oYVMs0IDZnwYXUw-SgixHAghMpQwKBNwCphHI9QAN0qw",
        "use": "sig"
      },
      "tokeninfo": {
        "url": "null",
        "maxcalls": 1,
        "desc": "string"
      },
      "gsp": null,
      "signature": {
        "signValue": "u2j8DsVyT1azpJC_NG84Ty5KKthuCaPod7iI7w0LK9orSMhBEwwZDCxTWq4aYWAchc8"
      },
      "type": null,
      "tags": null,
      "inboundports": null,
      "outboundports": null,
      "ips": [
        " "
      ],
      "credentialsPk": null,
      "oldEntityId": null
    }
  }
]
```

{% endcode %}
{% endtab %}
{% endtabs %}


# GET FIP List

### Environment

<table><thead><tr><th width="218">Environment</th><th>CR API BASE URL</th></tr></thead><tbody><tr><td>Saafe Hackathon</td><td><code>https://api.sandbox.sahamati.org.in/cr</code></td></tr><tr><td>Saafe Sandbox</td><td><code>https://uatcr.sahamati.org.in</code></td></tr></tbody></table>

### API Request

<mark style="color:green;">`POST`</mark> `{{CR API BASE URL}}/v2/entityInfo/FIP`

Gets the list of FIPs registered in the central registry

**Headers**

| Name          | Value                        |
| ------------- | ---------------------------- |
| Content-Type  | `application/json`           |
| Authorization | `Bearer <Entity Auth Token>` |

**Response**

{% tabs %}
{% tab title="200" %}
{% code overflow="wrap" %}

```json
[
  {
    "ver": "string",
    "timestamp": "string",
    "txnid": "string",
    "requester": {
      "name": "string",
      "id": "string"
    },
    "entityinfo": {
      "name": "string",
      "id": "string",
      "code": "string",
      "Identifiers": [
        {
          "category": "string",
          "type": "string"
        }
      ],
      "baseurl": "string",
      "fitypes": [
        "string"
      ],
      "certificate": {
        "alg": "string",
        "e": "string",
        "kid": "string",
        "kty": "string",
        "n": "string",
        "use": "string"
      },
      "inboundports": [
        "string"
      ],
      "outboundports": [
        "string"
      ],
      "ips": [
        "string"
      ]
    }
  }
]
```

{% endcode %}
{% endtab %}
{% endtabs %}


# GET FIU List

### Environment

<table><thead><tr><th width="218">Environment</th><th>CR API BASE URL</th></tr></thead><tbody><tr><td>Saafe Hackathon</td><td><code>https://api.sandbox.sahamati.org.in/cr</code></td></tr><tr><td>Saafe Sandbox</td><td><code>https://uatcr.sahamati.org.in</code></td></tr></tbody></table>

### API Request

<mark style="color:green;">`POST`</mark> `{{CR API BASE URL}}/v2/entityInfo/FIU`

Gets the list of FIUs registered in the central registry. As an FIU this will only return your own FIU Entity JSON

**Headers**

| Name          | Value                        |
| ------------- | ---------------------------- |
| Content-Type  | `application/json`           |
| Authorization | `Bearer <Entity Auth Token>` |

**Response**

{% tabs %}
{% tab title="200" %}
{% code overflow="wrap" %}

```json
[
  {
    "ver": "string",
    "timestamp": "string",
    "txnid": "string",
    "requester": {
      "name": "string",
      "id": "string"
    },
    "entityinfo": {
      "name": "string",
      "id": "string",
      "code": "string",
      "baseurl": "string",
      "certificate": {
        "alg": "string",
        "e": "string",
        "kid": "string",
        "kty": "string",
        "n": "string",
        "use": "string"
      },
      "inboundports": "string",
      "outboundports": "string",
      "ips": "string"
    }
  }
]
```

{% endcode %}
{% endtab %}
{% endtabs %}


# Introduction

FIU Module manages the interaction between the FIU and the AA.&#x20;

API Integration - Flow Diagram

<figure><img src="/files/VGA6dcebYE9RXal8qf6j" alt=""><figcaption></figcaption></figure>


# AA API v2.0.0

AA Endpoints are the list of endpoints that you will be calling from your FIU system to create consent and fetch data from AA.

Please refer the FIU API Spec (2.0.0) <https://api.rebit.org.in/spec/aa> in the ReBIT to implement the responses for different cases. The APIs below only has success response.

### Create JWS and Sign API Request

The API calls to AA ReBIT api's should have **x-jws-signature** in the header which is a detached JWS of the body.

[Here ](/fiu-module/jws-signature)you can find how to create JWS keys for creating the **x-jws-signature** and refer [AA Commons Documentation](https://sahamati.gitbook.io/aa-common-service/token-service/access-token-logistics) for how to sign the request that you send to AA and verify the request that you receive from AA.

### Consent Creation

You need to raise a consent to Saafe using /Consent API

<mark style="color:green;">`POST`</mark> `https://sandbox.saafe.in/api/v2/Consent`

#### Request

Header

<table><thead><tr><th width="193">Key</th><th width="556.3333333333333">Value</th></tr></thead><tbody><tr><td>x-jws-signature</td><td>string</td></tr><tr><td>client_api_key</td><td>string</td></tr></tbody></table>

Body

```json
{
    "ver": "2.0.0",
    "timestamp": "2024-05-09T15:23:55.384Z",
    "txnid": "644d2aff-e43b-4bb9-9047-498cbb9896d2",
    "ConsentDetail": {
        "consentStart": "2024-05-09T15:23:55.384Z",
        "consentExpiry": "2025-01-01T00:00:00.000Z",
        "consentMode": "STORE",
        "fetchType": "PERIODIC",
        "consentTypes": [
            "PROFILE",
            "TRANSACTIONS",
            "SUMMARY"
        ],
        "fiTypes": [
            "DEPOSIT"
        ],
        "DataConsumer": {
            "id": "central-trust-uat", // Your FIU Entity ID
            "type": "FIU"
        },
        "Customer": {
            "Identifiers": [
                {
                    "type": "MOBILE",
                    "value": "9944612241" //Customer Phone Number
                }
            ]
        },
        "Purpose": {
            "code": "101",
            "refUri": "https://api.rebit.org.in/aa/purpose/101.xml",
            "text": "To provide your asset insights",
            "Category": {
                "type": "Personal Finance"
            }
        },
        "FIDataRange": {
            "from": "2023-01-01T00:00:00.000Z",
            "to": "2025-01-01T00:00:00.000Z"
        },
        "DataLife": {
            "unit": "YEAR",
            "value": 3
        },
        "Frequency": {
            "unit": "DAY",
            "value": 10
        }
    }
}
```

#### Response 200

