Haufe-Lexware Open Banking & API Access Explained

Need programmatic visibility into your Haufe-Lexware (BIC DEUTDE6FXXX) accounts? open-banking.io gives you a single, privacy-first path to your balances and transactions across 2,600+ EU and UK institutions. Both business and personal account types are supported, and a single approval keeps your connection live for up to 180 days before you re-confirm.

Unlike traditional aggregators, open-banking.io is zero-knowledge and certificate-free. Your encryption keys are generated on your own device from a passphrase only you know, so the service stores your public key and nothing else. Every figure that reaches you is decrypted locally — the servers never see your Haufe-Lexware data in the clear.

How to connect Haufe-Lexware

Connecting happens entirely inside the open-banking.io dashboard — there is no API call, code, or key involved in this step.

  1. Sign up for open-banking.io and set your encryption passphrase. Your private key is created right there on your device.
  2. In the dashboard, search for and select Haufe-Lexware, then choose the account type you want to link (business or personal).
  3. You're redirected to Haufe-Lexware's own secure login and consent screen, where you authenticate and approve access under PSD2 — exactly as you would on their site.
  4. Once approved, your accounts sync back into your open-banking.io dashboard, ready to view.

That's the whole flow. You never hand credentials to open-banking.io, and you stay in control of the consent, which you can revoke at any time.

Access your data

For developers, reading the data programmatically is an optional step after the connection already exists. Open the Developers page, create an API key, and export a credentials.json — this bundles the API key together with your private decryption key.

With that in place you can use the CLI (openbanking accounts, openbanking transactions, openbanking sync), an SDK, or the REST API directly. Requests authenticate with the X-Api-Key header, and each response is decrypted locally with your own key. The API key alone only ever returns ciphertext — without your private key it stays unreadable, which is what keeps the whole system zero-knowledge.

All of this runs for around EUR 3/month.

Does connecting Haufe-Lexware require an API key?

No. You connect in the dashboard and approve on Haufe-Lexware's own consent screen. API keys are only for the optional developer read step afterward.

Can open-banking.io staff see my transactions?

No. Data is encrypted with keys held only on your device, so the service holds ciphertext and your public key — nothing readable.

Up to 180 days per approval, after which you re-confirm on Haufe-Lexware's login screen.

Start at open-banking.io.