Fio bank REST API implementation in PHP. It allows you to download and iterate through account balance changes. You can also upload payment orders.
There is a Symfony Bundle for using this library in a Symfony app.
- Install the latest version with
composer require webwingscz/fio-api-php - Create a token in the ebanking (Nastavení / API)
- Use it according to the example bellow and check the docblocks
<?php
require_once 'vendor/autoload.php';
$downloader = new FioApi\Download\Downloader('TOKEN@todo');
$transactionList = $downloader->downloadSince(new \DateTimeImmutable('-1 week'));
foreach ($transactionList->getTransactions() as $transaction) {
var_dump($transaction); //object with getters
}downloadFromTo(DateTimeInterface $from, DateTimeInterface $to): TransactionListdownloadSince(DateTimeInterface $since): TransactionListdownloadLast(): TransactionListsetLastId(string $id)- sets the last downloaded ID through the API
setBaseUrl(string $baseUrl)- override API base URL (sandbox/proxy/testing)setRequestTimeout(float $seconds)- total request timeout (timeoutin Guzzle)setConnectTimeout(float $seconds)- connection timeout (connect_timeoutin Guzzle)configureRetry(int $retryCount, int $initialDelayMs = 30000, float $backoffMultiplier = 2.0, ?int $maxDelayMs = null)- retries only failures where no response was received (PSR-18
NetworkExceptionInterface, which covers Guzzle'sConnectExceptionas well as Guzzle 8'sNetworkTimeoutException) - default initial delay is 30 seconds to respect Fio token rate limit
- retries only failures where no response was received (PSR-18
<?php
require_once 'vendor/autoload.php';
$uploader = new FioApi\Upload\Uploader('TOKEN@todo', 'accountFromWithoutBankCode@todo');
$uploader->addPaymentOrder(new FioApi\Upload\Entity\PaymentOrderCzech(...$params));
$response = $uploader->uploadPaymentOrders();
if ($response->hasUploadSucceeded()) {
// ...
}Both Downloader and Uploader accept an optional GuzzleHttp\ClientInterface, which is the seam for
anything the library does not configure itself (proxy, curl options, HTTP version, logging middleware):
$client = new GuzzleHttp\Client(['timeout' => 300]);
$downloader = new FioApi\Download\Downloader('TOKEN@todo', $client);Note that the Fio API endpoint advertises only http/1.1 over ALPN, so HTTP/2 is never used even
though Guzzle offers it.
Fio API PHP works with PHP 8.3 or higher.
- Current major line:
6.x - Supported PHP versions:
^8.3 - Supported Guzzle versions:
^7.0 || ^8.0 - Versioning policy: SemVer (
MAJOR.MINOR.PATCH) - Backward compatibility:
- No BC breaks in
6.xpatch/minor releases. - BC breaks are allowed only in next major version (
7.0).
- No BC breaks in
- Release policy:
masterbranch contains upcoming changes.- Tagged releases (
6.x.y) are considered stable and production-ready. - Security and critical bug fixes should be released as patch versions.
Bugs and feature request are tracked on GitHub
Please report vulnerabilities according to SECURITY.md.
Contribution guidelines are available in CONTRIBUTING.md.
Martin Hujer - https://www.martinhujer.cz Jiří Dorazil - https://www.webwings.cz
- support Guzzle 8 (
guzzlehttp/guzzle: ^7.0 || ^8.0); the previous~6.1 | ~7.0constraint capped consumers at Guzzle 7 and its Guzzle 6 support was untestable on modern PHP - send HTTP methods in upper case. Guzzle 8 no longer normalizes the request method, so the previous
'get'/'post'would have been sent to the Fio API verbatim - retry and wrap every no-response failure, not just
GuzzleHttp\Exception\ConnectException. Guzzle 8 classifies transport failures by phase, so a read timeout arrives asNetworkTimeoutException, which does not extendConnectException. The library now catches PSR-18NetworkExceptionInterface, which is correct on both Guzzle 7 and 8 - raise the minimum PHP version to 8.3 and declare
psr/http-client+psr/http-messageexplicitly - a malformed XML upload response now throws
InvalidResponseExceptioninstead of leaking libxmlE_WARNINGs alongside a bareException - mark every token parameter
#[\SensitiveParameter]so tokens are redacted in stack traces - drop the dead
Kdyby\CurlCaBundlecertificate fallback (composer/ca-bundleis a hard dependency) - modernize the codebase for PHP 8.3: readonly promoted constructor properties on the download entities,
native
staticreturn types on the fluent payment-order setters, nullsafe operators,neverreturn type - dev tooling: PHPUnit 9 → 11/12 with attribute metadata instead of doc-comment annotations; coverage is
now opt-in via
composer test-coverage, socomposer testno longer aborts without a coverage driver - CI: resolve dependencies with
composer update(a library does not commitcomposer.lock, socomposer installandcomposer audit --lockedcould not work), test PHP 8.3/8.4, lowest and highest dependencies, and Guzzle 7 and 8 separately
- add configurable base URL (
setBaseUrl) for sandbox/proxy/testing scenarios - add configurable request timeout and connect timeout
- add a configurable retry strategy with exponential backoff for connection errors
- improve downloader error handling for connection and invalid JSON responses
- remove invalid bundled CA certificate fallback and use explicit certificate resolution
- modernize coding standards from PSR-2 to PSR-12 and update PHP_CodeSniffer
- enforce release creation only after successful CI build
- make CI dependency installation deterministic via
composer install(lockfile-based) - add security checks to CI (
composer audit) and addroave/security-advisoriesto dev dependencies - add professional repository standards:
SECURITY.md,CONTRIBUTING.md, CODEOWNERS, issue and PR templates
- #31 add
composer/ca-bundleas a required dependency instead of bundled root cert (thx @�feldsam!)
- #28 use new Fio API URL (thx @�feldsam!)
- #19 gracefully handle response with empty column8 (thx @fmasa!)
- #17 added senderName (nazev protiuctu) (thx @jan-stanek!)
- #13 Support /last and /set-last-id endpoints (thx @jiripudil!)
- #12 handle empty transaction list (thx @soukicz!)
- #9 minimal supported version is PHP 7.1
- #9
DateTimereplaced withDateTimeImmutable(orDateTimeInterface) - #9 strict types and primitive typehints are used everywhere
- dropped support for PHP <7
- #7: added official composer CA bundle support (@soukicz)
- #2: added Kdyby/CurlCaBundle as an optional dependency (@mhujer)
- #1: updated default GeoTrust certificate (@soukiii)
- #1: added
specificationfield in transaction (@soukiii)
- upgraded to Guzzle 6
- support for PHP 5.4 dropped (as Guzzle 6 requires PHP 5.5+)
- updated root certificate (Root 3) as the Fio changed it on 2014-05-26
- initial release

