Skip to content

FAPI_Meeting_Notes_2025 03 05_Atlantic

Nat Sakimura edited this page Jul 10, 2026 · 1 revision

OpenID Foundation FAPI Working Group Meeting Notes

Date: 2025-03-05 14:00 UTC

Attendees

  • Nat Sakimura (Chair)
  • Dave Tonge
  • Mike Leszcz (OIDF)
  • Mark Haine
  • Dima Postnikov
  • George Fletcher
  • Takahiko Kawasaki
  • Peter Stanley (OBL)
  • Peter Wallach (Mastercard)
  • Robert Gallagher (Mastercard)

Agenda

  1. Roll Call
  2. Adoption of Agenda
  3. Events
  4. External Orgs & Liaisons
  5. Chilean Monetary Authority Discussion 5.5. iGov WG topics
  6. PRs
  7. Issues
  8. AOB

1-2. Roll Call & Agenda Adoption

The meeting started at 3 minutes past the hour. Attendees noted their names in the chat, and the agenda was adopted with the addition of iGov WG topics as item 5.5.

3. Events

Mike Leszcz provided updates on upcoming events:

  • Recently completed: OSW in Reykjavik (next year will be in Germany, dates TBC)
  • Upcoming events:
    • ISO SC 27 WG5 meetings in Fairfax, VA (next week) - Mark Haine will attend representing OIDF
    • MOSIP Connect (Philippines, next week) - Joseph Heenan will attend
    • ISO SC 27 meetings in Fairfax, VA (March 17-18)
    • IETF in Bangkok (March 15-21)
    • OIDF Workshop prior to IIW at Google in Mountain View (April 7) - Registration link shared
    • DCP WG meeting prior to the workshop at Google - Registration link shared
    • IIW (April 8-10)
    • RSA 2025 (April 28-May 1) in San Francisco
    • EIC in Berlin (May 6-9)
    • Identiverse in Las Vegas (June 3-6)

Takahiko Kawasaki reported on Japan Fintech Week activities:

  • FAPI and VC meeting at Pheno Lab in Tokyo was well-attended with a full house of 40-50 people
  • Good questions from the audience, including from government organizations interested in FAPI and VC activities

Mark Haine shared additional events:

  • ID4Africa in Addis Ababa (May 20-23) - Gail and Elizabeth will represent OIDF
  • Rwanda Open Banking community event in Kigali (May, exact date TBD) - Rwanda has selected FAPI 2
    • Mark noted Rwanda seems to be taking the lead on open banking in Africa

4. External Orgs & Liaisons

Mike Leszcz reported:

  • Certification team is prioritizing Brazil's open banking and open insurance certification requests
  • Team is working on conformance test development in parallel
  • Actively reaching out to ecosystem partners about FAPI 2 final specifications

Mark Haine provided an update on discussions with the Haus ID team from Norway:

  • They're targeting FAPI 2 and are keen to support it
  • They've started building their own conformance testing capability but weren't aware of OIDF's work
  • During testing at OSW, their implementation failed some tests, which helped them understand the value of the conformance tools
  • They have one singular IDP and currently about 300 relying parties, with plans to expand to thousands
  • They're looking at relying party conformance as a key focus

5. Chilean Monetary Authority Discussion

Dima Postnikov and Mark Haine reported on their meeting with the Chilean regulator:

  • Chile is planning to roll out open banking and has selected FAPI 2
  • They sought advice on whether to use a consent API approach or RAR plus Grant Management
  • The vendor appears to be steering them toward a consent API approach that the vendor has already implemented
  • The OIDF team presented pros and cons of both approaches:
    • Both are viable for individual ecosystems
    • Grant Management would help with standardization, security analysis, global expert support, and easier interoperability
    • Consent management might be easier for the sandbox provider to implement

Key points from the discussion:

  • CMF understands Grant Management is a newer spec with less maturity but has tests already
  • Chile is keen to achieve interoperability with other South American jurisdictions (Brazil, Colombia, Mexico)
  • OIDF didn't make a specific recommendation but indicated that for new implementers, they would lean toward recommending Grant Management + RAR to help progress global standards work
  • The team is preparing a write-up for CMF

Dima noted that work on Grant Management had been paused while waiting for ecosystem signals for adoption. The Chilean interest may be the signal they were waiting for.

5.5 iGov WG Topics

Mark Haine reported on his first attendance at the iGov working group:

  • The session evolved into helping them better understand FAPI
  • The main difference between iGov profile and FAPI is that iGov supports public clients
  • When questioned, iGov representatives didn't have a clear answer on why public clients are needed
  • They will inquire within their community for real-world use cases for public clients
  • Mark clarified that native mobile clients can be confidential clients, contrary to some apparent misunderstandings
  • Mark suggested iGov consider directly referencing FAPI 2 instead of creating a separate overlapping profile
  • iGov members were concerned about "keeping up with FAPI," but were reassured that FAPI 2 is final and won't undergo normative changes
  • There may be potential for more alignment and convergence between the two standards
  • Mark will meet with Tom Clancy (iGov working group co-chair) in person next week

Nat Sakimura noted that iGov typically requires logging assurance and OpenID Connect with acr. Mark confirmed this came up in the discussion, and he shared a real-world identity assurance payload. There may be reuse of the identity assurance spec in that context.

6-7. PRs and Issues

Dave Tonge reported:

  • No new PRs to review
  • Dima has done analysis on ID2 versus final FAPI 2 changes and is waiting for Joseph to confirm which parts will be tested by the conformance test
  • Issue #714 on private key JWT audience restrictions is pending feedback from the certification team
  • HTTP Message Signing spec is administratively waiting on Dave to kick off the formal process after working group last call
  • Other items in the queue include errata for JAM and charter changes

8. AOB (Any Other Business)

Discussed the need to start work on implementation notes and deployment advice:

  • Many issues have been raised
  • Need to distribute tasks among working group members
  • Volunteers welcome to pick up issues

Meeting adjourned 20 minutes early.

Clone this wiki locally