Skip to content

FAPI_Meeting_Notes_2025 03 19_Atlantic

Nat Sakimura edited this page Jul 10, 2026 · 1 revision

FAPI Working Group Meeting Notes - March 19, 2025

  • Date: 2025-03-19 14:00 UTC
  • Location: Zoom

Attendees

  • Nat Sakimura (Chair)
  • Dave Tonge
  • Dima Postnikov
  • George Fletcher
  • Filip Skokan
  • Joe DeCock
  • Peter Stanley
  • Jake Fenley (Observer)
  • Kosuke Koiwai
  • Peter Wallach
  • Bjorn Hjelm
  • Hideki Ikeda

1. Roll Call & Agenda Adoption

Meeting began with a roll call via chat, followed by agenda adoption. Jake Fenley joined as an observer from Dave Tonge's team (IPR contribution pending).

2. Events

Upcoming events were noted:

  • IETF in Bangkok (March 15-21)
  • OIDF Workshop prior to IIW at Google in Mountain View (April 7)
  • DCP Working Group meeting prior to the workshop at Google
  • IIW (April 8-10)
  • RSA 2025 (April 28-May 1) in San Francisco
  • EIC in Berlin (May 6-9)
  • ID4Africa in Addis Ababa (May 20-23)
  • Identiverse in Las Vegas (June 3-6)

3. External Organizations & Liaisons

Blog Posts

Dima Postnikov reported on two blog posts being prepared for publication:

  1. A post describing differences between FAPI 2 Implementers Draft 2 and FAPI 2 Final
  2. A post explaining Grant Management and RAR in relation to FAPI authorization

DCP WG: Voting on HAIP

Dima also noted that voting had opened for the DCP Working Group's HAIP profile and encouraged members to vote: https://openid.net/foundation/members/polls/355

OAuth WG: Step-Up Authentication

George Fletcher mentioned an active thread in the OAuth mailing list regarding step-up authentication with RAR, suggesting members keep an eye on this discussion.

4. Pull Requests

Message Signing Final Draft (PR #535)

Dave Tonge presented a PR for the message signing final draft that:

  • Adds security analysis link
  • Updates references
  • Makes editorial changes to prepare for publication
  • Adds line in the intro: "is for has been formally analyzed with reference for its security and non-repudiation properties"

The PR was approved by Nat during the call.

Audience PR for CIBA (#529)

Discussion on Joe DeCock's CIBA audience PR:

  • The group is waiting on changes to the underlying specs
  • The current plan is to wait until FAPI 1 errata is completed
  • Joe indicated he was open to either approach (explicit mention vs. relying on underlying specs)
  • No urgent action is needed as CIBA is not widely used currently

5. Issues

Conformance Testing Issues

typ in Request Header (Issue #693)

  • Discussion about conformance testing for typ in request
  • Filip Skokan reviewed the code and noted it only checks if the header is present and if the value is "jwt"
  • The code doesn't handle prefixes properly
  • Issue to remain open as the PR didn't fully address the requirements

Private Key JWT Audience Restrictions (Issue #714)

  • Filip Skokan reported waiting for resolution on private key JWT audience restrictions
  • Indicated there are tests failing when authorization servers enforce new value
  • Clash between updating test suite for new guidance vs. allowing OPs to reject non-compliant values
  • Filip expressed concern about the lack of progress on both this issue and FAPI 2 final tests

Dave Tonge proposed opening a new issue to get a timeline for the FAPI 2 final test suite.

Implementation and Deployment Considerations Document Issues

The group discussed items to include in a new Implementation and Deployment Considerations document:

AS Rejecting Suspicious Requests (Issue #598)

  • Discussion about authorization servers rejecting requests with suspicious state/nonce parameters (e.g., script tags)
  • Agreement that AS can reject suspicious requests but shouldn't wholesale block certain characters
  • Decided to include guidance on this in the document, with a short paragraph in security considerations

UX Guidelines and Consent (Issue #429)

  • Discussion about the importance of user experience and proper user consent
  • Agreed such guidelines should be ecosystem-specific rather than part of FAPI core specs
  • Peter Stanley offered to share UK Open Banking's customer experience checklist and process

x-fapi Headers (Issue #282)

  • Discussion about the use of X-FAPI headers that were in FAPI 1 but removed from FAPI 2
  • Dima noted that while most headers aren't properly used, the X-FAPI-Interaction-ID is valuable for debugging and tracking
  • Discussion about whether to standardize headers across ecosystems
  • Concerns about IP address disclosure and customer presence indications
  • Agreement to poll existing ecosystems about what headers they find useful
  • Note that x- prefix convention is outdated

Error Messages (Issue #434)

  • Discussion about appropriate error messages, particularly for unrecoverable errors
  • Certification team looking for guidance on acceptable error messages
  • Agreement that for unrecoverable errors (like invalid redirect URI), the message should inform users it's not recoverable
  • Some suggestion that "please try again later" might be appropriate for errors that could be fixed by configuration
  • Group to discuss more with Joseph in a future meeting

6. Next Steps

  • Dave Tonge to open an issue about getting a timeline for FAPI 2 final test suite
  • Dave to begin work on the Implementation and Deployment Considerations document
  • Peter Stanley to share UK Open Banking's customer experience guidelines process
  • Group to consult with Joseph on error message guidelines

7. Any Other Business

No other business was raised. The meeting adjourned at the top of the hour.

Clone this wiki locally