VKraft Software Services

Loading

Built for BNM ED-OFIN-25

Meet the mandate without rebuilding your stack.

A FAPI 2.0 authorisation server, consent engine, core-banking adapters and PayNet conformance sandbox, in one deployable platform. Banks, insurers, EMIs and DFIs go live in typically weeks rather than multi-year programmes.

What is in the box

OFM Ready ServerFAPI 2.0 authorisation, OIDC identity, token store, rate limiting
Consent engineCapture, scope, expiry, revoke and an immutable audit trail
Core-banking adaptersApache Camel routes and language SDKs for legacy APIs
Conformance sandboxAligned to PayNet OFP v1.2.2, with mock data for partner testing
  • FAPI 2.0 security profile
  • PayNet OFP v1.2.2 schema
  • Deployed in your own tenancy
  • Full data residency in Malaysia

What it does

The regulated plumbing, handled

None of this is impossible to build. It is five pieces of work sitting between you and the mandate date, and none of them differentiate your bank from the one next door.

CapabilityAssembled in-houseWith finX
AuthorisationBuild an OAuth server, add mTLS, PAR and PS256, then prove the profile holds.FAPI 2.0 profile implemented, with PKI, key rotation and JWKS automated.
ConsentSchema, approval screens, grant and revoke, plus an audit trail a regulator accepts.Schema builder, published forms, and an immutable trail compliance exports itself.
Core mappingAn adapter per endpoint, maintained through every core release.Camel route templates, authored and deployed by your own architects.
Partner testingA sandbox and mock data set, before you will expose production.Sandbox aligned to PayNet OFP v1.2.2, included from day one.
Staying currentRe-read the profile and re-test conformance on every publication.A mapping change and a conformance re-run, because schema is configuration.

Architecture

Where finX sits in your estate

In front of the core, not inside it. Third parties authenticate and are authorised at the edge; adapters translate to whatever your core already speaks.

DEPLOYED IN YOUR TENANCY OR DATA CENTREWHO CONNECTSfinX PLATFORMYOUR SYSTEMSTPPs & aggregatorsRegistered data consumersYour own appsMobile · web · partner portalsSandbox clientsPre-production conformanceThe customerGrants and revokes consentmTLS · PAROAUTH 2.0 · OIDCOFM Ready ServerFAPI 2.0 · PAR · JWS/JWE · tokensConsent engineSchemas · forms · grant · revokeIntegration StudioCamel routes · schema mappingAudit & conformanceImmutable trail · OFP sandboxADAPTERS · RESTMQ · CAMEL · SDKCore bankingAccounts · balances · paymentsIdentityCustomer authenticationData & reportingWarehouse · regulatory returnsSIEM & monitoringLogs · alerts · evidence

Scroll the diagram sideways →

Components

Three products, one platform

Each is deployable on its own and configured from the same console.

Authorisation · security · compliance

OFM Ready Server

A FAPI 2.0 authorisation server with the full BNM-aligned security profile, so data providers do not assemble one themselves.

  • ProtocolsOAuth 2.0, OpenID Connect, mTLS, private_key_jwt, PAR
  • SigningJWS signed with PS256, optional JWE encryption via ECDH-ES
  • PKICSR generation, key rotation and JWKS hosting, automated across the lifecycle
  • SchemaPayNet OFP v1.2.2, against the OpenAPI 3.0 specifications BNM and PayNet publish
01 mTLS · private_key_jwt assertion
02 POST /par · authorisation details
03 access token · JWS PS256 · optional JWE
FAPI 2.0 security profilePayNet OFP v1.2.2 aligned

Build · deploy · monitor

Integration Studio

A self-service workspace where your own team maps legacy core-banking APIs to the OFM schema, without waiting on ours.

studio · projects, integrations & recent activity
Integration Studio route editor

BNM Open Banking

Consent Management

Compliance and product teams design consent schemas, publish them as customer-facing approval screens, and govern every grant and revocation from one console.

console · active consent grants & status logs
Consent dashboard

Also included: forms console, form builder, customer approval screen

Reference application · Moneyview

What your partners will build against

Moneyview is a working consumer app running entirely on finX Open Finance APIs. It is also the quickest way to see what a third party experiences when it connects to you, and what your own customer sees while it happens.

moneyview · aggregated balances, spend trend & recent transactions
Moneyview dashboard
Flow 01Link an account

The consumer picks an institution and is handed to you.

Flow 02Grant consent

Scope and duration captured on your own approval screen.

Flow 03Read balances

Live account and balance data over the OFM schema.

Flow 04Pull transactions

Historical transaction streams, paged and filtered.

Flow 05Revoke

The customer withdraws access, and the data stops.

Under the hood

What it is built on

Standard protocols and components your architects already know, so a review is a reading exercise rather than an investigation.

Regulator checks

Security & standards

The profiles a regulator typically asks to see first.

FAPI 2.0OAuth 2.0OIDCmTLSPARJWS / JWEOpenAPI 3.0PayNet OFP v1.2.2

Runtime & integration

Components your architects already run, or can swap.

Apache CamelApache Camel (Spring Boot)KeycloakTyk

Data & messaging

Stays inside your tenancy with the rest of the platform.

PostgreSQLRedisRabbitMQ

Who uses it

Four teams, one platform

Each of them works in a different part of finX, which is the point: nobody has to queue behind another team to do their own job.

Open Finance & digital banking

Own the mandate date. Get APIs live and partners onboarding without a core programme in the way.

Console
Integration & API architects

Map the core once, keep the mapping when a schema version moves, and review a stack you already recognise.

Integration Studio
Compliance, risk & PDPA

Design the consent schema yourselves, and export the audit trail without raising a ticket with anyone.

Consent & audit
Developer & partner enablement

Point third parties at mock data so they integrate before production is ever exposed.

Sandbox

Standards & deployment

What we implement, and what we claim

Separated deliberately: the first four are external standards you can check, the last is our own architecture.

  • BNM ED-OFIN-25Built to the Bank Negara Malaysia Open Finance exposure draft, which is the reason the platform exists.
  • PayNet OFP v1.2.2Schema conformance tested against this version. State the test date alongside it, because the profile moves.
  • ISO 27001 alignedControls mapped to the standard across the platform and its delivery.
  • PDPA alignedData handling designed to support your obligations as data user under PDPA 2010. Compliance remains yours.
  • Zero-storage relayOur own architecture, not an external standard: finX relays permissioned data rather than retaining a copy of it.

Questions

Answers before you ask

Consent, authorisation and the first read endpoints are the usual first milestone. The pace usually depends on how quickly you can settle the identity decisions, and on how much of your core is already exposed through a supported interface.

Get started

Request a demo

Tell us about your institution and we will schedule a short technical walkthrough of finX.

  • A live walkthrough of the authorisation and consent flows
  • How the adapters would meet your core specifically
  • A view of where you stand against the mandate today

Loading security check…

Your details stay with VKraft and are used only to answer this enquiry.