Skip to content

ISECure / wscli

ISECure is a banking network..? That we use at least in TMS to manage banking-related activities.

How to set up wscli-php

wscli's own documentation: https://github.com/isecurefi/wscli-php Especially helpful is the syntax help: https://github.com/isecurefi/wscli-php/blob/master/wscli-php/src/wscli.php

ISECure API documentation: https://isecure.fi/wsapi_v2/index.html

wscli-php

OP:n Web Services (WS) -kanava on suunniteltu yritysten ja pankin välisen maksuliikenne- ja tilitietojen siirtoon. Sen kautta voidaan lähettää ja vastaanottaa erilaisia tiedostoja, ja tiedostomuodot määräytyvät yleensä maksuliikenteen standardien ja sovittujen palveluiden mukaan.

Yleisimpiä ja mainittuja tiedostotyyppejä ovat:
pain-tiedostot (Payment Initiation): Nämä ovat ISO 20022 -standardiin perustuvia tiedostoja, joita käytetään maksutoimeksiantojen lähettämiseen. Esimerkiksi:
pain.001.001.02 (Credit Transfer Initiation, yleinen maksutiedosto)
pain.005.001.01 (Payment Cancellation Request, maksun poistopyyntö)
camt-tiedostot (Cash Management): Myös ISO 20022 -standardiin perustuvia tiedostoja, joita käytetään tiliotteiden ja tilitapahtumaraporttien vastaanottamiseen. Esimerkiksi:
camt.053.001.02 (Bank to Customer Statement, tiliote)
camt.054.001.02 (Bank to Customer Debit/Credit Notification, tilitapahtumailmoitus)
camt.055.001.01 (Payment Cancellation Request, käytetään myös maksun poistopyyntöihin, kuten pain.005)

Finvoice-aineistot: Sähköisten laskujen siirtoon käytettävä kansallinen standardi. Näihin kuuluvat esimerkiksi:
E-laskut ja suoramaksulaskut (XS)
Laskuttajailmoitukset (SI)
Vastaanottoehdotukset (RP)
Välitettävät virhepalautteet (XJ)

KTL-tiedostot: Vanhempi, kansallinen standardi referenssilistojen (viitesiirtojen) osalta. Voi olla käytössä rinnakkain camt-muotoisten referenssilistojen kanssa riippuen sopimuksista.

On tärkeää huomata, että tarkat käytössä olevat tiedostotyypit ja niiden versiot riippuvat yrityksen OP:n kanssa tekemistä sopimuksista ja käytössä olevista palveluista. OP:n kehittäjäportaalista ja asiakasohjeista (esim. "Yrityksen pankkiyhteys (Web services) –kanavan asiakasohje") löytyy tarkempaa tietoa ja teknisiä spesifikaatioita kullekin tiedostotyypille.
Yleisesti ottaen OP pyrkii käyttämään ja tukemaan kansainvälisiä ISO 20022 -standardeja (pain ja camt) maksuliikenteessä.

