-
Notifications
You must be signed in to change notification settings - Fork 0
FAPI_Meeting_Notes_2025 05 14_Atlantic
Nat Sakimura edited this page Jul 10, 2026
·
1 revision
Date: May 14, 2025
- Nat Sakimura
- Joseph Heenan (OIDF & Authlete)
- Kosuke Koiwai
- Imran Ulghar (OBL)
- Peter Wallach (Mastercard)
- Bjorn Hjelm
- Robert Gallagher (Mastercard)
- Filip Skokan
- Dave Tonge
- Hideki Ikeda
- Brian Campbell
- Roll Call (Dave/Nat)
- Adoption of Agenda (Dave/Nat)
- Events (Mike L.)
- External Orgs & Liaisons (Mike L.)
- PRs (Dave)
- Issues (Dave)
- AOB (Nat)
- Meeting started at 4 minutes past the hour
- Roll call conducted via chat
- Default agenda adopted
Mike L. provided a list of upcoming events:
- May 5 – DCP WG event – Berlin (prior to EIC) – recordings have been published: https://openid.net/presentations-media/
- May 6 – OIDF workshop at EIC – recordings have been published: https://openid.net/presentations-media/
- May 20-23 -- ID4Africa -- Addis Ababa, Ethiopia (https://id4africaevents.com/) (Gail & Elizabeth)
- May -- Rwanda Open Banking Event/Workshop (private) – (Mark Haine will be participating virtually)
- June 3-6 -- Identiverse – Las Vegas
- June 17-18 -- Identity Week Europe 2025 — Amsterdam
- July 19-25 -- IETF 123 — Madrid
Joseph provided an update on the DCP meetings held in Berlin:
- Two in-person hybrid meetings were held on Monday and Thursday around EIC
- Good progress was made on the VCI spec
- Trying to get the VCI spec into public review period within the next month
- The EU wants something stable by the end of June
- Goal is to have specifications with no breaking changes in public review
- Discussion about whether the high assurance interoperability profile could reference FAPI 2 as the security profile
- Challenge: cannot use private key JWT or MTLS client authentication because it's wallets talking to issuers
- OAuth Attestation Based Client Authentication would be needed instead
- This leads to awkwardness in referencing FAPI 2, as they would need to say "follow FAPI 2 but ignore this clause"
Mike L. and Joseph had a call with the SAMA team:
- SAMA's transition to FAPI 2 and FAPI 2 certifications are aligned with OIDF milestones
- SAMA will transition to FAPI 2 beginning of June
- Certification team will have FAPI 2 KSA Profile ready at the same time the FAPI 2 Final tests are rolled into production
- Joseph noted that the timeline seems ambitious as SAMA has not published their standard referencing FAPI 2 Final yet
- Current SAMA project lead is moving on, and they were introduced to the new project lead
Public review periods are open for:
- Proposed Final EAP ACR Values Specification
- Proposed OpenID Attachments 1.0 Final Specification
- Proposed OpenID for Verifiable Presentations Final Specification
- Proposed Implementer's Draft of OpenID Connect Relying Party Metadata Choices
- Dave discussed updates for the JAM errata and FAPI 2 Message Signing Final
- Removed the abstract from the JAM errata as discussed in last week's call
- In the Message Signing document, adjusted the abstract to read: "FAPI 2.0 Message Signing is an API security profile for signing and verifying certain FAPI 2.0 security profile based requests and responses"
- Changes include removing "non-repudiation" and changing from O2 to referencing FAPI
- Joseph reviewed and approved the PR
- Dave will merge after the call so Joseph can help with publication
- Updates to implementation considerations document
- Added text suggested by George about logging header size in troubleshooting issues
- Dave noted that the document will need significant editorial work to ensure it flows well
Issue #728: "Clients Public Key Retrieval"
- New issue from Tacker about how a resource server can get a public key for the OAuth client
- Aaron mentioned his draft for retrieving metadata if client IDs are HTTP URLs
- Joseph noted this likely doesn't help in FAPI context
- Discussion about HTTP signatures and similar mechanisms:
- Joseph mentioned a possible solution could involve defining an extra field in JWT access tokens
- Brian Campbell expressed concerns about adding more complexity for questionable benefit
- Joseph noted it does belong in the FAPI HTTP Signing draft
- Multiple existing implementations were discussed:
- AWS exposes HTTP signatures externally
- Open Banking UK uses detached signature
- Berlin Group uses Cavage
- Federated systems like Mastodon might use Cavage
- Dave suggested documenting what people are already doing before deciding whether to specify something
- The group agreed to leave the issue open for further discussion
No additional business was raised.
Meeting adjourned early.
Next meeting: The following week.