Skip to content
Banque de France · France

ONEGATE — the Banque de France portal and test environment

Fintech Passport
August 26, 2026 · 12-min read
ONEGATE — the Banque de France portal and test environment

A French return is never late because the numbers were late. It is late because nobody was accredited on the right collection, or the certificate expired, or the period was already Fermé by the time the correction was ready. ONEGATE is the single window through which a payment or e-money firm delivers almost everything the Banque de France and the ACPR ask for, and it has its own vocabulary, its own enrolment clock and its own idea of what “submitted” means. This piece sets out how the channel works — the transmission modes, the test environment, the accreditation path, and how to read an acknowledgement.

1. What ONEGATE is

ONEGATE is the Banque de France’s collection window — an acronym the Bank spells out as Organisation Nouvelle des Échanges via un Guichet d’Alimentation et de Transferts vers l’Extérieur. One authenticated portal in front of many separate data collections, each defining its own format and cadence while the reporting firm holds a single set of credentials.

The obligations funnelled through it have their own legal roots. Under article L. 141-6 of the Code monétaire et financier the Bank’s power to obtain documents and information for its fundamental missions reaches credit institutions and expressly electronic money institutions and payment institutions; the payment-instrument statistics collections rest on articles L. 141-4 and L. 141-6-I, and above them sits Regulation (EC) No 2533/98 on ECB statistics. Accreditation is an administrative act; the duty to file is statutory and sits elsewhere.

ONEGATE is not a return. It is the pipe: each obligation — prudential statements, the balance-of-payments collections, the payment-security collections — arrives as a domaine with its own reports, periods and validation rules, and documentation for banking-sector collections is published on the Bank’s separate eSurfi site rather than inside the portal.

Four terms recur, and the portal’s screens and error messages use them literally:

TermWhat it means in ONEGATE
Déclarant (assujetti)The entity that owes the data — the regulated firm itself
RemettantThe actor authorised to key or load data, for itself or on behalf of a third party
RemiseOne delivery of expected data from a déclarant to the Banque de France
Canal de remiseThe transmission mode: through the browser (U2A) or system-to-system (A2A)

The déclarant/remettant split is not cosmetic. Rights are granted per collection and déclarant pair, so a group reporting for several French entities, or a firm using an external filing agent, has to think about a matrix rather than about “an account”.

2. Two channels, and two strengths of authentication

ONEGATE offers a human channel and a machine channel. The U2A channel (user to application) is the web interface, and which authentication strength applies depends on the sensitivity of the collection rather than the firm’s preference: weak access is an email address and a password, strong access an authentication certificate. Each runs on its own hostname, with a matching homologation twin (section 3). Certain surveys — the Bank’s guide names DATAGAPS and DATABRI among them — are certificate-only.

The A2A channel (application to application) removes the browser and comes in two protocols: an EAI link, requiring a route built between the Bank’s systems and the firm’s, or a web service call, requiring a machine connection certificate and a dedicated URL. Neither is self-service; both are set up with the Bank under the published technical notice.

Three consequences follow, all routinely discovered late. The certificate the portal accepts is an X.509 file exported in base-64 .CER form, public key only. Renewal is not automatic: the new certificate must be sent to ONEGATE support so the account is updated, making expiry a diarised task rather than an IT surprise. And passwords prompt for change every 63 calendar days, though on some collections they may not expire at all.

3. The homologation environment — and the ONEGATE test addresses

Every production hostname has a homologation twin, and the pairing is the most useful single fact about the portal for anyone building a return. Production sits on onegate.banque-france.fr for weak authentication and onegate-strong.banque-france.fr for certificate access; the test environment sits on onegate-test.banque-france.fr and onegate-strong-test.banque-france.fr respectively. The two worlds are separate by design: data placed in homologation is not migrated to production, so a test period is a rehearsal and never a filing.

The environment has become materially more useful than it was. Following a change announced on the Bank’s eSurfi site in December 2024, all reference periods and submission modules are available through the OneGate Homologation portal, so software providers and reporting institutions can test exhaustively rather than against a narrow subset. A firm can now rehearse the actual period and module it will file — loading a real-shaped file, collecting a ticket, and reading the per-step statuses in the form they will take in production.