```json
{
    "ver": "2.0.0",
    "timestamp": "2024-05-09T15:40:00.669Z",
    "txnid": "019fe3f7-edd6-45ac-9f29-24fad3e504ca",
    "Customer": {
        "id": "9944612241@dashboard-aa-preprod"
    },
    "ConsentHandle": "465d1f35-f716-484f-a38e-30797d97b525"
}
```

### Consent Handle Status

<mark style="color:green;">`POST`</mark> `https://sandbox.saafe.in/api/v2/Consent/handle`

#### Request

Header

<table><thead><tr><th width="193">Key</th><th width="556.3333333333333">Value</th></tr></thead><tbody><tr><td>x-jws-signature</td><td>string</td></tr><tr><td>client_api_key</td><td>string</td></tr></tbody></table>

Body

```json
{
    "ver": "2.0.0",
    "timestamp": "2024-05-09T15:41:49.974Z",
    "txnid": "e188d16d-cbb9-4898-ab3b-ab6b57195e8b",
    "ConsentHandle": "465d1f35-f716-484f-a38e-30797d97b525"
}
```

#### Response 200

```json
{
    "ver": "2.0.0",
    "timestamp": "2024-05-09T15:41:53.171Z",
    "txnid": "e188d16d-cbb9-4898-ab3b-ab6b57195e8b",
    "ConsentHandle": "465d1f35-f716-484f-a38e-30797d97b525",
    "ConsentStatus": {
        "id": "5278f924-2d15-4726-a974-2465cbf48d5c",
        "status": "APPROVED"
    }
}
```

### Consent Fetch

<mark style="color:green;">`POST`</mark> `https://sandbox.saafe.in/api/v2/Consent/fetch`

signedConsent is the Consent artefact signed using JWS which contains the list of Accounts that the user have approved the consent for.

#### Request

Header

<table><thead><tr><th width="193">Key</th><th width="556.3333333333333">Value</th></tr></thead><tbody><tr><td>x-jws-signature</td><td>string</td></tr><tr><td>client_api_key</td><td>string</td></tr></tbody></table>

Body

```json
{
    "ver": "2.0.0",
    "timestamp": "2024-05-09T15:44:59.012Z",
    "txnid": "fdc66dda-03e3-4df1-b8a2-22744a21180f",
    "consentId": "5278f924-2d15-4726-a974-2465cbf48d5c"
}
```

#### Response 200

{% code overflow="wrap" %}

```json
{
    "ver": "2.0.0",
    "txnid": "fdc66dda-03e3-4df1-b8a2-22744a21180f",
    "consentId": "5278f924-2d15-4726-a974-2465cbf48d5c",
    "status": "ACTIVE",
    "createTimestamp": "2024-05-09T15:45:02.284Z",
    "signedConsent": "eyJhbGciOiJSUzI1NiIsImtpZCI6ImI1YTE0NjhiLTFiZDQtNGJlNi1iNTA1LWJmMmM4ZDRkZjA1NiIsImI2NCI6dHJ1ZSwiY3JpdCI6WyJiNjQiXX0.eyJjb25zZW50U3RhcnQiOiIyMDI0LTA1LTA5VDE1OjM5OjU2Ljk4M1oiLCJjb25zZW50RXhwaXJ5IjoiMjAyNS0wMS0wMVQwMDowMDowMC4wMDBaIiwiY29uc2VudE1vZGUiOiJTVE9SRSIsImZldGNoVHlwZSI6IlBFUklPRElDIiwiY29uc2VudFR5cGVzIjpbIlBST0ZJTEUiLCJUUkFOU0FDVElPTlMiLCJTVU1NQVJZIl0sImZpVHlwZXMiOlsiREVQT1NJVCJdLCJEYXRhQ29uc3VtZXIiOnsiaWQiOiJjZW50cmFsLXRydXN0LXVhdCIsInR5cGUiOiJGSVUifSwiQ3VzdG9tZXIiOnsiaWQiOiI5OTQ0NjEyMjQxQGRhc2hib2FyZC1hYS1wcmVwcm9kIn0sIlB1cnBvc2UiOnsiY29kZSI6IjEwMSIsInJlZlVyaSI6Imh0dHBzOi8vYXBpLnJlYml0Lm9yZy5pbi9hYS9wdXJwb3NlLzEwMS54bWwiLCJ0ZXh0IjoiVG8gcHJvdmlkZSB5b3VyIGFzc2V0IGluc2lnaHRzIiwiQ2F0ZWdvcnkiOnsidHlwZSI6IlBlcnNvbmFsIEZpbmFuY2UifX0sIkZJRGF0YVJhbmdlIjp7ImZyb20iOiIyMDIzLTAxLTAxVDAwOjAwOjAwLjAwMFoiLCJ0byI6IjIwMjUtMDEtMDFUMDA6MDA6MDAuMDAwWiJ9LCJEYXRhTGlmZSI6eyJ1bml0IjoiWUVBUiIsInZhbHVlIjozfSwiRnJlcXVlbmN5Ijp7InVuaXQiOiJEQVkiLCJ2YWx1ZSI6MTB9LCJEYXRhRmlsdGVyIjpudWxsLCJEYXRhUHJvdmlkZXIiOnsiaWQiOiJkYXNoYm9hcmQtYWEtcHJlcHJvZCIsInR5cGUiOiJBQSJ9LCJBY2NvdW50cyI6W3siZmlUeXBlIjoiREVQT1NJVCIsImZpcElkIjoiZGhhbmFnYXJiYW5rIiwiYWNjVHlwZSI6IlNBVklOR1MiLCJsaW5rUmVmTnVtYmVyIjoiODI2OTc1YWEtZWJkMS00OTk0LWE3MDAtYTYyNTM1Mjk3NzBmIiwibWFza2VkQWNjTnVtYmVyIjoiWFhYWFgwMTQyIn1dfQ.GTx9lqyavTIDSUVWcua_37D7SxTEASa688YnQYcg61bWSIc_teQGw-Te9APy63EtvA7Hc27B-gtTWIN2zFfexAKVNoF7tKL7E118IScc6F7ToPlPxNFALliRCxnAKKljYhYoIuAYuUcZDiER3okssjk4S_YMVjuLIeexzy84pVH2Y_OZwCJVXiE-mK87lcnv1M5Q1S3WCX1OxU_M5QsfKVnPmjTg9JfvIHO8rLSYS7zRXy-A5fiOEdQKAhM1KOhnMF653fWuMTqL2FoAgenUdnodZgNyFkwcuuCv--7e6tghFUEK2G1tbVHKxJK_X1aIJ2STGXIgS9oLpvOyuFxgNw",
    "ConsentUse": {
        "logUri": "https://uat.saafe.in/",
        "count": 0,
        "lastUseDateTime": "2024-05-09T15:40:45.707Z"
    }
}
```

{% endcode %}

### Data Request

<mark style="color:green;">`POST`</mark> `https://sandbox.saafe.in/api/v2/FI/request`

**digitalSignature** is the signature part of the **signedConsent** which needs to sent to the AA to make the FI Request.

**KeyMaterial** Contains the cryptographic parameters that are required to perform End-to-End encryption for sharing the financial information between the producer and the consumer in a secure manner. Ref [End-to-end Encryption](/fiu-module/end-to-end-encryption) on implementing the ECDH

#### Request

Header

<table><thead><tr><th width="193">Key</th><th width="556.3333333333333">Value</th></tr></thead><tbody><tr><td>x-jws-signature</td><td>string</td></tr><tr><td>client_api_key</td><td>string</td></tr></tbody></table>

Body

{% code overflow="wrap" %}

