-
Notifications
You must be signed in to change notification settings - Fork 0
FAPI_Meeting_Notes_2025 08 27_Atlantic
Nat Sakimura edited this page Jul 10, 2026
·
1 revision
Date: 2025-08-27 14:00 UTC
- Mike Leszcz (OIDF)
- Dave Tonge (Chair)
- Gail Hodges
- Peter Wallach
- Robert Gallagher (Mastercard)
- Kosuke Koiwai
- Imran Ulghar (OBL)
- Joseph Heenan (OIDF & Authlete)
- Takahiko Kawasaki
- Bjorn Hjelm
- Brian Campbell
- George Fletcher
- Mike Leszcz reviewed the OpenID Foundation NoteWell statements
- Covered Code of Conduct policy and antitrust statement
- Noted requirement for signed contribution agreement to contribute to working groups
- All policies available at openid.net/policies
-
September 8-10: Finance of Tomorrow - Rio de Janeiro
- Mark Haine and Domingos Creado representing OIDF
-
October 13-16: FIDO Authenticate - Carlsbad, CA
- Mike Jones likely to represent OIDF
-
October 20: OIDF events including after lunch workshop prior to IIW (NEW DATE)
- Cisco confirmed as host in San Jose
- DCP working group meeting in morning
- After-lunch workshop
- Board of directors meeting in afternoon
- Blog post with registration link expected later this week or early next week
- October 21-23: IIW Fall 2025 - Mountain View (NEW DATES)
- November 1-7: IETF 124 Montreal
- Recent inquiry from Peruvian Financial Authority (SBS - https://www.sbs.gob.pe/)
- Exploring creation of Open Banking regulation
- Successful call on Friday, August 22nd with:
- Magno Condori (Chief of Information Security and Technology Risk)
- Jorge Polo (Principal Information Security and Cybersecurity Supervisor)
- Planning formal briefing with larger audience in October/November
- Will include deeper dive into OpenID specs and conformance
- Encouraged to sign contribution agreement and participate in FAPI working group
- Inquiry from Digital Identity Technology Standard Forum in Korea
- Appears legitimate and closely tied to Korean government and standards work
- Call scheduled for Friday with Mark Kane, Paul Brio, and Mike Leszcz
-
India: Awaiting next steps on login with Adhar deployment of FAPI 2
- They've expressed appetite to deploy FAPI 2 in near future
- Currently implementing first, collaboration with OIDF later
- Canada and Chile: Expressed interest in ecosystem community group participation
- Canada: Interested in providing feedback on reference architecture for open banking ecosystem (DEMA leading)
- Future of Finance (Rio): Mark Haine and Domingos will meet with other jurisdictions
-
Vote on Three Shared Signals Final Specifications: Closes Friday at 12pm PT
- About a handful of votes short of quorum
-
FAPI 2.0 Message Signing Final Specification: Vote published today
- Voting period: September 10-24, 2025
- Original announcement missed, adjustments made
- Working on expanding certification and conformance capabilities
- Mark Haine and Tony Duarte working on:
- Business case development
- MOU with FEEM as potential collaboration candidate
- Seeking feedback from ecosystems and managers
- Board decision expected September 11th
-
Note: Tony Duarte has left Open Banking UK organization (per Imran Ulghar)
- Peter Stanley is now best contact for updates
-
FAPI 1: Hodari and Nat working with workgroup for feedback on ISO's clients to FAPI 1
- Time-bound requirement for workgroup feedback
-
FAPI 2: Submitted by Mark Verstage
- Translation underway by various member countries
- Ballot expected to complete by December 30th
- Feedback and vote results expected after completion
- Plan to submit remaining OpenID core specifications
- Total of 12 specifications including one already submitted
- FAPI to follow after core specifications
- Informal ISO ITU Slack group established
- Includes OIDF staff, co-chairs, and contractors
- Processes are complex, requiring extra help from experts like Bjorn and Hadari
- Already approved
- Joseph Heenan to merge (Dave Tonge had Atlassian account issues)
- Addresses potential JARM downgrade attack (Issue #733)
- Proposed text: "A client receiving a response non-compliant with JARM in response to an authorization request instructing a JARM response from an authorization service supporting JARM, as indicated by its metadata, should reject the response."
