Skip to content

FAPI_Meeting_Notes_2025 05 14_Atlantic

Nat Sakimura edited this page Jul 10, 2026 · 1 revision

OIDF FAPI WG Atlantic Call Meeting Notes

Meeting Details

Date: May 14, 2025

Participants

  • Nat Sakimura
  • Joseph Heenan (OIDF & Authlete)
  • Kosuke Koiwai
  • Imran Ulghar (OBL)
  • Peter Wallach (Mastercard)
  • Bjorn Hjelm
  • Robert Gallagher (Mastercard)
  • Filip Skokan
  • Dave Tonge
  • Hideki Ikeda
  • Brian Campbell

Agenda

  1. Roll Call (Dave/Nat)
  2. Adoption of Agenda (Dave/Nat)
  3. Events (Mike L.)
  4. External Orgs & Liaisons (Mike L.)
  5. PRs (Dave)
  6. Issues (Dave)
  7. AOB (Nat)

1 & 2. Roll Call & Adoption of Agenda

  • Meeting started at 4 minutes past the hour
  • Roll call conducted via chat
  • Default agenda adopted

3. Events

Mike L. provided a list of upcoming events:

  • May 5 – DCP WG event – Berlin (prior to EIC) – recordings have been published: https://openid.net/presentations-media/
  • May 6 – OIDF workshop at EIC – recordings have been published: https://openid.net/presentations-media/
  • May 20-23 -- ID4Africa -- Addis Ababa, Ethiopia (https://id4africaevents.com/) (Gail & Elizabeth)
  • May -- Rwanda Open Banking Event/Workshop (private) – (Mark Haine will be participating virtually)
  • June 3-6 -- Identiverse – Las Vegas
  • June 17-18 -- Identity Week Europe 2025 — Amsterdam
  • July 19-25 -- IETF 123 — Madrid

Joseph provided an update on the DCP meetings held in Berlin:

  • Two in-person hybrid meetings were held on Monday and Thursday around EIC
  • Good progress was made on the VCI spec
  • Trying to get the VCI spec into public review period within the next month
  • The EU wants something stable by the end of June
  • Goal is to have specifications with no breaking changes in public review
  • Discussion about whether the high assurance interoperability profile could reference FAPI 2 as the security profile
  • Challenge: cannot use private key JWT or MTLS client authentication because it's wallets talking to issuers
  • OAuth Attestation Based Client Authentication would be needed instead
  • This leads to awkwardness in referencing FAPI 2, as they would need to say "follow FAPI 2 but ignore this clause"

4. External Organizations & Liaisons

Mike L. and Joseph had a call with the SAMA team:

  • SAMA's transition to FAPI 2 and FAPI 2 certifications are aligned with OIDF milestones
  • SAMA will transition to FAPI 2 beginning of June
  • Certification team will have FAPI 2 KSA Profile ready at the same time the FAPI 2 Final tests are rolled into production
  • Joseph noted that the timeline seems ambitious as SAMA has not published their standard referencing FAPI 2 Final yet
  • Current SAMA project lead is moving on, and they were introduced to the new project lead

Member Reminders

Public review periods are open for:

  • Proposed Final EAP ACR Values Specification
  • Proposed OpenID Attachments 1.0 Final Specification
  • Proposed OpenID for Verifiable Presentations Final Specification
  • Proposed Implementer's Draft of OpenID Connect Relying Party Metadata Choices

5. PRs

PR #538

  • Dave discussed updates for the JAM errata and FAPI 2 Message Signing Final
  • Removed the abstract from the JAM errata as discussed in last week's call
  • In the Message Signing document, adjusted the abstract to read: "FAPI 2.0 Message Signing is an API security profile for signing and verifying certain FAPI 2.0 security profile based requests and responses"
  • Changes include removing "non-repudiation" and changing from O2 to referencing FAPI
  • Joseph reviewed and approved the PR
  • Dave will merge after the call so Joseph can help with publication

PR #539

  • Updates to implementation considerations document
  • Added text suggested by George about logging header size in troubleshooting issues
  • Dave noted that the document will need significant editorial work to ensure it flows well

6. Issues

Issue #728: "Clients Public Key Retrieval"

  • New issue from Tacker about how a resource server can get a public key for the OAuth client
  • Aaron mentioned his draft for retrieving metadata if client IDs are HTTP URLs
  • Joseph noted this likely doesn't help in FAPI context
  • Discussion about HTTP signatures and similar mechanisms:
    • Joseph mentioned a possible solution could involve defining an extra field in JWT access tokens
    • Brian Campbell expressed concerns about adding more complexity for questionable benefit
    • Joseph noted it does belong in the FAPI HTTP Signing draft
    • Multiple existing implementations were discussed:
      • AWS exposes HTTP signatures externally
      • Open Banking UK uses detached signature
      • Berlin Group uses Cavage
      • Federated systems like Mastodon might use Cavage
    • Dave suggested documenting what people are already doing before deciding whether to specify something
    • The group agreed to leave the issue open for further discussion

7. AOB

No additional business was raised.

Meeting adjourned early.

Next meeting: The following week.

Clone this wiki locally