Three limits matter before a successful test is treated as clearance to file. A homologation account is not a production accreditation: rights are per collection and déclarant pair in each environment, so a firm can be fully exercised in test and still unaccredited in production. A certificate that works in test must still be registered with support for the production account. And the documentation moves with portal releases — a Guide Remettant with an English submitters’ version, a note on the newer version’s evolutions, and a separate notice technique for télétransmission governing the machine channel.

Worked example: the test that proved the wrong thing. Facts: a payment institution rehearses its first French return successfully in homologation on the weak-authentication host, and schedules the first production delivery for the deadline week. Rule: the two environments are separate, with accreditation per collection and déclarant pair in each, test data is not migrated, and production certificate registration is a support action. Action: confirm in Profil that the production pair is validated rather than requested, register the production certificate with support if the collection is certificate-only, and make one delivery on the matching production host in a period that is not the deadline period. Outcome: the first real delivery is the second delivery, which is the point of the twin environments.

4. Accreditation is the critical path

The identifier is an email address, and it must be nominative and professional — a generic address or shared mailbox cannot be used. For a function that habitually files from reporting@ that is structural: the person is the account, and holiday cover is a second accredited person, not a shared login.

The request forks on one question — do you have an accreditation code? Some collections are available exclusively by code, issued by the business referent. Without one the requester selects the collections and déclarants covered, and an acknowledgement email is sent to the address given.

Validation is performed by a collection manager, and — the part that surprises project plans — per collection/déclarant pair. A success produces one email with a provisional password plus a confirmation for each pair; a refusal produces an email with the reason for that pair. Being accredited on one collection and refused on another from the same request is normal.

Once inside, Profil manages the matrix: every validated authorisation with its roles, plus the function for requesting rights on a new déclarant/domain pair.

5. Making a remise

File loading. The home page carries a Chargement de fichiers area accepting .xml and .xbrl files, signed or unsigned, with .ZIP compression permitted, several at a time. On send the file moves to en cours d’intégration and a ticket number appears, which is the handle for everything that follows.

Online entry. The Rapports menu reaches the same obligations as web forms. Each period carries two attributes worth reading before keying anything: a life cycle — Initial, Ouvert or Fermé — and a state — Ok, Alerte or Erreur. On some surveys a UTF-8 .CSV can be imported instead of keying, in Ajout or Remplace mode, with an Historique des imports tab and an anomaly report for each file. The form is closed and sent with the padlock control.

Online-entry deliveries appear in the same tracking screens as file deliveries, but their ticket identifiers are prefixed with N-. That prefix is the fastest way to tell, months later, whether a period was keyed or loaded — which matters when a correction has to reproduce the original method.

6. Reading the acknowledgement

The Suivi > Suivi des remises screen lists deliveries with a status filter and a CSV export. Opening a ticket gives the delivery detail, where the real answer lives: each processing step carries its own status, and there are exactly three values — Succès, Avertissement, Échec. A Messages column counts what each step raised, and for many steps the processing report can be downloaded.

For signed deliveries the detail screen adds a signature block reporting four things separately: the signatory, the signature, the certificate and the habilitation. The fourth fails silently in practice — a technically valid signature from a person whose rights on that pair have lapsed.

Notifications are configurable per email address in Profil across three types — de remise, de retard for late-filing reminders, and métier for business collection reports. For A2A reporters, support has to link the addresses to the account.

The old messaging function has been replaced by document management: Suivi > Documents lists everything received, by domain and déclarant, with the document type — CRC, late-filing reminder and others — and a download link.

7. Two more scenarios

Scenario one: the branch that cannot file. A payment institution passporting into France opens a branch and appoints its group reporting team, in another Member State, to file. Facts to rule: rights are per collection/déclarant pair, and the identifier must be a nominative professional email. Action: name two individuals, register each separately, request the pairs for the French déclarant explicitly, then check Profil shows each pair validated rather than merely requested. The failure mode is one accredited person on leave the week a quarterly return closes.

