Open Banking connection and consent · How-to guide

Enter a Tide access token securely

Detailed client guidance covering enter a Tide access token securely, with exact eligibility, security, verification and troubleshooting boundaries for the shipped Tide payment and Open Banking controls.

Audience: Administrators and authorised payment operations staffPermission: Settings or relevant capabilityModule v1.0.0
Jump to steps
Where to goTide Payments → Settings
Before you startConfirm the intended tenant, remote account or invoice context, and your Settings or relevant capability access. Keep credentials and tokens out of screenshots, tickets and exported evidence. If a previous write may have reached an external service, verify remote state before retrying.

What you’ll accomplish

Detailed client guidance covering enter a Tide access token securely, with exact eligibility, security, verification and troubleshooting boundaries for the shipped Tide payment and Open Banking controls. This article is intentionally scoped to the behaviour enforced or exposed by the supplied module and does not treat provider marketing features as implemented integration capabilities.

How the workflow fits together

Tide payment instructions, AIS transaction import, exact reconciliation, native invoice payment status and audit evidence are connected but separately verifiable stages. A payment instruction is not proof of receipt; a bank transaction is not a certified invoice payment until it passes the reconciliation gates.

Follow these steps

  1. Open Tide Payments → Settings.
  2. Confirm the intended tenant, invoice/connection/transaction where applicable, and your Settings or relevant capability access before continuing.
  3. Select Sandbox or Production deliberately.
  4. Enter the application/redirect/scope/financial details supplied for the authorized Open Banking setup.
  5. Configure both mTLS certificate and key paths together where transport credentials are required.
  6. Enter the intended AccountID and a valid access token, then save to trigger connection verification.
  7. Confirm connected status and returned account identity before importing/reconciling.

Fields and decisions to review

This guide’s focusDetailed client guidance covering enter a Tide access token securely, with exact eligibility, security, verification and troubleshooting boundaries for the shipped Tide payment and Open Banking controls.
EnvironmentSandbox is the default. Production requires the organisation’s valid Open Banking onboarding, consent and transport credentials.
RedirectA configured Open Banking redirect URI must use HTTPS.
Connection identityBoth Tide account ID and access token are required to establish/verify the bank-feed connection.
mTLSCertificate and private-key paths must both be set or both be empty; production API access depends on valid readable transport material where required.
VerificationConnection verification confirms that the configured AccountID is returned by the authorized AIS consent.
SecretsAccess and refresh tokens are encrypted and are not rendered back in plaintext after saving.
DisconnectDisconnect clears stored active tokens/connection identity state while retaining historical payment/reconciliation/audit records.

How to confirm it worked

Reopen the intended invoice, Tide transaction/reconciliation register and audit evidence. Confirm the full Tide transaction identifier where available, exact amount/currency/reference, reconciliation state, native invoice payment and latest timestamps. If the bank-feed state cannot be independently verified, keep the task unresolved and use the supported troubleshooting flow.

Questions clients commonly ask

Does Sandbox access guarantee Production access?No. Production requires valid Open Banking onboarding, consent and transport credentials for the organization.
When is an invoice actually treated as paid?Only when an eligible Tide credit is exactly reconciled and the native gateway payment is recorded; showing transfer instructions is not payment confirmation.
Can staff override a close-but-not-exact bank match?The automatic flow intentionally requires exact eligibility, reference and current outstanding amount. Investigate the bank/reference/invoice state instead of weakening the control.
What should I include in a support case?Include invoice ID, Tide transaction ID if available, reference, amount/currency, booking timestamp, connection status and visible error. Never include access/refresh tokens or private keys.
Does disconnecting remove history?No. Active connection tokens/state can be removed while historical payment, reconciliation and audit evidence is retained.

Technical basis for this guidance

This guide was checked against the supplied module code paths: tide_payments.php; controllers/Tide_payments.php; controllers/Tide_payments_client.php; models/Tide_payments_model.php; helpers/tide_payments_helper.php; libraries/Tide_gateway.php; libraries/Tide_open_banking_client.php; libraries/Tide_partner_client.php; views/admin; views/client/pay.php; install.php; config/routes.php. It documents shipped behaviour, validation, routes and evidence controls; it does not claim successful live provider network calls from offline inspection.

Controls, checks and common mistakes

  • Work in the intended tenant and remote accounting/business context.
  • Do not paste credentials, access tokens, refresh tokens or private keys into tickets or notes.
  • Do not bypass a missing mapping, validation error, permission gate, duplicate check or remote-verification requirement.
  • Do not repeat a non-idempotent write until you know whether the previous request reached the remote service.
  • Keep native record, remote evidence and audit/history state aligned before closing the task.
Provider and accounting boundaryDisconnect clears stored active tokens/connection identity state while retaining historical payment/reconciliation/audit records.