CBA side illustration

ASB New Zealand Payments

Lists saved payees and initiates a New Zealand dollar payment, under the ASB platform and New Zealand rules. A separate jurisdiction with its own authorisation server.

This service is an illustration built on the CBA side of the boundary. It is not a Raidiam product. It exists to show what a resource server can demand of an agent, and to show that a refusal can always be explained.

What an agent has to discover

Resourcehttps://rs-nz-payments.demo.cba.raidiam.io
Authorization serverhttps://asb.demo.cba.raidiam.io
Trust anchorhttps://authority.directory.cba.raidiam.io/authority/5a27c88b-97ed-4d37-a3c8-59c66b19aa25
Detail typesnz_payment
Scopesopenid, nz.payments
Sender constrainingDPoP verified when presented, required for bound tokens
Mutabilityaccepts instructions

Authorization detail types

nz_payment

Authority to initiate a payment in New Zealand dollars to a saved payee, under the ASB platform.

Required members: type purpose

Optional members: none

{
  "type": "nz_payment",
  "purpose": "Settle a New Zealand supplier invoice"
}

Token claims this resource decides on

Tools

ToolPurposeRequiresEffect
list_payees The saved New Zealand payees on this account. nz_payment read only
initiate_nzd_payment Initiate a payment in New Zealand dollars to a saved payee. nz_payment changes state

Guardrails, published in advance

Every call carries a token from the named authorization server

Calls are accepted only with an access token issued by https://asb.demo.cba.raidiam.io and addressed to this resource as its audience. A token minted for a different resource is refused even when it is otherwise valid.

Refusal reason missing_access_token, invalid_token · decided at authorization · policy id rs.authenticated_caller

What clears it: Read this metadata document, then request a token from the authorization server it names, with this resource as the audience.

Authority is the RFC 9396 detail type, not a scope

Each tool names one authorization_details type. The token must carry that type, or an umbrella type that narrows to it. Holding a scope, or holding authority for a neighbouring resource, does not admit the call.

Refusal reason insufficient_authority · decided at authorization · policy id rs.authority_gate

What clears it: Obtain a token carrying the detail type the tool names. Delegation only ever narrows, so the delegating envelope must already contain it.

A revoked delegation stops working before its tokens expire

Revocation arrives as a Shared Signals event and is applied to the delegation, not to a single token. Every token issued under a revoked delegation is refused from that moment, whatever its expiry says.

Refusal reason delegation_revoked · decided at authorization · policy id rs.revocation_honoured

What clears it: The customer must grant a fresh delegation. There is no way to appeal a revocation at the resource.

Sender constrained tokens are bound to the key that holds them

A DPoP proof is verified whenever one is presented, and is required whenever the access token names a key in its cnf.jkt claim. Each proof is accepted once, so a captured proof cannot be replayed.

Refusal reason dpop_proof_required, invalid_dpop_proof, dpop_key_mismatch, dpop_proof_replayed, access_token_not_dpop_bound · decided at authorization · policy id rs.dpop_binding

What clears it: Request the access token with a DPoP proof so the authorization server binds it to your key, then send a fresh proof with every call.

A malformed request is refused with the reason it was malformed

Arguments are validated before any business rule runs, and the refusal names the argument at fault rather than returning a bare failure.

Refusal reason tool_error, invalid_amount, unknown_tool · decided at execution · policy id rs.request_validity

What clears it: Correct the named argument. The tool schemas are published in this document.

Australian payment authority is not New Zealand payment authority

This resource honours nz_payment and nothing else. An agent holding payment_initiation, however large its envelope, holds no authority here. The jurisdictional boundary is expressed in the capability vocabulary rather than left to deployment topology, so it is visible to a consumer before it calls.

Refusal reason capability_denied · decided at authorization · policy id nz.jurisdiction_is_a_capability_type

What clears it: Obtain nz_payment authority from the ASB platform.

Saved payees only

A payment can only be sent to a payee already saved on the account. An agent cannot introduce a new destination, which is the control that makes a compromised agent unable to redirect money.

Refusal reason unknown_payee · decided at execution · policy id nz.saved_payees_only

What clears it: A new payee is added by a human in ASB FastNet.

Observability

Every admission decision, allowed and refused, is recorded with the policy that decided it and the values it turned on. Read them at /decisions.