Skip to content

FAPI_Meeting_Notes_2025 05 07_Atlantic

Nat Sakimura edited this page Jul 10, 2026 · 1 revision

OIDF FAPI WG Meeting Notes - May 7, 2025

Attendees

  • Dave Tonge (Chair)
  • Mike Leszcz (OIDF)
  • Kosuke Koiwai
  • Robert Gallagher (Mastercard)
  • Bjorn Hjelm
  • Jake Fenley
  • Filip Skokan
  • Brian Campbell
  • Imran Ulghar (OBL)

Agenda

  1. Roll Call
  2. Adoption of Agenda
  3. Events (Mike L.)
  4. External Orgs & Liaisons (Mike L.)
  5. PRs (Dave)
  6. Issues (Dave)
  7. AOB (Nat)

Events

Mike Leszcz provided the following updates:

  • May 5 – DCP WG event – Berlin (prior to EIC) – presentations published: https://openid.net/presentations-media/
  • May 6-9 -- EIC –– Berlin
  • May 20-23 -- ID4Africa -– Addis Ababa, Ethiopia (https://id4africaevents.com/) (Gail & Elizabeth)
  • May -- Rwanda Open Banking Event/Workshop (private) – May (Mark Haine will be participating virtually)
  • June 3-6 -- Identiverse – Las Vegas
  • June 17-18 -- Identity Week Europe 2025 — Amsterdam
  • July 19-25 -- IETF 123 — Madrid

The OIDF calendar on the website is current (as is the OIDF Google calendar): https://openid.net/calendar/

Member Reminders

Mike Leszcz noted the following public review periods in progress:

Pull Requests

PR #538 - Message Signing Abstract

The group discussed finalizing the FAPI 2.0 Message Signing specification, focusing on creating an appropriate abstract for the document as part of the OIDF process requirements.

Key discussion points:

  1. Initially, Dave proposed describing it as "an API security profile that provides interoperable support for non-repudiation against OAuth 2 base request and responses."

  2. Issues raised:

    • Filip suggested changing "OAuth 2" to "FAPI 2" to be more specific
    • Brian raised concerns about claiming "non-repudiation" in the abstract when that claim is qualified later in the document
  3. Brian noted that the spec is essentially profiling three specific artifacts for signing:

    • Signed authorization requests
    • Signed authorization responses
    • Signed introspection responses
  4. After discussion, a simpler abstract was proposed:

    "OIDF FAPI 2.0 Message Signing is an API security profile that provides interoperable support for:

    • Signed authorization requests
    • Signed authorization responses
    • Signed introspection responses"
  5. Brian also raised concerns about retroactively applying process requirements to finalized documents, specifically regarding JARM errata fixes being combined with the Message Signing PR.

  6. Resolution: Dave will adjust the PR to:

    • Use the simplified abstract that accurately describes what the spec provides
    • Remove the JARM-related changes from this PR to decouple them
    • Handle the JARM errata separately

Dave noted that there are other pending PRs related to implementation advice that need to be addressed in future meetings.

Issues

No specific issues were discussed.

AOB (Any Other Business)

No additional business was raised.

Next Meeting

Next regular call will be held on May 14, 2025.

Meeting adjourned after approximately 19 minutes due to light attendance (many members attending EIC in Berlin).

Clone this wiki locally