```json
{
    "ver": "2.0.0",
    "timestamp": "2024-05-09T18:29:21.158Z",
    "txnid": "c5e74a42-36c4-4f7b-b85d-4e59871a3f5e",
    "FIDataRange": {
        "from": "2024-05-05T00:00:00.000Z",
        "to": "2024-05-07T00:00:00.000Z"
    },
    "Consent": {
        "id": "5278f924-2d15-4726-a974-2465cbf48d5c",
        "digitalSignature": "GTx9lqyavTIDSUVWcua_37D7SxTEASa688YnQYcg61bWSIc_teQGw-Te9APy63EtvA7Hc27B-gtTWIN2zFfexAKVNoF7tKL7E118IScc6F7ToPlPxNFALliRCxnAKKljYhYoIuAYuUcZDiER3okssjk4S_YMVjuLIeexzy84pVH2Y_OZwCJVXiE-mK87lcnv1M5Q1S3WCX1OxU_M5QsfKVnPmjTg9JfvIHO8rLSYS7zRXy-A5fiOEdQKAhM1KOhnMF653fWuMTqL2FoAgenUdnodZgNyFkwcuuCv--7e6tghFUEK2G1tbVHKxJK_X1aIJ2STGXIgS9oLpvOyuFxgNw"
    },
    "KeyMaterial": {
        "cryptoAlg": "ECDH",
        "curve": "Curve25519",
        "params": "",
        "DHPublicKey": {
            "expiry": "2024-05-10T18:26:49.031Z",
            "Parameters": "",
            "KeyValue": "-----BEGIN PUBLIC KEY-----MIIBMTCB6gYHKoZIzj0CATCB3gIBATArBgcqhkjOPQEBAiB/////////////////////////////////////////7TBEBCAqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqYSRShRAQge0Je0Je0Je0Je0Je0Je0Je0Je0Je0Je0JgtenHcQyGQEQQQqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqq0kWiCuGaG4oIa04B7dLHdI0UySPU1+bXxhsinpxaJ+ztPZAiAQAAAAAAAAAAAAAAAAAAAAFN753qL3nNZYEmMaXPXT7QIBCANCAARrS/CNE3TmgabxB9KupD1FN4L4weI7cqx+zjkqZcJEfDY22ar/e8t9tYWKcH1T0Q23h0adHoiIKipIZr2O5j3r-----END PUBLIC KEY-----"
        },
        "Nonce": "JRsHMYjdy8qENzydIf3iYFks+XgaZeckzsVjl9n1Xxs="
    }
}
```

{% endcode %}

#### Response 200

```json
{
    "ver": "2.0.0",
    "timestamp": "2024-05-09T18:29:24.478Z",
    "txnid": "c5e74a42-36c4-4f7b-b85d-4e59871a3f5e",
    "consentId": "5278f924-2d15-4726-a974-2465cbf48d5c",
    "sessionId": "8c582ed7-b114-4b66-adb3-81e6bd430708"
}
```

### Data Fetch

<mark style="color:green;">`POST`</mark> `https://sandbox.saafe.in/api/v2/FI/fetch`

#### Request

Header

<table><thead><tr><th width="193">Key</th><th width="556.3333333333333">Value</th></tr></thead><tbody><tr><td>x-jws-signature</td><td>string</td></tr><tr><td>client_api_key</td><td>string</td></tr></tbody></table>

Body

```json
{
    "ver": "2.0.0",
    "timestamp": "2024-05-09T15:44:59.012Z",
    "txnid": "3dd436f8-0747-4a8f-9001-375e419430be",
    "sessionId": "8c582ed7-b114-4b66-adb3-81e6bd430708",
    "fipId": "FIP-1",
    "linkRefNumber": [
        {
            "id": "XXXX-XXXX-XXXX"
        }
    ]
}
```

#### Response 200

{% code overflow="wrap" %}

