Skip to content

FAPI_Meeting_Notes_2026 01 07_Atlantic

Nat Sakimura edited this page Jul 10, 2026 · 1 revision

FAPI Working Group Meeting Notes

Date: 2026-01-07
Time: 14:00 UTC
Meeting: First FAPI Atlantic Call of 2026


Attendees

  • Nat Sakimura (Chair)
  • Dave Tonge (Co-Chair)
  • Dima Postnikov (Co-Chair)
  • Matthew Murphy (Mastercard)
  • Kosuke Koiwai
  • George Fletcher
  • Imran Ulghar (OBL)
  • Filip Skokan
  • Robert Gallagher (Mastercard)
  • Hideki Ikeda (Authlete)
  • Peter Stanley (OBL)
  • Bjorn Hjelm
  • Brian Campbell
  • Christopher Robbertse (Open Banking) - partial attendance

Agenda

  1. Roll Call (Dave/Nat)
  2. Adoption of Agenda (Dave/Nat)
  3. Events (Mike L.)
  4. External Orgs & Liaisons (Mike L.)
  5. PRs (Dave)
  6. Issues (Dave)
  7. AOB (Nat)

1. Roll Call

Nat welcomed attendees to the first FAPI Atlantic call of 2026. Attendees provided their names via chat.


2. Adoption of Agenda

No additions were proposed. The agenda was adopted as presented.


3. Events

Mike Leszcz was unable to attend but provided updates via email. Nat shared the following Q1 2026 events:

  • March 9-13: ISO/IEC JTC 1/SC 27 WG Meeting - Nürnberg, Germany
  • March 14-20: IETF 125 - Shenzhen, China
  • March 16-17: ISO/IEC JTC 1/SC 27 Plenary - Nürnberg, Germany

Q2-Q4 2026 meetings and events will be added to calendars and the website once confirmed. Members are encouraged to send any 2026 events to mike.leszcz@oidf.org for inclusion.


4. External Organizations & Liaisons

End-of-year coordination calls with ecosystem partners are underway for 2026 planning and budgeting:

Chile/CMF

  • Plan to have regulation in place by August 2026
  • Anticipate a few FAPI2 certifications in 2026
  • Ecosystem going live in earnest in early 2027
  • Minstait (CMF's implementation partner) may join the Foundation in place of CMF to provide directed funding

SAMA (Saudi Arabia)

  • Anticipate directed funding early 2026 to support new KSA FAPI2 Profile
  • Ecosystem will then certify to the new profile

UAE

  • Follow-up call scheduled for mid-January
  • Discussion will focus on transition from FAPI2 ID to FAPI2 Final

Open Finance Brazil (OFB) & OPIN

  • 2026 certification confirmed

Peru

  • Introduction call scheduled for January
  • Domingos has made introductions to OFB and CMF

5. Member Reminders

Authorization API 1.0 Final Specification

  • Notice of Vote to Approve was approved yesterday (January 6, 2026)
  • Announcement to be published today

2026 OpenID Foundation Board Elections


6. Pull Requests

PR #558 - Editorial Spacing Fixes

PR #559 - Editorial Fixes

Other PRs

  • Dave noted with some embarrassment that some PRs he opened date back to April 2025
  • Action: Dave will work to complete outstanding PRs
  • Request for volunteers to help with implementation guidelines

7. Issues Discussion

Issue #821 - Use of Non-Standard Port Numbers for HTTPS

Issue #404 - Interoperability Validation

Issue #778 - FAPI1 ISO/IEC 25791-1 Review Comments (Key Length)

  • Link: https://github.com/openid/fapi/issues/778
  • Status: Under discussion
  • Previous call (December 17, 2025) had substantive discussion
  • Current direction: Likely not making normative changes; may add a note about ecosystems considering longer key lengths for algorithm agility

UK Open Banking Feedback (Peter Stanley)

  • Peter took an action to raise this with TDA (UK Technical Design Authority)
  • Raised today; will receive final input in two weeks
  • Concerns raised about exponential increase in processing times with larger key lengths
  • Mixed feedback from UK ecosystem:
    • One implementer moved to larger key lengths without substantial issues
    • Another implementer doubled key lengths (to 4096) and experienced significant performance impact
  • Key questions being addressed:
    • If current key lengths are removed from spec and reference to FIPS is added, how would changes be introduced (errata vs. FAPI 1.1)?
    • NIST currently says 2048-bit RSA is acceptable; likely review around 2030
    • Is NIST the appropriate reference for UK ecosystem?
    • BCP195 would be an easier reference point for UK ecosystem
  • Action: Peter to return in two weeks with consolidated UK ecosystem position

Related Considerations

  • Post-quantum cryptography will add another dimension to this discussion
  • Imran noted a request regarding DHE deprecation as part of post-quantum considerations; awaiting IANA feedback
  • BCP195 is currently silent on specific key lengths but references "at least 2048" for TLS
  • Discussion about benefits of referencing BCPs that will be updated over time vs. static NIST documents

Issue #834 - Abstract Should Not Be There for FAPI1 (ISO Submission)

