Bank integration · OP Financial Group

How to connect your ERP or system to OP.

OP Web Services, often called pankkiyhteyskanava in Finland, is the cornerstone of corporate bank integrations in the Finnish market. It is highly standardized and stable, and fundamentally different from a User ID and PIN setup. OP runs on a Public Key Infrastructure with signed SOAP, GZIP payloads and ISO 20022 messages. BankConnector handles the certificate flow, the signing, the renewals and the formats, so your product just calls one JSON API.

OP connectivity profile

Formats, security, setup.

Bank
OP Financial Group (Osuuspankki)
Markets
Finland · all local OP cooperative banks via one central gateway
Connectivity
OP Web Services (pankkiyhteyskanava) · SOAP over HTTPS · GZIP payload
Outgoing payments
pain.001 SEPA Credit Transfers · International payments
Status reports
pain.002 acknowledgements and rejections
Statements
camt.053 end-of-day · camt.054 reference payment confirmations
Security
X.509 client certificate · XMLDSIG-signed SOAP · SHA-256 (mandatory by November 2025)
Onboarding
Web Services agreement + Transfer Key, CSR, certificate exchange, then live
Standard origin
Joint OP, Nordea and Danske Web Services specification (v1.05, October 2008)

Connectivity

OP Web Services.

A traditional SOAP web service over HTTPS. Each SOAP envelope carries an ApplicationRequest or ApplicationResponse, and the actual business payload (ISO 20022 pain.001, camt.053 and the rest) travels GZIP-compressed inside it. Every request is signed with XMLDSIG using your OP-issued client certificate.

One integration, every local OP bank

OP Financial Group is a cooperative of over 100 independent local banks running on one unified core. One integration to the central OP Web Services gateway covers a corporate customer at any local OP cooperative.

PKI, not passwords

You sign a Web Services agreement and OP issues a User ID and a one-time Transfer Key (Siirtoavain). BankConnector generates the key pair, submits a CSR to OP's Certificate Authority and stores the returned X.509 client certificate.

Renewals on autopilot

Certificates expire. BankConnector renews them before they do, and stays ahead of OP's crypto upgrades, including the SHA-1 to SHA-256 migration mandated by November 2025.

Why integration quality matters

Anyone can POST a SOAP envelope to OP. Doing it properly is the hard part.

There are a lot of shortcuts vendors take to get a green checkmark in a demo. Skip the signature check. Fire-and-forget the upload. Let a certificate quietly expire. It works right up until the day it does not, and with payments, that day means real money in the wrong place.

We do not build it that way. If you care about security and usability the way we do, you do the unglamorous work:

Verify bank signatures

Every ApplicationResponse and statement file from OP is cryptographically verified before we trust a single byte of it. If a file is not signed by OP, it does not enter your reconciliation.

Sign our own requests properly

Every SOAP request is XMLDSIG-signed with the private key tied to your OP-issued client certificate. Keys are encrypted at rest and never logged. Your signing material is treated like the crown jewels, because it is.

Rotate certificates before they expire

OP client certificates expire on a schedule. BankConnector tracks expiration and renews automatically, so the integration never breaks at 03:00 on a Monday because a certificate quietly aged out.

Handle duplicates, every time

Network blips, retries, and double-clicks happen. We use end-to-end identifiers and idempotency checks so a payment is submitted once. A resend never becomes a second debit.

Reconcile status, do not assume it

We do not mark a payment done because the SOAP call returned 200. We read OP's pain.002 acknowledgements and camt statements back, match them to what we sent, and tell you the real state: accepted, rejected, or pending, with the reason.

Stay ahead of crypto upgrades

OP is forcing all software vendors from SHA-1 to SHA-256 by November 2025. We move with the bank, not after the bank, so your integration is compliant before the deadline matters.

The lazy version of this integration is faster to ship. Ours is the one you actually want sitting between your ERP and your bank account.

How an OP integration goes live

From signed agreement to first reconciled payment.

  1. 1. Signed agreement. The customer signs a Web Services agreement with their local OP cooperative bank, listing the accounts and services.
  2. 2. Transfer Key and User ID. OP issues a User ID and a one-time Transfer Key (Siirtoavain). You enter them in BankConnector.
  3. 3. Certificate exchange. BankConnector generates a private/public key pair, uses the Transfer Key to authenticate a CSR to OP's Certificate Authority and stores the returned X.509 client certificate.
  4. 4. Production. From here every SOAP request is signed automatically. The same integration covers any local OP cooperative bank.Wait?? Legacy Bank Integrators really charges thousands for this process?

Things teams ask about OP

Common questions.

What do I need to set up OP Web Services?

A Web Services agreement with your local OP cooperative bank, a User ID and a one-time Transfer Key. BankConnector handles the CSR, the certificate exchange and every signed request from there.

Does one integration cover every local OP bank?

Yes. The 100+ local OP cooperative banks share one core and one central Web Services gateway. One integration covers customers at any of them.

Which formats does OP support?

pain.001 SEPA and international credit transfers, pain.002 status reports, camt.053 end-of-day statements and camt.054 reference payment confirmations.

How does authentication work?

PKI. BankConnector generates a key pair, uses the Transfer Key to authenticate a CSR to OP's Certificate Authority and receives an X.509 client certificate. Every SOAP request is XMLDSIG-signed with the matching private key.

What happens when certificates expire?

BankConnector renews them automatically before expiration, so the integration never breaks because of a stale certificate.

What about the SHA-1 to SHA-256 migration?

OP is requiring all software vendors to upgrade to SHA-256 by November 2025. BankConnector already signs with SHA-256, so customers are compliant before the deadline.

Ready to connect your OP accounts?

Talk to us about your accounts and your local OP cooperative. We will tell you exactly what OP needs you to sign and how soon you can be live.