Skip to content

FAPI_Meeting_Notes_2025 08 13_Atlantic

Nat Sakimura edited this page Jul 10, 2026 · 1 revision

FAPI Working Group Meeting Notes

Date: August 13, 2025
Time: 14:00 GMT
Chair: Nat Sakimura (Dave unavailable)

Attendees

  • Nat Sakimura (Chair)
  • Filip Skokan
  • Joe DeCock
  • Robert Gallagher (Mastercard)
  • Peter Wallach
  • Dima Postnikov
  • Chris Wood
  • Bjorn Hjelm
  • Joseph Heenan (OIDF & Authlete)
  • Christopher Robbertse (OB)
  • Hideki Ikeda
  • Imran Ulghar (OBL)
  • Peter Stanley
  • Kosuke Koiwai

1. Roll Call & Agenda Adoption

  • Attendees confirmed via chat
  • Agenda adopted without modifications
  • Dave unavailable but provided reports for events and external orgs

2. Events

Upcoming Events

  • September 8-10: Finance of Tomorrow - Rio de Janeiro
    • Mark Haine and Domingos Creado representing OIDF
  • October 13-16: FIDO Authenticate - Carlsbad, CA
    • Mike Jones likely to represent OIDF
  • October 20: OIDF events including after lunch workshop prior to IIW (NEW DATE)
    • Host still TBC (likely Cisco based on date changes)
  • October 21-23: IIW Fall 2025 - Mountain View (NEW DATES)
    • IIW shifted dates one week earlier, causing scheduling conflicts
  • November 1-7: IETF 124 Montreal

Community Announcements

3. Ecosystem Engagement

Ecosystem Support Community Group

  • Kicked off Monday, July 28th
  • First "Pacific" call: Friday, August 15th 10am Sydney (Thursday, August 14th 5pm PT/8pm ET)
  • Existing ecosystem partners being invited to participate
  • Details and participation agreement: https://openid.net/cg/ecosystem-support-community-group/
  • Note: Separate participation agreement required (different from working group agreement)
  • Dima Postnikov: Sign participation agreement to access mailing list and Slack channel

ISO Activities

  • FAPI1 ISO Vote: Approved with one negative vote
    • 149 comments received requiring disposition
    • Hodari McClain working on addressing the negative vote
    • Subgroup formation needed to create disposition of comments
    • Work to be conducted on Slack channel and Zoom calls
    • Nat to send participation request after meeting

Japanese Financial Services Agency

  • Public consultation on authentication in stockbrokerage and securities companies
  • Translated version shared with liaison committee
  • Considering response from OpenID Foundation perspective

ISO Liaison Upgrades

  • TC68: Currently liaison A status
  • SC27 & SC17: Currently liaison C status (working group level only)
  • Nat drafted letter to upgrade SC27 liaison from Category C to Category A
  • Similar upgrade may be needed for SC17
  • Bjorn Hjelm confirmed: WG4 and WG10 have liaison A status for technical comments
  • SC27 meeting in September - upgrade request needs to be submitted soon

TC68 Fintech Subgroup

  • Dormant for 4 years post-COVID, recently restarted
  • First reconvening meeting held week prior
  • Next meeting in few weeks with more substantial content

4. Pull Requests

Status

  • Waiting for Dave's return to resolve conflicts
  • PR 529: Joe DeCock reported waiting on BIS 7523 audience changes resolution

5. Issues Discussion

Issue #740: Tailored FAPI 2.0 Conformance Testing (Mastercard)

Context: Mastercard seeks FAPI compliance but current conformance suite assumes optional features are in use.