```json
{
    "ver": "2.0.0",
    "timestamp": "2024-05-09T20:13:05.687Z",
    "txnid": "c5e74a42-36c4-4f7b-b85d-4e59871a3f5e",
    "FI": [
        {
            "fipID": "dhanagarbank",
            "data": [
                {
                    "linkRefNumber": "826975aa-ebd1-4994-a700-a6253529770f",
                    "maskedAccNumber": "XXXXX0142",
                    "encryptedFI": "tb5RzcVSgfJHEEv5MKEknFG676iQJq9k4EchUhdu4/WM2K1C5S68KmPVz3lR3NaqwWGdZfJ5HcHVZARW/apOeyTEbVE+KKC1XVmjLZlwAOVE7bHizF77kiGj7T/mL4nSgWZIHSYEVnDNru7wd2Tk0xCQtmKEqLq2yNhAV6fT06YO8DOqwxcE96bEQDqHxeqGtkXSTOUQbXgWGMWxds/Pc4+wsRzhw7Qb7/wI7oEtMY1ccvGrMTUQy1ufjdsIN+iY+oi63QWr/wKY5hOzA7PJmEaULLM7HGeKa2rUhP8zH9Xge7QpiOF09AJm+cVgyLwb443bxSln+eu1gIWvEHkGb1Sx4kKrB1LxEc+Lr3IUANZMLSFGz/rL8a6vTjVQBKrIN9O/wmPb0wKYMQzdl+pPYNxtVtYVG0tT+FpgN8ktGRxxn69vRHTDG8biQjtKb6ZH00R+z4WLMdFKVcd8YAIRELy1JbgXHP7TaNYfTI0YDeh6vajBMgvgsegmOMi/iU+a5KsNOR+TZLpvl5UGAQaZt5aiSYkvMziWj57ziRx8EBLgM4QymT9bLTSSJ29S/hqTjueeiTrT3jV3jmgqhA6tnuQbHZBPyWWyK59A45jB926pE8WU8VYqotpq3B3QVCU6dFA7kWofCyoeIEm16Ez2QpPwfZkuR+9DLFLytYj8RUAw3PH5nhVqXXymAJoQ6WxbksofQXQbbFP81JIDDGc0u6jBU9LrsUwLexZvaZ7A9TGLdoMY42cjupATeN3aPygqOeXl1i1PxJ5RO/ar9DiPXirZoseztwgEJyZY02yO+k6EDhx+Wsc49HgOw5xY/SEW0dt4UrBecQkZO/0pBbhonQT07p4XUVbIGCM7unbOh8OQatBgcwxpTpN7sDsVTq9/nXH2YuGL94D4NvqS9eZHZKQ9fr92P+QVCecgS4a1sKVsHo2wqNs70D0am00tCmtvM4v1zcvVPGPVM5rXXulhT49XlOZJ9cPLfOpiuwasix2OBCduABy19D/VoftsJpZkWjbxl1/rIHisLNMbD7ZUfO/Sm79g0txx4MqS+GQDnQNlzEJjUL9tGiZEQFyGX190ZGi+JQXWDx1HYc4I2Q6MS3ULDU5B5n2QDNXydhNXugx6xebZLhUBMQky87CyUe5LYZDSZZr56t3UdYfoVih0OaJvK/p1XnVz5qkvlXIRJdEJYc8/Cd2Na9rXg8mAeQbBa1q9o1lvR3VoWQPfIuFf9WRIq7as68E6RVbIvE3KYnJGZYDigkpAbmPNxRaH4svX48HYKYWZpRAXg6i/00MDCZlGstlspWCSkUPiEhw+RHCHG5cMHrDxGzAlBBav4eiVcTJB0HPskmuhI208E3q9PG45iLu9exaoyiOtEfsrkMjOlkJtFyOPnRIFJIUAIuRD7s9fDrLA4z5QosBD+8R3++XO1Cvb0MmjYy6Muhkj794tVoOGoh3MGGTcyHh+WJUWlwBdyRPRFfIY"
                }
            ],
            "KeyMaterial": {
                "cryptoAlg": "ECDH",
                "curve": "Curve25519",
                "params": "None",
                "DHPublicKey": {
                    "expiry": "2024-05-10T18:29:24.838Z",
                    "Parameters": "None",
                    "KeyValue": "-----BEGIN PUBLIC KEY-----MIIBMTCB6gYHKoZIzj0CATCB3gIBATArBgcqhkjOPQEBAiB/////////////////////////////////////////7TBEBCAqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqYSRShRAQge0Je0Je0Je0Je0Je0Je0Je0Je0Je0Je0JgtenHcQyGQEQQQqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqq0kWiCuGaG4oIa04B7dLHdI0UySPU1+bXxhsinpxaJ+ztPZAiAQAAAAAAAAAAAAAAAAAAAAFN753qL3nNZYEmMaXPXT7QIBCANCAAQhZyUnHx0W3GtbtP0j+c9vVr5+LJIqm7usd8eS8COqm2hd/PSnqe0kqKrXOY3UrfaGgBfgpK6CW/TwrtFODV7R-----END PUBLIC KEY-----"
                },
                "Nonce": "fQOZ2qAptqq8kR0AVQ2d31PCs80V5JXxiHztW9UjBV0="
            }
        }
    ]
}
```

{% endcode %}


# FIU API v2.0.0

FIU Endpoints are the list of endpoints that you will need to implement on your system to receive Consent and FI notifications from AA.

Please refer the FIU API Spec (2.0.0) <https://api.rebit.org.in/spec/fiu> in the ReBIT to implement the responses for different cases. The APIs below only has success response.

### API signature verification

You need to verify the API calls that you receive from the AA. Use Saafe's public key available in the Central Registry to verify the API request that Saafe made to your FIU endpoints.&#x20;

You can refer [AA Commons Documentation](https://sahamati.gitbook.io/aa-common-service/token-service/access-token-logistics) for how to verify the request that you receive from AA.

### Consent Notification

POST {your-base-url}/Consent/Notification

#### Request

Header

<table><thead><tr><th width="193">Key</th><th width="556.3333333333333">Value</th></tr></thead><tbody><tr><td>x-jws-signature</td><td>string</td></tr><tr><td>aa_api_key</td><td>string</td></tr></tbody></table>

Body

```json
{
    "ver": "2.0.0",
    "timestamp": "2024-05-09T15:40:45.717Z",
    "txnid": "019fe3f7-edd6-45ac-9f29-24fad3e504ca",
    "Notifier": {
        "type": "AA",
        "id": "dashboard-aa-preprod"
    },
    "ConsentStatusNotification": {
        "consentId": "5278f924-2d15-4726-a974-2465cbf48d5c",
        "consentHandle": "465d1f35-f716-484f-a38e-30797d97b525",
        "consentStatus": "ACTIVE"
    }
}
```

#### Response 200

Header

<table><thead><tr><th width="193">Key</th><th width="556.3333333333333">Value</th></tr></thead><tbody><tr><td>x-jws-signature</td><td>string</td></tr></tbody></table>

Body

<pre class="language-json"><code class="lang-json"><strong>{
</strong>    "ver": "2.0.0",
    "timestamp": "2024-05-09T15:40:45.717Z",
    "txnid": "019fe3f7-edd6-45ac-9f29-24fad3e504ca",
    "response": "OK"
}
</code></pre>

### FI Notification

POST {your-base-url}/FI/Notification

#### Request

Header

<table><thead><tr><th width="193">Key</th><th width="556.3333333333333">Value</th></tr></thead><tbody><tr><td>x-jws-signature</td><td>string</td></tr><tr><td>aa_api_key</td><td>string</td></tr></tbody></table>

Body

