← All supported banks

Germany  ·  Aareal Bank AG  ·  EBICS

Connect Aareal Bank without learning EBICS.

Aareal's host speaks EBICS 2.5 and 3.0, publishes fifty order types, and changes two of them in 2026. We handle the payments and the statements, and every protocol step underneath. You follow five steps.

No EBICS knowledge needed. We draft the emails, generate the keys and print the letter the bank asks for.

Aareal's host, checked live

10 Sep 2026
<ebicsHEVResponse xmlns="http://www.ebics.org/H000">
  <SystemReturnCode>
    <ReturnCode>000000</ReturnCode>
    <ReportText>[EBICS_OK] OK</ReportText>
  </SystemReturnCode>
  <VersionNumber ProtocolVersion="H004">02.50</VersionNumber>
  <VersionNumber ProtocolVersion="H005">03.00</VersionNumber>
</ebicsHEVResponse>
Host ID
AAREAL
EBICS 2.5
H004
EBICS 3.0
H005
Answered in
0.31 s

BankConnector

What is built and shipped for this bank today.

Exactly what we have done for Aareal

Aareal is not a generic EBICS target in our system. It has its own bank profile, carrying the German rulebook, the field limits, the scheme coverage and the bank's own key fingerprints.

Payment files

Your canonical JSON becomes pain.001.001.03 shaped to the German DK Anlage 3 v3.9 rulebook. Charge bearer SLEV, remittance capped at 140 characters, names at 70, and non-Latin characters transliterated before the bank ever sees them.

Statements back

We read camt.053 end-of-day, camt.052 intraday and camt.054 notifications, plus pain.002 status reports, and normalise all four into one format. You do not parse per-bank XML.

Both protocol versions

Aareal's host offers 2.5 and 3.0. We speak both, with A006 signatures on RSA 2048 keys, so the 3.0 move is a setting on the connection.

Bank keys, pinned

Aareal publishes its E002 and X002 fingerprints. We hold them on file and check the keys the bank hands us against the ones it printed, so the one exchange that cannot be re-verified later is verified at the time.

Two signatures on a payment

Aareal supports the distributed signature, and so do we. A payment can be raised by one person and released by another, with your approval policy deciding who, and the bank enforcing it.

The paperwork

We generate your keys, print the initialisation letter as a signed-ready PDF carrying the fingerprints Aareal checks, and draft the email that opens the agreement. Private keys never leave the system.

One thing we found, and planned around. Aareal retires its old EBICS address at the end of 2026. Any connection still pointed at it stops working that day, so the new address is what we set up against from the start.

Published by Aareal

From the bank's own EBICS page and its order-type schedule, dated June 2026.

What Aareal supports

Aareal publishes its access parameters openly, which is not universal. A treasury team can see the whole shape of the connection before speaking to anyone at the bank.

Host IDAAREAL
EBICS addresshttps://ebics.aareal-bank.com/ebics/EbicsServlet
Protocol versionsH004 (2.5) and H005 (3.0)
Signature versionA006 · RSA 2048
Bank key hashesE002 and X002, published for both versions
Distributed signatureSupported — HVE, HVS, HVD, HVT, HVU, HVZ
Order types50 — 28 send, 22 download
EBICS since2008

Published by Aareal

Aareal Bank EBICS order types, all fifty, mapped to 3.0

EBICS 3.0 replaces the three-letter order type with a business transaction format: a service, a scope, an option and the ISO 20022 message it carries. Aareal publishes both columns side by side, so a 3.0 migration can be planned from the document. The last column is ours: what BankConnector drives on your behalf, and what it leaves alone.

