Open Banking Specifics in Sweden

# Authentication flows and SCA

Major banks operating in Sweden support both redirect and decoupled auth flows in their Open Banking interfaces. Primary Strong Customer Authentication (SCA) method supported by all Swedish banks is BankID, Sweden’s widely used national e-identification system.

Although BankID exists as desktop and mobile application, Mobile BankID (Mobilt BankID) is the one used the most.

App-to-app switching is used when Mobile BankID is installed on the device where authentication is initiated. On desktop, a QR code is presented for the user to scan with their mobile device to complete authentication.

In Sweden, Personal Identity Number (personnummer) — commonly referred to as Swedish SSN — plays a crucial role in user identification. Most major Swedish banks support SSN verification via their Open Banking APIas as part of the authentication flow. When using BankID for Open Banking SCA, the user's SSN is provided by the TPP to the bank, which uses it in the BankID auth session.

# Major Banks (ASPSPs)

The most widely used Swedish ASPSPs are:

A full list of Swedish banks (as per EBA) is available here (opens new window).

# Payment Specifics

All Swedish banks support domestic credit transfers in SEK and SEPA Credit Transfers (SCT) in EUR** via their open banking APIs.

SEPA Instant Credit Transfers (SCT Inst) are not supported in Sweden. Most payments are processed as regular SCTs or domestic transfers.

Domestic account numbers follow the bank clearing number + account number scheme and need to be provided in this format when domestic payments are initiated via open banking APIs.

Domestic payments in SEK are the most common, however real-time settlement between banks is not supported and there are strict cut-off times after which payments are not executed.

Bankgirot (opens new window) is a proprietary clearing system in Sweden used for bill payments. Bankgirot provides its own account numbers for receiving payments, which differ from the domestic account numbers. After settled by the Bankgirot, multiple payments are transferred to the receiver's bank account in batches. Most Swedish banks support initiation of Bankgirot payments through their open banking APIs.

# Specifics per ASPSP

# Danske Bank

Danske Bank provides redirect authentication flow only.

# Handelsbanken

Handelsbanken provides both redirect and decoupled auth flows for Open Banking.

Domestic payments in SEK and SEPA payments in EUR are supported.

# Länsförsäkringar Bank

Länsförsäkringar Bank offers only the redirect flow in the Open Banking interface.

Payments in SEK and EUR are supported.

# Nordea

In Sweden, Nordea provides both redirect and decoupled auth flows for Open Banking.

As with Nordea in Finland, Swedish Nordea users must specify a debtor account when initiating a payment. If not specified, additional SCA steps may be required.

For the business users Nordea provides multiple account types managed through different systems. Open banking APIs differ for this systems and correspondingly when using Enable Banking API end-users have to choose different "brands" depending on the system they use. Available the options are:

When initiating a payment without explicitly specifying a debtor account in the request, Nordea requires double SCA: the first authentication is used to fetch the list of accounts, and the second is used to authorise the selected payment.

Guides for end users on authorisation and actions, which might be required to enable access to open banking are available here:

# SEB

SEB provides both redirect and decoupled auth flows for Open Banking.

# Swedbank

Swedbank provides both redirect and decoupled auth flows for Open Banking.