Saafe Account Aggregator — Developer Documentation
Build and integrate the Saafe Account Aggregator Redirection Flow APIs — from decoding the FIU request through authentication, discovery, linking, consent, and encode.
API versions
Choose the API version that matches your integration.
API v2.0.0 (paths without /redirection, no mandatory sessionId) will be
deprecated on 3 August 2026. Migrate to v2.1.0
(aaUrl/redirection/... + sessionId header) before that date.
| API Version | Published Date | Release Notes | Status | Deprecation Date |
|---|---|---|---|---|
| 2.1.0 | 10-07-2026 | Base path /api/v2/redirection/.... sessionId header required on all APIs except Decode (missing → HTTP 400). | Active (Latest) | — |
| 2.0.0 | — | Paths without /redirection (e.g. aaUrl/public/decode). sessionId header not required. | Active | 03-08-2026 |
/redirection APIs. Send sessionId from Decode on every later call.Latestv2.0.0 — Classic pathsStandard AA paths. No /redirection prefix. No mandatory sessionId header. Deprecates 3 Aug 2026.Deprecates 3 AugSAANS & FIP HealthPush metrics to Sahamati and your URL, or pull via Admin GET/POST APIs.AdminGlobal environment
All API requests are made against your AA environment base URL:
aaUrl = https://<your-aa-environment-url>
Note: Replace the placeholder with the actual URL of your environment.
| Environment | Base URL |
|---|---|
| UAT / Sandbox | https://sandbox.saafe.in/api/v2 |
| Production | https://app.saafe.in/api/v2 |
Path difference by version
| Version | Example Decode URL |
|---|---|
| 2.1.0 | aaUrl/redirection/public/decode → https://sandbox.saafe.in/api/v2/redirection/public/decode |
| 2.0.0 | aaUrl/public/decode → https://sandbox.saafe.in/api/v2/public/decode |
How the redirection flow works
The typical end-to-end journey a user goes through in the redirection flow:
- FIU initiates a consent request and redirects the user to the AA.
- Decode the incoming request to read the user context (
decode). - Authenticate the user with a phone number + OTP (
init-otp→verify-otp). - Add / verify identifiers (mobile, PAN) if required.
- Discover accounts across FIPs (Partial Auto Discovery or FIP-specific discovery).
- Link accounts and verify with the FIP OTP.
- Review the consent (
Consent/handle) and approve or reject it. - Encode the response and redirect the user back to the FIU.
See the Flow Overview for your version: v2.1.0 or v2.0.0.
Authentication & headers
Most user-facing endpoints require a Bearer access token obtained from OTP Verify. Pass it as:
Authorization: Bearer <access_token>
If a request returns 401 Unauthorized, refresh the token using Refresh Token.
In v2.1.0, Decode returns sessionid. Send it as the sessionId header on every
later /redirection API. Missing header → HTTP 400.
In v2.0.0, the sessionId header is not required.