Germany · Hamburger Sparkasse · EBICS
Connect Haspa without learning EBICS.
A published order-type schedule mapped to EBICS 3.0, a 24:00 cut-off for electronic orders, and new bank keys on 16 September 2026. We handle the payments, the statements and every protocol step underneath.
The host, checked live
<ebicsHEVResponse xmlns="http://www.ebics.org/H000"> <ReturnCode>000000</ReturnCode> <ReportText>[EBICS_OK] OK</ReportText> <VersionNumber ProtocolVersion="H004">02.50</VersionNumber> <VersionNumber ProtocolVersion="H005">03.00</VersionNumber> </ebicsHEVResponse>
Published by the bank
The bank's imprint and annual report.
Bank details
| BIC | HASPDEHH |
| Bank code | 200 505 50 |
| Legal name | Hamburger Sparkasse AG |
| Registered office | Dammtorstraße 1, 20354 Hamburg |
| Register | HRB 80 691, Amtsgericht Hamburg |
| Owner | HASPA Finanzholding — 100%, a free savings bank |
Published by the bank
The bank's own documents, plus our live check of the host.
Access data
| EBICS address | https://hh7ebics.sparkasse-banking.de/ebicsweb/ebicsweb |
| Host ID | G87-ELKO |
| Protocol versions | H004 (02.50) and H005 (03.00) |
| Gateway operator | Finanz Informatik — one instance per institute |
| Bank key hashes | Four, published — X002 and cert, auth and encryption |
| Bank keys change | 16 Sep 2026 from ~09:00, then yearly |
| Distributed signature | Supported in full — and required for checked files |
| Statement formats | camt and MT — C53, C52, C54, STA, VMK |
| Same-day cut-off | 24:00 for an electronic order |
| Instant transfers | No cut-off — every day, around the clock |
The gateway is a Sparkassen-Finanzgruppe platform with one instance per institute, so the address and Host ID name the instance and are the same for every Haspa customer. Sending a sibling savings bank’s Host ID here returns a plain HTTP 404, not an EBICS error.
Published by the bank
Haspa's own schedule, issued August 2026.
Order types published by Haspa
| 2.5 | What it does | Dir | Message | Service | Scope | Option | Container |
|---|---|---|---|---|---|---|---|
| CCT | SEPA credit transfer, payee check opt-out | Send | pain.001 | SCT | — | VOO | — |
| CTV | SEPA credit transfer, payee check opt-in | Send | pain.001 | SCT | — | VOI | — |
| CIP | Instant credit transfer, opt-out | Send | pain.001 | SCI | — | VOO | — |
| CIV | Instant credit transfer, opt-in | Send | pain.001 | SCI | — | VOI | — |
| CCU | Same-day urgent transfer in euro | Send | pain.001 | XCT | DE | URG | — |
| AXZ | Foreign credit transfer, ISO 20022 | Send | pain.001 | XCT | DE | — | — |
| AZV | Foreign credit transfer, DTAZV — retiring | Send | dtazv | XCT | DE | — | — |
| CDD | SEPA core direct debit | Send | pain.008 | SDD | — | COR | — |
| CD1 | SEPA core direct debit, COR1 | Send | pain.008 | SDD | — | 0CD1 | — |
| CDB | SEPA B2B direct debit | Send | pain.008 | SDD | — | B2B | — |
| C55 | Recall a submitted direct debit | Send | camt.055 | SDD | DE | — | — |
| 2.5 | What it does | Dir | Message | Service | Scope | Option | Container |
|---|---|---|---|---|---|---|---|
| C53 | End-of-day account statement | Download | camt.053 | EOP | DE | — | ZIP |
| STA | End-of-day statement, SWIFT MT940 | Download | mt940 | EOP | DE | — | — |
| C52 | Intraday transactions, every 30 min 06:00–19:00 | Download | camt.052 | STM | DE | — | ZIP |
| VMK | Intraday transactions, SWIFT MT942 | Download | mt942 | STM | DE | — | — |
| C54 | Debit and credit notification, batch detail | Download | camt.054 | STM | DE | — | ZIP |
| CRZ | Payment status report, credit transfers | Download | pain.002 | REP | DE | SCT | ZIP |
| CIZ | Payment status report, instant transfers | Download | pain.002 | REP | DE | SCI | ZIP |
| VPZ | Payee verification result report | Download | pain.002 | REP | VOP | — | ZIP |
| CDZ | Payment status report, direct debits | Download | pain.002 | REP | DE | SDD | ZIP |
| C29 | Resolution of a recall request | Download | camt.029 | REP | DE | — | ZIP |
| BKA | Account statement as a signed PDF | Download | EOP | DE | — | ZIP |
Eleven more cover service-centre submission, foreign-exchange rates, direct-debit collection files and documentary credits.
The rest are key management and protocol housekeeping. You never see one — we run them during setup and afterwards.
Two payee-verification rules change how an automated flow has to behave. A file holding only one payment cannot use the opt-out form at all. And a checked file is authorised or cancelled through the distributed signature: signatures already present when you submit are discarded, and the file reaches the signature folder only once the result report is final.
BankConnector
What is built and shipped for this bank today.
What our engine produces
| Payment format | pain.001.001.03 |
| Also produced | pain.001.001.09 — live for other banks today |
| Rulebook | German DK Anlage 3 v3.9 / 2025-03 |
| Charge bearer | SLEV |
| Remittance limit | 140 characters |
| Name limit | 70 characters |
| Read back | camt.053, camt.052, camt.054, pain.002 — one format |
| Not supported | Direct debits |
Published by the bank
Dates the bank has announced. What we do about each one is ours.
Upcoming events in our register
The bank’s own EBICS keys are replaced, from around 09:00, and yearly from then on. Every client must fetch the new keys and confirm the published hashes or the connection stops. Your own keys are untouched.
The older SEPA format versions are withdrawn, AXZ replaces DTAZV for foreign payments, and addresses must be structured or hybrid. We produce pain.001.001.09 and have never produced DTAZV.
Every EBICS key pair has to reach 4096 bits. New keys and a new initialisation letter.
If all of this looks like a lot · it does not have to be
Five steps to a live Haspa connection.
You do not need to know what any of the codes above mean. Our setup guide walks you through it one screen at a time.
- 1
Request the agreement from Haspa
EBICS starts with paperwork. We draft the email, you send it, and you tell us when it has gone. There is nothing to configure until the bank replies.
- 2
Set up and send your keys
Enter the values from the agreement Haspa returns. We already hold the ones that are public, so most of the form is filled in. Then one press generates your three key pairs and sends the public halves.
- 3
Prove your identity on paper
EBICS confirms the key exchange on paper, by design. We print the initialisation letter carrying the fingerprints Haspa will check. You sign it by hand and send it.
- 4
Verify Haspa and go live
While you wait, we fetch the bank's public keys and check them against the fingerprints it gives you over a separate channel. When that lands, you choose which approval policy governs payments here, and the connection switches on.
- 5
You are now in production with Haspa
Payments go out as pain.001 and statements come back as camt. The connection runs unattended from here.
Sources — Haspa’s EBICS page, its order-type schedule and key-rotation notice both issued August 2026, its EBICS implementation document for payee verification, its terms for remote data transmission, its price and services list, and the EBICS specifications published by Die Deutsche Kreditwirtschaft. BankConnector is not affiliated with Hamburger Sparkasse AG.
How BankConnector handles the November 2026 pain.001.001.09 migration for Haspa →