Skip to main content

Glossary

Common terms you may encounter when integrating with our APIs

API Integration

API integration glossary
TermDefinition
API (Application Programming Interface)A set of rules and protocols that allows different software systems to communicate with each other
API KeyA unique identifier used to authenticate and authorise API requests
AuthenticationThe process of verifying the identity of a user, application, or system
Authorisation (API)The process of determining what actions or resources an authenticated user or system can access
Digital Certificate

An electronic credential used to verify the identity of systems and support secure communication. CommBank X9 certificates via DigiCert.

EndpointA specific URL or path used to access an API function or resource
EnvironmentA deployment stage used for development, testing, or production (e.g. sandbox, UAT/non-prod, production)
Go-LiveThe point at which an integration or service is moved into production and made available for real customer use
HTTP MethodThe type of operation being performed in an API request (e.g. GET, POST, PUT, DELETE)
IdempotencyA mechanism that ensures repeating the same API request does not create duplicate actions or results
IP WhitelistingThe process of restricting system or API access to approved IP addresses
mTLS (Mutual TLS)A security mechanism where both the client and server authenticate each other using digital certificates
OAuth 2.0An industry-standard authentication framework used to securely obtain access tokens for API access
PayloadThe data sent within an API request or response
RequestA message sent from a client system to an API to perform an action or retrieve information
ResponseThe data returned by an API after processing a request
Sandbox EnvironmentA non-production environment used for testing and development
Status or CodeA standard HTTP code indicating the outcome of an API request (e.g. 200, 400, 500)
TokenA temporary credential used to authenticate API requests
WebhookAn automated callback notification sent to a client system when a specific event occurs

NameCheck

NameCheck glossary
TermDefinition
Account DetailsThe BSB number, account number and account name entered by users to be validated by NameCheck
Account NumberA unique numeric identifier used by a financial institution to identify a customer's bank account
BSBBank State Branch. A six-digit number used to identify a specific bank and branch in Australia
Close Match / Partial Match

A result indicating the entered account name is similar to, but not an exact match for, the account holder name held by the receiving bank

Exact MatchA result indicating the entered account name matches the account holder name held by the receiving bank
No MatchA result indicating the entered account name does not match the account holder name held by the receiving bank
Not Enough Information Match

A result indicating there is insufficient information available to confidently determine whether the entered account name matches the account details held by the receiving financial institution, i.e. the account could be new or has not made/received many transactions to date

Verification RequestThe API request sent to NameCheck containing the account details to validate

Fast Payments

Fast Payments glossary
TermDefinition
BSBBank State Branch. A six-digit number used to identify a specific bank and branch in Australia
Fast Payments APIAn API capability that enables the initiation and processing of near real-time account-to-account payments
Payment InitiationThe process of submitting a payment instruction through the API
Payment ReferenceA description or identifier attached to a payment transaction
Real-time PaymentsPayments processed and settled almost instantly between financial institutions
Receiving Financial InstitutionThe bank or financial institution receiving the payment
SettlementThe movement of funds between financial institutions to complete a payment
Source AccountThe bank account from which funds are debited
Target AccountThe bank account receiving the funds
X-JWS Signature HeaderA security header containing a digitally signed JSON Web Signature (JWS) used to verify the integrity and authenticity of API requests

PayTo®

PayTo glossary
TermDefinition
Adhoc (Agreement)A flexible PayTo agreement that allows payments to be initiated irregularly, without a fixed schedule
BSBBank State Branch. A six-digit number used to identify a specific bank and branch in Australia
Card-on-file (Agreement)An arrangement where a customer's card details are stored for future payments, commonly used for subscriptions or repeat purchases
One-off (Agreement)A PayTo agreement that authorises a single payment only
Recurring (Agreement)A PayTo agreement that enables repeated payments on a defined schedule, e.g. subscription service
Australian Payments PlusThe organisation that operates and governs payment infrastructure in Australia, including PayTo and the NPP
Authorisation (PayTo)Customer approval of a PayTo agreement via their banking app
BECSBulk Electronic Clearing System; Australia's legacy direct debit system that PayTo is designed to modernise and eventually replace
Mandate (PayTo Agreement)The agreement that allows a business to debit a customer's account
Mandate CancellationEnding the PayTo agreement
Mandate CreationSetup of the PayTo agreement for customer approval
NPP (New Payments Platform)Australia's real-time payments infrastructure that underpins PayTo and other payment solutions
Payee / MerchantThe business receiving the funds
PayerThe customer authorising the payment
Payment InitiationWhen a merchant triggers a payment under a mandate
PayTo

A real-time, account-to-account payment capability that enables businesses to initiate payments from a customer's bank account via pre-authorised agreements on the NPP

SettlementThe movement of funds between financial institutions to complete a payment
PayTo is a registered trade mark of NPP Australia Ltd ABN 68 601 428 737.