-
Notifications
You must be signed in to change notification settings - Fork 0
FAPI_Meeting_Notes_2026 01 07_Atlantic
Date: 2026-01-07
Time: 14:00 UTC
Meeting: First FAPI Atlantic Call of 2026
- Nat Sakimura (Chair)
- Dave Tonge (Co-Chair)
- Dima Postnikov (Co-Chair)
- Matthew Murphy (Mastercard)
- Kosuke Koiwai
- George Fletcher
- Imran Ulghar (OBL)
- Filip Skokan
- Robert Gallagher (Mastercard)
- Hideki Ikeda (Authlete)
- Peter Stanley (OBL)
- Bjorn Hjelm
- Brian Campbell
- Christopher Robbertse (Open Banking) - partial attendance
- Roll Call (Dave/Nat)
- Adoption of Agenda (Dave/Nat)
- Events (Mike L.)
- External Orgs & Liaisons (Mike L.)
- PRs (Dave)
- Issues (Dave)
- AOB (Nat)
Nat welcomed attendees to the first FAPI Atlantic call of 2026. Attendees provided their names via chat.
No additions were proposed. The agenda was adopted as presented.
Mike Leszcz was unable to attend but provided updates via email. Nat shared the following Q1 2026 events:
- March 9-13: ISO/IEC JTC 1/SC 27 WG Meeting - Nürnberg, Germany
- March 14-20: IETF 125 - Shenzhen, China
- March 16-17: ISO/IEC JTC 1/SC 27 Plenary - Nürnberg, Germany
Q2-Q4 2026 meetings and events will be added to calendars and the website once confirmed. Members are encouraged to send any 2026 events to mike.leszcz@oidf.org for inclusion.
End-of-year coordination calls with ecosystem partners are underway for 2026 planning and budgeting:
- Plan to have regulation in place by August 2026
- Anticipate a few FAPI2 certifications in 2026
- Ecosystem going live in earnest in early 2027
- Minstait (CMF's implementation partner) may join the Foundation in place of CMF to provide directed funding
- Anticipate directed funding early 2026 to support new KSA FAPI2 Profile
- Ecosystem will then certify to the new profile
- Follow-up call scheduled for mid-January
- Discussion will focus on transition from FAPI2 ID to FAPI2 Final
- 2026 certification confirmed
- Introduction call scheduled for January
- Domingos has made introductions to OFB and CMF
- Notice of Vote to Approve was approved yesterday (January 6, 2026)
- Announcement to be published today
- Voting is open until Monday, January 13, 2026
- Link: https://openid.net/announcing-the-2026-openid-foundation-community-representatives-election/
- Dima and George are running for the board
- Corporate Representative election is happening in parallel via email to corporate members in good standing
- Link: https://bitbucket.org/openid/fapi/pull-requests/558
- Status: Ready for review and merge
- Contains spacing fixes including BCP212 reference formatting
- Kosuke identified the BCP212 issue; Nat has applied the fix
- Action: Awaiting approvals to merge
- Link: https://bitbucket.org/openid/fapi/pull-requests/559
- Status: Has merge conflicts that need resolution
- Contains similar editorial fixes (missing spaces between RFC/BCP references)
- Action: Nat to resolve merge conflicts
- Dave noted with some embarrassment that some PRs he opened date back to April 2025
- Action: Dave will work to complete outstanding PRs
- Request for volunteers to help with implementation guidelines
Issue #821 - Use of Non-Standard Port Numbers for HTTPS
- Link: https://github.com/openid/fapi/issues/821
- Status: CLOSED
- Dima provided a reply that resolved the issue
- Nat confirmed agreement to close
Issue #404 - Interoperability Validation
- Link: https://github.com/openid/fapi/issues/404
- Status: Remains open
- Action on Lucas to contact Ralph
- Lucas was not on the call to provide an update
Issue #778 - FAPI1 ISO/IEC 25791-1 Review Comments (Key Length)
- Link: https://github.com/openid/fapi/issues/778
- Status: Under discussion
- Previous call (December 17, 2025) had substantive discussion
- Current direction: Likely not making normative changes; may add a note about ecosystems considering longer key lengths for algorithm agility
- Peter took an action to raise this with TDA (UK Technical Design Authority)
- Raised today; will receive final input in two weeks
- Concerns raised about exponential increase in processing times with larger key lengths
- Mixed feedback from UK ecosystem:
- One implementer moved to larger key lengths without substantial issues
- Another implementer doubled key lengths (to 4096) and experienced significant performance impact
- Key questions being addressed:
- If current key lengths are removed from spec and reference to FIPS is added, how would changes be introduced (errata vs. FAPI 1.1)?
