omnibank / bridge
Omnibank Bridge: bank aggregation through Bridge API v3 (bridgeapi.io) - its Connect sessions for the consent, accounts, balances, transactions, item webhooks.
Requires
- php: >=8.2
- glitchr/omnibank: ^1.0@dev
- symfony/http-client-contracts: ^3.0
Requires (Dev)
- phpunit/phpunit: ^11.0
- symfony/http-client: ^6.4|^7.0|^8.0
Suggests
- symfony/http-client: The HTTP client the gateway talks through
Provides
None
Conflicts
None
Replaces
None
This package is auto-updated.
Last update: 2026-10-03 16:12:01 UTC
README
Bridge (bridgeapi.io, by Perspecteev) for glitchr/omnibank,
its API v3: the user connects their banks in a Bridge Connect session; their accounts, balances
and transactions are read with the user's access token; item.* webhooks say when the data is
fresh or the consent must be renewed.
Unverified. Written from Bridge's published v3 documentation and recorded answers (
Tests/Fixtures); it has not yet been run against a real Bridge sandbox. Try it with real keys (docker compose run --rm omnibank connect bridgeinglitchr/omnibank'sdocker/) before relying on it, and drop this notice once it holds - the webhook signature above all.
omnibank: gateways: banks: factory: bridge options: client_id: '%env(BRIDGE_CLIENT_ID)%' client_secret: '%env(BRIDGE_CLIENT_SECRET)%' version: '2025-01-15' # Bridge-Version webhook_secret: '%env(BRIDGE_WEBHOOK_SECRET)%' # for notify() callback_url: 'https://app.example/bank/back' # when connect() is given no return URL country_code: FR
Every call carries Client-Id, Client-Secret and Bridge-Version; a user's, the user's token.
connect()- the first time,POST /v3/aggregation/userscreates the Bridge user (itsexternal_user_idthe state's, or one made up);POST /v3/aggregation/authorization/tokengives its token;POST /v3/aggregation/connect-sessions(the return URL ascallback_url, the state'suser_emailwhen there is one) gives the page. The state keepsuser_uuid,external_user_id,access_token,expires_at: keep the connection. When the consent is NEEDS_RENEWAL and the state hasitem_id, the session is for that item.accounts()-GET /v3/aggregation/accounts, every page;balances()-GET /v3/aggregation/accounts/{id}:balance(booked),instant_balance(instant).transactions()-GET /v3/aggregation/transactions?account_id=&since=&until=&limit=, every page (pagination.next_uri); future and deleted transactions left out;provider_descriptionis the label. A token past itsexpires_atis renewed for the call.notify()-item.*events: the item (content.item_id) asconnectionId; a status the user must act on - 402 (credentials), 429 (action on the bank's site), 430 (password), 1010 (SCA to renew), 1100 (pro account to validate) - is NEEDS_RENEWAL, a deleted item REVOKED, any other status ACTIVE. Other events come back with consent NONE.- No
transfer()in this version.
Webhook signature - an assumption. This package reads BridgeApi-Signature as
v1=<HMAC-SHA256 of the raw body with the webhook secret, hex>, several comma-separated while a
secret is rotated, the hex in either case. Check it against a real sandbox webhook.
A 5xx, a 429 or a network failure is an UnavailableException, never an empty list.
Credentials: in Bridge's dashboard (dashboard.bridgeapi.io), a sandbox application's
client_id and client_secret, its callback URL registered, and a webhook on the item.*
events with its secret.
License: LGPL-3.0-or-later.