Search by

omnibank / bridge

GlitchArt

Omnibank Bridge: bank aggregation through Bridge API v3 (bridgeapi.io) - its Connect sessions for the consent, accounts, balances, transactions, item webhooks.

1.x-dev 2026-10-03 16:02 UTC

This package is auto-updated.

Last update: 2026-10-03 16:12:01 UTC


README

Bridge (bridgeapi.io, by Perspecteev) for glitchr/omnibank, its API v3: the user connects their banks in a Bridge Connect session; their accounts, balances and transactions are read with the user's access token; item.* webhooks say when the data is fresh or the consent must be renewed.

Unverified. Written from Bridge's published v3 documentation and recorded answers (Tests/Fixtures); it has not yet been run against a real Bridge sandbox. Try it with real keys (docker compose run --rm omnibank connect bridge in glitchr/omnibank's docker/) before relying on it, and drop this notice once it holds - the webhook signature above all.

omnibank:
    gateways:
        banks:
            factory: bridge
            options:
                client_id: '%env(BRIDGE_CLIENT_ID)%'
                client_secret: '%env(BRIDGE_CLIENT_SECRET)%'
                version: '2025-01-15'                            # Bridge-Version
                webhook_secret: '%env(BRIDGE_WEBHOOK_SECRET)%'   # for notify()
                callback_url: 'https://app.example/bank/back'    # when connect() is given no return URL
                country_code: FR

Every call carries Client-Id, Client-Secret and Bridge-Version; a user's, the user's token.

  • connect() - the first time, POST /v3/aggregation/users creates the Bridge user (its external_user_id the state's, or one made up); POST /v3/aggregation/authorization/token gives its token; POST /v3/aggregation/connect-sessions (the return URL as callback_url, the state's user_email when there is one) gives the page. The state keeps user_uuid, external_user_id, access_token, expires_at: keep the connection. When the consent is NEEDS_RENEWAL and the state has item_id, the session is for that item.
  • accounts() - GET /v3/aggregation/accounts, every page; balances() - GET /v3/aggregation/accounts/{id}: balance (booked), instant_balance (instant).
  • transactions() - GET /v3/aggregation/transactions?account_id=&since=&until=&limit=, every page (pagination.next_uri); future and deleted transactions left out; provider_description is the label. A token past its expires_at is renewed for the call.
  • notify() - item.* events: the item (content.item_id) as connectionId; a status the user must act on - 402 (credentials), 429 (action on the bank's site), 430 (password), 1010 (SCA to renew), 1100 (pro account to validate) - is NEEDS_RENEWAL, a deleted item REVOKED, any other status ACTIVE. Other events come back with consent NONE.
  • No transfer() in this version.

Webhook signature - an assumption. This package reads BridgeApi-Signature as v1=<HMAC-SHA256 of the raw body with the webhook secret, hex>, several comma-separated while a secret is rotated, the hex in either case. Check it against a real sandbox webhook.

A 5xx, a 429 or a network failure is an UnavailableException, never an empty list.

Credentials: in Bridge's dashboard (dashboard.bridgeapi.io), a sandbox application's client_id and client_secret, its callback URL registered, and a webhook on the item.* events with its secret.

License: LGPL-3.0-or-later.