-
Notifications
You must be signed in to change notification settings - Fork 0
FAPI_Meeting_Notes_2024 12 12_Pacific
Nat Sakimura edited this page Jul 10, 2026
·
1 revision
Date & Time: 2024-12-13 00:00 UTC Location: https://zoom.us/j/97456084642?pwd=bTRFVzk4ZmlRK1M3bEprRlN5c3JFZz09
Agenda
The meeting was called to order at 00:00 UTC.
- Attendees: Nat, Dina, Adam, Joseph and Anoop
- Regrets:
- OAuth Security Workshop 2025 (February 26-28, 2025) Location: Reykjavik, Iceland
-
- OIDF is a sponsor
-
- Final deadline for presentation submissions: January 12, 2025
-
- Certification team will meet prior to workshop
OIDF calendar on website is current: https://openid.net/calendar/
- UAE Workshop completed and recording is on OIDF website.
- UAE certification is opening soon and step-step guide has been developed.
- OIDF/FAPI overview presentation planned for UAE Central Bank officials
- Norway Health ID
-
- ~350 organizations using FAPI 2 for e-prescriptions
-
- Blog post planned about successful FAPI 2 adoption
- DPoP Error Code Discussion (from Atlantic call)
-
- Question raised about error codes when clients don't send required DPoP requests
-
- Consensus that "invalid_request" is appropriate error code
-
- Discussion of T-Mobile US requiring sender-constrained tokens for new APIs
-
- Noted that some implementations may need to support both DPoP and non-DPoP flows
- FAPI 1 Errata (Issue #700) - Private key JWT language to be imported from FAPI 2 - New issue created to track this
- JARM IANA Registrations (Issue #703) - Fixed through merged PR
- Working Group Purpose and Scope (Issue #425) - Awaiting details on new rechartering process - Need to align with current working group activities
- PR #523 - IANA registration section updates
- PR #524 - JAR errata fixes
- PR #525 - Name spelling correction
- PR #522 :
-
- Extended discussion on client requirements
-
- Concerns about implementation complexity during transition period
-
- Agreement to merge based on working group consensus despite not being unanimous
-
- Decision to document reasoning in PR comments
- PR #528 - Editorial changes to correct numbering
- PR #526 - Document link updates
- PR #519 - Separating HTTP signing (pending merge resolution)
- Final Review Process
-
- Agreement to restart the public review process
-
-
- Final Specification public review period: Monday, December 9, 2024 to Friday, February 7, 2025 (60 days)
-
-
-
- Final Specification vote announcement: Saturday, January 25, 2025
-
-
-
- Final Specification early voting opens: Saturday, February 1, 2025
-
-
-
- Final Specification voting period: Saturday, February 8, 2024 to Saturday, February 15, 2025 (7 days)*
-
-
- Message Signing spec to be handled separately
-
- One PR remaining for HTTP signatures separation
- FAPI 1.0 Maintenance
-
- Discussion of potential FAPI 1.1 vs errata approach for security updates. (Resolved to be done as Errata).
-
- Waiting for clarification on what changes can be included in errata
-
- Need to balance supporting existing ecosystems while encouraging FAPI 2 adoption
-
- Consideration of certification implications
- Anoop vacation 12/16/24 to 01/06/2025.
-
- Should we have call on 12/26/2024 and 01/02/2025. - Cancel these two occurrence.
Next call will be an Pacific Call. Next Pacific call will be in Next year (01-16-2025 @ 5pm PST) UTC - 01-17-2025 1:00 AM.