Troubleshooting and production readiness · How-to guide

Why Tide settings require both mTLS certificate and key paths

Detailed client guidance covering why Tide settings require both mTLS certificate and key paths, with exact eligibility, security, verification and troubleshooting boundaries for the shipped Tide payment and Open Banking controls.

Audience: Administrators and authorised payment operations staffPermission: Settings or relevant capabilityModule v1.0.0
Jump to steps
Where to goTide Payments → relevant workspace
Before you startConfirm the intended tenant, remote account or invoice context, and your Settings or relevant capability access. Keep credentials and tokens out of screenshots, tickets and exported evidence. If a previous write may have reached an external service, verify remote state before retrying.

What you’ll accomplish

Detailed client guidance covering why Tide settings require both mTLS certificate and key paths, with exact eligibility, security, verification and troubleshooting boundaries for the shipped Tide payment and Open Banking controls. This article is intentionally scoped to the behaviour enforced or exposed by the supplied module and does not treat provider marketing features as implemented integration capabilities.

How the workflow fits together

Tide payment instructions, AIS transaction import, exact reconciliation, native invoice payment status and audit evidence are connected but separately verifiable stages. A payment instruction is not proof of receipt; a bank transaction is not a certified invoice payment until it passes the reconciliation gates.

Follow these steps

  1. Open Tide Payments → relevant workspace.
  2. Confirm the intended tenant, invoice/connection/transaction where applicable, and your Settings or relevant capability access before continuing.
  3. Capture the exact validation/connection/reconciliation error before changing settings.
  4. Check field format, environment, account ID/token, mTLS pair and consent/transport conditions.
  5. For an unreconciled transfer, check booking status, Credit indicator, GBP currency, exact reference and exact outstanding amount.
  6. Correct only the proven cause and run the supported reconciliation once.
  7. Verify the native invoice payment and audit evidence after recovery.

Fields and decisions to review

This guide’s focusDetailed client guidance covering why Tide settings require both mTLS certificate and key paths, with exact eligibility, security, verification and troubleshooting boundaries for the shipped Tide payment and Open Banking controls.
ValidationSort code, account number, redirect URI, mTLS pair, lookback and account/token requirements are validated before settings are accepted.
ConnectionA connection can show error when the selected environment, account ID, access token, transport material or consent does not verify.
CronAutomatic reconciliation depends on the auto-reconcile setting, module tables, a valid connection and the normal application cron.
Customer transferA transfer can remain unreconciled if it is not yet Booked, is not a Credit, is not GBP, has a reference mismatch or does not equal the current outstanding balance.
ProductionProduction use requires legitimate Open Banking onboarding/consent and correctly managed credentials; sandbox success is not proof that production authorization exists.
Incident responsePreserve transaction ID, reference, invoice ID, amount, timestamps and audit evidence before changing settings or attempting another run.

How to confirm it worked

Reopen the intended invoice, Tide transaction/reconciliation register and audit evidence. Confirm the full Tide transaction identifier where available, exact amount/currency/reference, reconciliation state, native invoice payment and latest timestamps. If the bank-feed state cannot be independently verified, keep the task unresolved and use the supported troubleshooting flow.

Questions clients commonly ask

When is an invoice actually treated as paid?Only when an eligible Tide credit is exactly reconciled and the native gateway payment is recorded; showing transfer instructions is not payment confirmation.
Can staff override a close-but-not-exact bank match?The automatic flow intentionally requires exact eligibility, reference and current outstanding amount. Investigate the bank/reference/invoice state instead of weakening the control.
What should I include in a support case?Include invoice ID, Tide transaction ID if available, reference, amount/currency, booking timestamp, connection status and visible error. Never include access/refresh tokens or private keys.
Does disconnecting remove history?No. Active connection tokens/state can be removed while historical payment, reconciliation and audit evidence is retained.

Technical basis for this guidance

This guide was checked against the supplied module code paths: tide_payments.php; controllers/Tide_payments.php; controllers/Tide_payments_client.php; models/Tide_payments_model.php; helpers/tide_payments_helper.php; libraries/Tide_gateway.php; libraries/Tide_open_banking_client.php; libraries/Tide_partner_client.php; views/admin; views/client/pay.php; install.php; config/routes.php. It documents shipped behaviour, validation, routes and evidence controls; it does not claim successful live provider network calls from offline inspection.

Controls, checks and common mistakes

  • Work in the intended tenant and remote accounting/business context.
  • Do not paste credentials, access tokens, refresh tokens or private keys into tickets or notes.
  • Do not bypass a missing mapping, validation error, permission gate, duplicate check or remote-verification requirement.
  • Do not repeat a non-idempotent write until you know whether the previous request reached the remote service.
  • Keep native record, remote evidence and audit/history state aligned before closing the task.
Provider and accounting boundaryPreserve transaction ID, reference, invoice ID, amount, timestamps and audit evidence before changing settings or attempting another run.