wscli-php installation

  1. apt install php-cli
  2. apt install php-curl
  3. curl -LSs https://isecurefi.github.io/wscli-php/installer.php | php
    1. Test wscli-php:
      1. ./wscli.phar --version
    2. Remember to chmod +x the wscli binary
  4. install mikefarah's yq (wget from github repo)
    1. Remember to chmod +x the yq binary
  5. create ~/.wscli/settings.yaml
  6. Add in all details required for logging in:
  7. settings:
    1. Note: I am not sure if name, phone number and company details should be included. These may be soft identifiers used by the bank to later confirm the validity of these requests..? But at least they are not necessary to the function of the API calls
    2. filetype: KTL | camt.053.001.02
    3. filestatus: ALL
    4. bank: nordea | osuuspankki | danskebank etc.
    5. environment: testing|production
    6. email:
    7. apikey: "0"
    8. password:
    9. mode: admin | data
  8. Put stricter permissions to settings file: chmod 600 settings.yaml
  9. add env variable:
    1. export SESSION=~/.wscli/settings.yaml
  10. run wscli.phar session login -c $SESSION
  11. Copy the API key that you received as part of the response and replace it with the "0" value of the apikey in settings.yaml
{
    "ApiKey": "n0Cp...",
    "ExpiresIn": "3600",
    "IdToken": "eyJraWQiOiJNbmVZY2FoUENQSDlFQ3FOZTVcL2Rnd0JtZ0tHdFE3VnY0dk9lZUI4aW9zQT0iLCJhbGciOiJSUzI1NiJ9.eyJzdWIiOiIyYTNkODM4OS03YzU5LTRhNmYtYThlNy1kZmY2ZGUxODgzZjgiLCJlbWFpbF92ZXJpZmllZCI6dHJ1ZSwiaXNzIjoiaHR0cHM6XC9cL2NvZ25pdG8taWRwLmV1LXdlc3QtMS5hbWF6b25hd3MuY29tXC9ldS13ZXN0LTFfaVRIeTdrREh4IiwicGhvbmVfbnVtYmVyX3ZlcmlmaWVkIjp0cnVlLCJjb2duaXRvOnVzZXJuYW1lIjoiZV9pbmZvX3RoX2F0X2Fob2xhZGlnaXRhbC5jb21fX2RhdGEiLCJhdWQiOiIxZTA1ZGRhOWNpYWYzMGFyMnBqMDloMDN2OSIsImV2ZW50X2lkIjoiOGIyNDljNTMtNTI1YS00YmVjLTk0YzEtMmUyMmZhYzY1YzRiIiwidG9rZW5fdXNlIjoiaWQiLCJhdXRoX3RpbWUiOjE3NTI1Njc2NTcsInBob25lX251bWJlciI6IiszNTg0MDg2MTU3OTUiLCJleHAiOjE3NTI1NzEyNTcsImlhdCI6MTc1MjU2NzY1NywiZW1haWwiOiJpbmZvX3RoQGFob2xhZGlnaXRhbC5jb20ifQ.A2mgDPHS5oI1GVDYB7J4EEzDPl117mtTERcZGw5V4_-JsF6waT4n3OmXr7v6VPqdsA7lIOO6ru-Moaiqo9JOEJGQ_p8dHaAZFfMDJ7hDJqM2eSRGfuYaJEYh0mRq0zKk_uDvIUhGjA_Aa-QwoN4ym0S5qC5QMZIohxyjMD8n0eWdeE9p5AgBP3jYOkoHzBO_mk9PKP2ZX4DASEnwhL5aHvdiZtaVrAgx7-pT8plcUCFrDml_VsDLAGnRNRtodbB3r83zLEuq5jcEZKzzLaB9xbuqi-QeL5HfzCO7seGw0XFdZJDuUPco_iYArhvthK1CVEoo7_4XqJmXCUTeeJSEEg",
    "ResponseCode": "00",
    "ResponseText": "Login OK"
}

How to download files (call the API)

Get list of files:

curl -H Authorization:`yq -r .settings.idtoken $SESSION` -H x-api-key:`yq -r .settings.apikey $SESSION` https://ws-api.isecure.fi/v2/files/osuuspankki > isecure-full-listfiles-2025-07-17.txt

Get a specific file from the list of files:

curl -v -H Authorization:`yq -r .settings.idtoken $SESSION` -H x-api-key:`yq -r .settings.apikey $SESSION` https://ws-api.isecure.fi/v2/files/osuuspankki/camt.053.001.02/682788373 > isecure-file-682788373.txt

De-code the base64 from the file:

BASE64_CONTENT=$(jq -r '.Content' isecure-file-678112288.txt)
echo "$BASE64_CONTENT" | base64 -d > isecure-file-678112288-base64-decoded.xml

#another way to decode
jq -r '.Content' isecure-file-688031038.txt | base64 -d -i > isecure-file-688031038-base64-decoded.xml