```json
{
    "ver": "2.0.0",
    "timestamp": "2024-05-09T18:29:24.909Z",
    "txnid": "e2086003-a792-40f9-b80a-912985626292",
    "Notifier": {
        "type": "AA",
        "id": "dashboard-aa-preprod"
    },
    "FIStatusNotification": {
        "sessionId": "8c582ed7-b114-4b66-adb3-81e6bd430708",
        "sessionStatus": "COMPLETED",
        "FIStatusResponse": [
            {
                "fipID": "dhanagarbank",
                "Accounts": [
                    {
                        "linkRefNumber": "826975aa-ebd1-4994-a700-a6253529770f",
                        "FIStatus": "READY",
                        "description": "Data is ready"
                    }
                ]
            }
        ]
    }
}
```

#### Response 200

Header

<table><thead><tr><th width="193">Key</th><th width="556.3333333333333">Value</th></tr></thead><tbody><tr><td>x-jws-signature</td><td>string</td></tr></tbody></table>

Body

```json
{
    "ver": "2.0.0",
    "timestamp": "2024-05-09T18:29:24.909Z",
    "txnid": "e2086003-a792-40f9-b80a-912985626292",
    "response": "OK"
}
```


# JWS Signature


# Create JSON Web Key (JWK)

To create JSON Web Signature (JWS) you need to create the signing certificate public and private key and then share public key with the AA.&#x20;

You need to give the public key in the Certificate field when creating your FIU entity at the central registry aacommons portal. Refer - [Create FIU Entity](/central-registry/create-fiu-entity)

Steps to create the signature keys.

1. Open <https://mkjwk.org/> - This is an online JSON Web Key generator
2. Use RSA (encryption algorithm)
3. Key Size = 2048
4. Key Use = Signature
5. Algorithm = RS256
6. Key ID = Unique UUID (Use [online UUID Generator](https://www.uuidgenerator.net/) to create an UUID)
7. Click generate to create the Public and Private Key

You will get 3 JSON objects.

<table><thead><tr><th width="278">Values</th><th>Description</th></tr></thead><tbody><tr><td><mark style="color:red;">Public and Private Keypair</mark></td><td>Keep this <mark style="color:red;">confidential</mark> and share this with your developer.</td></tr><tr><td><mark style="color:red;">Public and Private Keypair Set</mark></td><td>Keep this <mark style="color:red;">confidential</mark> and share this with your developer.</td></tr><tr><td><mark style="color:green;">Public Key</mark></td><td>Use this public key in the Certificate field when <a href="/pages/P8RZNuk6Kz2oSMi8iHkN">creating the FIU entity</a></td></tr></tbody></table>


# Create JWS

### Code Samples

```go
package main

import (
	"encoding/json"
	"fmt"
	"time"

	"github.com/google/uuid"
	"github.com/lestrrat-go/jwx/v2/jwa"
	"github.com/lestrrat-go/jwx/v2/jwk"
	"github.com/lestrrat-go/jwx/v2/jws"
)

type Data struct {
	Ver           string `json:"ver"`
	Timestamp     string `json:"timestamp"`
	TxnId         string `json:"txnid"`
	ConsentHandle string `json:"ConsentHandle"`
}

func main() {

	data := Data{
		Ver:           "2.0.0",
		Timestamp:     time.Now().UTC().Format("2006-01-02T15:04:05.999Z"),
		TxnId:         uuid.New().String(),
		ConsentHandle: "465d1f35-f716-484f-a38e-30797d97b525",
	}
	// Convert struct to JSON string
	jsonData, err := json.Marshal(data)
	if err != nil {
		fmt.Println("Error: ", err)
		return
	}

	// Print the JSON data
	fmt.Println("Payload: ")
	fmt.Println(string(jsonData))

