Signing and mTLS certificates
To validate your request, Rabobank applies the following security checks to ensure authenticity and integrity:
- Mutual TLS (mTLS) - The request must be authenticated using an EV SSL certificate. For more info read Mutual TLs
- HTTP Request Signing - The request is cryptographically signed following the IETF HTTP Signatures draft standard. The request must be signed using a different EV SSL certificate. For more info read Signing API Requests
- Digest header - A hash of the request body is included, as defined in RFC 3230 to guarantee body integrity. Digest information is available in the API reference for each API.
- OAuth 2.0 - Used to authorize access to the API. For more info read Authorization Services
- Rate limits - Applied to ensure fair usage and maintain system stability. Rate limit information is available in the Product overview (Guides) of each API.
EV SSL Certificates
Rabobank accepts certificates from the certificates issuers in the Mozilla Certificate Report .
- TLS Client Certificate: EV SSL certificate from an accepted CA (RSA ≥ 2048 bits, max validity 1 year).
- Signing Certificate: EV SSL certificate for signing requests.
TLS Certificate
Public
Upload the public part of the TLS certificate (full chain in PEM format) in the Rabobank developer portal under My Organizations → Apps → Configuration → Certificate.
Private
Keep the private key secure in your infrastructure, it is used to set up the mTLS connection.
Signing certificate
Public
The public key should be shared with Rabobank in the Signature-Certificate header of a request.
Private
Keep the private key secure in your infrastructure, it is used for creating the HTTP Signature. Rabobank does not store your signing certificate.
| Environment | Certificate | Domain | Signature |
|---|---|---|---|
| Sandbox | Any certificate works for mTLS and Signing; Rabobank provides downloadable test sandbox certificates and keys for convenience and testing. TLS Download Example Certificate Download Example Private Key Signing | Rabobank servers use EV SSL certificates (e.g., api.rabobank.nl). | Requires Digest and Signature headers. |
| Production | Requires Two valid EV SSL certificates from an accepted CA. One for mTLS, and | Rabobank servers use EV SSL certificates (e.g., api.rabobank.nl). | Requires Digest and Signature headers. |
Updated about 2 hours ago