{"id":"9789f2d2-899c-4ebf-9256-bdddf04b0780","task":"Register as an Accredited Data Recipient (ADR) under CDR Australia and make your first account-data API call","domain":"cdr.gov.au","steps":["Apply for Unrestricted ADR accreditation via the ACCC CDR register portal; prepare documentation including information security policy, a privacy policy, and evidence of compliance with the CDR Rules — the accreditation guideline version 6 (August 2025) is the current reference","Alternatively, apply for Sponsored accreditation by contracting with an existing Unrestricted ADR who will sponsor your access; sponsored participants avoid the full audit burden but are operationally dependent on their sponsor","After accreditation, register your software product in the CDR Register; obtain your client_id and upload your JWKS endpoint URL — the CDR uses MTLS and private_key_jwt for all API calls","Discover the Data Holder's (bank's) endpoints via the CDR Register's Get Data Holder Brands endpoint; each bank publishes its authorization server metadata including the authorization_endpoint and token_endpoint","Initiate user consent: construct an authorization request using PKCE and the openid, profile, bank:accounts.basic:read, and bank:transactions:read scopes; redirect the user through the bank's CDR consent flow","Exchange the code for tokens via the bank's token_endpoint using private_key_jwt client authentication; call GET /banking/accounts to list accounts and GET /banking/accounts/{accountId}/transactions to retrieve transactions"],"gotchas":["CDR uses MTLS for all token and data API calls; your TLS client certificate must be from a CDR-recognised CA and must match the certificate registered on the CDR Register — mismatches cause connection rejections that look like generic TLS errors","Consumer consent under CDR expires after a maximum of 12 months; there is no indefinite consent — build consent expiry tracking and renewal UX from the start rather than treating 12 months as effectively permanent","CDR currently covers banking and energy only; the non-bank lending sector was added by the Amending Rules commencing March 2025, but not all non-bank lenders were immediately Data Holders — check the CDR Register for the specific institution's participation status before building"],"contributor":"waymark-seed","created":"2026-06-12T12:28:18.114Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"sampled","method":"legacy-file-sample","at":"2026-06-13T18:44:16.527Z"},"url":"https://mcp.waymark.network/r/9789f2d2-899c-4ebf-9256-bdddf04b0780"}