	const privateKeyJson = `{
		"p": "4xjtcjnYMkkX97rViwxE9ZfhegRLVCQ7begAE_tBZe6-imKCSdQlw5Hasv5XPjY_SvEwkF0PD5oK-VIPRm40qjFSvSKjpz4myJabfbMwZQYhvsxOcPRqVRolCDW_OIQ7lXVjDEvl_4GmwRyp_sWaAUKaVIoyWLas2QvXZ8q4Yz0",
		"kty": "RSA",
		"q": "rtTjLo-H9nuOWEbl403YTf34acVOAyhNXDMgkim2v0TpMDWOCgEJOFuGH2ILEVRY1Rrcep7ups4wiqDXP7aN8icA96okOhSUlMFPvropk9uabPdPJvM9jh6VE2SP1VEAMf4BeDwq_dE_FyKWxGLZrRbN4joJheY75YYYyWELMDU",
		"d": "FR73dPuWZgcvu57y8fHCaKQ142SCxvLxvC9mAsN4ztxWxCd7jjvqzJN7QUweEeqLHeQeTLcI7YcGL6cpUMGjA07XNSFjCKZyHtkeyCDNMvL91GVGluYxmIF66qu2f7EXqSsVElwlAHYUIs29b_H95Qpa53PiSMl97jfzQsG7W9X24KJM_NshPEmKvou0BWNmSFxNs66C-pq5i6Up224OY5a9bGXrRw5Vkv6QR7SwPhj0EFNkonMt1TK9vU4P5KLQ-82sEOqkTKtKYC86egj7gZKguqzhUkfw_kfghu-dGvnYeQ6h_7HQUvVsYRQJOutFrEuNvGay44SgDf1X0nZRcQ",
		"e": "AQAB",
		"use": "sig",
		"kid": "57ea893e-7e1c-4383-b013-f6c96e3bf776",
		"qi": "e3D3bnlVAPdqvg85eDh4Tp9VwM2VQjHSN_BLDl_8tm8Xbe68VzEpqBm_AEfA7OwlFuFWOGsQwCXO89kYJ6eF61jE_72zXRdrzseUM80c_nKIyx-ZlbijpTRp9VUnClMg4JcyZT4eWKkNurMFsf9vTWI4yayZqkJHc9J39B2MqLk",
		"dp": "sVO3pWfxn2Jf6rrjIA5WkockM0jDIVKhbTKpTPD2ogeIlTpSjh-v1URAx1--8_8b8QLgbvmbVw1r4D7pWo-XZAXbm4A-1cq8MgkYJVEUSu48z2VtItpXZVhi7kQ5qoHmnM_qpaFmWNr-QPCG9T-K_8zoAXdf1NHfqiOK8arjy-k",
		"alg": "RS256",
		"dq": "TS_EFRxdRJ8MG0FB4XbO1rAX6mqnpJE4hko0SRONkShVY2lhil0muvD9aAGbLU114q_3Q1PDvXUuzSVxorlwNcaukKlXUSUg7APktyntjU_Y_9633VRqisJJwsQVFHKsiWXBNFosCN9G4Wnt8kpKHDcDMqu45JrfOthXPSFRFTk",
		"n": "mxfLkK5DVngBOlVDdeFu_OQp3dIcfvHvoB1vU0DXTsTfZqpQa5ry9pI5N5lo5XxB_AUNw2bDPGCZBF6u6NKHsy50DXDfyh4VFz2SoxUQJELphfRwrHeugGsHuF3iyHxaXERyFjxjmzy9c3KKPszo_yzjVvZTfPesdyXRjZTXg-bqNIZbD8SrNDF8U0Nvh9kLlp0cfopbxuO4azts0rs3Z9WJZ-KnccFnEcgPvPkvLicsnlIyl3qUbZWFuoDKFgmItvGiOtwNBFtcwTRegrvbER-9bXByDB67KDryzzvdsLfRvs31snvdXSjF4BfXAXTuccQPLprKoHO0HkTq62b7oQ"
	}`
	privateKey, err := jwk.ParseKey([]byte(privateKeyJson))
	if err != nil {
		fmt.Printf("failed parse key: %sn", err)
		return
	}
	headers := jws.NewHeaders()
	headers.Set("b64", false)
	headers.Set("crit", []string{"b64"})

	serialized, err := jws.Sign(nil,
		jws.WithKey(jwa.RS256,
			privateKey,
			jws.WithProtectedHeaders(headers),
		),
		jws.WithDetachedPayload([]byte(jsonData)),
	)
	if err != nil {
		fmt.Printf("failed to sign payload: %sn", err)
		return
	}
	fmt.Println("Detached JWS Signature:")
	fmt.Println(string(serialized))
}
```

{% code title="Java" overflow="wrap" lineNumbers="true" %}

```java
public String signJws(String payload) throws JoseException {

  payload = signature Creation using the payload;

  Key = Public and Private Keypair Set

  JsonWebKeySet rsaJsonWebKeySet = new JsonWebKeySet(key);

  // Create a new JsonWebSignature object for the signing

  JsonWebSignature signerJws = new JsonWebSignature();

  // The content is the payload of the JWS
  signerJws.setPayload(payload);

  // Set the signature algorithm on the JWS
  signerJws.setAlgorithmHeaderValue(AlgorithmIdentifiers.RSA_USING_SHA256);

  RsaJsonWebKey jwk = (RsaJsonWebKey)rsaJsonWebKeySet.getJsonWebKeys().get(0);

  // The private key is used to sign
  signerJws.setKey(jwk.getPrivateKey());

  // Set the Key ID (kid) header because it's just the polite thing to do.
  signerJws.setKeyIdHeaderValue(jwk.getKeyId());

  // Set the "b64" header to false, which indicates that the payload is not
  // encoded 
  // when calculating the signature (per RFC 7797)
  signerJws
      .getHeaders()
      .setObjectHeaderValue(HeaderParameterNames.BASE64URL_ENCODE_PAYLOAD, false);

  // Produce the compact serialization with an empty/detached payload,
  // which is the encoded header + ".." + the encoded signature

  return signerJws.getDetachedContentCompactSerialization();
}
```

{% endcode %}

{% code title="Python" overflow="wrap" lineNumbers="true" fullWidth="false" %}

```python
from joserfc.rfc7797 import serialize_compact
from joserfc.jwk import RSAKey
import json

# Private Key 
private_key = RSAKey.import_key({
    "p": "4xjtcjnYMkkX97rViwxE9ZfhegRLVCQ7begAE_tBZe6-imKCSdQlw5Hasv5XPjY_SvEwkF0PD5oK-VIPRm40qjFSvSKjpz4myJabfbMwZQYhvsxOcPRqVRolCDW_OIQ7lXVjDEvl_4GmwRyp_sWaAUKaVIoyWLas2QvXZ8q4Yz0",
    "kty": "RSA",
    "q": "rtTjLo-H9nuOWEbl403YTf34acVOAyhNXDMgkim2v0TpMDWOCgEJOFuGH2ILEVRY1Rrcep7ups4wiqDXP7aN8icA96okOhSUlMFPvropk9uabPdPJvM9jh6VE2SP1VEAMf4BeDwq_dE_FyKWxGLZrRbN4joJheY75YYYyWELMDU",
    "d": "FR73dPuWZgcvu57y8fHCaKQ142SCxvLxvC9mAsN4ztxWxCd7jjvqzJN7QUweEeqLHeQeTLcI7YcGL6cpUMGjA07XNSFjCKZyHtkeyCDNMvL91GVGluYxmIF66qu2f7EXqSsVElwlAHYUIs29b_H95Qpa53PiSMl97jfzQsG7W9X24KJM_NshPEmKvou0BWNmSFxNs66C-pq5i6Up224OY5a9bGXrRw5Vkv6QR7SwPhj0EFNkonMt1TK9vU4P5KLQ-82sEOqkTKtKYC86egj7gZKguqzhUkfw_kfghu-dGvnYeQ6h_7HQUvVsYRQJOutFrEuNvGay44SgDf1X0nZRcQ",
    "e": "AQAB",
    "use": "sig",
    "kid": "57ea893e-7e1c-4383-b013-f6c96e3bf776",
    "qi": "e3D3bnlVAPdqvg85eDh4Tp9VwM2VQjHSN_BLDl_8tm8Xbe68VzEpqBm_AEfA7OwlFuFWOGsQwCXO89kYJ6eF61jE_72zXRdrzseUM80c_nKIyx-ZlbijpTRp9VUnClMg4JcyZT4eWKkNurMFsf9vTWI4yayZqkJHc9J39B2MqLk",
    "dp": "sVO3pWfxn2Jf6rrjIA5WkockM0jDIVKhbTKpTPD2ogeIlTpSjh-v1URAx1--8_8b8QLgbvmbVw1r4D7pWo-XZAXbm4A-1cq8MgkYJVEUSu48z2VtItpXZVhi7kQ5qoHmnM_qpaFmWNr-QPCG9T-K_8zoAXdf1NHfqiOK8arjy-k",
    "alg": "RS256",
    "dq": "TS_EFRxdRJ8MG0FB4XbO1rAX6mqnpJE4hko0SRONkShVY2lhil0muvD9aAGbLU114q_3Q1PDvXUuzSVxorlwNcaukKlXUSUg7APktyntjU_Y_9633VRqisJJwsQVFHKsiWXBNFosCN9G4Wnt8kpKHDcDMqu45JrfOthXPSFRFTk",
    "n": "mxfLkK5DVngBOlVDdeFu_OQp3dIcfvHvoB1vU0DXTsTfZqpQa5ry9pI5N5lo5XxB_AUNw2bDPGCZBF6u6NKHsy50DXDfyh4VFz2SoxUQJELphfRwrHeugGsHuF3iyHxaXERyFjxjmzy9c3KKPszo_yzjVvZTfPesdyXRjZTXg-bqNIZbD8SrNDF8U0Nvh9kLlp0cfopbxuO4azts0rs3Z9WJZ-KnccFnEcgPvPkvLicsnlIyl3qUbZWFuoDKFgmItvGiOtwNBFtcwTRegrvbER-9bXByDB67KDryzzvdsLfRvs31snvdXSjF4BfXAXTuccQPLprKoHO0HkTq62b7oQ"
})

