Last Updated: August 2026
API Introduction
At PingPong, the best way to create value for our customers is through openness and collaboration. We’ve transformed the regulatory compliance, security, and licensing requirements into an end-to-end international payment solution via API services, allowing our clients to access other opportunities worldwide via a single API integration with their preferred TPPs. Our API services comply with the requirements of PSD2 in the European Economic Area and the Payment Services Regulations 2017 (PSRs 2017) in the United Kingdom.
Our APIs are built in Java, using the Spring framework for high scalability and robustness, and secured via IP whitelisting and SHA-256 hashing. To secure data transferred in our API and ensure maximum convenience for TPPs, we have applied the eIDAS framework in the EEA, relying on qualified certificates for mutual identification and authentication while establishing a secure communications channel using Transport Layer Security (TLS).
In the United Kingdom, TPP identification and authentication is carried out in accordance with the FCA’s regulatory framework under the PSRs 2017.
Your right to use third-party providers
If you hold a payment account with PingPong Europe S.A. or PingPong Payments (UK) Limited, you have the right to use authorised third-party providers to access your account information or initiate payments on your behalf, in accordance with PSD2 (in the EEA) and the Payment Services Regulations 2017 (in the United Kingdom).
Authorised Account Information Service Providers (AISPs) and Payment Initiation Service Providers (PISPs) registered with the Financial Conduct Authority, the CSSF, or another competent authority may access your payment account through our dedicated interface, subject to your explicit consent.
Access for third-party providers
Authorised TPPs may request access to our interface by contacting us using the details below. We will provide API documentation and access to our testing facility upon verification of the TPP’s regulatory status.
API Service Scope
Our APIs are designed to be flexible and give you control over how and when you convert currencies, make payments and manage your accounts. Below are the available services you can access via API endpoints currently:
- Balance Enquiry
- Transaction Authorization
- Access Transaction Records
More API services will be made available in the near future.
API Access Procedure
- Pre-Test — Explore our API documentation and dedicated sandbox environment.
- Connection — Contact PingPong to help you set up the API connectivity.
- Go-Live — Go-live with the API integration.
Our API has been designed with RESTful principles to make integration familiar, easy and quick. You can find the API documentation here.
Purpose of SCA
As remote electronic payment transactions are subject to a higher risk of fraud, Strong Customer Authentication (SCA) must be applied. SCA is a mandatory requirement for payment institutions authorised in the European Economic Area under PSD2 and in the United Kingdom under the Payment Services Regulations 2017, which aims to reduce the likelihood of fraudulent activity taking place and enhance the protection of user information.
SCA Implementation Process
At PingPong, we perform SCA through a two-factor authentication method (2FA) using ‘knowledge’ (something only the user knows, such as a password) and ‘possession’ (something only the user possesses, such as a one-time code generated by a security token or access through a trusted device, such as an SMS).
The SCA process is implemented as below:
- Input your account information — When initiating a payment or accessing account information, customers must input their login username and password on the screen displayed by PingPong.
- Two-factor authentication — To perform the SCA 2FA process, customers need to input the verification code or one-time 6-digit confirmation code received via SMS.
- Confirm access — Upon successfully entering the passcode, customers will be authenticated, and the action processed.
You can find a detailed description of the SCA integration in the API documentation.
Availability and performance statistics
Quarterly statistics on the availability and performance of our interfaces are published here in accordance with the Regulatory Technical Standards on Strong Customer Authentication.
Data protection
Personal data shared via our API is processed in accordance with the UK GDPR and the EU GDPR (as applicable) and our Privacy Policy. Customer data is only shared with authorised TPPs where the customer has provided explicit consent.
Contact us
If you have questions or are an authorised TPP wishing to request access to our interface, please contact us:
- EEA: psd2-api@pingpongx-eu.com
- United Kingdom: ppuk-api@pingpongx-uk.com