Pure-Python client for the EBICS 3.0 (H005) banking protocol
Project description
ebicsclient — a pure-Python EBICS 3.0 (H005) client
A from-scratch, pure-Python client for the EBICS banking protocol. It downloads account statements (camt.053) and initiates payments (pain.001) over EBICS 3.0 / H005 — starting with Zürcher Kantonalbank (ZKB), against which the whole flow is validated live.
- Stack: Python 3.11+, just two runtime deps —
cryptography(RSA/AES) andlxml(XML / inclusive Canonical XML 1.0); everything else stdlib. No PHP/Java sidecar. (Rationale: docs/04-implementation-plan.md.) - License model: source-available — free for personal use, paid license for commercial/business use (see docs/02-licensing-strategy.md).
- Reusable & app-agnostic: designed to be embedded as a dependency in a downstream application, not tied to any one consumer — a stable, reusable standard.
Why this exists
EBICS access now requires EBICS 3.0 / H005 (the pre-3.0 protocol was retired ~Nov 2025), and the ISO 20022 "2009" message vintage retires 21 Nov 2026 — so a client must speak H005 and consume camt.053.001.08 (the 2019 vintage) and submit pain.001.001.09 payments. There is no other pure-Python client for this. We build one, kept tightly scoped. EBICS is a stable, formally versioned standard, so a scoped client is low ongoing maintenance — the cost is upfront correctness. See docs/03-library-landscape.md for the landscape.
Quickstart
from ebicsclient import Bank, User, Client, generate_keyring, save_keyring, PAIN_001
bank = Bank(host_id="ZKBKCHZZ", url="https://ebicsweb.example.com/ebicsweb")
user = User(partner_id="PARTNER1", user_id="USER1")
# 1. Generate the three RSA key pairs (once) and store them encrypted.
keyring = generate_keyring()
save_keyring(keyring, "keyring.json", passphrase="…")
client = Client(bank, user, keyring)
# 2. Key initialisation: submit your keys, then print/sign/send the letter and wait for activation.
client.ini()
client.hia()
letter = client.make_ini_letter() # HTML, or PDF with the optional [pdf] extra
# … send letter.content to the bank; once activated:
# 3. Fetch the bank's public keys (verify their published hashes out of band).
client.hpb()
# 4. Read: download and parse the end-of-day statements.
for statement in client.download_statements():
print(statement.iban, statement.closing_balance)
# 5. Write: initiate a payment (a pain.001.001.09 document, as bytes).
transaction_id = client.upload(PAIN_001, pain001_bytes)
The certificate-based ("mit Zertifikaten") profile is a constructor option — see docs/11-certificate-profiles.md.
Documentation index
| Doc | Contents |
|---|---|
| docs/01-protocol-and-formats.md | EBICS/H005 background, the two regulatory deadlines, message formats |
| docs/02-licensing-strategy.md | Dual-licensing plan, legal reasoning, reimplementation |
| docs/03-library-landscape.md | Existing EBICS libraries and the gap this library fills |
| docs/04-implementation-plan.md | Scope, modules, the two hard parts, build order, test strategy |
| docs/05-zkb-onboarding.md | The INI/HIA + signed-letter ceremony, ZKB BTF/order params |
| docs/06-engineering-conventions.md | Baseline practices: layout, logging, errors, security, typing, testing, CI |
| docs/07-handshake-testing.md | Validating INI/HIA/HPB + download/upload against the ZKB test platform |
| docs/08-parity-and-xsd-findings.md | The inclusive-vs-exclusive c14n correction and verification discipline |
| docs/09-zkb-test-platform-settings.md | What the ZKB test platform exposes, and its upload/simulation model |
| docs/10-btf-order-types.md | ZKB's EBICS order-type → H005 BTF catalogue |
| docs/11-certificate-profiles.md | "mit Schlüsseln" vs "mit Zertifikaten", and the certificate seam |
../local/ (outside the repo) |
Real ZKB connection credentials, kept in the workspace outside the repo — can't be committed |
Development
Contributors: see CONTRIBUTING.md. One-command setup with uv:
git clone https://github.com/schulluk/ebicsclient && cd ebicsclient && uv sync --all-groups
(or pip install -e . --group dev on pip ≥ 25.1).
This is a money-moving library — the engineering bar is docs/06-engineering-conventions.md.
Status
Read and write validated live against the ZKB test platform. The key ceremony, the statement download path, and the payment upload (envelope, authentication signature, A006 electronic signature, and order-data encryption) are all accepted by the bank, and the camt.053 parser is validated against a real bank statement.
