Bank integration · OP Financial Group
How to connect your ERP or system to OP.
OP Web Services, often called pankkiyhteyskanava in Finland, is the cornerstone of corporate bank integrations in the Finnish market. It is highly standardized and stable, and fundamentally different from a User ID and PIN setup. OP runs on a Public Key Infrastructure with signed SOAP, GZIP payloads and ISO 20022 messages. BankConnector handles the certificate flow, the signing, the renewals and the formats, so your product just calls one JSON API.
OP connectivity profile
Formats, security, setup.
Connectivity
OP Web Services.
A traditional SOAP web service over HTTPS. Each SOAP envelope carries an ApplicationRequest or ApplicationResponse, and the actual business payload (ISO 20022 pain.001, camt.053 and the rest) travels GZIP-compressed inside it. Every request is signed with XMLDSIG using your OP-issued client certificate.
One integration, every local OP bank
OP Financial Group is a cooperative of over 100 independent local banks running on one unified core. One integration to the central OP Web Services gateway covers a corporate customer at any local OP cooperative.
PKI, not passwords
You sign a Web Services agreement and OP issues a User ID and a one-time Transfer Key (Siirtoavain). BankConnector generates the key pair, submits a CSR to OP's Certificate Authority and stores the returned X.509 client certificate.
Renewals on autopilot
Certificates expire. BankConnector renews them before they do, and stays ahead of OP's crypto upgrades, including the SHA-1 to SHA-256 migration mandated by November 2025.
Why integration quality matters
Anyone can POST a SOAP envelope to OP. Doing it properly is the hard part.
There are a lot of shortcuts vendors take to get a green checkmark in a demo. Skip the signature check. Fire-and-forget the upload. Let a certificate quietly expire. It works right up until the day it does not, and with payments, that day means real money in the wrong place.
We do not build it that way. If you care about security and usability the way we do, you do the unglamorous work:
Verify bank signatures
Every ApplicationResponse and statement file from OP is cryptographically verified before we trust a single byte of it. If a file is not signed by OP, it does not enter your reconciliation.
Sign our own requests properly
Every SOAP request is XMLDSIG-signed with the private key tied to your OP-issued client certificate. Keys are encrypted at rest and never logged. Your signing material is treated like the crown jewels, because it is.
Rotate certificates before they expire
OP client certificates expire on a schedule. BankConnector tracks expiration and renews automatically, so the integration never breaks at 03:00 on a Monday because a certificate quietly aged out.
Handle duplicates, every time
Network blips, retries, and double-clicks happen. We use end-to-end identifiers and idempotency checks so a payment is submitted once. A resend never becomes a second debit.
Reconcile status, do not assume it
We do not mark a payment done because the SOAP call returned 200. We read OP's pain.002 acknowledgements and camt statements back, match them to what we sent, and tell you the real state: accepted, rejected, or pending, with the reason.
Stay ahead of crypto upgrades
OP is forcing all software vendors from SHA-1 to SHA-256 by November 2025. We move with the bank, not after the bank, so your integration is compliant before the deadline matters.
The lazy version of this integration is faster to ship. Ours is the one you actually want sitting between your ERP and your bank account.
How an OP integration goes live
From signed agreement to first reconciled payment.
- 1. Signed agreement. The customer signs a Web Services agreement with their local OP cooperative bank, listing the accounts and services.
- 2. Transfer Key and User ID. OP issues a User ID and a one-time Transfer Key (Siirtoavain). You enter them in BankConnector.
- 3. Certificate exchange. BankConnector generates a private/public key pair, uses the Transfer Key to authenticate a CSR to OP's Certificate Authority and stores the returned X.509 client certificate.
- 4. Production. From here every SOAP request is signed automatically. The same integration covers any local OP cooperative bank.Wait?? Legacy Bank Integrators really charges thousands for this process?
Things teams ask about OP
Common questions.
What do I need to set up OP Web Services?
A Web Services agreement with your local OP cooperative bank, a User ID and a one-time Transfer Key. BankConnector handles the CSR, the certificate exchange and every signed request from there.
Does one integration cover every local OP bank?
Yes. The 100+ local OP cooperative banks share one core and one central Web Services gateway. One integration covers customers at any of them.
Which formats does OP support?
pain.001 SEPA and international credit transfers, pain.002 status reports, camt.053 end-of-day statements and camt.054 reference payment confirmations.
How does authentication work?
PKI. BankConnector generates a key pair, uses the Transfer Key to authenticate a CSR to OP's Certificate Authority and receives an X.509 client certificate. Every SOAP request is XMLDSIG-signed with the matching private key.
What happens when certificates expire?
BankConnector renews them automatically before expiration, so the integration never breaks because of a stale certificate.
What about the SHA-1 to SHA-256 migration?
OP is requiring all software vendors to upgrade to SHA-256 by November 2025. BankConnector already signs with SHA-256, so customers are compliant before the deadline.
Ready to connect your OP accounts?
Talk to us about your accounts and your local OP cooperative. We will tell you exactly what OP needs you to sign and how soon you can be live.