Skip to content

FAPI_Meeting_Notes_2022 06 01_Atlantic

Nat Sakimura edited this page Jul 10, 2026 · 1 revision

FAPI WG Meeting Notes (2022-06-01)

Agenda

The meeting was called to order at 14:__ UTC.

  • Attending:
    • Bjorn Hjelm
    • Dave Tonge
    • David Januchowski
    • Dima
    • Gail Hodges
    • Joseph Heenan
    • Kosuke Koiwai
    • Lukasz Jaromin
    • Mike Leszcz
    • Nat Sakimura
    • Takahiko Kawasaki
    • Brian Campbell
    • Danillo Branco
    • Don Thibeau
    • Filip Skokan
  • Regrets:
  • Guest:

Added potential FAPI 2 value add

Feedback on Canadian OB comments

  • F2F FAPI meeting Wednesday 6/22 normal meeting time
  • Remote attending available.
  • Norway Health Group testing FAPI 2.
  • Paypal
    • Discussed interoperability challenges in implementing FAPI in various jurisdictions
    • Indicated they will move onto FAPI 2
    • Testing FAPI 2 tests
    • Will have meeting later
  • Questions from analysis team:
    • Which commit to analysing?
    • Contact points?
      • Use Mailing list
  • Work of FAPI 2.0 security analysis on the way @ U. Stuttgart.
  • Gail was introduced to South Wales University of Australia who will help with the analysis
  • Still trying to finalize CIBA for Open Banking.
  • Outreach Workshops for Open Insurance in July and August
    • Will cover specs and conformance testing and submission
  • Phase 2 certifications to start in September 2022
  • Working on finalizing recommendation changes to certification program requested by Brazil and Saudi
  • N/A
  • Discussed Feedback response for FAPI 2 on Canadian OB policy requirements
  • https://docs.google.com/document/d/1-99-DU_B24NjywHpD_zS-Ga5FLoXgghRaL0DB91PvB0/edit
  • Accessible and inclusive for all accredited system participants without requiring additional arrangements (such as bilateral contracts)
    • FAPI specs are open and do not require contracts for usage
    • Add that specs are IPR protected to protect implementors from getting sued
  • Enable a positive consumer experience without overly onerous steps that the consumer must follow to realize the benefits of open banking
    • FAPI only defines the wire protocol
    • Ecosystems define the user experience guidelines
    • FAPI supports a range of user experiences
  • Enable the safe and efficient transfer of data among system participants
    • Specs are formally verified
    • Certification program verifies implementations
    • Serves as an *informal*, global defense against the global threat of criminal networks and rogue nation states…
  • Capable of evolving with technological change to keep pace with the rapidly evolving sector
    • Add that FAPI is expanding breath of capabilities (e.g. Grant Management, CIBA, Dynamic Client Registration)
    • Mention various OIDF work (GAIN, Open Data/Health, Verifiable Credentials, etc…)
    • Canadian Participants can join OIDF to participate in work
  • Sufficiently flexible to enable the development of new and innovative products
    • FAPI specs do not only apply to OB and Finance but to others (Insurance, telecom, health, etc…)
    • Can explore options for others applications
  • Compatible and interoperable with international approaches
    • Specs are inherently compatible
    • Leading security profile selected by most markets
    • Core specs enable cross border use cases
  • Add links to OpenID for Identity Assurance
  • n/a
  • Discussions on step-up authentication.
  • Mentioned the draft about it @ OAuth WG.
  • DPoP shepherd writeup being done.
  • Some implementation feedback to be incorporated.
  • n/a
  • n/a
  • n/a
  • Follow up call to be scheduled for June 15 or 16.
  • n/a
  • n/a
  • n/a
  • N/A
  • Name change PR.
  • Just moving to "FAPI"
  • FAPI 2 Baseline ==> FAPI 2 Security Profile
  • FAPI 2 Advanced ==> FAPI 2 Message Signing

etc.

PR is to be created.

  • none

The call adjourned at 15:59 UTC

Clone this wiki locally