> ## Documentation Index
> Fetch the complete documentation index at: https://docs.yapily.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create Hosted Consent Request

> Used to initiate a consent request using Yapily Hosted Pages.

<Info>Learn more: [Hosted Consent Pages](/tools-and-services/hosted-pages/overview)</Info>


## OpenAPI

````yaml /openapi-converted.json post /hosted/consent-requests
openapi: 3.0.1
info:
  description: >-
    The Yapily API enables connections between your application and users'
    banks. For more information check out our [documentation](/introduction).


    In particular, make sure to view our [Getting
    Started](/getting-started/get-started) steps if this is your first time
    here.


    While testing the API, our list of [sandbox
    credentials](/resources/sandbox/sandbox-credentials) maybe useful.
  title: Yapily API
  version: 12.3.4
  contact:
    name: Yapily Support
    url: https://docs.yapily.com/resources/support
    email: support@yapily.com
servers:
  - url: https://api.yapily.com
security:
  - basicAuth: []
tags:
  - description: >-
      The `Application` is the base entity that is used to interact with the API
      and contains a collection of `Institution` objects. You can have multiple
      Applications associated with your account e.g. a production application
      with live access to each `Institution` and a development application with
      access to sandboxes.
    name: Application
  - description: >-
      The Users endpoints are used to manage each user (otherwise known as the
      PSU) in Yapily. Each user belongs to an Application and as a consequence,
      so do each `Consent` created for a particular `User`.
    name: Users
  - description: >-
      An `Institution` object represents any Account Serving Payment Servicing
      Provider (ASPSP) that has been integrated and is accessible through the
      Yapily APIs (ASPSPs are entities that publish Read/Write APIs to permit,
      with customer consent, payments initiated by third party providers and/or
      make their customers financial data available to third party providers via
      their API endpoints).


      Any one of the following would be represented as Institution:


      - Traditional banks e.g. Santander

      - Neo-banks e.g. Monzo

      - Building societies e.g. Cumberland Building Society
    name: Institutions
  - description: >-
      The Consents endpoints are used to manage each `Consent` created by Yapily
      in response to an authorisation created for a user.


      The `Consent` object contains data that identifies a user's consent for a
      specific `Institution` within a Yapily application. Other than the id of
      the consent, the `institution-id` for the corresponding `Institution` and
      the user identifiers (`user-uuid` and `application-user-id`), it contains
      various details that indicates how the `Consent` can be used.
    name: Consents
  - description: >-
      Before calling [Financial Data](#yapily-api-financial-data) or
      [Payments](#yapily-api-payments) endpoints, a consent from an end-user
      must be obtained.


      Consents are valid for up to 90 days for Financial Data endpoints and have
      a single-use for Payment endpoints i.e. a new consent must be obtained for
      each payment.


      NOTE: A user consent is also referred to as an 'Authorisation'.
    name: Authorisations
  - description: >-
      In order to access a user's Financial Data, you are required to request an
      [Authorisation](#tag/Authorisations) from the user to share the account
      information the bank has. Once a `consent-token` is obtained, you can call
      the necessary Financial Data endpoint(s) to retrieve the user's data.
    name: Financial Data
  - description: >-
      In order to make a Payment on behalf of a user, you are required to
      request an [Authorisation](#tag/Authorisations) from the user to authorise
      the user's account to make the payment from. Once a `consent-token` is
      obtained, you can call the necessary Payments endpoint(s) to execute a
      payment.
    name: Payments
  - description: >+
      The Notifications endpoints provide an interactive way for user to receive
      notifications according to different event-types. This feature is
      currently in private beta. Please reach out if you require access. 

    name: Notifications
  - description: >-
      Variable Recurring Payments enables transfer of money between accounts
      held by the same person or transfer of money for business payments. 


      In order to make Sweeping Variable Recurring Payments on behalf of a user,
      you are required to request an [Consent](#tag/Authorisations) from the
      user by calling the Sweeping Consent endpoint to authorise the user's
      account to make the payment. Once a `consent-token` is obtained, you can
      call the Payments endpoint to execute the Sweeping Variable Recurring
      Payments transaction. Before executing the payment, you have the option to
      confirm availability of funds in the user's account by calling the Funds
      Confirmation endpoint. 


