Skip to content

FAPI_Meeting_Notes_2025 08 20_Atlantic

Nat Sakimura edited this page Jul 10, 2026 · 1 revision

FAPI Working Group Meeting Notes

Date: August 20, 2025
Time: 14:00-15:00 GMT
Meeting Type: FAPI Working Group Call

Attendees

  • Nat Sakimura (Co-chair)
  • Dave Tonge (Co-chair)
  • Mike Leszcz - OIDF
  • Peter Stanley
  • Kosuke Koiwai
  • Robert Gallagher - Mastercard
  • Hideki Ikeda
  • Bjorn Hjelm
  • George Fletcher
  • Peter Wallach
  • Christopher Robbertse - OB
  • Filip Skokan
  • Brian Campbell
  • Dima Postnikov

Agenda

  1. Roll Call (Dave/Nat)
  2. Adoption of Agenda (Dave/Nat)
  3. Events (Mike L.)
  4. External Orgs & Liaisons (Mike L.)
  5. PRs (Dave)
  6. Issues (Dave)
  7. AOB (Nat)

1. Roll Call & Note Well

  • Mike Leszcz presented the Note Well statement covering:
    • Code of Conduct Policy emphasizing honesty, fairness, integrity, respect and dignity
    • Antitrust policy governing all Foundation meetings
    • Requirement for signed contribution agreement for OpenID Foundation working groups
    • Requirement for signed participation agreement for OIDF community groups
    • All policies available at openid.net/policies

2. Adoption of Agenda

  • Agenda adopted with no additional items

3. Events (Mike Leszcz)

Upcoming Events

  • September 8-10 – Finance of Tomorrow – Rio de Janeiro
    • Mark Haine and Domingos Creado representing OIDF
  • October 13-16 – FIDO Authenticate – Carlsbad, CA
    • Mike Jones likely to represent OIDF
  • October 20 – OIDF events including after lunch workshop prior to IIW (NEW DATE)
    • Host still TBC (likely Cisco based on date changes)
    • Schedule:
      • Morning: DCP working group meeting
      • 12:30-3:45 PM: After-lunch workshop
      • 4:00-6:00 PM: OpenID Foundation Board of Directors meeting
  • October 21-23 – IIW Fall 2025 – Mountain View (NEW DATES - moved from Oct 28-31)
  • November 1-7 – IETF 124 Montreal

Impact of IIW Date Changes

  • Date change from October 28-31 to October 21-23 has "wreaked havoc" on many personal and foundation plans
  • OIDF adjusting their Monday events to October 20th accordingly
  • Calendar on website and OIDF Google calendar are current

Member Reminders

4. External Organizations & Liaisons (Mike Leszcz)

Recent Inquiries

  • Digital Identity Technology Standard Forum (Korea)
    • Working to coordinate introduction call
    • Challenging due to holidays and time zones
  • Peruvian Financial Authority
    • Defining Peruvian Open Banking regulation
    • Call confirmed for Friday, August 22nd
    • Participants: Mark Haine, Domingos Creado, Mike Leszcz (while Gail is on holiday)

ISO Activities (Nat Sakimura)

  • ISO TC68 FinTech TAG meeting September 19th
    • Agenda not busy yet, time slots available for OIDF reports
    • Contributions welcome
  • SC27 Meeting in second week of September
    • Liaison statement to SC27 WG5 needed soon
    • Regular report will be sent unless special contributions received

5. Pull Requests (Dave Tonge)

Completed

  • PR #544 - Editorial update to Philip's affiliation in JAM spec
    • Simple editorial change that was missed
    • Approved by Nat during meeting

Pending

  • Several HTTP signing related PRs not ready for review yet
  • Dave needs to schedule time to work on remaining PRs

6. Issues Discussion

Issue #739: Collective Issues Impacting FAPI-1

Status: Active preparation by Nat Sakimura

Background:

  • Peter Stanley raised issue to get spotlight on all FAPI-1 impacting changes
  • Two main FAPI-1 issues waiting for RFC updates and BCP on crypto algorithms
  • Need to assess impact on FAPI-1 test suite

Key Dependencies:

  • RFC 7523 updates (audience claim changes)
  • Crypto algorithm BCP updates
  • Both PRs still under review in IETF

Current Status (Brian Campbell & Filip Skokan):

  • RFC 7523 moving slowly despite interest in quick resolution
  • Significant rewrite efforts by Mike caused overreaching changes
  • Now working to back changes into more reasonable scope
  • Last IETF update was significant improvement
  • Filip has PRs to further improve content
  • One PR aims to relax requirement from strictly string value to single value for audience claim

Timeline Concerns:

  • Peter Stanley expects resolution in 2026 rather than 2025
  • Early visibility needed for ecosystem planning
  • Ecosystem recently moved to FAPI-1 Advanced
  • Need consistent view on approach (errata vs new release)

Good News:

  • FAPI-1 ecosystems using MTLS were not impacted by vulnerability
  • Two RFC 7523 authors (Brian Campbell, Filip Skokan) regularly participate in working group
  • Working to minimize scope of necessary changes

Next Steps:

  • Nat plans to drive toward closure by Montreal IETF meeting (November)
  • Peter will contribute time after holiday to update ticket
  • Need to determine whether errata or new release approach for FAPI-1

