Skip to content

FAPI_Meeting_Notes_2024 12 12_Pacific

Nat Sakimura edited this page Jul 10, 2026 · 1 revision

FAPI WG Agenda & Meeting Notes (2024-12-12)

Date & Time: 2024-12-13 00:00 UTC Location: https://zoom.us/j/97456084642?pwd=bTRFVzk4ZmlRK1M3bEprRlN5c3JFZz09

The meeting was called to order at 00:00 UTC.

  • Attendees: Nat, Dina, Adam, Joseph and Anoop
  • Regrets:
  • OAuth Security Workshop 2025 (February 26-28, 2025) Location: Reykjavik, Iceland
    • OIDF is a sponsor
    • Final deadline for presentation submissions: January 12, 2025
    • Certification team will meet prior to workshop

OIDF calendar on website is current: https://openid.net/calendar/

  • UAE Workshop completed and recording is on OIDF website.
  • UAE certification is opening soon and step-step guide has been developed.
  • OIDF/FAPI overview presentation planned for UAE Central Bank officials
  • Norway Health ID
    • ~350 organizations using FAPI 2 for e-prescriptions
    • Blog post planned about successful FAPI 2 adoption
  • DPoP Error Code Discussion (from Atlantic call)
    • Question raised about error codes when clients don't send required DPoP requests
    • Consensus that "invalid_request" is appropriate error code
    • Discussion of T-Mobile US requiring sender-constrained tokens for new APIs
    • Noted that some implementations may need to support both DPoP and non-DPoP flows
  • FAPI 1 Errata (Issue #700) - Private key JWT language to be imported from FAPI 2 - New issue created to track this
  • JARM IANA Registrations (Issue #703) - Fixed through merged PR
  • Working Group Purpose and Scope (Issue #425) - Awaiting details on new rechartering process - Need to align with current working group activities
  • PR #523 - IANA registration section updates
  • PR #524 - JAR errata fixes
  • PR #525 - Name spelling correction
  • PR #522 :
    • Extended discussion on client requirements
    • Concerns about implementation complexity during transition period
    • Agreement to merge based on working group consensus despite not being unanimous
    • Decision to document reasoning in PR comments
  • PR #528 - Editorial changes to correct numbering
  • PR #526 - Document link updates
  • PR #519 - Separating HTTP signing (pending merge resolution)
  • Final Review Process
    • Agreement to restart the public review process
      • Final Specification public review period: Monday, December 9, 2024 to Friday, February 7, 2025 (60 days)
      • Final Specification vote announcement: Saturday, January 25, 2025
      • Final Specification early voting opens: Saturday, February 1, 2025
      • Final Specification voting period: Saturday, February 8, 2024 to Saturday, February 15, 2025 (7 days)*
    • Message Signing spec to be handled separately
    • One PR remaining for HTTP signatures separation
  • FAPI 1.0 Maintenance
    • Discussion of potential FAPI 1.1 vs errata approach for security updates. (Resolved to be done as Errata).
    • Waiting for clarification on what changes can be included in errata
    • Need to balance supporting existing ecosystems while encouraging FAPI 2 adoption
    • Consideration of certification implications
  • Anoop vacation 12/16/24 to 01/06/2025.
    • Should we have call on 12/26/2024 and 01/02/2025. - Cancel these two occurrence.

Next call will be an Pacific Call. Next Pacific call will be in Next year (01-16-2025 @ 5pm PST) UTC - 01-17-2025 1:00 AM.

Clone this wiki locally