      See [VRP Payments](/payments/vrps/additional-information) for more
      information.
    name: Variable Recurring Payments
  - description: Hosted Payment Pages endpoints for payments products
    name: Hosted Payment Pages
  - description: Hosted Consent Pages endpoints for data products
    name: Hosted Consent Pages
  - description: >-
      The constraints endpoints can be used to retrieve institution specific
      data requirements and rules that will apply when performing other
      operations.
    name: Constraints
  - description: >-
      Application Management endpoints help with creating and managing client
      sub-applications.
    name: Application Management
  - description: 'Data Plus endpoints enable our customers to enrich transaction data. '
    name: Data Plus
  - description: Webhook endpoints
    name: Webhooks
  - description: Application Beneficiaries Endpoints
    name: Application Beneficiaries
  - description: User Beneficiaries Endpoints
    name: User Beneficiaries
paths:
  /hosted/consent-requests:
    post:
      tags:
        - Hosted Consent Pages
      summary: Create Hosted Consent Request
      description: Used to initiate a consent request using Yapily Hosted Pages.
      operationId: createHostedConsentRequest
      parameters:
        - $ref: '#/components/parameters/SubAppHeader'
      requestBody:
        content:
          application/json;charset=UTF-8:
            examples:
              Create Hosted Consent Request:
                $ref: '#/components/examples/create-hosted-consent-request'
            schema:
              $ref: '#/components/schemas/CreateHostedConsentRequest'
        required: true
      responses:
        '201':
          content:
            application/json;charset=UTF-8:
              examples:
                Create Hosted Consent Request Response:
                  $ref: '#/components/examples/create-hosted-consent-response'
              schema:
                $ref: '#/components/schemas/ApiResponseOfCreateHostedConsentRequest'
          description: Created
        '400':
          content:
            application/json;charset=UTF-8:
              examples:
                400 Error Response:
                  $ref: '#/components/examples/400-error-response'
              schema:
                $ref: '#/components/schemas/ApiResponseError'
          description: Bad Request
        '401':
          content:
            application/json;charset=UTF-8:
              examples:
                401 Error Response:
                  $ref: '#/components/examples/401-error-response'
              schema:
                $ref: '#/components/schemas/ApiResponseError'
          description: Unauthorized. Credentials are missing or invalid
        '500':
          content:
            application/json;charset=UTF-8:
              examples:
                500 Error Response:
                  $ref: '#/components/examples/500-error-response'
              schema:
                $ref: '#/components/schemas/ApiResponseError'
          description: Unexpected Error
        default:
          content:
            application/json;charset=UTF-8:
              examples:
                Error Response:
                  $ref: '#/components/examples/error-response-code-401'
              schema:
                $ref: '#/components/schemas/ApiResponseError'
          description: Error Response
components:
  parameters:
    SubAppHeader:
      description: The sub-application ID to which event type is being subscribed to
      in: header
      name: sub-application
      required: false
      schema:
        type: string
        format: uuid
  examples:
    create-hosted-consent-request:
      description: Create Hosted Consent Request
      value:
        userId: ca412fdf-5a30-43a2-88b7-5964a24a8e55
        applicationUserId: string
        institutionIdentifiers:
          institutionId: modelo-sandbox
          institutionCountryCode: GB
        userSettings:
          language: en
          location: GB
        redirectUrl: https://tpp-application.com/
        authorisationExpiresAt: '2021-06-10T11:36:54.887Z'
        oneTimeToken: false
        accountRequest:
          transactionFrom: '2023-07-01T00:00:00.000Z'
          transactionTo: '2023-08-01T00:00:00.000Z'
          expiresAt: '2023-11-01T00:00:00.000Z'
          featureScope:
            - ACCOUNTS
            - ACCOUNT
            - ACCOUNT_BALANCES
            - ACCOUNT_TRANSACTIONS
            - IDENTITY
    create-hosted-consent-response:
      description: Create Hosted Consent Response
      value:
        meta:
          tracingId: 2dbfd85b4f2940c6a206e96dd90e52d0
        data:
          consentRequestId: 507e515f-c22d-4bab-9801-606c94e7f749
          userId: 3ddf5dd0-aa48-4d0f-baa7-fa057e9e911d
          applicationUserId: string
          applicationId: 64949de6-6510-4d70-9500-d4aa094c506c
          institutionIdentifiers:
            institutionId: modelo-sandbox
            institutionCountryCode: GB
          userSettings:
            language: en
            location: GB