# Headers
protected = {"alg": private_key.alg, "kid": private_key.kid, "b64": False, "crit": ["b64"]}

# Request Payload
payload = json.dumps({
    "ver":"1.1.2",
    "timestamp":"2024-04-25T12:51:22.638Z",
    "txnid":"f5e123a9-202c-4c7e-8bfa-9db9eea89ff2"
    }, separators=(',', ':'))
print("Payload: " + payload)

# Detached JWS Creation
value = serialize_compact(protected, payload, private_key)
print("Detached JWS: " + value)
```

{% endcode %}


# Verify JWS

### Code Samples

{% code overflow="wrap" lineNumbers="true" fullWidth="true" %}

```go
package main

import (
	"fmt"
	"log"

	"github.com/lestrrat-go/jwx/v2/jwa"
	"github.com/lestrrat-go/jwx/v2/jwk"
	"github.com/lestrrat-go/jwx/v2/jws"
)

type Data struct {
	Ver           string `json:"ver"`
	Timestamp     string `json:"timestamp"`
	TxnId         string `json:"txnid"`
	ConsentHandle string `json:"ConsentHandle"`
}

func main() {

	bodyBytes := []byte(`{"ver":"2.0.0","timestamp":"2024-05-10T06:13:09.814Z","txnid":"265ac007-71d4-40e7-91d9-b72491f46c35","ConsentHandle":"465d1f35-f716-484f-a38e-30797d97b525"}`)

	const publicKeyJson = `{
		"kty": "RSA",
		"e": "AQAB",
		"use": "sig",
		"kid": "57ea893e-7e1c-4383-b013-f6c96e3bf776",
		"alg": "RS256",
		"n": "mxfLkK5DVngBOlVDdeFu_OQp3dIcfvHvoB1vU0DXTsTfZqpQa5ry9pI5N5lo5XxB_AUNw2bDPGCZBF6u6NKHsy50DXDfyh4VFz2SoxUQJELphfRwrHeugGsHuF3iyHxaXERyFjxjmzy9c3KKPszo_yzjVvZTfPesdyXRjZTXg-bqNIZbD8SrNDF8U0Nvh9kLlp0cfopbxuO4azts0rs3Z9WJZ-KnccFnEcgPvPkvLicsnlIyl3qUbZWFuoDKFgmItvGiOtwNBFtcwTRegrvbER-9bXByDB67KDryzzvdsLfRvs31snvdXSjF4BfXAXTuccQPLprKoHO0HkTq62b7oQ"
	}`

	publicKey, err := jwk.ParseKey([]byte(publicKeyJson))
	if err != nil {
		fmt.Printf("failed parse key: %sn", err)
		return
	}

	// Check if the target header exists and print its value
	xJwsSignature := "eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il0sImtpZCI6IjU3ZWE4OTNlLTdlMWMtNDM4My1iMDEzLWY2Yzk2ZTNiZjc3NiJ9..bogawIsv__rLEutcNBYIpkRC-TysvIGyN9uodR6sL87iMU2X43mJ2_T3Sd9VPGRH7UMJo2yBgFKIVjF1VYol7AVCfs_jqskI8IPZ84S7r7mu8U9YuxM-DJFX1zG-Qnva03SZMaFIpTXEZh7Q0dqvxOJdfk6MJfVZ0xlT_lLaOtU-cjdLIhcI8QazM89Gwfbq1SL33szt1KbDlJ2G4Ah8uN-YDiu7qhyLZRkmlfubiyqVST_dBkIDyF_uSIaeTY_s5nGtPKbN5YEgltT2ScYTt7T5Whg12ZAnVEZmk9ox7DJVYId6XlpJxirdREhg4b6WCQVJcsa2wA54OETyOKR_kg"

	fmt.Printf("Response Header X-Jws-Signature: %s\n", xJwsSignature)

	verified, err := jws.Verify([]byte(xJwsSignature), jws.WithKey(jwa.RS256, publicKey), jws.WithDetachedPayload(bodyBytes))
	if err != nil {
		log.Printf("failed to verify message: %s", err)
		return
	}
	log.Printf("signed message verified! -> %s", verified)

}
```

{% endcode %}

{% code title="Java" overflow="wrap" lineNumbers="true" fullWidth="true" %}

