These guidelines provide examples for where the consumer authenticates using the data holder’s app.
<aside>
Redirect to App provides a faster, safer and more convenient way for consumers to authenticate with a data holder before sharing their CDR data. When a consumer has their data holder’s app installed on their device, this flow streamlines authentication and improves security while also reducing friction.
To support this, data holders must use a separate issuer identifier for each app they provide — as set out in the Authentication Flows section of the Security Profile Standards and the Decision 369 Explanatory Document. In some cases, this may mean using different identifiers for different customer groups, e.g. retail vs. business customers. Where data holders offer multiple apps across lines of business, each brand must be represented independently in the CDR Register so ADRs can direct consumers to the correct app during consent.
Data holders should align these choices with how consumers already interact with their services and brands across existing digital channels.
All data holders and data recipients must implement the relevant redirect to app and authentication standards by 10 May 2027. If implemented prior to this date, CDR participants will also need to meet other relevant standards, including Fallback Authentication Flows, unless otherwise stated.
<aside> <img src="/icons/info-alternate_gray.svg" alt="/icons/info-alternate_gray.svg" width="40px" />
Note: The wireframes shown are examples of how to implement key rules, standards, and guidelines. Use the on-screen functions to adjust zoom level or expand the wireframes to be viewed at full screen.
</aside>
The following wireframes show a basic example of Redirect to App.
https://embed.figma.com/design/wRppfTQZm4LPw8QUnLK5U7/WIP25-MI24-|-2AU1.-Redirect-to-App-v1.XX.X.2025.09.XX?node-id=424-0&embed-host=notion&footer=false&theme=system