Bring your own licence
Bring your own PISP licence. We run the rest.
You did the hard regulatory work to become a payment initiation service provider. MVP Payments is the infrastructure underneath that licence: direct bank connections in nine markets, monitored around the clock, behind one API — with every payment initiated in your name, under your certificates.
Who does what
The line is clean. Everything regulatory and commercial stays with you; everything technical is run by us.
You bring
Your authorisation as a payment initiation service provider. Your eIDAS certificates — QWAC and QSealC. Your merchants, your contracts, your pricing and your compliance framework.
You stay the regulated party and the owner of every customer relationship.
We run
The bank connections and their upkeep. Connectivity monitoring and incident response. The payments API, the hosted payment page, signed webhooks, the dashboard and the audit trail.
We act as your technical service provider and never hold funds.
How bring-your-own-licence works
Your licence on record
Your regulator, licence number and home country are recorded against your account and shown wherever our operators work on it — so nobody is ever in doubt whose authorisation a payment runs under.
Your certificates installed
Your QWAC and QSealC go into an encrypted secrets vault through a supervised, audited upload. The account only switches to your licence once both are present and valid.
Every payment stamped
Each payment records the licence mode it was created under. A certificate rotation or a configuration change never shifts a payment already in flight onto different credentials.
Infrastructure, not another intermediary
Most Open Banking providers sell payments under their licence. That suits a merchant who wants a payment method. It does not suit a licensed PISP: the provider becomes the regulated party in the flow, owns the bank relationship, and takes a margin on every payment for a permission you already hold.
Building it all yourself is the other option, and it is a long one. Each bank implements PSD2 differently, connections need constant upkeep, and none of that work sets you apart from your competitors. Our guide to building versus buying Open Banking connectivity sets out the real costs.
MVP Payments is the third way. You keep the licence, the merchants and the economics. We supply the part that is pure engineering, and we are paid for infrastructure — not for standing in the middle.
Built for your compliance team as well as your engineers
Hosted in the EU
Platform data is hosted in the European Union — Frankfurt, Germany — encrypted in transit and at rest, with point-in-time recovery on every data store.
An audit trail by default
Every operator action on your account, every credential rotation and every certificate change leaves an audit record. Sensitive actions require a typed confirmation.
Credentials never touch us
Your customers authenticate with their own bank. Where a bank's journey passes credentials through the platform, they are forwarded in transit only — never stored, never logged.
Bringing a technical provider under your licence is an outsourcing decision. Our guide to outsourcing to a technical service provider covers what regulators expect and what to ask any provider — including us.
Bring-your-own-licence questions
- Who is the regulated party when we use MVP Payments?
- You are. Payments are initiated under your authorisation as a payment initiation service provider, and each bank identifies you from your own eIDAS certificates. MVP Payments is a technical service provider: we supply and operate the technology, never enter into possession of funds, and have no contract with your merchants.
- Which certificates do we need?
- For EU and EEA banks, a QWAC and a QSealC issued to your firm by a qualified trust service provider, each carrying the payment initiation role and your authorisation number. The platform will not switch an account to bring-your-own-licence mode until both are installed. In the United Kingdom the equivalent certificates are OBWAC and OBSeal, issued to FCA-authorised firms through the UK Open Banking Directory.
- How are our certificates and private keys stored?
- In a dedicated, encrypted secrets vault — never in the platform database, never in logs and never in source control. Upload is supervised and audited, certificate expiry is scanned daily with warnings raised 30 and 7 days ahead, and rotation requires a typed confirmation.
- Is using MVP Payments an outsourcing arrangement?
- For most licensed firms, yes — operating bank connectivity on your behalf will usually count as outsourcing of an operational function, and for EU firms as an ICT service under DORA. You remain responsible to your regulator. We support your due diligence with a description of the architecture, data location, security review record, audit trail and incident handling.
- We are still applying for our PISP licence. Can we start now?
- Yes. The sandbox needs no licence and no certificates, and it behaves exactly like live — same API, same statuses, same signed webhooks. Teams commonly integrate during the application period so they are ready to go live when the authorisation lands.
- Can we passport into other countries on the platform?
- Yes. Your home authorisation plus passport notifications covers every EU and EEA market MVP Payments connects to, with the same certificates. MVP Payments currently has live bank connections in Austria, Belgium, France, Germany, Lithuania, Latvia, the Netherlands, Spain and the United Kingdom. The United Kingdom is outside EU passporting and needs a separate FCA authorisation.
- Can we leave?
- Yes, and that is the point of the model. The licence, the certificates, the merchant contracts and the customer relationships are all yours. Nothing about your regulatory standing depends on MVP Payments.
Tell us about your licence
Where you are authorised, where you passport and what you want to build. We'll map it to live coverage and show you the platform end to end.