- NIST currently says 2048-bit RSA is acceptable; likely review around 2030
- Is NIST the appropriate reference for UK ecosystem?
- BCP195 would be an easier reference point for UK ecosystem
- Action: Peter to return in two weeks with consolidated UK ecosystem position
- Post-quantum cryptography will add another dimension to this discussion
- Imran noted a request regarding DHE deprecation as part of post-quantum considerations; awaiting IANA feedback
- BCP195 is currently silent on specific key lengths but references "at least 2048" for TLS
- Discussion about benefits of referencing BCPs that will be updated over time vs. static NIST documents
Issue #834 - Abstract Should Not Be There for FAPI1 (ISO Submission)
- Link: https://github.com/openid/fapi/issues/834
- Status: Editorial fix needed
- Abstract needs to be removed for ISO submission (interesting as it was required for OIDF submission)
- Action: Proceed with fix
Issue #831 - Browser Swapping Attacks
- Link: https://github.com/openid/fapi/issues/831
- Status: Remains open, awaiting OAuth WG conclusion
- Raised by Joseph regarding attacks discussed at IETF 114
- Question: Should this attacker scenario be covered in FAPI attacker model?
- OAuth WG discussion moving toward "S1" solution: enforce PKCE plus nonce token request without code verifier
- FAPI already enforces PKCE, so likely no action needed
- Filip Skokan: Cautioned against rushing FAPI changes until this lands in OAuth; avoid diverging recommendations (similar to audience injection issue)
- Action: Dave added a note; will wait for Joseph to provide update
Issue #743 - FAPI2SP Clauses About Authorization
- Link: https://github.com/openid/fapi/issues/743
- Status: Assigned to Dima, awaiting PR
- Action: Dima to review and create PR
Issue #295 - Possible Support for Embedded SCA Mode
- Link: https://github.com/openid/fapi/issues/295
- Status: CLOSED (Won't Fix)
- Raised in 2020; Dave suggested closing in 2023
- Finally closed as no longer relevant
Issue #587 - FAPI Acronym
- Link: https://github.com/openid/fapi/issues/587
- Status: CLOSED
- Decision confirmed: FAPI is pronounced "Fappy"
Issue #487 - RS Must Check x-fapi-interaction-id is a UUID
- Link: https://github.com/openid/fapi/issues/487
- Status: Remains open for implementation advice documents
- Originally raised after Log4Shell vulnerability
- Mark (Australia) was keen on adding this as errata
- Decision: Leave open for implementation advice; may not be appropriate for errata
Issue #595 - Create a Resource Server Profile on Top of FAPI
- Link: https://github.com/openid/fapi/issues/595
- Status: Remains open
- Raised by Mark about having a resource server profile
- Topics include: headers, interaction IDs, idempotency patterns, data sharing patterns, event notifications, fraud/risk metadata
- Nat noted potential relationship to HTTP message signing work
- Working group likely lacks capacity to develop this comprehensively
- Action: Dima to contact Mark to see if he's still interested (may have changed jobs)
Issue #602 - Pandoc Publishing Internal Link Names Changed
- Link: https://github.com/openid/fapi/issues/602
- Status: Needs analysis
- Raised by Joseph
- May need review but late to change
- Action: Requires further investigation
Issue #594 - Address Concerns Related to JWT (Hacker News)
- Link: https://github.com/openid/fapi/issues/594
- Status: Under consideration for implementation advice
- Originated from Hacker News discussion about JWTs
- Nat suggested having a paragraph in implementation advice document or FAQ
- Relates to guidance like "don't use alg:none"
- Action: Consider adding to implementation advice with BCP references
Issue #293 - PKCE/Nonce Security Considerations
- Link: https://github.com/openid/fapi/issues/293
- Status: Remains open
- Nat noted FAPI-1 should encourage using PAR in deployment advice
- Decision: Leave open for now
Issue #327 - Dynamic Client Registration Management
- Link: https://github.com/openid/fapi/issues/327
- Status: Under discussion
- Another candidate for implementation deployment advice
- Document may become quite lengthy with all additions
Issue #469 - Add Protocol Version and Variant (DCR/DCM Spec)
- Link: https://github.com/openid/fapi/issues/469