          redirectUrl: https://tpp-application.com/
          accountRequestDetails:
            featureScope:
              - ACCOUNTS
              - ACCOUNT
              - ACCOUNT_BALANCES
              - ACCOUNT_TRANSACTIONS
              - IDENTITY
          hostedUrl: https://prototypes.yapily.com/auth-link1.html
          createdAt: '2024-09-13T11:14:04.766Z'
          authorisationExpiresAt: '2024-09-13T11:24:04.000Z'
    400-error-response:
      description: 400 Error
      value:
        error:
          tracingId: 0c2d0973bdd24224a65e5d0f7d1b6154
          code: 400
          status: BAD_REQUEST
          supportUrl: https://support.yapily.com/
          source: YAPILY
          issues:
            - type: BAD_REQUEST
              code: 10600
              message: >-
                The server could not understand the request due to invalid
                syntax
    401-error-response:
      description: 401 Error
      value:
        error:
          tracingId: 0c2d0973bdd24224a65e5d0f7d1b6154
          code: 401
          status: UNAUTHORIZED
          supportUrl: https://support.yapily.com/
          source: YAPILY
          issues:
            - type: CREDENTIALS
              code: 10700
              message: Authorization header invalid or credentials not authenticated
    500-error-response:
      description: 500 Error
      value:
        error:
          tracingId: 0c2d0973bdd24224a65e5d0f7d1b6154
          code: 500
          status: INTERNAL SERVER ERROR
          supportUrl: https://support.yapily.com/
          source: YAPILY
          issues:
            - type: INTERNAL_SERVER_ERROR
              code: 11000
              message: Unexpected server error
    error-response-code-401:
      description: Error Response
      value:
        error:
          code: 401
          status: UNAUTHORIZED
          message: Full authentication is required to access this resource
  schemas:
    CreateHostedConsentRequest:
      required:
        - redirectUrl
        - institutionIdentifiers
      type: object
      properties:
        userId:
          type: string
          format: uuid
          description: >-
            __Conditional__. Yapily Identifier for the `User` returned by the
            create user step POST /users. You must provide either a `userId` or
            `applicationUserId`.
        applicationUserId:
          type: string
          description: >-
            __Conditional__. Your own `User` reference. This field allows you to
            use your own unique references for individual users. Where the
            `User` reference doesn't have an associated Yapily `userId`, a new
            `userId` is created and linked to it. You must provide either a
            `userId` or `applicationUserId`.
        institutionIdentifiers:
          $ref: '#/components/schemas/InstitutionIdentifiers'
        userSettings:
          $ref: '#/components/schemas/UserSettings'
        redirectUrl:
          type: string
          description: >-
            URL of your server to redirect the user after completion of the
            consent flow.
          example: https://tpp-application.com
        oneTimeToken:
          type: boolean
          description: >-
            Used to receive a oneTimeToken rather than a consentToken at the
            redirectUrl for additional security.
          example: 'false'
        accountRequest:
          $ref: '#/components/schemas/HostedAccountRequest'
    ApiResponseOfCreateHostedConsentRequest:
      type: object
      properties:
        meta:
          $ref: '#/components/schemas/ResponseMeta'
        data:
          $ref: '#/components/schemas/HostedConsentRequestResponse'
    ApiResponseError:
      type: object
      properties:
        error:
          $ref: '#/components/schemas/ApiError'
        raw:
          deprecated: true
          type: array
          items:
            $ref: '#/components/schemas/RawResponse'
      description: >-
        Used to return errors from the bank from each request


        - `400` - Returned by any `POST` endpoint when the body does not conform
        to the contract

        - `401` - Returned by any endpoint when an invalid `authToken` is used
        for authentication

        - `403` - Returned by any [Financial
        Data](/api-reference#financial-data) and any
        [Payments](/api-reference#payments) endpoint when the `Consent` is no
        longer authorised to access financial data or to make a payment

        - `404` - Returned by any endpoint where there are path parameters and
        the path parameters supplied are unable to find the desired resource

        - `409` - Returned by any `POST` endpoint when creating a resource that
        conflicts with any other existing resource e.g. [Create
        User](/api-reference/addUser)

        - `424` - Returned by any [Financial
        Data](/api-reference#financial-data) and any
        [Payments](/api-reference#payments) endpoint when the feature to be
        accessed is not supported by the `Institution`.

