Skip to content

FAPI_Meeting_Notes_2024 10 16_Atlantic

Nat Sakimura edited this page Jul 10, 2026 · 1 revision

FAPI Working Group Meeting Notes - October 16, 2024

Attendees

  • Nat Sakimura
  • Dave Tonge
  • Mike Leszcz
  • Joseph Heenan
  • Kosuke Koiwai
  • Filip Skokan
  • Peter Stanley
  • Robert Gallagher
  • Hideki Ikeda
  • Aaron Parecki
  • Anders Rundgren
  • Dima Postnikov
  • Bjorn Hjelm
  • Brian Campbell
  • George Fletcher
  • Gail Hodges

Agenda

  1. Roll Call
  2. Adoption of Agenda
  3. Events & External Orgs & Liaisons
  4. Open Banking 2.0
  5. FAPI 2.0 issues
  6. PRs
  7. Issues
  8. AOB

Events & External Orgs Update

Mike Leszcz provided updates on upcoming events and ecosystem engagement:

  • OIDF workshop at Microsoft on October 28th prior to IIW. Registration open until October 21st.
  • IIW on October 29-31. 20% discount code available: OIDF_XXIX_20
  • DCP WG meeting prior to the OIDF workshop on October 28th, registration required
  • CMF Chile workshop - blog post with recordings and slides published
  • Continuing work with UAE on FAPI conformance testing
  • Coordinating next check-in with Open Banking Canada team

Mike also reminded members to vote on the poll to approve updated IPR Policy and Process Document.

Open Banking 2.0 Presentation

Anders Rundgren presented on his concept for "Open Banking 2.0":

  • Proposes a "banking as an operating system" approach
  • Aims to provide a core API that different wallet schemes and PSD2 interfaces could be built on top of
  • Goal is to make it easier and less costly to implement interfaces to banks
  • Applications would be loosely coupled to the core banking API
  • Could potentially allow for certification of applications that could then be deployed across multiple banks
  • Intended to be more flexible for innovation and continuous iteration

FAPI 2.0 Issues

Dave Tonge discussed some recent changes to FAPI 2.0 that impacted the security posture:

  • A change was made 9 months ago that altered how the issuer value is handled in private_key_jwt client authentication
  • This change was not reflected in the formal security analysis
  • Proposal to revert the client-side change back to the implementer's draft 2 behavior
  • Discussion on whether to make a corresponding change on the authorization server side for parity

Key points from the discussion:

  • Reverting the client-side change seems acceptable
  • Changing the server-side behavior would be a more significant change that could impact interoperability
  • Current server behavior supports interoperability but has caused some confusion for implementers
  • Concerns raised about relying solely on client conformance without server-side enforcement
  • Suggestion to potentially address this in a future update rather than delaying the current draft

Next Steps

  • Further discussions needed offline to determine how to proceed
  • Working group will need to review and agree on any changes before moving to public review
  • Goal is still to move to 60-day public review for final draft, but some issues may need resolution first

Action Items

  • Dave to organize follow-up discussions on the FAPI 2.0 issuer handling issue
  • Working group to review proposed changes once prepared
  • Anders to share slides from Open Banking 2.0 presentation

The meeting concluded early to allow for separate discussions.

Clone this wiki locally