- Status: Discussion about closure
- Originally about creating DCR/DCM specifications
- Joseph noted in July 2023 that ecosystems looking at OIDC Federation instead
- No draft spec was created
- Dima: Need for this reduced significantly; many new ecosystems adopting automatic-style registrations and federation
- Discussion about whether to close this vs. the federation issue
- Separate issue exists about using Federation or creating a federation profile
- Dima was one of the people pushing for this originally
- Brian Campbell: Cautioned against calling federation a "best practice" - it's not that yet
- Dima clarified: The move was more about moving away from dynamic client registration model, which puts burden on relying parties and creates long-term ecosystem maintenance issues
- The standardization effort is happening within the federation space
- Action: Dima to add nuanced comment and get feedback from the group
- Action: Dave to leave issue #469 with Dima; group currently lacks capacity for DCR/DCM spec development
Issue #457 - Create JSON Schema for Grant Management
- Link: https://github.com/openid/fapi/issues/457
- Status: Assigned to Stuart
- Action: Dima volunteered to take on this issue
Issue #555 - Tracking Implementers of FAPI 1.0 and FAPI 2.0
- Link: https://github.com/openid/fapi/issues/555
- Status: Under consideration for handover
- Question: Is a Bitbucket issue the best place for tracking ecosystem adoption?
- Mike and others now handling ecosystem engagement
- Dima: Agrees issue tracker is not the right place; suggests handing over to OpenID Foundation staff
- Could be part of the working group assistance requests for 2026
- Relevant for FAPI WG, DCP WG, and Ecosystems Community Group
- Action: Dima to respond to Elizabeth's request for working group assistance items
- Action: Dave to email Mike Leszcz to discuss best approach
Dave needs to chase up IANA registrations. He submitted them but hasn't received a reply.
Action: Dave to follow up on IANA registration submissions
No other business was raised.
| Owner | Action | Issue/PR |
|---|---|---|
| Nat | Resolve merge conflicts in PR #559 | PR #559 |
| Dave | Work on outstanding PRs from April 2025 | Various |
| Dave | Follow up on IANA registration submissions | - |
| Dave | Email Mike Leszcz about issue #555 tracking approach | #555 |
| Dave | Wait for Joseph's input on browser swapping attacks | #831 |
| Peter Stanley | Return in 2 weeks with UK ecosystem position on key lengths | #778 |
| Dima | Create PR for issue #743 | #743 |
| Dima | Contact Mark about resource server profile interest | #595 |
| Dima | Add nuanced comment on federation issue | #469 |
| Dima | Take on JSON Schema for Grant Management issue | #457 |
| Dima | Respond to Elizabeth's request re: ecosystem tracking | #555 |
| All | Consider adding JWT concerns to implementation advice | #594 |
| All | Volunteers needed for implementation guidelines | - |
- #821 - Use of non-standard port numbers (resolved)
- #295 - Embedded SCA mode (won't fix)
- #587 - FAPI acronym (decided: "Fappy")
Next week (January 14, 2026)
Board Elections: https://openid.net/announcing-the-2026-openid-foundation-community-representatives-election/
PRs Discussed:
- PR #558: https://bitbucket.org/openid/fapi/pull-requests/558
- PR #559: https://bitbucket.org/openid/fapi/pull-requests/559
Issues Discussed:
- #821: https://github.com/openid/fapi/issues/821
- #404: https://github.com/openid/fapi/issues/404
- #778: https://github.com/openid/fapi/issues/778
- #834: https://github.com/openid/fapi/issues/834
- #831: https://github.com/openid/fapi/issues/831
- #743: https://github.com/openid/fapi/issues/743
- #295: https://github.com/openid/fapi/issues/295
- #587: https://github.com/openid/fapi/issues/587
- #487: https://github.com/openid/fapi/issues/487
- #595: https://github.com/openid/fapi/issues/595
- #602: https://github.com/openid/fapi/issues/602
- #594: https://github.com/openid/fapi/issues/594
- #293: https://github.com/openid/fapi/issues/293
- #327: https://github.com/openid/fapi/issues/327
- #469: https://github.com/openid/fapi/issues/469
- #457: https://github.com/openid/fapi/issues/457
- #555: https://github.com/openid/fapi/issues/555