Skip to main content

Nightly Refresh success depends on the institution’s Multi-Factor Authentication (MFA)

While Nightly Refresh is supported, the actual response depends on the financial institution, not on Flinks.A nightly refresh runs without the end user present. That only works when the institution allows an unattended reconnection. When the institution requires a one-time password, a push notification approval, or another challenge that only the end user can answer, the refresh cannot be completed. Most Canadian institutions now apply MFA on every login, so a significant share of connections will not refresh on their own. OAuth-connected institutions are the exception and refresh reliably.What this means for your integration:
  • Treat Nightly Refresh as a way to keep part of your account base current, not all of it. Plan for partial coverage.
  • Check the age of the data before you act on it. Do not assume a connection refreshed last night
  • For a guaranteed refresh, the end user must be present and complete a live connection through Flinks Connect. You can implement a “Refresh” button in your application that triggers a live /Authorize call withMostRecentCached: false. The user must complete the MFA step if prompted.
  • Reconnect reduces friction when an end user does need to reconnect. Do not rely on automatic nightly refresh for your use case.
Talk to your Flinks Representative about which institutions your customer base connects to. That mix is the best predictor of the refresh rate you will see.

Eligibility Criteria

A card must comply with certain eligibility criteria before being refreshed. For a card to be refreshed, it must satisfy the following conditions:
  • The Schedule Refresh parameter must be set to true. You can enable it in two ways:
    • Flinks Connect iframe: Add scheduleRefresh=true to your iframe URL parameters
    • API: Call the /SetScheduledRefresh endpoint to enable or disable nightly refresh for specific accounts
  • The card must have had a successful refresh in the last seven days.
  • (Not applicable for Webhooks integrations) The card must have received a cached call in the past seven days.
  • The card should not have any errors during Authorization. However, if an error has occurred, the card will still be eligible for refresh if the error is one of the following:
    • RETRY_LATER
    • AGGREGATION_ERROR
    • SESSION_EXPIRED
    • DISABLED_INSTITUTION
    • UNAUTHORIZED
    • SESSION_NONEXISTENT
    • BANK MAINTENANCE_RETRY_LATER
Security questions are not always prompted during Nightly Refresh. If MFA answers have been stored using the /AnswerMFAQuestions endpoint and Enhanced MFA is enabled, Flinks can answer them automatically, minimizing MFA interruptions during nightly refreshes.

Enabling Nightly Refreshes

You can enable automatic account refreshes using Nightly Refresh and Enhanced MFA.

Nightly Refresh

If your use case requires automatic account refresh to keep track of transactional history changes, you can enable Nightly Refresh for new accounts. For this, you need to set the scheduleRefresh parameter to true in the iframe URL.

Enhanced MFA (Deprecated)

Enhanced MFA is no longer supported

Enhanced MFA is no longer an actively supported feature. Most Canadian financial institutions have moved to one-time passwords and push notifications for MFA, which cannot be answered automatically. The enhancedMFA and skipEnhancedMFA iframe parameters should not be used in new integrations.For refreshing account data, implement a user-initiated reconnection flow instead. See the Reconnect guide for recommended approaches.

Useful Endpoints

/GetNightlyRefreshStatus: This endpoint returns a list with all of the loginIds that are set to Nightly Refresh ("isScheduledRefresh"=true), yet are no longer refreshing due to errors. The endpoint’s JSON response will clarify what error was encountered on the refresh attempt. /Authorize: This endpoint will also return the error message from the previous refresh attempt when running the batched cached calls. In cases where the JSON response doesn’t return any errors, please make sure you check the date of the latest refresh. An example can be seen in the image below: If the date of your last refresh is too long ago for your use case, perform a manual refresh: call /Authorize with MostRecentCached: false and Save: true, then call the aggregation endpoints with the returned requestId. See Reconnect for the full refresh and MFA-during-refresh flow.

Suggested daily routine

Complete the following steps in our suggested daily routine for refreshes:

Step 1: Check which loginIds are no longer eligible

Call the /GetNightlyRefreshStatus endpoint to identify accounts that are set to refresh but no longer meet the eligibility criteria:

Step 2: Handle loginIds not on the list

If any loginIds are not on the list, follow this flowchart to manually refresh them:

Nightly Refresh routine

The Nightly Refresh job has a daily routine. The job is scheduled to run from 4 a.m. to 8 a.m. (UTC). It will only impact all cards that meet the Eligibility Criteria.

Coverage

For more information about which financial institutions we support Nightly Refreshes for, contact your Flinks Representative.