Germany · Aareal Bank AG · EBICS
Connect Aareal Bank without learning EBICS.
Aareal's host speaks EBICS 2.5 and 3.0, publishes fifty order types, and changes two of them in 2026. We handle the payments and the statements, and every protocol step underneath. You follow five steps.
No EBICS knowledge needed. We draft the emails, generate the keys and print the letter the bank asks for.
Aareal's host, checked live
10 Sep 2026<ebicsHEVResponse xmlns="http://www.ebics.org/H000"> <SystemReturnCode> <ReturnCode>000000</ReturnCode> <ReportText>[EBICS_OK] OK</ReportText> </SystemReturnCode> <VersionNumber ProtocolVersion="H004">02.50</VersionNumber> <VersionNumber ProtocolVersion="H005">03.00</VersionNumber> </ebicsHEVResponse>
BankConnector
What is built and shipped for this bank today.
Exactly what we have done for Aareal
Aareal is not a generic EBICS target in our system. It has its own bank profile, carrying the German rulebook, the field limits, the scheme coverage and the bank's own key fingerprints.
Payment files
Your canonical JSON becomes pain.001.001.03 shaped to the German DK Anlage 3 v3.9 rulebook. Charge bearer SLEV, remittance capped at 140 characters, names at 70, and non-Latin characters transliterated before the bank ever sees them.
Statements back
We read camt.053 end-of-day, camt.052 intraday and camt.054 notifications, plus pain.002 status reports, and normalise all four into one format. You do not parse per-bank XML.
Both protocol versions
Aareal's host offers 2.5 and 3.0. We speak both, with A006 signatures on RSA 2048 keys, so the 3.0 move is a setting on the connection.
Bank keys, pinned
Aareal publishes its E002 and X002 fingerprints. We hold them on file and check the keys the bank hands us against the ones it printed, so the one exchange that cannot be re-verified later is verified at the time.
Two signatures on a payment
Aareal supports the distributed signature, and so do we. A payment can be raised by one person and released by another, with your approval policy deciding who, and the bank enforcing it.
The paperwork
We generate your keys, print the initialisation letter as a signed-ready PDF carrying the fingerprints Aareal checks, and draft the email that opens the agreement. Private keys never leave the system.
One thing we found, and planned around. Aareal retires its old EBICS address at the end of 2026. Any connection still pointed at it stops working that day, so the new address is what we set up against from the start.
Published by Aareal
From the bank's own EBICS page and its order-type schedule, dated June 2026.
What Aareal supports
Aareal publishes its access parameters openly, which is not universal. A treasury team can see the whole shape of the connection before speaking to anyone at the bank.
| Host ID | AAREAL |
| EBICS address | https://ebics.aareal-bank.com/ebics/EbicsServlet |
| Protocol versions | H004 (2.5) and H005 (3.0) |
| Signature version | A006 · RSA 2048 |
| Bank key hashes | E002 and X002, published for both versions |
| Distributed signature | Supported — HVE, HVS, HVD, HVT, HVU, HVZ |
| Order types | 50 — 28 send, 22 download |
| EBICS since | 2008 |
Published by Aareal
Aareal Bank EBICS order types, all fifty, mapped to 3.0
EBICS 3.0 replaces the three-letter order type with a business transaction format: a service, a scope, an option and the ISO 20022 message it carries. Aareal publishes both columns side by side, so a 3.0 migration can be planned from the document. The last column is ours: what BankConnector drives on your behalf, and what it leaves alone.
