TestBank
TestBank is a fictional financial entity we implement to illustrate Flanks' capabilities and to facilitate the integration with our API, simulating connections and their behavior.
In the Connect Widget, TestBank lets you choose how a connection behaves (challenges, failures, delays and data errors) through its Advanced fields.
Connect Widget: Advanced fields
TestBank asks for a Username and a Password, which can be any value, and collapses everything else into an Advanced fields section below them. Every advanced field is optional except Dataset, which is prefilled: leave the others empty and the connection is created with the default data and no challenge.
To go straight to the TestBank form, create the Connect Session
with connector_id set to multi:testbank.
| Field | What it does |
|---|---|
| Dataset | The data the connection returns, one of the datasets below. Required, prefilled with minimal. |
| Login delay (seconds) | How long the login takes, from 0 to 30. Defaults to 0.5. |
| Forced login failure | Makes the login fail with the chosen error. The connection is not created. See the error codes below. |
| Forced challenges (in order) | The challenges the user is asked for, one after the other, in the order they are picked. The first one is asked right after the login. |
| Challenge delay (seconds) | How long each challenge takes to resolve once answered, from 0 to 30. Defaults to 0.5. |
| Forced challenge failure | Makes the challenge fail with the chosen error once it is answered. The connection is not created. |
| Initial date | The date the data is built around: its dates are relative to it. Defaults to the day the connection is created. |
| Failing products | The login succeeds and the connection is created, but retrieving the chosen products fails. Bank unavailable simulates an outage instead: retrieving any data fails, so it cannot be combined with the products. |
| Force AlreadyExists | A second connection created with it is recognised as a duplicate of the first one, as described in Uniqueness. |
Fields that contradict each other are disabled as soon as one of them is set. For example, a Forced login failure aborts the login, so the challenge fields are disabled.
Datasets
| Dataset | Purpose |
|---|---|
minimal |
A minimal set of data, to quickly test the connection flow. |
reco |
Data with some deliberate breaks, to test the reconciliation tool. |
global |
Comprehensive data with examples of a wide range of products and transactions. |
pat |
Data designed to fit the capabilities of the analytics tool. |
Challenges
Picking several Forced challenges chains them: once the user answers one, the next one
is asked. Any answer resolves a challenge, except INVALID_SCA, which fails it with
InvalidChallengeResponse.
Banks ask for a second factor in many different ways: a code by SMS, a QR to scan, an approval in their app... TestBank can simulate every challenge type the Connect Widget supports, so you can check how each one looks and behaves before connecting a real bank.
| Challenge | What the user is asked for |
|---|---|
APP |
Approve the login in the bank's app. |
APP_CODE |
Approve the login in the bank's app with a PIN. |
CALL |
Confirm the login through a phone call. |
CARD_READER |
A code generated with a card reader. |
CODE |
A generic code. |
CODE_DEVICE |
The code shown by a physical device. |
CODE_FROM_APP |
The code shown in the bank's app. |
COORDINATE |
A coordinate from the security card, such as B4. |
COORDINATE_CARD |
A coordinate from one of several security cards. |
CRYPTOCALCULATOR |
The code generated by a crypto calculator. |
DIGIPASS |
The code generated by a Digipass token. |
EMAIL |
The code received by email. |
EXTERNAL_WAIT |
Nothing to type: wait until the bank confirms the login elsewhere. |
GOOGLE_AUTHENTICATOR |
A time-based one-time code (TOTP) from an authenticator app. |
MISCELLANEOUS |
A generic challenge, for methods without a specific type. |
QR_ACCEPT |
Scan a QR code and accept the login on the phone. |
QR_CODE_OR_OK |
Scan a QR code, then type the code it gives or accept on the phone. |
QR_INPUT |
Scan a QR code and type the code it gives. |
SECURE_KEY |
Approve the login on a trusted device. |
SECURITY_QUESTION |
The answer to a security question. |
SMS |
The code received by SMS. |
SYNCHRONOUS_APP |
Confirm in the bank's app that it shows the same code. |
UPDATABLE_QR |
Scan a QR code that keeps changing while it is shown. |
Error codes
Each forced failure ends the Connect Session with this error code:
| Value | Forced login failure | Forced challenge failure |
|---|---|---|
| Invalid credentials | InvalidCredentials |
InvalidCredentials |
| Login error | InternalError |
InternalError |
| Internal error | InternalError |
InternalError |
| User interaction needed | UserInteractionNeeded |
UserInteractionNeeded |
| Challenge type not allowed | UnsupportedChallengeMethod |
InternalError |