```java
detachedSignature = Received jwsSignature

Payload = received Payload

publicKeyString = entity Certificate of the AA 

public void validateJws(String detachedSignature, String payload, String publicKeyString) {
  try {
    print("jws Validation Started...");
    // Use a JsonWebSignature object to verify the signature
    JsonWebSignature verifierJws = new JsonWebSignature();

    // Set the algorithm constraints based on what is agreed upon or expected from
    // the sender
    print("Setting up the algorithm constraints");

    verifierJws.setAlgorithmConstraints(
        new AlgorithmConstraints(
            AlgorithmConstraints.ConstraintType.WHITELIST,
            AlgorithmIdentifiers.RSA_USING_SHA256));

    if (payload == null) {
      print("Setting up the embedded content as compact serialization");
      // The JWS with embedded content is the compact serialization
      verifierJws.setCompactSerialization(detachedSignature);
    } else {
      print(“Setting up the detached content as compact serialization");
      // The JWS with detached content is the compact serialization
      verifierJws.setCompactSerialization(detachedSignature);

      // The unencoded detached content is the payload
      verifierJws.setPayload(payload);
    }

    JsonWebKey jsonWebKey = JsonWebKey.Factory.newJwk(publicKeyString);
    verifierJws.setKey(jsonWebKey.getKey());

    // The public key is used to verify the signature
    // This should be the public key of the sender.
    print("verifying signature with the public key: {}", publicKeyString);
    if (!verifierJws.verifySignature()) {
      log.error(VALIDATION_OF_JWS_FAILED);
      throw new InvalidSignatureException(
          FIUErrorType
              .SIGNATURE_DOES_NOT_MATCH, SIGNATURE_DOES_NOT_MATCH);
    }

  } catch (Exception e) {
    
  }
  Print("JWS verification process completed");
}
```

{% endcode %}

{% code title="Python" overflow="wrap" lineNumbers="true" fullWidth="true" %}

```python
from joserfc.rfc7797 import deserialize_compact
from joserfc.jwk import RSAKey
import json

# Public Key
public_key = RSAKey.import_key({
    "alg": "RS256",
    "e": "AQAB",
    "kid": "b5a1468b-1bd4-4be6-b505-bf2c8d4df056",
    "kty": "RSA",
    "n": "p6DCZYiVNsq3WRgzCWuFvXTGUs3BeDJydPMQMjyzXoXb-s_tvkquED0IeMcj30oic-W7xAkqAm579b9epk0aB5bkWmfSy1tlnzCnNmIsHxA0QEXI9PuohSHLfNFHIk921ymPNji5mlRpoKHzt4029MZvRAxytTcNNGxA3GvicHZFuHLio7AENfhEAmVSURuZPNQeolTcLjYjiArypLV_vtXdTI9sz0OhHOh8whC82efpfxz69LMm86WkISFSSCGG_gMvjtGonxRnKE-iqvkOv4ol6ksZs8xnbzFT-Cmlt13n6DbHJ7s4ZVmwlX8H8GEFBuiUb9I-YSt8sbA-KUi76w",
    "use": "sig"
})

detached_jws = "eyJhbGciOiJSUzI1NiIsImtpZCI6ImI1YTE0NjhiLTFiZDQtNGJlNi1iNTA1LWJmMmM4ZDRkZjA1NiIsImI2NCI6ZmFsc2V9..UeC-M7l9cVufBTjOgsVlAqryR6v7DlFyDawbWfU6tUNm8UfHbjFNsuuiZ4efl7co2P7zpF1JXmEMhNNX9Fqc3G-oau1Ya1cqG7AHJ19UDhIrDfOrDd7EH9Q2pn-D0HgZ_3lteoWngLyYVnGN1hwNWRwFaxIF94Jierxc0xfGHvRxXHZumdiIszNwHo13ydgdknMYpXsmXSyjmCPmyRRvbL2enPcMTFqOghbWuIr43hcC_BC173h2Sk0b7YfyobERST_wRkhxDS9W4fEvbpVM9jILNUVhAxDksBP98VmVlbpdYmui6D2j025koOOyjgR4YEeIhhe3fEC5QoxTsjA6OA"

# Request Payload
payload = json.dumps({"ver":"1.1.2","timestamp":"2024-04-26T06:53:00.370Z","txnid":"f5e123a9-202c-4c7e-8bfa-9db9eea89ff2","Notifier":{"type":"AA","id":"dashboard-aa-preprod"},"ConsentStatusNotification":{"consentId":"bf32b951-c2db-476c-9bb7-4d5fd9489f98","consentHandle":"23d0adf0-da22-4de8-bad0-1913e16f39cb","consentStatus":"ACTIVE"}}, separators=(',', ':'))

obj = deserialize_compact(detached_jws, public_key, payload)
print("Signature is valid!")
```

{% endcode %}


# End-to-end Encryption

Ref - <https://github.com/Sahamati/rahasya>

This is required when making FI Request to initate data fetch.

Note: The 2.0.0 ReBIT version supports both curve25519 and X25519 curve, So you can use either one of the curve in ECDH.


# Overview

FIP Module will host set of ReBIT API that the AA will call from their Backend. Those APIs are defined here <https://api.rebit.org.in/spec/fip> you will have to implement 2.0.0 version or 2.1.0 for Insurance FIPs

Your FIP module will further call your CBS to discover accounts and fetch data.

**Central Registry FIP Entity Onboarding**

You can follow the steps here [Create FIU Entity](/central-registry/create-fiu-entity) to create an FIP entity as well. Just select FIP instead of FIU

### **(CR) Central Registry APIs**

Ref- [Central Registry APIs](/central-registry/central-registry-apis)

Central Registry host a list of APIs that you can use

1\.      Token Generation API

2\.      AA List

When you are making API call to the AA you need to pass the token generated in the CR to be sent in the header as fip\_api\_key

### **Detached JWS Signature**

All API response that you are sending needs to have the x-jws-signature refer - [JWS Signature](/fiu-module/jws-signature)

### End-to-end encryption of Data Request

Ref - <https://github.com/Sahamati/rahasya>

Note: The 2.0.0 ReBIT version requires you to support both curve25519 and X25519 curve of ECDH


# Web Redirection

### Standard Web Redirection

Refer AA Redirection Guidelines <https://sahamati.gitbook.io/aa-redirection-guidelines> to create a web redirection URL after creating a consent handle.

You will need SECRETKEY from Saafe to create the Redirection URL. Which we will share it with you through email.