Issue #831 - Browser Swapping Attacks

  • Link: https://github.com/openid/fapi/issues/831
  • Status: Remains open, awaiting OAuth WG conclusion
  • Raised by Joseph regarding attacks discussed at IETF 114
  • Question: Should this attacker scenario be covered in FAPI attacker model?
  • OAuth WG discussion moving toward "S1" solution: enforce PKCE plus nonce token request without code verifier
  • FAPI already enforces PKCE, so likely no action needed
  • Filip Skokan: Cautioned against rushing FAPI changes until this lands in OAuth; avoid diverging recommendations (similar to audience injection issue)
  • Action: Dave added a note; will wait for Joseph to provide update

Issue #743 - FAPI2SP Clauses About Authorization

Issue #295 - Possible Support for Embedded SCA Mode

Issue #587 - FAPI Acronym

Issue #487 - RS Must Check x-fapi-interaction-id is a UUID

  • Link: https://github.com/openid/fapi/issues/487
  • Status: Remains open for implementation advice documents
  • Originally raised after Log4Shell vulnerability
  • Mark (Australia) was keen on adding this as errata
  • Decision: Leave open for implementation advice; may not be appropriate for errata

Issue #595 - Create a Resource Server Profile on Top of FAPI

  • Link: https://github.com/openid/fapi/issues/595
  • Status: Remains open
  • Raised by Mark about having a resource server profile
  • Topics include: headers, interaction IDs, idempotency patterns, data sharing patterns, event notifications, fraud/risk metadata
  • Nat noted potential relationship to HTTP message signing work
  • Working group likely lacks capacity to develop this comprehensively
  • Action: Dima to contact Mark to see if he's still interested (may have changed jobs)

Issue #602 - Pandoc Publishing Internal Link Names Changed

Issue #594 - Address Concerns Related to JWT (Hacker News)

  • Link: https://github.com/openid/fapi/issues/594
  • Status: Under consideration for implementation advice
  • Originated from Hacker News discussion about JWTs
  • Nat suggested having a paragraph in implementation advice document or FAQ
  • Relates to guidance like "don't use alg:none"
  • Action: Consider adding to implementation advice with BCP references

Issue #293 - PKCE/Nonce Security Considerations

Issue #327 - Dynamic Client Registration Management

Issue #469 - Add Protocol Version and Variant (DCR/DCM Spec)

  • Link: https://github.com/openid/fapi/issues/469
  • Status: Discussion about closure
  • Originally about creating DCR/DCM specifications
  • Joseph noted in July 2023 that ecosystems looking at OIDC Federation instead
  • No draft spec was created
  • Dima: Need for this reduced significantly; many new ecosystems adopting automatic-style registrations and federation
  • Discussion about whether to close this vs. the federation issue

Federation Discussion

  • Separate issue exists about using Federation or creating a federation profile
  • Dima was one of the people pushing for this originally
  • Brian Campbell: Cautioned against calling federation a "best practice" - it's not that yet
  • Dima clarified: The move was more about moving away from dynamic client registration model, which puts burden on relying parties and creates long-term ecosystem maintenance issues
  • The standardization effort is happening within the federation space
  • Action: Dima to add nuanced comment and get feedback from the group
  • Action: Dave to leave issue #469 with Dima; group currently lacks capacity for DCR/DCM spec development

Issue #457 - Create JSON Schema for Grant Management

Issue #555 - Tracking Implementers of FAPI 1.0 and FAPI 2.0

  • Link: https://github.com/openid/fapi/issues/555
  • Status: Under consideration for handover
  • Question: Is a Bitbucket issue the best place for tracking ecosystem adoption?
  • Mike and others now handling ecosystem engagement
  • Dima: Agrees issue tracker is not the right place; suggests handing over to OpenID Foundation staff
  • Could be part of the working group assistance requests for 2026
  • Relevant for FAPI WG, DCP WG, and Ecosystems Community Group
  • Action: Dima to respond to Elizabeth's request for working group assistance items
  • Action: Dave to email Mike Leszcz to discuss best approach

8. IANA Registrations

Dave needs to chase up IANA registrations. He submitted them but hasn't received a reply.

Action: Dave to follow up on IANA registration submissions


9. Any Other Business

No other business was raised.


Action Items Summary

Owner Action Issue/PR
Nat Resolve merge conflicts in PR #559 PR #559
Dave Work on outstanding PRs from April 2025 Various
Dave Follow up on IANA registration submissions -
Dave Email Mike Leszcz about issue #555 tracking approach #555
Dave Wait for Joseph's input on browser swapping attacks #831
Peter Stanley Return in 2 weeks with UK ecosystem position on key lengths #778
Dima Create PR for issue #743 #743
Dima Contact Mark about resource server profile interest #595
Dima Add nuanced comment on federation issue #469
Dima Take on JSON Schema for Grant Management issue #457
Dima Respond to Elizabeth's request re: ecosystem tracking #555
All Consider adding JWT concerns to implementation advice #594
All Volunteers needed for implementation guidelines -

Issues Closed This Meeting

  • #821 - Use of non-standard port numbers (resolved)
  • #295 - Embedded SCA mode (won't fix)
  • #587 - FAPI acronym (decided: "Fappy")

Next Meeting

Next week (January 14, 2026)


Reference Links

Note Well: https://docs.google.com/presentation/d/11XcAkVY5ZahDjeGhRaK1l0VRDlUDKPsr/edit?usp=sharing&ouid=109638882098300721101&rtpof=true&sd=true

Board Elections: https://openid.net/announcing-the-2026-openid-foundation-community-representatives-election/

PRs Discussed:

Issues Discussed:

Clone this wiki locally