Milestone 1 — Key ceremony (validated live on ZKB)
- Key generation + encrypted keyring, and EBICS public-key hashes
- Authentication signature (inclusive Canonical XML 1.0 + RSA-SHA256)
- HTTPS transport (TLS 1.2 floor, certifi fallback via the optional
tlsextra) - INI/HIA/HPB handshake
- X.509 key transmission: mit Schlüsseln (self-signed) and mit Zertifikaten (CA certs)
- Initialisation letter (HTML, or PDF via the optional
pdfextra) - Bank-key pinning across sessions (
hpb(pinned=...))
Milestone 2 — Read (validated live on ZKB)
- Order-data decryption (RSA-unwrap + AES-128-CBC)
- Statement download —
EOP/camt.053BTD transaction (initialise → transfer → receipt) - camt.053 parsing (balances + entries) — validated on a real ZKB statement
Milestone 3 — Write (validated live on ZKB)
- Order-data encryption and the A006 electronic signature (RSASSA-PSS)
- Payment upload —
MCT/pain.001BTU transaction — accepted live
Milestone 4 — Verification & release
- Exception model with retryability classification
- Offline verification: H005 XSD validation, C14N golden vectors, ebics-client-php parity
- Golden regression fixture from a real ZKB statement
- CI (ruff / mypy --strict / pytest) and tag-triggered PyPI releases (Trusted Publishing)
Milestone 5 — Message formats (parsers built against genuine ZKB messages)
- pain.002 status-report parser (group / payment / transaction statuses, reason codes)
- camt.052 intraday reports
- camt.054 booking advices (incl. the QRR / SCOR / LSV variants via
service_option)
Milestone 6 — Protocol conveniences & breadth
- Subscriber self-inspection — available order types (HAA) and subscriber info (HTD)
- Distributed signatures (EDS)
- Further EBICS versions (e.g. H004) via the
protocol/seam
License
Source-available under the PolyForm Noncommercial License 1.0.0 — free for noncommercial use; commercial/business use requires a paid license. See LICENSE.md and the rationale in docs/02-licensing-strategy.md.
Project details
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file ebicsclient-0.2.0.tar.gz.
File metadata
- Download URL: ebicsclient-0.2.0.tar.gz
- Upload date:
- Size: 176.1 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
01b94cf448b7c955a0d7c1a9bc0d6063c33e4312fd44685d68d8ef7198a5a04c
|
|
| MD5 |
091900f6c5b7819ce82943d41136769c
|
|
| BLAKE2b-256 |
10b1e52d2ff3b5bea482b5d6570c32269e2db0c75e57abc7c7f2f5dbda839a05
|
Provenance
The following attestation bundles were made for ebicsclient-0.2.0.tar.gz:
Publisher:
release.yml on schulluk/ebicsclient
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
ebicsclient-0.2.0.tar.gz -
Subject digest:
01b94cf448b7c955a0d7c1a9bc0d6063c33e4312fd44685d68d8ef7198a5a04c - Sigstore transparency entry: 2087621387
- Sigstore integration time:
-
Permalink:
schulluk/ebicsclient@a6700adffaf342bc8b73e31d4f96c49a7391b8c1 -
Branch / Tag:
refs/tags/v0.2.0 - Owner: https://github.com/schulluk
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@a6700adffaf342bc8b73e31d4f96c49a7391b8c1 -
Trigger Event:
push
-
Statement type:
File details
Details for the file ebicsclient-0.2.0-py3-none-any.whl.
File metadata
- Download URL: ebicsclient-0.2.0-py3-none-any.whl
- Upload date:
- Size: 59.2 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
b7b69bb9bbe2c2fbf1d38772dd6948a97de3f275bc66991461d68eeb3236dbc2
|
|
| MD5 |
7557caf4c88012f734a41aad7fc3bbfe
|
|
| BLAKE2b-256 |
8de1ef8af68bb0c64c9f7b4a618482efd1031ce6ec757b746e4ec779874a0e4d
|
Provenance
The following attestation bundles were made for ebicsclient-0.2.0-py3-none-any.whl:
Publisher:
release.yml on schulluk/ebicsclient
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
ebicsclient-0.2.0-py3-none-any.whl -
Subject digest:
b7b69bb9bbe2c2fbf1d38772dd6948a97de3f275bc66991461d68eeb3236dbc2 - Sigstore transparency entry: 2087621456
- Sigstore integration time:
-
Permalink:
schulluk/ebicsclient@a6700adffaf342bc8b73e31d4f96c49a7391b8c1 -
Branch / Tag:
refs/tags/v0.2.0 - Owner: https://github.com/schulluk
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@a6700adffaf342bc8b73e31d4f96c49a7391b8c1 -
Trigger Event:
push
-
Statement type: