Skip to content

FAPI_Meeting_Notes_2025 04 23_Atlantic

Nat Sakimura edited this page Jul 10, 2026 · 1 revision

FAPI Atlantic Call Meeting Notes

Date: 2025-04-23 14:00 UTC

Attendees

  • Nat Sakimura (Chair)
  • Mike Leszcz (OIDF)
  • Filip Skokan
  • Hideki Ikeda
  • Peter Stanley (OBL)
  • Kosuke Koiwai
  • Robert Gallagher (Mastercard)
  • George Fletcher
  • Bjorn Hjelm
  • Brian Campbell (partial attendance, carpool)

Regrets

  • Dave Tonge
  • Joseph Heenan (at FDX Summit and OIDF Board meeting)

1. Roll Call

Attendees typed their names in the chat.

2. Adoption of Agenda

Errata issues were added.

3. Events (Mike L.)

  • April 7: OIDF Workshop prior to IIW – deck and recording published at https://openid.net/presentations-media/
  • April 28-30: OpenID Federation Interop Event at SUNET in Stockholm: https://openid.net/openid-federation-interop-apr-28-30-2025/
  • April 28 - May 1: RSA 2025 in San Francisco
  • May 5: DCP WG meeting + interop in Berlin (prior to EIC) with details being finalized
  • May 6-9: EIC in Berlin
  • May 20-23: ID4Africa in Addis Ababa, Ethiopia (Gail & Elizabeth)
  • May (TBD): Rwanda Open Banking Event/Workshop (Mark)
  • June 3-6: Identiverse in Las Vegas
  • June 17-18: Identity Week Europe 2025 in Amsterdam
  • July 19-25: IETF 123 in Madrid

The OIDF calendar on the website is current, as is the OIDF Google calendar: https://openid.net/calendar/

4. Ecosystem Engagement (Mike L.)

  • Saudi Arabia (SAMA): Call in process to coordinate SAMA's transition to FAPI2 and FAPI2 certifications. Plan to transition in Q3/Q4.
  • US: Gail & Joseph at FDX Summit. Getting positive feedback that people like FAPI2 and have deployed/are planning to deploy it. Received unprompted comments about FAPI2 being a big improvement over FAPI1.

Member Reminders:

Additional Update (Nat):

  • Nat and Dima are collecting ecosystem data in a spreadsheet, which will be shared on the mailing list
  • This data will be used to prepare for the EIC Open Banking session
  • Contributions to the data are welcome
  • Mike L. mentioned he's working on a similar deck for the Australian government and will contribute to the spreadsheet

5. Discussion on Errata Process (Brian)

Brian raised concerns about two errata-related issues:

5.1 JARM Errata

  • Dave sent proposed changes for JARM to fix copy-paste mistakes in registry entries
  • Mark responded with process-related requirements
  • Brian expressed frustration about engaging in extensive review for what should be simple errata

5.2 FAPI Errata and Breaking Changes

  • Concerns about Errata including breaking changes without proper notification
  • Difficulty in determining what changes have been made due to document restructuring
  • Main change in FAPI Part 2 appears to be removing requirements for specifying cipher suite and instead referring to BCP on TLS, plus editorial changes
  • Nat will create a diff of the changes and send to the mailing list
  • Discussion concerning making audience value related changes due to security implications in a errata is inappropriate since they are breaking changes
  • There were expectations that audience value related changes will be in the errata but currently are not
  • No diff or history for specs makes it difficult to find out what has been changed
  • Restructuring document (especially for an errata) also makes a diff difficult

5.3 Process Concerns

Discussion covered several problematic areas:

  1. Introducing breaking protocol changes as errata
  2. Document restructuring/reformatting making it difficult to identify changes
  3. Process maturity and tooling issues (Bitbucket limitations compared to GitHub)
  4. Process requirements being applied inconsistently

5.4 Action:

  • Nat will provide diff documents comparing final and latest versions of FAPI Part 1/Part 2
  • Nat will raise the issue of introducing breaking changes via errata with the OIDF Board
  • Nat will follow up on other issues Brian raised

6. PRs and Issues

  • Most PRs related to Implementation Advice document, which will be deferred to next week when Dave is present
  • Nat shared a PR (https://bitbucket.org/openid/fapi/pull-requests/538/overview) related to JARM and message signing spec
  • Brian expressed concern about pull requests on finalized documents that are in a different pipeline process
  • No issues requiring immediate attention

7. AOB

No other business was raised.

Meeting adjourned 20 minutes early.

Clone this wiki locally