Requirements:

  • Client Authentication Type: private_key_jwt
  • Sender Constraining: DPoP
  • Authorization Request Type: None (this option doesn't exist)
  • Test OpenID: None (should be optional)
  • FAPI Profile: plain_fapi

Discussion Points:

  • Need for client credentials grant-only certification profiles
  • No authorization endpoint interactions required
  • Access token binding to TLS certificate or DPoP for client credentials flow
  • Robert Gallagher: Machine-to-machine only, no ID/password flows

Technical Analysis:

  • Joseph Heenan: Need FAPI certification profiles for client credentials grant only
  • Joe DeCock: Spec language assumes authorization codes will be issued
    • Example: "authorization servers shall issue authorization codes with maximum lifetime of 60 seconds"
    • May need errata to clarify applicability
  • Dima Postnikov: Spec already split into sections:
    • General requirements for authorization server
    • Authorization code flows
    • Most requirements properly sectioned, some cleanup needed

Resolution:

  • Working group supports creating machine-to-machine certification profiles
  • Prioritization depends on OIDF resource allocation and member funding
  • Need to assess broader demand beyond Mastercard
  • Joe DeCock: Will create PR to move misplaced authorization code requirement
  • May require FAPI 2.1 for proper specification support

Issue #706: HTTP Signature Requirements

Status:

  • Justin and Takahiko actively discussing
  • Waiting for their conclusions before proceeding
  • Open for additional participant input

Issue #741: NBF (Not Before) Claim Requirement

Status:

  • Waiting for additional implementer feedback
  • Dima Postnikov: Will send reminder to mailing list for broader input
  • Secondary concern about statement placement (may belong in message signing vs main profile)

Issue #739: FAPI 1 Collective Issues

Status:

  • Nat added diff list to ticket
  • Peter Stanley: Requests previous chat content be added to ticket
  • Need comprehensive view of all proposed FAPI1 changes
  • Determine errata vs new release approach
  • Action: Nat to find and add previous chat logs to ticket

Issue #733: JARM Downgrade

Resolution:

  • Too late for JARM errata (voting in progress)
  • Agreed to provide clarification in FAPI Implementation Advice Document
  • Action: Component changed from JARM to Implementation Advice Document

Issue #737: FAPI Without Long-Lived API Access

Background:

  • Mark Haine raised concerns about sender constraining requirements
  • Two main issues:
    1. Refresh token issuance requirements
    2. Access token sender constraining when no resource server used

Discussion:

  • Joseph Heenan: Generic FAPI clients should still support access tokens
  • Only update tests for specific ecosystem profiles with different requirements
  • Dima Postnikov: Apply same logic for both refresh tokens and access tokens
  • If ecosystem governing body specifies no resource server needed, implementations shouldn't fail conformance

Technical Considerations:

  • Joseph Heenan: May need additional endpoint to end client tests
  • Dima Postnikov: Will summarize discussion in ticket for clarity

Resolution:

  • Ecosystem-specific profiles can relax requirements
  • Generic FAPI maintains current requirements
  • Consider FAPI 2.1 for specification updates

Issue #738: FAPI2 ID2 Tests Deprecation

Status Check:

  • March 26 deadline works for Connect ID
  • Joseph Heenan: Will check with UAE (Mike Les)
  • Peter Stanley: UK still using FAPI1, no impact
  • Awaiting final confirmation from UAE

6. Action Items

  1. Nat Sakimura:

    • Send ISO subgroup participation request after meeting
    • Find and add previous chat logs to Issue #739
    • Submit SC27 liaison upgrade request before September meeting
    • Get SC17 meeting schedule information
  2. Dima Postnikov:

    • Send mailing list reminder for Issue #741 (NBF claim)
    • Summarize Issue #737 discussion in ticket
  3. Joe DeCock:

    • Create PR to move authorization code requirement to appropriate section
  4. Joseph Heenan:

    • Check with UAE regarding Issue #738 timeline
  5. Bjorn Hjelm:

    • Provide ISO liaison status documentation link

7. Next Steps

  • Continue monitoring PR resolution pending Dave's return
  • Await ecosystem feedback on various issues
  • Proceed with ISO liaison upgrade processes
  • Follow up on certification profile requirements for machine-to-machine scenarios

Meeting adjourned early, giving back 4 minutes before eKYC Working Group session.

Clone this wiki locally