Issue #737: FAPI Without Long-lived API Access

Status: Resolved via working group decision

Resolution (Dima Postnikov):

  • OIDF certification test profiles for specific ecosystems can be updated on request not to test:
    1. Refresh token support where ecosystem rules out support
    2. Sender-constraining access tokens where ecosystem rules out resource server APIs
  • Default FAPI2 certification profiles will continue testing for these features
  • Ecosystem-specific test profiles must be funded by requesting ecosystem

Funding Model (Mike Leszcz):

  • Directed funding required for ecosystem-specific profiles
  • Examples:
    • Open Finance Brazil provided significant funding
    • ConnectID Australia provided directed funding
    • SAMA Saudi Arabia funding FAPI2 KSA profile (in process)

Next Steps:

  • Leave open one more week for final comments before resolution
  • Joseph will be back next week for additional input

Issue #733: JARM Downgrade

Status: Assigned to implementation advice

Resolution:

  • Issue to be picked up in implementation advice document
  • Assigned to Yaron for text contribution
  • Good opportunity for community PR contribution

Note on JARM Errata:

  • Errata vote passed successfully
  • This particular issue not included in errata (appropriately)
  • Better suited for implementation advice than formal errata

Issue #740: Request for Tailored FAPI 2.0 Conformance

Status: Under discussion

Background (Robert - Mastercard):

  • Mastercard implementing FAPI-compliant machine-to-machine system
  • No user authentication involved
  • Current conformance tests fail because optional FAPI features not implemented
  • Large ecosystem impact: top 10 banks, top 5 merchants globally

Technical Discussion (Dima Postnikov):

  • Valid use case discussed couple years ago
  • Current FAPI2 specification allows non-user participating flows
  • Some statements may be misplaced due to spec structure
  • General section vs authorization code-specific sections need clarification
  • Would benefit from dedicated conformance test profile

Working Group Opinions:

  • Brian Campbell: Questioning value of machine-to-machine specific tests, beyond FAPI scope
  • Dave Tonge: Sees value in standardization of machine-to-machine protocols
  • Dima Postnikov: Strong support, has live implementations that cannot be tested

Key Technical Issue:

  • Client requirement: "shall initiate authorization process only with end user's explicit or implicit consent"
  • Problematic placement for machine-to-machine flows

Next Steps:

  • Keep open for discussion when Joseph returns
  • Need comments from Brian and Dima on relative positions
  • Determine if spec clarification needed vs conformance profile only

Issue #741: Is NBF Mandatory Requirement for Request Objects?

Status: Under discussion

Background (Dima Postnikov):

  • Question about mandatory NBF (Not Before) claim in request objects
  • Implementers asking for rationale
  • Complexity concerns around validation logic and clock skew

Technical Context (Filip Skokan & Brian Campbell):

  • Current Status: Text says NBF is mandatory
  • FAPI-1 Rationale: IAT timestamp doesn't have defined validation in JWT spec
  • NBF provides 100% way to ensure timestamp is in past/close to now
  • Important for front-channel scenarios in FAPI-1
  • FAPI-2 Context: Different security model, less reliance on NBF

Historical Context (Brian Campbell):

  • Likely added for attacker controlling clock on signing side
  • Decision made during working group calls
  • Some uncertainty about original rationale

Implementation Impact:

  • Filip Skokan: FAPI2 message signing conformance profiles already live
  • People already implementing with NBF requirement
  • Changing now would impact existing implementations
  • Suggests keeping as-is for stability

Security Analysis Request:

  • Dima requested feedback from security researchers
  • Need to understand if requirement considered during security analysis

Different Specs Comparison:

  • FAPI2 Security Profile: NBF not mandatory
  • FAPI2 Message Signing: NBF is mandatory for request objects
  • Differences table notes NBF/EXP not used for replay prevention in Security Profile

Next Steps:

  • Document rationale referencing previous issues (Dave Tonge)
  • Reference issue #177 for historical context
  • Consider for future FAPI 2.1 rather than current spec changes
  • Review alignment with CIBA flows
  • Keep issue open for rationale documentation

7. Any Other Business

  • No additional business raised
  • Good discussion overall on various technical issues

Action Items

  1. Nat Sakimura: Continue preparation of FAPI-1 collective issues impact assessment
  2. Peter Stanley: Contribute time after holiday to update issue #739
  3. Yaron: Provide text for JARM downgrade implementation advice (issue #733)
  4. Brian Campbell & Dima Postnikov: Provide comments on issue #740 (machine-to-machine conformance)
  5. Dave Tonge: Document NBF rationale referencing historical issues (issue #741)
  6. Mike Leszcz: Confirm OIDF October 20th event details and publish blog with registration
  7. All members: Vote on Three Shared Signals specifications to achieve quorum

Key Decisions

  1. Issue #737 resolved with ecosystem-specific test profile approach
  2. Issue #733 assigned to implementation advice rather than spec changes
  3. Issue #741 NBF requirement to remain for stability, focus on documentation

Next Meeting

  • Date: August 27, 2025
  • Notable: Joseph will be back from holiday
  • Focus: Continue discussion on issues #740 and #741 with full co-chair participation

Clone this wiki locally