Authentication
The OpenBanking API uses OAuth 2.0 client credentials. Your integration is an OAuth client registered on the MagniFinance authorization server; it exchanges its client id and secret for a short-lived access token and sends that token as a Bearer token on every call.
Client credentials are created by MagniFinance for each integration and bound to your Magni client. Contact us to be provisioned; there is no self-service sign-up, no password login and no API-key management endpoint.
Getting a token
curl -X POST 'https://auth.magnifinance.com/connect/token' \
-H 'Content-Type: application/x-www-form-urlencoded' \
-d 'grant_type=client_credentials' \
-d 'client_id=YOUR_CLIENT_ID' \
-d 'client_secret=YOUR_CLIENT_SECRET' \
-H 'User-Agent: my-integration/1.0' \
-d 'scope=openbanking.api'
| Parameter | Value |
|---|---|
grant_type | client_credentials |
client_id, client_secret | issued by MagniFinance |
scope | openbanking.api |
The response is a standard token response (access_token, token_type: Bearer, expires_in). Request a new token when the current one expires — there is no refresh token for client credentials.
The authorization server rejects requests with an empty or bare curl User-Agent, and the rejection looks like an authentication failure. Send a normal User-Agent header (your integration name and version) on token requests.
Calling the API
curl 'https://app.openbanking.magnifinance.com/api/v1/transactions?accountId=...' \
-H 'Authorization: Bearer ACCESS_TOKEN'
Every request without a valid token answers 401 Unauthorized. A token without the openbanking.api scope answers 403 InsufficientScope; a client that is not yet bound to a Magni client answers 403 MissingClientBinding (see Error handling).
Staging
Test credentials target https://app.openbanking.office.mag.ni/api/v1 and the staging authorization server https://auth.office.mag.ni. They are issued together with production credentials on request.