Implementation of Open Application Programming Interfaces in the banking sector in Vietnam from March 1, 2025

Implementation of Open Application Programming Interfaces in the banking sector in Vietnam from March 1, 2025
Anh Hao

Below is the content of the regulation regarding the implementation of Open Application Programming Interfaces in the banking sector from March 1, 2025, according to the new Circular of the State Bank of Vietnam.

Implementation  of  Open  Application  Programming  Interface  in  the  Banking  Sector  from  March  1,  2025

Implementation of Open Application Programming Interfaces in the banking sector in Vietnam from March 1, 2025​ (Image from the internet)

On December 31, 2024, the Governor of the State Bank of Vietnam issued Circular 64/2024/TT-NHNN stipulating the implementation of Open Application Programming Interfaces in the banking sector.

Implementation of Open Application Programming Interfaces in the banking sector in Vietnam from March 1, 2025

According to sections 1, 2, and 3 of Circular 64/2024/TT-NHNN, regulations on Open Application Programming Interfaces in the Banking Sector (Open API) are as follows:

- Application Programming Interface (API) is an interface that allows communication between software applications within an organization or between organizations.

- Open Application Programming Interface in the Banking Sector (Open API) is a collection of APIs provided by banks to third parties for direct connection and data processing to offer services to customers. Open APIs include: Basic Open APIs and Other Open APIs.

- Open API Testing System is the information system provided by banks to third parties for testing Open APIs before official deployment.

Article 4 of Circular 64/2024/TT-NHNN outlines the general principles for implementing open application programming interfaces in the banking sector as follows:

Banks, customers, and third parties (hereinafter referred to as the parties) must comply with the following requirements when implementing Open APIs:

- Comply with legal regulations on confidentiality, customer information provision, and personal data protection. The processing of customers' personal data is solely for the service of those customers, unless otherwise stipulated by law.

- Data processing must be managed, stored, exploited, and used for the purposes set out in the contract between the parties and in accordance with legal regulations.

- Data processing must ensure accuracy and be updated. In case of discrepancies, corrections must be promptly executed according to the agreement between the parties.

Implementation principles and Open API list in Vietnam

* Principles of Open API Implementation

- When implementing basic open APIs as stipulated in Article 6 of this Circular, banks must comply with the regulations in Appendix 01 and Appendix 02 issued together with Circular 64/2024/TT-NHNN.

- When implementing other Open APIs according to actual needs and legal compliance outside of the Open API list stipulated in Article 6 of Circular 64/2024/TT-NHNN, banks must comply with the regulations in Appendix 02 issued along with Circular 64/2024/TT-NHNN.

- Banks are only allowed to implement the Open API stipulated in point c, clause 1, Article 6 of Circular 64/2024/TT-NHNN for third parties that are banks or organizations offering intermediary payment services.

(Article 5 Circular 64/2024/TT-NHNN)

* Open API List

The basic Open API list is organized into the following groups:

+ Open API for querying exchange rate and interest rate information from banks, including: API for Interest Rate Information, API for Exchange Rate Information;

+ Open API for querying customer information, including: API for Customer Verification and Consent, API for Access Token Retrieval, API for Access Token Refresh, API for Access Token Revocation, API for Account List Retrieval, API for Account Information Retrieval, API for Transaction History Retrieval;

+ Open API for initiating payments, e-wallet top-ups, and withdrawals from e-wallets, including:

++ Open API for payment initiation, including: Payment Initiation API, Customer Authentication API Redirect Flow, Access Token Retrieval API Redirect Flow, Customer Payment Confirmation Status Update API Decoupled Flow, Payment Confirmation API, Transaction Status Retrieval API, Customer Payment Confirmation Status Retrieval API Decoupled Flow;

++ Open API for e-wallet top-up, including: E-wallet Top-up API, OTP Confirmation API, Customer E-wallet Top-up Confirmation Status Update API Decoupled Flow, Customer E-wallet Top-up Confirmation Status Retrieval API Decoupled Flow, E-wallet Top-up Confirmation API, Transaction Status Retrieval API;

++ Open API for withdrawing from e-wallets.

Detailed specifications of the Open API list as prescribed in clause 1, Article 6 of Circular 64/2024/TT-NHNN are specifically stipulated in Appendix 01 attached to this Circular.

More details can be found in Circular 64/2024/TT-NHNN, effective from March 1, 2025.

>> CLICK HERE TO READ THIS ARTICLE IN VIETNAMESE

0 lượt xem



  • Address: 19 Nguyen Gia Thieu, Vo Thi Sau Ward, District 3, Ho Chi Minh City
    Phone: (028) 7302 2286
    E-mail: info@lawnet.vn
Parent company: THU VIEN PHAP LUAT Ltd.
Editorial Director: Mr. Bui Tuong Vu - Tel. 028 3935 2079
P.702A , Centre Point, 106 Nguyen Van Troi, Ward 8, Phu Nhuan District, HCM City;