| 2.5 | What it does | Service | Scope | Option | Message | BankConnector | |
|---|---|---|---|---|---|---|---|
| CCT | SEPA credit transfer, payee check opt-out | SCT | — | — | pain.001 | — | Supported |
| CTV | SEPA credit transfer, payee check opt-in | SCT | — | VOI | pain.001 | — | Supported |
| CCC | SEPA credit transfer, XML container | SCT | DE | — | pain.001 | XML | Supported |
| CIP | Instant credit transfer, payee check opt-out | SCI | DE | VOO | pain.001 | — | Supported |
| CIV | Instant credit transfer, payee check opt-in | SCI | — | VOI | pain.001 | — | Supported |
| CCU | Urgent credit transfer via TARGET2 | XCT | DE | URG | pain.001 | — | Supported |
| AZV | Foreign credit transfer, retires 15 Nov 2026 | XCT | DE | — | dtazv | — | Supported |
| CDD | SEPA core direct debit | SDD | — | COR | pain.008 | — | Not used |
| CDC | SEPA core direct debit, XML container | SDD | DE | COR | pain.008 | XML | Not used |
| C1C | SEPA core direct debit, shortened lead time | SDD | BIL | 0C1C | pain.008 | XML | Not used |
| CDB | SEPA B2B direct debit | SDD | DE | B2B | pain.008 | — | Not used |
| C2C | SEPA B2B direct debit, XML container | SDD | DE | B2B | pain.008 | XML | Not used |
| CCX | Service-centre release, credit transfer opt-out | SCT | DE | 0CCX | pain.001 | — | Not used |
| VCX | Service-centre release, credit transfer opt-in | SCT | DE | 0VCX | pain.001 | — | Not used |
| CIX | Service-centre release, instant opt-out | SCI | DE | 0CIX | pain.001 | — | Not used |
| VIX | Service-centre release, instant opt-in | SCI | DE | 0VIX | pain.001 | — | Not used |
| XSA | Aareal maintenance files, upload | OTH | BIL | 0XSA | MISC | — | Not used |
| XWS | Aareal maintenance files, upload (Wodis only) | OTH | BIL | 0XWS | MISC | — | Not used |
| 2.5 | What it does | Service | Scope | Option | Message | BankConnector | |
|---|---|---|---|---|---|---|---|
| C53 | End-of-day account statement | EOP | DE | — | camt.053 | ZIP | Supported |
| C52 | Intraday transactions, not yet booked | STM | DE | — | camt.052 | ZIP | Supported |
| C54 | Debit and credit notification, batch detail | STM | DE | — | camt.054 | ZIP | Supported |
| C5N | Credit advice for SEPA instant | STM | DE | SCI | camt.054 | ZIP | Supported |
| CIZ | Payment status report, instant credit transfer | REP | DE | SCI | pain.002 | ZIP | Supported |
| VPZ | Verification of payee status report | REP | DE | VOP | pain.002 | ZIP | Supported |
| STA | End-of-day statement, MT940 | EOP | DE | — | mt940 | — | Supported |
| VMK | Intraday transactions, MT942 | STM | DE | — | mt942 | — | Not used |
| BKA | Account statement as a signed PDF | EOP | DE | — | ZIP | Not used | |
| XSA | Aareal feedback and maintenance files | OTH | BIL | 0XSA | misc | ZIP | Not used |
| XWS | Aareal feedback files (Wodis only) | OTH | BIL | 0XWS | misc | ZIP | Not used |
The remaining twenty-one are key management and protocol housekeeping. They keep their three-letter names in 3.0 and carry no business transaction format. These are ours end to end: you never see one, and we run them for you during setup and afterwards.
Published by Aareal
Known changes.
Two deadlines already handled
Aareal has published both dates. We set new connections up against them from the start, and we move existing ones before they land.
AZV retires. Foreign payments move to a new order type, AXZ, on ISO 20022 instead of the old DTAZV file format. Anything still submitting AZV stops being accepted.
The old EBICS address stops answering. Clients still pointed at bk01kom.first-financial.biz must move to ebics.aareal-bank.com. The Host ID does not change.
Published by Aareal
Read out of the order-type schedule.
Verification of payee is already wired in
Aareal has separate order types for checked and unchecked submission, on both ordinary and instant credit transfers, plus a dedicated status report. All six are in the published schedule today.
| Rail | Opt in to the check | Opt out | Status report |
|---|---|---|---|
| SEPA credit transfer | CTV | CCT | VPZ |
| SEPA instant | CIV | CIP | VPZ |
| Service-centre release | VCX · VIX | CCX · CIX | VPZ |
If all of this looks like a lot · it does not have to be
Five steps to a live Aareal connection.
You do not need to know what any of the codes above mean. Our setup guide walks you through it one screen at a time.
- 1
Request the agreement from Aareal
EBICS starts with paperwork. We draft the email, you send it, and you tell us when it has gone. There is nothing to configure until the bank replies.
- 2
Set up and send your keys
Enter four values from the agreement Aareal returns. We already hold the ones that are public, so most of the form is filled in. Then one press generates your keys and sends the public halves.
- 3
Prove your identity on paper
EBICS confirms the key exchange on paper, by design. We print the initialisation letter carrying the fingerprints Aareal will check. You sign it by hand and post it.
- 4
Verify Aareal and go live
While you wait, we fetch Aareal's public keys on a schedule and check them against the hashes Aareal publishes. When that lands, you choose which approval policy governs payments here, and the connection switches on.
- 5
You are now in production with Aareal Bank
Payments go out as pain.001 and statements come back as camt.053. The connection runs unattended from here.
Sources — Aareal’s EBICS service page, its order-type schedule dated June 2026 and the EBICS specifications published by Die Deutsche Kreditwirtschaft. Host response measured 10 September 2026. BankConnector is not affiliated with Aareal Bank AG.