Skip to content

FAPI_Meeting_Notes_2025 08 27_Atlantic

Nat Sakimura edited this page Jul 10, 2026 · 1 revision

FAPI Working Group Meeting Notes

Date: 2025-08-27 14:00 UTC

Attendees

  • Mike Leszcz (OIDF)
  • Dave Tonge (Chair)
  • Gail Hodges
  • Peter Wallach
  • Robert Gallagher (Mastercard)
  • Kosuke Koiwai
  • Imran Ulghar (OBL)
  • Joseph Heenan (OIDF & Authlete)
  • Takahiko Kawasaki
  • Bjorn Hjelm
  • Brian Campbell
  • George Fletcher

Administrative Items

NoteWell Statements

  • Mike Leszcz reviewed the OpenID Foundation NoteWell statements
  • Covered Code of Conduct policy and antitrust statement
  • Noted requirement for signed contribution agreement to contribute to working groups
  • All policies available at openid.net/policies

OIDF Updates (Mike Leszcz)

Upcoming Events

  • September 8-10: Finance of Tomorrow - Rio de Janeiro
    • Mark Haine and Domingos Creado representing OIDF
  • October 13-16: FIDO Authenticate - Carlsbad, CA
    • Mike Jones likely to represent OIDF
  • October 20: OIDF events including after lunch workshop prior to IIW (NEW DATE)
    • Cisco confirmed as host in San Jose
    • DCP working group meeting in morning
    • After-lunch workshop
    • Board of directors meeting in afternoon
    • Blog post with registration link expected later this week or early next week
  • October 21-23: IIW Fall 2025 - Mountain View (NEW DATES)
  • November 1-7: IETF 124 Montreal

Ecosystem Engagement

Peru

  • Recent inquiry from Peruvian Financial Authority (SBS - https://www.sbs.gob.pe/)
  • Exploring creation of Open Banking regulation
  • Successful call on Friday, August 22nd with:
    • Magno Condori (Chief of Information Security and Technology Risk)
    • Jorge Polo (Principal Information Security and Cybersecurity Supervisor)
  • Planning formal briefing with larger audience in October/November
  • Will include deeper dive into OpenID specs and conformance
  • Encouraged to sign contribution agreement and participate in FAPI working group

Korea

  • Inquiry from Digital Identity Technology Standard Forum in Korea
  • Appears legitimate and closely tied to Korean government and standards work
  • Call scheduled for Friday with Mark Kane, Paul Brio, and Mike Leszcz

Additional Ecosystem Updates (Gail Hodges)

  • India: Awaiting next steps on login with Adhar deployment of FAPI 2
    • They've expressed appetite to deploy FAPI 2 in near future
    • Currently implementing first, collaboration with OIDF later
  • Canada and Chile: Expressed interest in ecosystem community group participation
  • Canada: Interested in providing feedback on reference architecture for open banking ecosystem (DEMA leading)
  • Future of Finance (Rio): Mark Haine and Domingos will meet with other jurisdictions

Member Reminders

  • Vote on Three Shared Signals Final Specifications: Closes Friday at 12pm PT
    • About a handful of votes short of quorum
  • FAPI 2.0 Message Signing Final Specification: Vote published today
    • Voting period: September 10-24, 2025
    • Original announcement missed, adjustments made

Certification and Conformance Updates (Gail Hodges)

Third-Party Test Houses

  • Working on expanding certification and conformance capabilities
  • Mark Haine and Tony Duarte working on:
    • Business case development
    • MOU with FEEM as potential collaboration candidate
  • Seeking feedback from ecosystems and managers
  • Board decision expected September 11th
  • Note: Tony Duarte has left Open Banking UK organization (per Imran Ulghar)
    • Peter Stanley is now best contact for updates

ISO and ITU Actions

ISO Activities

  • FAPI 1: Hodari and Nat working with workgroup for feedback on ISO's clients to FAPI 1
    • Time-bound requirement for workgroup feedback
  • FAPI 2: Submitted by Mark Verstage
    • Translation underway by various member countries
    • Ballot expected to complete by December 30th
    • Feedback and vote results expected after completion

ITU Activities (Bjorn Hjelm)

  • Plan to submit remaining OpenID core specifications
  • Total of 12 specifications including one already submitted
  • FAPI to follow after core specifications

ISO/ITU Working Structure

  • Informal ISO ITU Slack group established
  • Includes OIDF staff, co-chairs, and contractors
  • Processes are complex, requiring extra help from experts like Bjorn and Hadari

Technical Discussions

Pull Requests

PR 545 - Philip's Affiliation Update

  • Already approved
  • Joseph Heenan to merge (Dave Tonge had Atlassian account issues)

