Skip to main content

Saafe Account Aggregator — Developer Documentation

Build and integrate the Saafe Account Aggregator Redirection Flow APIs — from decoding the FIU request through authentication, discovery, linking, consent, and encode.

API versions​

Choose the API version that matches your integration.

warning

API v2.0.0 (paths without /redirection, no mandatory sessionId) will be deprecated on 3 August 2026. Migrate to v2.1.0 (aaUrl/redirection/... + sessionId header) before that date.

API VersionPublished DateRelease NotesStatusDeprecation Date
2.1.010-07-2026Base path /api/v2/redirection/.... sessionId header required on all APIs except Decode (missing → HTTP 400).Active (Latest)—
2.0.0—Paths without /redirection (e.g. aaUrl/public/decode). sessionId header not required.Active03-08-2026

Global environment​

All API requests are made against your AA environment base URL:

aaUrl = https://<your-aa-environment-url>

Note: Replace the placeholder with the actual URL of your environment.

EnvironmentBase URL
UAT / Sandboxhttps://sandbox.saafe.in/api/v2
Productionhttps://app.saafe.in/api/v2

Path difference by version​

VersionExample Decode URL
2.1.0aaUrl/redirection/public/decode → https://sandbox.saafe.in/api/v2/redirection/public/decode
2.0.0aaUrl/public/decode → https://sandbox.saafe.in/api/v2/public/decode

How the redirection flow works​

The typical end-to-end journey a user goes through in the redirection flow:

  1. FIU initiates a consent request and redirects the user to the AA.
  2. Decode the incoming request to read the user context (decode).
  3. Authenticate the user with a phone number + OTP (init-otp → verify-otp).
  4. Add / verify identifiers (mobile, PAN) if required.
  5. Discover accounts across FIPs (Partial Auto Discovery or FIP-specific discovery).
  6. Link accounts and verify with the FIP OTP.
  7. Review the consent (Consent/handle) and approve or reject it.
  8. Encode the response and redirect the user back to the FIU.

See the Flow Overview for your version: v2.1.0 or v2.0.0.

Authentication & headers​

Most user-facing endpoints require a Bearer access token obtained from OTP Verify. Pass it as:

Authorization: Bearer <access_token>

If a request returns 401 Unauthorized, refresh the token using Refresh Token.

sessionId (v2.1.0 only)

In v2.1.0, Decode returns sessionid. Send it as the sessionId header on every later /redirection API. Missing header → HTTP 400.

In v2.0.0, the sessionId header is not required.