        - `500` - Returned by any endpoint when Yapily is down. If you encounter
        any false positives, please [notify us](mailto:support@yapily.com)
      example:
        error:
          tracingId: 74b13ce8ed51419f92c5d609e04532de
          code: 424
          institutionError:
            errorMessage: >-
              {"Code":"500 Internal Server
              Error","Id":"5ff8d331-4282-41e0-b5ef-1ac9ac39f009","Message":"Technical
              Error. Please try again
              later","Errors":[{"ErrorCode":"UK.OBIE.UnexpectedError","Message":"There
              was a problem processing your request. Please try again later"}]}
            httpStatusCode: 500
          source: INSTITUTION
          status: FAILED_DEPENDENCY
    InstitutionIdentifiers:
      description: >-
        Specifies the institution requirements for making the payment. Skips the
        bank selection screen in payment flow if the `institutionId` and
        `institutionCountryCode` are provided.
      type: object
      required:
        - institutionCountryCode
      properties:
        institutionId:
          type: string
          description: >-
            Yapily identifier which identifies the `Institution` the payment
            request is sent to.
        institutionCountryCode:
          type: string
          description: >-
            2 letter ISO Country code of the `Institution` the payment request
            is sent to.
          example: GB
    UserSettings:
      description: Specifies the language and location preferences of the user.
      type: object
      properties:
        language:
          type: string
          description: >-
            2 letter ISO Language code which denotes the language preference for
            the `User`.
          example: en
        location:
          type: string
          description: >-
            2 letter ISO Country code which denotes the location preference for
            the `User`.
          example: GB
    HostedAccountRequest:
      type: object
      description: >-
        __Conditional__. Used to further specify details of the `Consent` to
        request 


        Conditions:


        1. Mandatory to specify the individual scopes to request from the user
        at the `Institution` for an account authorisation

        2. Mandatory to specify an expiry time on the created `Consent` at which
        time will render it unusable

        3. Mandatory to specify the date range that the created `Consent` will
        be able to access transactions for (given the range is support for the
        `Institution`)
      properties:
        transactionFrom:
          type: string
          description: >-
            __Optional__. Specifies the earliest date of the transaction records
            to be returned.

             You must supply this field to retrieve transactions older than 90 days for banks accessed via the the [CBI Globe Gateway](/data/financial-data-resources/data-restrictions#cbi-globe-gateway).
          format: date-time
          example: '2020-01-01T00:00:00Z'
        transactionTo:
          type: string
          description: >-
            __Optional__. Specifies the latest date of the transaction records
            to be returned.
          format: date-time
          example: '2021-01-01T00:00:00Z'
        expiresAt:
          type: string
          description: >-
            __Optional__. Used to set a hard date for when the user's associated
            `Consent` will expire.


            **Note**: If this supported by the bank, specifying this is property
            is opting out of having a long-lived consent that can be perpetually
            re-authorised by the user. This will add an `expiresAt` field on the
            `Consent` object which will render it unusable after this date.


            **Note**: This is not supported by every `Institution`. In such
            case, the request will not fail but the property will be ignored and
            the created `Consent` will not have an expiry date.
          format: date-time
          example: '2025-01-01T00:00:00Z'
        featureScope:
          uniqueItems: true
          type: array
          description: >-
            __Optional__. Used to granularly specify the set of features that
            the user will give their consent for when requesting access to their
            account information. Depending on the `Institution`, this may also
            populate a consent screen which list these scopes before the user
            authorises.


            This endpoint accepts allow all [Financial Data
            Features](/guides/financial-data/features/#feature-list) that the
            `Institution` supports.To find out which scopes an `Institution`
            supports, check [GET Institution](./#get-institution).
          items:
            $ref: '#/components/schemas/FeatureEnum'
    ResponseMeta:
      type: object
      properties:
        tracingId:
          type: string
    HostedConsentRequestResponse:
      type: object
      properties:
        consentRequestId:
          type: string
          format: uuid
          description: Unique Id of the consent request.
        userId:
          type: string
          format: uuid
          description: Unique Id for the `User` assigned by Yapily.
        applicationUserId:
          type: string
          description: Your reference to the `User`.
        applicationId:
          type: string
          format: uuid
          description: Unique Id of the `Application` the user is associated with.
        institutionIdentifiers:
          $ref: '#/components/schemas/InstitutionIdentifiersResponse'
        userSettings:
          $ref: '#/components/schemas/UserSettings'
        redirectUrl:
          type: string
          description: >-
            URL of consent server to redirect the user after completion of the
            consent flow.
          example: https://tpp-application.com
        accountRequestDetails:
          $ref: '#/components/schemas/HostedAccountRequestDetailsResponse'
        hostedUrl:
          type: string
          description: >-
            The URL of Hosted UI page for the applicationId which initiates the
            user journey for the consent. 

