w3c / payment-method-credit-transfer

http://w3c.github.io/webpayments-methods-credit-transfer-direct-debit/
Other
11 stars 13 forks source link

authorizationToken to enable initiation by PISP #44

Closed CYV closed 7 years ago

CYV commented 7 years ago

The european regulation authorize regulated entities (Payment Initiation Service Provider) to initiate the payment under the mandate of the owner of the account. To enable this regulatory provision, the authorization token is set by the Payer's bank during the check-out process, put in the response and will be used shorly after in a bilateral mode between the PISP and the payer's bank (namend ASPSP in the european regulation, for Account Service Payment Service Provider).

mattsaxon commented 7 years ago

I've merged this PR, but I think we need to consider if the return of a token is part of a seperate PMI (not in a separate spec). I think the difference between Pull, Push and also Push Async are important dinstinctions, which are best 'flagged' with a seperate PMI, e.g. CT-Push, CT-Pull, CT-Push-Deferred