
Consulting your bank accounts online at Crédit Agricole des Côtes-d’Armor requires mastering two distinct elements: classic identification (username and personal code) and strong authentication mandated by the European DSP2 regulation. These two layers of security do not function the same way, and their interplay determines what you can actually do once connected.
SécuriPass and DSP2: What Really Conditions Access to CA 22 Account
The most common confusion concerns the difference between connection and operational access. A correct username associated with the personal code allows you to view the balance and transaction history. However, without SécuriPass activated, sensitive operations are blocked, even if your credentials are perfectly valid.
Specifically, adding a beneficiary for a transfer, validating an online payment, or modifying card limits require validation via the Ma Banque app installed on your smartphone. This requirement stems from the European DSP2 directive, which imposes strong authentication for any operation involving financial risk.
For clients of the Côtes-d’Armor regional bank, the procedure is identical to that of other regional banks of Crédit Agricole. You can access my CA 22 account online via the dedicated portal, but prior activation of SécuriPass remains a prerequisite to go beyond simple consultation.
| Feature | Username + code only | With SécuriPass activated |
|---|---|---|
| Balance consultation | Yes | Yes |
| Transaction history | Yes | Yes |
| Transfer to registered beneficiary | No | Yes |
| Adding a new beneficiary | No | Yes |
| Online payment (3D Secure) | No | Yes |
| Modification of card limits | No | Yes |
| Document download | Yes | Yes |

Detection of Unusual Connections at Crédit Agricole: Alerts and Blocks
Since 2023, Crédit Agricole has deployed a system for detecting unusual connections that analyzes several parameters: new device, unknown geographical location, atypical browsing behavior. When an anomaly is detected, the system triggers an alert via SMS and may require strong revalidation before allowing access.
This mechanism adds a layer of protection that operates independently of your personal vigilance. If you connect from a computer you have never used, expect to receive a verification SMS, even if your username and code are correct.
A common trap: some clients interpret this alert as a malfunction and contact their agency when the system is functioning exactly as intended. An unusual connection alert protects the account; it does not indicate a failure.
Virtual Keyboard and Personal Code: How the CA 22 Identification System Works
The identification procedure on the Crédit Agricole Côtes-d’Armor website relies on a virtual keyboard whose numbers change position with each connection. This system prevents malware such as keyloggers from recording your code by capturing keystrokes.
The connection steps are as follows:
- Enter your account number in the designated field, using the physical keyboard
- Compose your confidential code by clicking on the numbers of the virtual keyboard displayed on the screen
- In case of an error, use the “correct” button which only erases the last character entered
- Confirm by clicking on “confirm” to access your personal space
The personal code and username do not change when the virtual keyboard is implemented. If you already had online access, your credentials remain the same.
What to Do If the Virtual Keyboard Does Not Display
The absence of the virtual keyboard usually results from a script blocker or an outdated browser. The keyboard relies on an interactive element that requires JavaScript to be enabled. Check your browser settings before contacting support.
Ma Banque App and Phishing: Two Points of Vigilance on CA 22 Account
The Ma Banque app, available on Android and iOS stores, is the preferred channel for managing your CA 22 account on a daily basis. It directly integrates SécuriPass and allows you to receive validation notifications without leaving the app.
The main risk does not come from the app itself but from phishing attempts that mimic communications from Crédit Agricole. The bank never asks for your credentials via email or SMS. Any solicitation of this type should be ignored and reported.
Some reflexes significantly reduce the risk:
- Always access the site via the official URL of the regional bank, never from a link received by message
- Ensure that the address in the browser’s address bar starts with the official domain of Crédit Agricole
- Never provide your personal code or SécuriPass number to a phone contact, even if they present themselves as an advisor

Access to the CA 22 account relies on the interplay between a classic username and strong authentication via SécuriPass. Consultation alone remains accessible with just the credentials, but any active banking operation requires SécuriPass on an associated smartphone. Unusual connection alerts and the virtual keyboard complement this system without requiring any additional action on your part.