             URL would be appended with authToken, applicationId and userSettings.
        createdAt:
          type: string
          format: date-time
          description: The date and time at which the consent was created.
        authorisationExpiresAt:
          type: string
          format: date-time
          description: The date and time at which the auth Token will expire.
    ApiError:
      type: object
      description: Provides details of the error that has occurred.
      properties:
        code:
          type: integer
          description: __Mandatory__. Numeric `HTTP` status code associated with the error.
          format: int32
        institutionError:
          $ref: '#/components/schemas/InstitutionError'
        message:
          type: string
          description: >-
            __Mandatory__. Description of the exact error that has been
            experienced.
        source:
          type: string
        status:
          type: string
          description: __Mandatory__. Textual description of the `HTTP` error status type.
        tracingId:
          type: string
          description: >-
            __Optional__.  A unique identifier assigned by Yapily for the
            request that can be used for support purposes.
    RawResponse:
      deprecated: true
      type: object
      description: >-
        [DEPRECATED] Interaction (raw request and response) that occurred with
        the `Institution` in order to fulfil a request.
      properties:
        request:
          $ref: '#/components/schemas/RawRequest'
        duration:
          type: string
          format: iso8601
        headers:
          type: object
          additionalProperties:
            type: string
        resultCode:
          type: integer
          format: int32
        result:
          type: object
    FeatureEnum:
      type: string
      description: >-
        Used to describe what functions are supported by the associated
        `Institution`.        


        For more information on each feature, see the following links:        


        - [Financial Data
        Features](/data/financial-data-resources/financial-data-features)

        - [Payments Features](/payments/payment-resources/payment-features)
      enum:
        - INITIATE_PRE_AUTHORISATION
        - INITIATE_PRE_AUTHORISATION_ACCOUNTS
        - INITIATE_PRE_AUTHORISATION_PAYMENTS
        - INITIATE_ACCOUNT_REQUEST
        - INITIATE_EMBEDDED_ACCOUNT_REQUEST
        - ACCOUNT_REQUEST_DETAILS
        - ACCOUNTS
        - ACCOUNT
        - ACCOUNT_TRANSACTIONS
        - ACCOUNT_STATEMENTS
        - ACCOUNT_STATEMENT
        - ACCOUNT_STATEMENT_FILE
        - ACCOUNT_SCHEDULED_PAYMENTS
        - ACCOUNT_DIRECT_DEBITS
        - ACCOUNT_PERIODIC_PAYMENTS
        - ACCOUNT_TRANSACTIONS_WITH_MERCHANT
        - IDENTITY
        - ACCOUNTS_WITHOUT_BALANCE
        - ACCOUNT_WITHOUT_BALANCE
        - ACCOUNT_BALANCES
        - INITIATE_SINGLE_PAYMENT_SORTCODE
        - EXISTING_PAYMENT_INITIATION_DETAILS
        - CREATE_SINGLE_PAYMENT_SORTCODE
        - EXISTING_PAYMENTS_DETAILS
        - INITIATE_DOMESTIC_SINGLE_PAYMENT
        - INITIATE_EMBEDDED_DOMESTIC_SINGLE_PAYMENT
        - CREATE_DOMESTIC_SINGLE_PAYMENT
        - INITIATE_EMBEDDED_BULK_PAYMENT
        - INITIATE_DOMESTIC_SINGLE_INSTANT_PAYMENT
        - CREATE_DOMESTIC_SINGLE_INSTANT_PAYMENT
        - INITIATE_DOMESTIC_VARIABLE_RECURRING_PAYMENT
        - CREATE_DOMESTIC_VARIABLE_RECURRING_PAYMENT
        - INITIATE_DOMESTIC_VARIABLE_RECURRING_PAYMENT_SWEEPING
        - CREATE_DOMESTIC_VARIABLE_RECURRING_PAYMENT_SWEEPING
        - INITIATE_DOMESTIC_VARIABLE_RECURRING_PAYMENT_COMMERCIAL
        - CREATE_DOMESTIC_VARIABLE_RECURRING_PAYMENT_COMMERCIAL
        - INITIATE_DOMESTIC_SCHEDULED_PAYMENT
        - CREATE_DOMESTIC_SCHEDULED_PAYMENT
        - INITIATE_DOMESTIC_PERIODIC_PAYMENT
        - CREATE_DOMESTIC_PERIODIC_PAYMENT
        - PERIODIC_PAYMENT_FREQUENCY_EXTENDED
        - INITIATE_INTERNATIONAL_SCHEDULED_PAYMENT
        - CREATE_INTERNATIONAL_SCHEDULED_PAYMENT
        - INITIATE_INTERNATIONAL_PERIODIC_PAYMENT
        - CREATE_INTERNATIONAL_PERIODIC_PAYMENT
        - INITIATE_INTERNATIONAL_SINGLE_PAYMENT
        - CREATE_INTERNATIONAL_SINGLE_PAYMENT
        - INITIATE_BULK_PAYMENT
        - CREATE_BULK_PAYMENT
        - EXISTING_BULK_PAYMENT_DETAILS
        - TRANSFER
        - OPEN_DATA_PERSONAL_CURRENT_ACCOUNTS
        - OPEN_DATA_ATMS
        - READ_DOMESTIC_SINGLE_REFUND
        - READ_DOMESTIC_SCHEDULED_REFUND
        - READ_DOMESTIC_PERIODIC_PAYMENT_REFUND