New PR from Yaron - JARM Downgrade Protection

  • Addresses potential JARM downgrade attack (Issue #733)
  • Proposed text: "A client receiving a response non-compliant with JARM in response to an authorization request instructing a JARM response from an authorization service supporting JARM, as indicated by its metadata, should reject the response."
  • Discussion about editorial improvements needed
  • Implementation advice document format consideration (not normative spec)
  • Dave Tonge to suggest editorial changes

HTTP Signatures Discussion (Takahiko Kawasaki)

Technical Resolution with Justin

  • Reached consensus on specification modification
  • Change from: "shall include the request signature and the request signature input, and the response signature input"
  • To: "shall include all the components covered by the request signature in the response signature input"

Content-Digest Header Handling

  • If content-digest request header is available: include in covered components
  • If content-digest header not present: resource server should not treat as error
  • Should sign HTTP response without including content-digest as component

Implementation Feedback

  • Specification needs more examples for clearer implementation
  • Takahiko willing to prepare examples if time permits
  • No PR prepared yet, will create after no objections raised

Ecosystem Adoption Discussion

  • Limited adoption observed despite specification completion
  • Discussion about theoretical vs. practical utility
  • Question raised about continuing HTTP signature work

NBF (Not Before) Requirement Discussion

  • Issue #741 raised about NBF as mandatory requirement for request objects
  • Joseph Heenan noted it's too late for changes to FAPI 2 message signing
  • Agreed to add rationale in errata or future version
  • Original rationale related to user-controlled device scenarios
  • Issue to remain open with documented rationale

Client Credentials Flow Certification (Robert - Mastercard)

Use Case Presentation

  • Mastercard gateway serving ~150 large customers (banks and merchants)
  • Machine-to-machine flows without user consent
  • Volume multiple times larger than entire country ecosystems (Brazil, Australia, UAE)
  • Customers requesting FAPI 2 compliance evidence before integration
  • Non-user scoped data, workload-to-workload communication

Technical Feasibility (Joseph Heenan)

  • Not trivial but manageable implementation (~couple weeks work)
  • Need to modify tests for client credentials grant
  • Questions about refresh token requirements (Brian Campbell noted requirement the other way around)
  • Concerns about potential confusion between different certification types

Business Considerations

  • Working group decision required to launch test program
  • Subject to OIDF prioritization process
  • Directed funding could influence prioritization
  • Board involvement in budget process (November timeframe)
  • Robert to work with Mastercard board representative
  • Discussion with Gail Hodges recommended

Working Group Sentiment

  • No strong pushback observed
  • George Fletcher supportive given cross-domain use case
  • Need for more use case examples identified
  • Prioritization remains main challenge

Ongoing Issues and Future Work

Implementation Advice Document

  • Multiple PRs pending for implementation advice
  • Dave Tonge behind on processing due to time constraints

HTTP Signatures Continuation Debate (Brian Campbell)

  • Questioned value of continuing HTTP signature work
  • Noted lack of adoption despite ecosystem requests
  • Suggested discontinuing to focus resources elsewhere
  • Takahiko acknowledged limited motivation, treating as "hobby" project
  • Joseph Heenan surprised by lack of adoption
  • Agreement to raise issue for working group feedback on pros/cons of continuing

CFPB Request for Comment (Gail Hodges - via chat)

  • CFPB opened request for comment on 4 points (August 22)
  • 60-day comment period until October 21
  • OIDF using US/CAN open banking subgroup for response
  • Lead editors volunteered: Ralph, Mark Andrus, Dima, and Mark V
  • Contact gail@oidf.org to join US/CAN subgroup if interested

Action Items

  1. Joseph Heenan: Merge PR 544 (Philip's affiliation update)
  2. Dave Tonge: Suggest editorial changes for Yaron's JARM PR
  3. Takahiko Kawasaki: Create PR for HTTP signatures modification if no objections
  4. Takahiko Kawasaki: Consider preparing examples for HTTP signatures spec (time permitting)
  5. Dave Tonge: Create issue for HTTP signatures continuation discussion
  6. Robert (Mastercard): Discuss client credentials certification with board representative
  7. Robert (Mastercard): Connect with Gail Hodges for detailed discussion
  8. Dave Tonge: Document NBF requirement rationale in existing issue
  9. Working Group: Provide feedback on HTTP signatures continuation via upcoming issue

Next Steps

  • Continue technical discussions on pending PRs
  • Await board decision on third-party test house collaboration (September 11)
  • Monitor ISO/ITU submission progress
  • Follow up on ecosystem engagement initiatives
  • Address client credentials certification through board and prioritization process

Clone this wiki locally