BANK & PARTNER ECOSYSTEM

Connect through a controlled partnership model.

Open Banking, POS, device, integration and channel partnerships with explicit responsibilities and measurable acceptance.

PARTNER APPLICATION

Connect your bank or technology platform

Describe the intended partnership and technical scope without submitting secrets, credentials or customer data.

01

Bank and Open Banking path

Define the money-flow contract before integration.

VA model

Ownership, customer/merchant mapping, naming, lifecycle, receiving account and reconciliation key.

Credit events

Authentication, signing, timestamp, anti-replay, idempotency, retry, ordering and acknowledgement.

Exceptions

Unmatched, duplicate, delayed, reversed, invalid signature, amount mismatch and manual review.

Responsibility

Bank, merchant, PalmPay and licensed parties agree settlement, refund, support and evidence roles.

02

Technology partner path

Integrate product components without weakening governance.

POS/ECR

Order context, amount integrity, result callback, receipt, retry, offline and certification test pack.

Palm device/SDK

Capture, quality, PAD/liveness evidence, template strategy, protocol, security, firmware and support.

CRM/ERP/BI

Customer, campaign, store, transaction, point, reconciliation and reporting data contracts.

Channel/deployment

Sales scope, installation, training, inventory, SLA, escalation and controlled branding.

03

Pilot and evidence

Partnership moves by measurable acceptance.

Workshop

Business model, roles, target environment, integration, security and KPI.

Sandbox and contract test

API, event, certificate, error model, sample data and negative cases.

Field pilot

Controlled stores/users, monitoring, support, fraud/exception handling and reconciliation.

Scale decision

Evidence pack, lessons, changes, commercial terms, rollout plan and governance cadence.

OPEN BANKING CONTRACT

The integration contract must make every credit event explainable

Event identity

Each notification should carry a stable bank transaction identifier, VA, merchant account, amount, currency, value time, posting status, event version and correlation reference. Repeated delivery must not create repeated wallet credit.

Authenticity and replay

mTLS, approved signatures or MAC, timestamp, nonce, key rotation, source allow-listing and API gateway controls establish event authenticity. The receiver records verification outcome before business processing.

Reconciliation

Real-time events are reconciled against bank statements or authoritative enquiry. Unmatched and delayed items enter a controlled queue; reversal and correction use new immutable entries rather than deleting history.

Shared operations

The bank, merchant and PalmPay agree incident severity, contact paths, retry windows, maintenance, certificate renewal, settlement cut-off, reporting, complaint handling and change notification before pilot.

Does PalmPay open the VA?

The bank or authorized provider owns the VA capability. PalmPay consumes the approved mapping and event contract to reconcile the merchant-specific internal ledger.

What happens to an unmatched transfer?

It is not silently credited. It enters an exception workflow for evidence, mapping, approval, customer communication and eventual credit, return or rejection according to the agreed model.

Can multiple banks participate?

Yes, through separate adapters and bank-specific contracts while preserving a common internal event and reconciliation model.

MOBILE-ID / TRUSTED PALMPAY

Start partner onboarding

Mobile-ID will qualify the business path, integration contract, security evidence, support model and pilot plan.

Start partner onboarding