-
Notifications
You must be signed in to change notification settings - Fork 0
FAPI_Meeting_Notes_2025 03 26_Atlantic
Nat Sakimura edited this page Jul 10, 2026
·
1 revision
- Date: 2025-03-26 14:00 UTC
- Location: Zoom
- Nat Sakimura (Chair)
- Dima Postnikov
- Filip Skokan
- George Fletcher
- Bjorn Hjelm
- Hideki Ikeda
- Imran Ulghar (OBL)
- Kosuke Koiwai
- Mike Leszcz (OIDF)
- Robert Gallagher (Mastercard)
Regrets
- Dave Tonge
- Roll Call (Dave/Nat)
- Adoption of Agenda (Dave/Nat)
- Events (Mike L.)
- External Orgs & Liaisons (Mike L.)
- PRs (Dave)
- Issues (Dave)
- AOB (Nat)
- Participants listed above attended the call
Mike shared upcoming events:
-
April 7 - OIDF Workshop prior to IIW at Google, Mountain View
- Registration required: https://openid.net/attend-the-oidf-workshop-prior-to-iiw-spring-2025-on-7th-april-2025/
- DCP WG meeting prior to the workshop (9am-12pm) also at Google
- Registration link: https://DCPWG_IIW_07Apr25.eventbrite.co.uk
-
April 8-10 - IIW Spring 2025, Mountain View
-
April 11 - DCP WG meeting at Apple after IIW (details to be published soon)
-
April 28 - May 1 - RSA 2025, San Francisco
-
May 6-9 - EIC, Berlin
-
May 20-23 - ID4Africa, Addis Ababa, Ethiopia
-
May - Rwanda Open Banking Event/Workshop (private)
-
June 3-6 - Identiverse, Las Vegas
The OIDF calendar on the website is current: https://openid.net/calendar/
- Most ecosystem work is focused on activity in Brazil, specifically the Open Finance and Open Insurance annual FAPI recertifications
- High volume of recertification requests that the team is managing
- Teams also working on developing conformance tests for Federation, Shared Signals, Verifiable Credentials, and Verifiable Presentations
- Nat and Gail will be presenting about Open Banking/Open Finance ecosystems at EIC
- Nat requested collecting information about the FAPI ecosystem worldwide in a comparable format
- Mike and Dima have existing maps/slides of FAPI adoption that they will share
- Discussion about creating a template to collect ecosystem information consistently
- Dima mentioned there is an existing issue in the bitbucket tracking this
- Vote open for the Proposed Implementer's Draft of OpenID4VC High Assurance Interoperability Profile
- Link: https://openid.net/foundation/members/polls/355
Two PRs currently open:
-
PR #536 - FAPI2 Message Signing editorial change (fixing file names)
- Nat has approved, awaiting others to review and approve
-
PR #529 - Previously discussed last week
- Joe was updated that since there's no time pressure (unlike FAPI2), the group will wait for underlying spec updates
- No immediate action required
Issue #719: FAPI2-MS Add reference to security analysis
- Discussion about adding a link to security analysis
- Tim recommended a DOI link
- Action: Create a PR for this with the DOI link
Issue #621: Implementations of FAPI2 Message Signing
- This is just for tracking implementations of FAPI2 Message Signing
- Last comment from Taka in last week's meeting
- Action: If anyone has new implementations, please report on the ticket
Issue #273: Security considerations re: large access tokens
- Filip noted it's hard to give specific recommendations here
- Even with RSA 4096 or MLDSA87, signatures will be large (4+ KB)
- George suggested adding implementation guidance about adjusting deployments to support larger token sizes
- Action: George will update the issue with proposed text
Issue #260: Add section in implementation advice document about supporting mobile apps
- Last comment was from George regarding Android app link and app attestation
- Joseph might know which Android version fixed the issue
- Action: Nat will ask Joseph during their meeting tomorrow
Issue #197: New document proposal - FAPI Implementation Guide
- Document has started but needs content
- Action: Continue development of the guide
Issue #223: Need of a customer unique immutable identity as part of Id Token
- From Manoop
- Action: This will be added to the agenda for the next Pacific call (April 4th)
Issue #306: Webhook support in FAPI
- Last discussed in 2023
- Original suggestion was to add a section in implementation guidance, not a normative document
- Dima suggested it might evolve into a separate profile of both webhooks and FAPI
- Action: Nat will check with Anoop about the current status and need for this
- Potentially related to Shared Signals work
Issue #290: X-FAPI-Interaction-ID across client to AS
- Assigned to Dima
- Action: Dima will review before next meeting
Issue #282: FAPI 2.0 X-FAPI Headers
- Updated last week
- Comment from unknown about potential issues with API gateways forwarding headers
- Dima explained the issue involves two questions:
- Whether the header should be required/specified
- What to name the header (X- convention is technically deprecated but widely supported)
- Discussion about surveying ecosystems (UK, Brazil, etc.) to understand header usage and importance
Issue #537: Document trade-offs between DPoP and MTLS
- Started in 2022 but no progress yet
- George asked about guidance for deploying MTLS with partners, including certificate expiration/rotation
- Dima noted all existing Open Banking ecosystems use MTLS (DPoP wasn't available when they started)
- MTLS also used as a boundary control mechanism for ecosystems
- Discussion about the need for guidance comparing:
- Properties, benefits, pros and cons of each approach
- Ecosystem considerations
- Implementation challenges
- Action: Need a driver who has experience with both approaches to lead this work
None.
- Create a PR for issue #719 using DOI link
- Report any new FAPI2 Message Signing implementations on issue #621
- George to update issue #273 with proposed text about large tokens
- Nat to ask Joseph about Android version fix (issue #260)
- Add issue #223 to the Pacific call agenda (April 4th)
- Nat to contact Anoop about the current status of webhook needs (issue #306)
- Dima to review issue #290 before next meeting
- Mike and Dima to share FAPI ecosystem maps and adoption information
- Find a driver for documenting DPoP vs MTLS trade-offs
Next regular call: Wednesday, April 3, 2025