← All supported banks

Germany  ·  Hamburger Sparkasse  ·  EBICS

Connect Haspa without learning EBICS.

A published order-type schedule mapped to EBICS 3.0, a 24:00 cut-off for electronic orders, and new bank keys on 16 September 2026. We handle the payments, the statements and every protocol step underneath.

The host, checked live

<ebicsHEVResponse xmlns="http://www.ebics.org/H000">
  <ReturnCode>000000</ReturnCode>
  <ReportText>[EBICS_OK] OK</ReportText>
  <VersionNumber ProtocolVersion="H004">02.50</VersionNumber>
  <VersionNumber ProtocolVersion="H005">03.00</VersionNumber>
</ebicsHEVResponse>
Host ID
G87-ELKO
EBICS 2.5
H004
EBICS 3.0
H005
Answered in
0.14 s

Published by the bank

The bank's imprint and annual report.

Bank details

BICHASPDEHH
Bank code200 505 50
Legal nameHamburger Sparkasse AG
Registered officeDammtorstraße 1, 20354 Hamburg
RegisterHRB 80 691, Amtsgericht Hamburg
OwnerHASPA Finanzholding — 100%, a free savings bank

Published by the bank

The bank's own documents, plus our live check of the host.

Access data

EBICS addresshttps://hh7ebics.sparkasse-banking.de/ebicsweb/ebicsweb
Host IDG87-ELKO
Protocol versionsH004 (02.50) and H005 (03.00)
Gateway operatorFinanz Informatik — one instance per institute
Bank key hashesFour, published — X002 and cert, auth and encryption
Bank keys change16 Sep 2026 from ~09:00, then yearly
Distributed signatureSupported in full — and required for checked files
Statement formatscamt and MT — C53, C52, C54, STA, VMK
Same-day cut-off24:00 for an electronic order
Instant transfersNo cut-off — every day, around the clock

The gateway is a Sparkassen-Finanzgruppe platform with one instance per institute, so the address and Host ID name the instance and are the same for every Haspa customer. Sending a sibling savings bank’s Host ID here returns a plain HTTP 404, not an EBICS error.

Published by the bank

Haspa's own schedule, issued August 2026.

Order types published by Haspa

Send
2.5What it doesDirMessageServiceScopeOptionContainer
CCTSEPA credit transfer, payee check opt-outSendpain.001SCTVOO
CTVSEPA credit transfer, payee check opt-inSendpain.001SCTVOI
CIPInstant credit transfer, opt-outSendpain.001SCIVOO
CIVInstant credit transfer, opt-inSendpain.001SCIVOI
CCUSame-day urgent transfer in euroSendpain.001XCTDEURG
AXZForeign credit transfer, ISO 20022Sendpain.001XCTDE
AZVForeign credit transfer, DTAZV — retiringSenddtazvXCTDE
CDDSEPA core direct debitSendpain.008SDDCOR
CD1SEPA core direct debit, COR1Sendpain.008SDD0CD1
CDBSEPA B2B direct debitSendpain.008SDDB2B
C55Recall a submitted direct debitSendcamt.055SDDDE
Download
2.5What it doesDirMessageServiceScopeOptionContainer
C53End-of-day account statementDownloadcamt.053EOPDEZIP
STAEnd-of-day statement, SWIFT MT940Downloadmt940EOPDE
C52Intraday transactions, every 30 min 06:00–19:00Downloadcamt.052STMDEZIP
VMKIntraday transactions, SWIFT MT942Downloadmt942STMDE
C54Debit and credit notification, batch detailDownloadcamt.054STMDEZIP
CRZPayment status report, credit transfersDownloadpain.002REPDESCTZIP
CIZPayment status report, instant transfersDownloadpain.002REPDESCIZIP
VPZPayee verification result reportDownloadpain.002REPVOPZIP
CDZPayment status report, direct debitsDownloadpain.002REPDESDDZIP
C29Resolution of a recall requestDownloadcamt.029REPDEZIP
BKAAccount statement as a signed PDFDownloadpdfEOPDEZIP

Eleven more cover service-centre submission, foreign-exchange rates, direct-debit collection files and documentary credits.

CCXVCXCDXC2XDKIEABEADAIAAIDAKAAKD

The rest are key management and protocol housekeeping. You never see one — we run them during setup and afterwards.

INIHIAHPBHCAHCSPUBSPRHAAHTDHKDHPDHEVHACPTKHVEHVSHVDHVTHVUHVZ

Two payee-verification rules change how an automated flow has to behave. A file holding only one payment cannot use the opt-out form at all. And a checked file is authorised or cancelled through the distributed signature: signatures already present when you submit are discarded, and the file reaches the signature folder only once the result report is final.

BankConnector

What is built and shipped for this bank today.

What our engine produces

Payment formatpain.001.001.03
Also producedpain.001.001.09 — live for other banks today
RulebookGerman DK Anlage 3 v3.9 / 2025-03
Charge bearerSLEV
Remittance limit140 characters
Name limit70 characters
Read backcamt.053, camt.052, camt.054, pain.002 — one format
Not supportedDirect debits

Published by the bank

Dates the bank has announced. What we do about each one is ours.

Upcoming events in our register

  1. The bank’s own EBICS keys are replaced, from around 09:00, and yearly from then on. Every client must fetch the new keys and confirm the published hashes or the connection stops. Your own keys are untouched.

  2. The older SEPA format versions are withdrawn, AXZ replaces DTAZV for foreign payments, and addresses must be structured or hybrid. We produce pain.001.001.09 and have never produced DTAZV.

  3. Every EBICS key pair has to reach 4096 bits. New keys and a new initialisation letter.

If all of this looks like a lot  ·  it does not have to be

Five steps to a live Haspa connection.

You do not need to know what any of the codes above mean. Our setup guide walks you through it one screen at a time.

  1. 1

    Request the agreement from Haspa

    EBICS starts with paperwork. We draft the email, you send it, and you tell us when it has gone. There is nothing to configure until the bank replies.

  2. 2

    Set up and send your keys

    Enter the values from the agreement Haspa returns. We already hold the ones that are public, so most of the form is filled in. Then one press generates your three key pairs and sends the public halves.

  3. 3

    Prove your identity on paper

    EBICS confirms the key exchange on paper, by design. We print the initialisation letter carrying the fingerprints Haspa will check. You sign it by hand and send it.

  4. 4

    Verify Haspa and go live

    While you wait, we fetch the bank's public keys and check them against the fingerprints it gives you over a separate channel. When that lands, you choose which approval policy governs payments here, and the connection switches on.

  5. 5

    You are now in production with Haspa

    Payments go out as pain.001 and statements come back as camt. The connection runs unattended from here.

Sources — Haspa’s EBICS page, its order-type schedule and key-rotation notice both issued August 2026, its EBICS implementation document for payee verification, its terms for remote data transmission, its price and services list, and the EBICS specifications published by Die Deutsche Kreditwirtschaft. BankConnector is not affiliated with Hamburger Sparkasse AG.

How BankConnector handles the November 2026 pain.001.001.09 migration for Haspa →

← Back to all supported banks