Yes, digiRunner supports the OAuth 2.0 authorization framework and allows configuration of expiration period and validity times for access token & refresh token, which fully complies with the open banking regulations in Taiwan.
You can manage JWT settings for your APIs simply through the Admin Console of digiRunner. Configurations such as JWS for requests and JWE encryption for responses can all be done through the Admin Console with ease.
Yes, digiRunner provides API Portal (as shown in the figure below), which is your exclusive API Store. Your internal/external API users can request an account and API authorization through the digiRunner API Portal. You can review and approve the requests through the Admin Console.
The core of open banking is to share data to third-parties (Third-Party Service Providers, TSPs) with consent of bank customers (consumers) through an open application programming interface (OpenAPI).
Data openness will accelerate innovative application and development of financial technology, create better user experience, expand business scenarios and ecosystems, and further provide customers with more convenient and diversified services.