Skip to content

FAPI_Meeting_Notes_2025 03 26_Atlantic

Nat Sakimura edited this page Jul 10, 2026 · 1 revision

OpenID FAPI Working Group Meeting Notes (March 26, 2025)

  • Date: 2025-03-26 14:00 UTC
  • Location: Zoom

Participants

  • Nat Sakimura (Chair)
  • Dima Postnikov
  • Filip Skokan
  • George Fletcher
  • Bjorn Hjelm
  • Hideki Ikeda
  • Imran Ulghar (OBL)
  • Kosuke Koiwai
  • Mike Leszcz (OIDF)
  • Robert Gallagher (Mastercard)

Regrets

  • Dave Tonge

Agenda

  1. Roll Call (Dave/Nat)
  2. Adoption of Agenda (Dave/Nat)
  3. Events (Mike L.)
  4. External Orgs & Liaisons (Mike L.)
  5. PRs (Dave)
  6. Issues (Dave)
  7. AOB (Nat)

1. Roll Call

  • Participants listed above attended the call

2. Events (Mike L.)

Mike shared upcoming events:

The OIDF calendar on the website is current: https://openid.net/calendar/

3. External Orgs & Liaisons (Mike L.)

  • Most ecosystem work is focused on activity in Brazil, specifically the Open Finance and Open Insurance annual FAPI recertifications
  • High volume of recertification requests that the team is managing
  • Teams also working on developing conformance tests for Federation, Shared Signals, Verifiable Credentials, and Verifiable Presentations

Follow-up Discussion:

  • Nat and Gail will be presenting about Open Banking/Open Finance ecosystems at EIC
  • Nat requested collecting information about the FAPI ecosystem worldwide in a comparable format
  • Mike and Dima have existing maps/slides of FAPI adoption that they will share
  • Discussion about creating a template to collect ecosystem information consistently
  • Dima mentioned there is an existing issue in the bitbucket tracking this

4. Member Reminder

5. PRs

Two PRs currently open:

  1. PR #536 - FAPI2 Message Signing editorial change (fixing file names)

    • Nat has approved, awaiting others to review and approve
  2. PR #529 - Previously discussed last week

    • Joe was updated that since there's no time pressure (unlike FAPI2), the group will wait for underlying spec updates
    • No immediate action required

6. Issues

Issue #719: FAPI2-MS Add reference to security analysis

  • Discussion about adding a link to security analysis
  • Tim recommended a DOI link
  • Action: Create a PR for this with the DOI link

Issue #621: Implementations of FAPI2 Message Signing

  • This is just for tracking implementations of FAPI2 Message Signing
  • Last comment from Taka in last week's meeting
  • Action: If anyone has new implementations, please report on the ticket

Issue #273: Security considerations re: large access tokens

  • Filip noted it's hard to give specific recommendations here
  • Even with RSA 4096 or MLDSA87, signatures will be large (4+ KB)
  • George suggested adding implementation guidance about adjusting deployments to support larger token sizes
  • Action: George will update the issue with proposed text

Issue #260: Add section in implementation advice document about supporting mobile apps

  • Last comment was from George regarding Android app link and app attestation
  • Joseph might know which Android version fixed the issue
  • Action: Nat will ask Joseph during their meeting tomorrow

Issue #197: New document proposal - FAPI Implementation Guide

  • Document has started but needs content
  • Action: Continue development of the guide

Issue #223: Need of a customer unique immutable identity as part of Id Token

  • From Manoop
  • Action: This will be added to the agenda for the next Pacific call (April 4th)

Issue #306: Webhook support in FAPI

  • Last discussed in 2023
  • Original suggestion was to add a section in implementation guidance, not a normative document
  • Dima suggested it might evolve into a separate profile of both webhooks and FAPI
  • Action: Nat will check with Anoop about the current status and need for this
  • Potentially related to Shared Signals work

Issue #290: X-FAPI-Interaction-ID across client to AS

  • Assigned to Dima
  • Action: Dima will review before next meeting

Issue #282: FAPI 2.0 X-FAPI Headers

  • Updated last week
  • Comment from unknown about potential issues with API gateways forwarding headers
  • Dima explained the issue involves two questions:
    1. Whether the header should be required/specified
    2. What to name the header (X- convention is technically deprecated but widely supported)
  • Discussion about surveying ecosystems (UK, Brazil, etc.) to understand header usage and importance

Issue #537: Document trade-offs between DPoP and MTLS

  • Started in 2022 but no progress yet
  • George asked about guidance for deploying MTLS with partners, including certificate expiration/rotation
  • Dima noted all existing Open Banking ecosystems use MTLS (DPoP wasn't available when they started)
  • MTLS also used as a boundary control mechanism for ecosystems
  • Discussion about the need for guidance comparing:
    • Properties, benefits, pros and cons of each approach
    • Ecosystem considerations
    • Implementation challenges
  • Action: Need a driver who has experience with both approaches to lead this work

7. AOB

None.

Action Items

  1. Create a PR for issue #719 using DOI link
  2. Report any new FAPI2 Message Signing implementations on issue #621
  3. George to update issue #273 with proposed text about large tokens
  4. Nat to ask Joseph about Android version fix (issue #260)
  5. Add issue #223 to the Pacific call agenda (April 4th)
  6. Nat to contact Anoop about the current status of webhook needs (issue #306)
  7. Dima to review issue #290 before next meeting
  8. Mike and Dima to share FAPI ecosystem maps and adoption information
  9. Find a driver for documenting DPoP vs MTLS trade-offs

Next Meeting

Next regular call: Wednesday, April 3, 2025

Clone this wiki locally