v3.1.15

Creation Date: 16.09.2025

Air API and Open Banking Infrastructure Studies

220974 - Visa Institutions - API Software

The document sending API v1/StatementDelivery API that Visa will call was written and the sub-environment certificates were created and sent.

220917 - [ONPREM] - Redirecting Traffic to OnPrem

Here, the requests have now been transferred to KT OnPrem and the entire process has been completed successfully.

213919 - Development of Low Level Alert Structure

By using the performance level report API provided by BKM, a structure has been designed to send an informational email in case of a decrease in the report level.

214451 - Sağlam Pay Process Tracking

Here, the BOA local launch process has been successfully completed. Installation meetings were held for the BOA environment, API Gateway, and Identity Server. AirApi Prod environment installations were completed. Meetings were held for the OBAWEB screens as part of the KeyCloack project.

205349 - Fixing bugs in the robust Pay BOA build

BOA Compilation processes have been completed successfully.

214100 - HHS2.0 Mobile Application Call Service Regulations

All services provided to Mobile have been tested. Any problems that arose have been corrected.

214105 - Adding a New Contract to the KT - YOS Screen

Contracts were defined to rotate dynamically. Our processes observed that the contract rotated correctly. It was observed to appear on the screen in the iOS test environment. This issue is not occurring on Android; the Dijital-4 team will investigate. Our work has been completed.

213409 - Investigation and correction of errors in the requests received from the KT API (Sub-environment)

Transactions are reflected instantly.

213407 - 2025 Information Systems and Business Processes Independent Audit - Process Improvement

Attached is the document I prepared for Article 41, requested as part of the 2025 Information Systems and Business Processes Independent Audit. The content of the document is as follows.

Ref. 1601-Article 41

Evidence of end-to-end secure communication between the customer or the party acting on their behalf and the bank during the use of open banking services.

End-to-end communication with companies and financial technology companies (fintechs) using Kuveyt Türk APIs.

Client Credentials API Call GET API Access Token Procurement Signature Transactions Result POST API Access Token Procurement Signature Transactions Result

Authorization Code API Call GET API Access Token Procurement Signature Transactions Result POST API Access Token Procurement Signature Transactions Result End-to-end communication with banks using Payment Services Data Sharing Services.

Ref. 1602-Article 41

Evidence of the resources the customer can connect to and the authentication methods used for these accesses.

Token Mechanism BKM Signature Check (x-jws-signature) Fraud Checks IP Whitelist Checks Signature Check

214012 - HHS - OBH One-Step Approval Process Relevant meetings were attended. Customer definitions and data required for testing were provided to the relevant team.

213366 - [KT Bank AG] AirApi Regular Payment Deletion - Authorize API

tests have been completed successfully

214118 - Management Portal Custom Environment Dashboard Development

The UI design of the Management Portal Custom Environment Dashboard was created using mock data.

205358 - API Market Phase 2 - Change Password

Development of Change Password screens has been completed within the scope of API Market Phase 2.

205356 - API Market Faz 2 - Reset Password

The development of Reset Password screens within the scope of API market Phase 2 has been completed.

213416 - API Market Phase 2 - Dashboard Report

Users logging into the API Market website will be presented with a specially designed dashboard. This screen has been developed in accordance with the UX design designed to maximize the user experience. The dashboard contains comprehensive data such as the number of applications, traffic analysis, average response time, total number of requests, successful requests, success rate, and a list of APIs used. This data allows users to quickly and easily access detailed information about the API Market.

214268 - API Market Phase 2 - Dashboard Report Backend Development

Developer Portal dashboard backend development has been completed.

213412 - API Market - Opening the API Market language as TR

The Kuveyt Turk API Market website was opened in English (EN) by default, but after the development, it is now opened in Turkish (TR) by default.

213391 - API Market - How To Starts Screen Document Adding Ability Improvement

Testing has been completed in the test environment. POCheck is available.

210501 - Correction of the logic of the sorting feature in the Developer Portal settings menus

Due to our test engineer being on leave, the prep pass could not be completed. Therefore, the development was successfully tested in the market environment and a POC check was received.

219259 - Archiving KT YOS Log Tables

Archiving work has been carried out. The screenshots below show that the relevant log tables in the production environment were transferred to BOAArchiveCold until August 1st, and that they remained in the main table after August 1st.

PORTAL
TASK
ISSUE
ACTION
STATUS

[TCMB][ZKB]

216166

YÖS-Active accounts cannot be listed. Loader remains on the screen.

Backend fixed

Done

[Developer Portal]

216754

API market logo appears incorrectly in live environment

Backend fixed

Done

[Management Portal]

216645

Restrictions > IP White List > Search Text

Backend fixed

Done

[KT]

215811

An error is received when a request is sent to the airapi prep environment.

Backend fixed

Done

[Management Portal]

215805

When there is a long client name on the gateway log screen, the screen scrolls.

Backend fixed

Done

[Management Portal]

213989

When there is a long client name on the gateway log screen, the screen scrolls.

Backend fixed

Done

[TCMB]

198148

When the x access token is not sent to some endpoints, a false error is received.

Backend fixed

Done

[TCMB]

186587

When a request is made with an empty x access token on some endpoints, an incorrect error is received.

Backend fixed

Done

Mercek - Sprint 27

213823

Last updated