Send — 18 business order types
2.5What it doesServiceScopeOptionMessageBankConnector
CCTSEPA credit transfer, payee check opt-outSCTpain.001Supported
CTVSEPA credit transfer, payee check opt-inSCTVOIpain.001Supported
CCCSEPA credit transfer, XML containerSCTDEpain.001XMLSupported
CIPInstant credit transfer, payee check opt-outSCIDEVOOpain.001Supported
CIVInstant credit transfer, payee check opt-inSCIVOIpain.001Supported
CCUUrgent credit transfer via TARGET2XCTDEURGpain.001Supported
AZVForeign credit transfer, retires 15 Nov 2026XCTDEdtazvSupported
CDDSEPA core direct debitSDDCORpain.008Not used
CDCSEPA core direct debit, XML containerSDDDECORpain.008XMLNot used
C1CSEPA core direct debit, shortened lead timeSDDBIL0C1Cpain.008XMLNot used
CDBSEPA B2B direct debitSDDDEB2Bpain.008Not used
C2CSEPA B2B direct debit, XML containerSDDDEB2Bpain.008XMLNot used
CCXService-centre release, credit transfer opt-outSCTDE0CCXpain.001Not used
VCXService-centre release, credit transfer opt-inSCTDE0VCXpain.001Not used
CIXService-centre release, instant opt-outSCIDE0CIXpain.001Not used
VIXService-centre release, instant opt-inSCIDE0VIXpain.001Not used
XSAAareal maintenance files, uploadOTHBIL0XSAMISCNot used
XWSAareal maintenance files, upload (Wodis only)OTHBIL0XWSMISCNot used
Download — 11 business order types
2.5What it doesServiceScopeOptionMessageBankConnector
C53End-of-day account statementEOPDEcamt.053ZIPSupported
C52Intraday transactions, not yet bookedSTMDEcamt.052ZIPSupported
C54Debit and credit notification, batch detailSTMDEcamt.054ZIPSupported
C5NCredit advice for SEPA instantSTMDESCIcamt.054ZIPSupported
CIZPayment status report, instant credit transferREPDESCIpain.002ZIPSupported
VPZVerification of payee status reportREPDEVOPpain.002ZIPSupported
STAEnd-of-day statement, MT940EOPDEmt940Supported
VMKIntraday transactions, MT942STMDEmt942Not used
BKAAccount statement as a signed PDFEOPDEpdfZIPNot used
XSAAareal feedback and maintenance filesOTHBIL0XSAmiscZIPNot used
XWSAareal feedback files (Wodis only)OTHBIL0XWSmiscZIPNot used

The remaining twenty-one are key management and protocol housekeeping. They keep their three-letter names in 3.0 and carry no business transaction format. These are ours end to end: you never see one, and we run them for you during setup and afterwards.

INIHIAHPBHCAHCSPUBVPKPWASPRHTDHKDHPDBPDHACPTKHVEHVSHVDHVTHVUHVZ

Published by Aareal

Known changes.

Two deadlines already handled

Aareal has published both dates. We set new connections up against them from the start, and we move existing ones before they land.

  1. AZV retires. Foreign payments move to a new order type, AXZ, on ISO 20022 instead of the old DTAZV file format. Anything still submitting AZV stops being accepted.

  2. The old EBICS address stops answering. Clients still pointed at bk01kom.first-financial.biz must move to ebics.aareal-bank.com. The Host ID does not change.

Published by Aareal

Read out of the order-type schedule.

Verification of payee is already wired in

Aareal has separate order types for checked and unchecked submission, on both ordinary and instant credit transfers, plus a dedicated status report. All six are in the published schedule today.

RailOpt in to the checkOpt outStatus report
SEPA credit transferCTVCCTVPZ
SEPA instantCIVCIPVPZ
Service-centre releaseVCX · VIXCCX · CIXVPZ

If all of this looks like a lot  ·  it does not have to be

Five steps to a live Aareal connection.

You do not need to know what any of the codes above mean. Our setup guide walks you through it one screen at a time.

  1. 1

    Request the agreement from Aareal

    EBICS starts with paperwork. We draft the email, you send it, and you tell us when it has gone. There is nothing to configure until the bank replies.

  2. 2

    Set up and send your keys

    Enter four values from the agreement Aareal returns. We already hold the ones that are public, so most of the form is filled in. Then one press generates your keys and sends the public halves.

  3. 3

    Prove your identity on paper

    EBICS confirms the key exchange on paper, by design. We print the initialisation letter carrying the fingerprints Aareal will check. You sign it by hand and post it.

  4. 4

    Verify Aareal and go live

    While you wait, we fetch Aareal's public keys on a schedule and check them against the hashes Aareal publishes. When that lands, you choose which approval policy governs payments here, and the connection switches on.

  5. 5

    You are now in production with Aareal Bank

    Payments go out as pain.001 and statements come back as camt.053. The connection runs unattended from here.

Sources — Aareal’s EBICS service page, its order-type schedule dated June 2026 and the EBICS specifications published by Die Deutsche Kreditwirtschaft. Host response measured 10 September 2026. BankConnector is not affiliated with Aareal Bank AG.

← Back to all supported banks