Skip to content

FAPI_Meeting_Notes_2017 03 15

Nat Sakimura edited this page Jul 10, 2026 · 1 revision

FAPI WG Meeting Notes (2017-03-15)

Date & Time: 2017-03-15 14:00 UTC

Location: GoToMeeting https://global.gotomeeting.com/join/321819862

The meeting was called to order at 14:05 UTC.

  • Present: Nat, John, Tom, Bjorn, Joseph, Dave.
  • Regrets: Henrik
  • Guest:
  • Adopted as is
  • Sacha has opened a pull request
  • Consensus to change "can" to "may"
  • WG discussed new draft for JWT Pop Token Usage <https://tools.ietf.org/html/draft-sakimura-oauth-jpop-01>
  • Discussion around the use of "Common Name" rather than "Distinguished Name"
  • Dave to circulate with UK Open Banking for feedback
  • WG discussed whether there should be "mandatory to implement" sections of the spec
  • WG decided that it was important that the client only need to support a small number of PoP methods - even if AS supported many
  • WG discussed how access tokens would be presented - Bearer vs Jpop. Draft to be reviewed to ensure this is clear. Feedback requested on feasibility of support within time constraints.
  • WG discussed Issue #72
  • WG agreed that where possible the implementation must support token binding and if not supported must require hybrid flow
  • Draft to be adjusted
  • N/A
  • N/A
  • N/A
  • FAPI Spec is in strong consideration
  • Need to work closely to ensure that the spec balances security requirements and real world implementation issues

Followings were not discussed.

  • No other external orgs were discussed
  • Next call is Pacific shift and is in next week.

The meeting adjourned at 15:01 UTC.

Clone this wiki locally