        - READ_INTERNATIONAL_SINGLE_REFUND
        - READ_INTERNATIONAL_SCHEDULED_REFUND
        - ACCOUNT_BENEFICIARIES
        - INITIATE_ONETIME_PRE_AUTHORISATION_PAYMENTS
        - INITIATE_ONETIME_PRE_AUTHORISATION_ACCOUNTS
        - INITIATE_ONETIME_PRE_AUTHORISATION
        - VARIABLE_RECURRING_PAYMENT_FUNDS_CONFIRMATION
    InstitutionIdentifiersResponse:
      description: Specifies the institution selected for making the payment.
      type: object
      properties:
        institutionId:
          type: string
          description: >-
            Yapily identifier which identifies the `Institution` the payment
            request is sent to.
        institutionCountryCode:
          type: string
          description: >-
            2 letter ISO Country code of the `Institution` the payment request
            is sent to.
          example: GB
    HostedAccountRequestDetailsResponse:
      description: Details of the Account Request.
      type: object
      properties:
        transactionFrom:
          type: string
          description: >-
            Specifies the earliest date of the transaction records to be
            returned.

             You must supply this field to retrieve transactions older than 90 days for banks accessed via the the [CBI Globe Gateway](/data/financial-data-resources/data-restrictions#cbi-globe-gateway).
          format: date-time
          example: '2020-01-01T00:00:00Z'
        transactionTo:
          type: string
          description: Specifies the latest date of the transaction records to be returned.
          format: date-time
          example: '2021-01-01T00:00:00Z'
        expiresAt:
          type: string
          description: >-
            Specify the set a hard date for when the user's associated `Consent`
            will expire.


            **Note**: If this supported by the bank, specifying this is property
            is opting out of having a long-lived consent that can be perpetually
            re-authorised by the user. This will add an `expiresAt` field on the
            `Consent` object which will render it unusable after this date.


            **Note**: This is not supported by every `Institution`. In such
            case, the request will not fail but the property will be ignored and
            the created `Consent` will not have an expiry date.
          format: date-time
          example: '2025-01-01T00:00:00Z'
        featureScope:
          uniqueItems: true
          type: array
          description: >-
            Specify the set of features that the user will give their consent
            for when requesting access to their account information. Depending
            on the `Institution`, this may also populate a consent screen which
            list these scopes before the user authorises.


            This endpoint accepts allow all [Financial Data
            Features](/guides/financial-data/features/#feature-list) that the
            `Institution` supports.To find out which scopes an `Institution`
            supports, check [GET Institution](./#get-institution).
          items:
            $ref: '#/components/schemas/FeatureEnum'
    InstitutionError:
      type: object
      description: >-
        Raw error details provided by the `Institution`, when it was the error
        source.
      properties:
        errorMessage:
          type: string
          description: Textual description of the `Institution` error.
        httpStatusCode:
          type: integer
          description: Numeric HTTP status code associated with the `Institution` error.
          format: int32
    RawRequest:
      type: object
      properties:
        method:
          type: string
        url:
          type: string
        requestInstant:
          type: string
          format: date-time
        headers:
          type: object
          additionalProperties:
            type: string
        body:
          type: object
        bodyParameters:
          type: object
          additionalProperties:
            type: string
        startTime:
          type: string
          format: date-time
        startedAt:
          type: string
          format: date-time
          deprecated: true
  securitySchemes:
    basicAuth:
      description: >-
        Use HTTP Basic Authentication with your Application ID as username and
        Application Secret as password. Manage credentials in the [Yapily
        Console](https://console.yapily.com/). See
        [Authentication](/api-reference/authentication) for details.
      scheme: basic
      type: http

````