- Discussion about editorial improvements needed
- Implementation advice document format consideration (not normative spec)
- Dave Tonge to suggest editorial changes
- Reached consensus on specification modification
- Change from: "shall include the request signature and the request signature input, and the response signature input"
- To: "shall include all the components covered by the request signature in the response signature input"
- If content-digest request header is available: include in covered components
- If content-digest header not present: resource server should not treat as error
- Should sign HTTP response without including content-digest as component
- Specification needs more examples for clearer implementation
- Takahiko willing to prepare examples if time permits
- No PR prepared yet, will create after no objections raised
- Limited adoption observed despite specification completion
- Discussion about theoretical vs. practical utility
- Question raised about continuing HTTP signature work
- Issue #741 raised about NBF as mandatory requirement for request objects
- Joseph Heenan noted it's too late for changes to FAPI 2 message signing
- Agreed to add rationale in errata or future version
- Original rationale related to user-controlled device scenarios
- Issue to remain open with documented rationale
- Mastercard gateway serving ~150 large customers (banks and merchants)
- Machine-to-machine flows without user consent
- Volume multiple times larger than entire country ecosystems (Brazil, Australia, UAE)
- Customers requesting FAPI 2 compliance evidence before integration
- Non-user scoped data, workload-to-workload communication
- Not trivial but manageable implementation (~couple weeks work)
- Need to modify tests for client credentials grant
- Questions about refresh token requirements (Brian Campbell noted requirement the other way around)
- Concerns about potential confusion between different certification types
- Working group decision required to launch test program
- Subject to OIDF prioritization process
- Directed funding could influence prioritization
- Board involvement in budget process (November timeframe)
- Robert to work with Mastercard board representative
- Discussion with Gail Hodges recommended
- No strong pushback observed
- George Fletcher supportive given cross-domain use case
- Need for more use case examples identified
- Prioritization remains main challenge
- Multiple PRs pending for implementation advice
- Dave Tonge behind on processing due to time constraints
- Questioned value of continuing HTTP signature work
- Noted lack of adoption despite ecosystem requests
- Suggested discontinuing to focus resources elsewhere
- Takahiko acknowledged limited motivation, treating as "hobby" project
- Joseph Heenan surprised by lack of adoption
- Agreement to raise issue for working group feedback on pros/cons of continuing
- CFPB opened request for comment on 4 points (August 22)
- 60-day comment period until October 21
- OIDF using US/CAN open banking subgroup for response
- Lead editors volunteered: Ralph, Mark Andrus, Dima, and Mark V
- Contact gail@oidf.org to join US/CAN subgroup if interested
- Joseph Heenan: Merge PR 544 (Philip's affiliation update)
- Dave Tonge: Suggest editorial changes for Yaron's JARM PR
- Takahiko Kawasaki: Create PR for HTTP signatures modification if no objections
- Takahiko Kawasaki: Consider preparing examples for HTTP signatures spec (time permitting)
- Dave Tonge: Create issue for HTTP signatures continuation discussion
- Robert (Mastercard): Discuss client credentials certification with board representative
- Robert (Mastercard): Connect with Gail Hodges for detailed discussion
- Dave Tonge: Document NBF requirement rationale in existing issue
- Working Group: Provide feedback on HTTP signatures continuation via upcoming issue
- Continue technical discussions on pending PRs
- Await board decision on third-party test house collaboration (September 11)
- Monitor ISO/ITU submission progress
- Follow up on ecosystem engagement initiatives
- Address client credentials certification through board and prioritization process