Scenario two: the correction that overwrote nothing. A firm keys a period through the Rapports forms, then finds an error after closing and sending. Facts to rule: the period life cycle and state are visible before anything is re-opened, and online-entry deliveries carry the N- ticket prefix. Action: read the period first — one showing Fermé cannot simply be re-keyed — retrieve the original ticket, and follow the correction route the collection defines rather than assuming a second delivery supersedes the first. Outcome: one authoritative version instead of two deliveries and no evidence of which the Bank holds.

8. Planning around the channel

The portail ONEGATE, as the Banque de France and the ACPR both label it in French, publishes a separate test environment for exactly this purpose, and using it is the single cheapest risk reduction available on a new collection. A test remise exercises the parts of the chain that production will exercise for the first time under deadline pressure: whether the accreditation actually covers the collection and déclarant pair being used, whether the certificate the client presents is the one the portal holds, whether the file passes the format check, and whether the acknowledgement is retrievable by the person who will have to read it. None of those four is verified by a successful login. Firms that run one test cycle per collection before the first production period, rather than one before go-live overall, catch the pair-level gaps that a single end-to-end rehearsal hides.

The sequencing that works: identify the domains before the deadlines, request accreditation the moment the entity is authorised rather than the month the first return falls due, and treat homologation as part of the build.

Two support facts belong in the runbook, because they decide what can be resolved on a filing day. ONEGATE support runs 08:00 to 19:00, by phone on 01 42 92 60 05 and at Support-OneGate@banque-france.fr. And the home page carries colour-coded notes informatives — red for unplanned outages, orange for planned, blue for general notices, green for new releases — the first place to look before escalating a failed delivery.

Is there a ONEGATE test environment, and what is its address?

Yes. Homologation mirrors production on separate hostnames: onegate-test.banque-france.fr for login-and-password access and onegate-strong-test.banque-france.fr for certificate access. Since a change announced in December 2024, all reference periods and submission modules are available there.

Does data submitted in the ONEGATE test environment carry over to production?

No. Homologation data is not migrated to production, and a homologation account is not a production accreditation — rights are granted per collection and déclarant pair in each environment. A successful test proves the file and the process, not that you are cleared to file.

Is ONEGATE a return, or a channel?

A channel. Each obligation arrives at the portal as a separate domain with its own reports, periods, formats and validation rules. Being accredited on ONEGATE says nothing about which returns a firm owes.

Can a reporting agent file on behalf of a regulated firm?

Yes — the portal’s own definition of a remettant covers acting for a third party. Rights are still granted per collection and déclarant pair, so the agent needs the pair for each entity it files for.

What does the ticket number prove?

That the file was staged for integration. Acceptance is established by the per-step status inside the delivery detail — success, warning or failure — and, where the collection is configured for it, by the business collection report delivered afterwards under Suivi > Documents.

9. What to do, today

  • List the domains your French entity owes and map each to the person accredited for that collection/déclarant pair — gaps in that matrix are the most common cause of a missed French deadline.
  • Replace any shared-mailbox filing identity with named individuals, at least two per collection.
  • Put certificate expiry in the reporting calendar; renewal means sending the new base-64 .CER to support.
  • Monitor the delivery step status, not receipt of a ticket number.
  • Route late-filing notifications to a monitored group address rather than one person’s inbox.
  • Rehearse on onegate-test.banque-france.fr or onegate-strong-test.banque-france.fr before the first production period closes — and then confirm the production pair is validated, because test access is not accreditation.
  • Record the N- prefix convention, so a later correction reproduces the original delivery method.

Related: OneGate at the NBB — the Belgian original · Reporting channels compared across the EU · SURFI — French supervisory reporting · The French reporting calendar for a payment firm · Testing a new return before first submission · RPC, CRT and CRC — French balance-of-payments returns · FCC and FNCI — the French cheque registers · FICP — the French credit-incident register · QLB — the ACPR annual AML questionnaire · ERMES TRACFIN — the déclaration de soupçon platform · SIREN, SIRET and the French RNE · Rapport de contrôle interne LCB-FT — the ACPR’s 30 April report

Related reads.