Skip to content

FAPI_Meeting_Notes_2026 01 21_Atlantic

Nat Sakimura edited this page Jul 10, 2026 · 1 revision

FAPI Working Group Meeting Notes

Date: January 21, 2026
Time: 14:00 UTC
Chair: Nat Sakimura


Attendees

Roll Call

  • Nat Sakimura (Chair)
  • Kosuke Koiwai
  • Chris Wood
  • George Fletcher
  • Robert Gallagher (Mastercard)
  • Bjorn Hjelm
  • Filip Skokan
  • Matthew Murphy (Mastercard)
  • Hideki Ikeda
  • Hodari McClain (VND)
  • Open Banking Limited:
    • Christopher Robbertse
    • Peter Stanley
    • Imran Ulghar

Regrets:

  • Mike Leszcz (providing updates via Nat)
  • Dave Tonge (transportation delayed)
  • Mark Haine
  • Joseph Heenan

1. Adoption of Agenda

The proposed agenda was adopted.

2. Events

Q1 2026 internal meetings and industry events have been added to all calendars:

  • February 2 – FIDO Paris Seminar (Paris)
  • February 3 – FIDO Alliance Member Plenary (Paris)
  • February 9-12 – TIIME Unconference (Amsterdam)
  • March 9-13 – ISO/IEC JTC 1/SC 27 WG Meeting (Nürnberg, Germany)
  • March 14-20 – IETF 125 (Shenzhen, China)
  • March 16-17 – ISO/IEC JTC 1/SC 27 Plenary (Nürnberg, Germany)
  • March 16-19 – FDX Global Summit 2026 (Washington, DC)
  • April 27 – OIDF Workshop prior to IIW Spring 2026 (Mountain View)
  • April 28-30 – IIW Spring 2026 (Mountain View)
  • May 12-15 – ID4Africa (Abidjan)
  • May 19-22 – EIC 2026 (Berlin)
  • May 27-29 – OAuth Security Workshop (OSW) (Leipzig, Germany)
  • June 2 – FIDO Authenticate APAC 2026 (Singapore)
  • June 15-18 – Identiverse (Las Vegas)
  • June 22-24 – Dice 2026 (Copenhagen)

Q2 meetings have been added to calendars; Q3-Q4 meetings to be added this week and next.


3. External Organizations & Liaisons

3.1 Ecosystem Partner Updates

End-of-year coordination calls with ecosystem partners for 2026 planning and budgeting have been completed:

  • Chile/CMF: Regulation planned for August 2026. Anticipating a few FAPI2 certifications in 2026 with ecosystem going live in early 2027. Minstait is CMF's implementation partner and may join the Foundation in place of CMF to provide directed funding.

  • SAMA (Saudi Arabia): Anticipate directed funding early 2026 to support new KSA FAPI2 Profile. Ecosystem will then certify to new profile.

  • UAE: Follow-up call scheduled for mid-January to discuss transition from FAPI2 ID to FAPI2 Final.

  • OFB & OPIN: 2026 certification confirmed.

  • Peru: Positive introductory call completed. Peruvian Monetary Authority (PMA) is adopting FAPI2 as part of Peru's Open Banking initiative and has partnered with Minstait (who is also supporting CMF in Chile). PMA will share draft profile soon.

3.2 UK FCA Request for Comment

Deadline: January 30, 2026

The UK FCA has published a feedback request on open banking/open finance. Gail Hodges has contacted Dave Tonge regarding OIDF/FAPI Working Group drafting a response. Dave has agreed to take the lead on this effort.

Link: https://www.fca.org.uk/news/news-stories/fca-publishes-feedback-call-input-open-finance

Chris Robbertse noted that while supportive, Open Banking Limited representatives will need to recuse themselves from some elements of the response drafting to avoid undue influence, but remain available for clarifications as needed.


4. Member Reminders


5. Pull Requests

PR #560 – Implementation Advice (Private Key Handling)

PR #541 – Add Clause on AS Rejecting Non-Source Data

PR #540 – Advice on DPoP versus MTLS

PR #542 – FAPI JARM Updates

PR #545 – Security Considerations (JARM Downgrade Attack)


6. Issues

6.1 Issue #835 – TLS Cipher Suite / ChaCha20-Poly1305

Link: https://github.com/openid/fapi/issues/835

Background: Current FAPI specification's allow-list approach to TLS cipher suites is causing false negatives with newer AEAD algorithms including ChaCha20-Poly1305.

Discussion:

Nat proposed leveraging the IANA TLS Cipher Suite Registry which includes "Recommended" and "Deprecated" flags:

Filip Skokan supported this approach and reiterated his earlier suggestion to change from an allow-list to an explicit block-list approach:

  • The spec cannot keep up with new algorithm recommendations
  • A deny-list would prevent false negatives in the future
  • He has also encountered false negatives involving ChaCha in the past

IANA Registry Guidance:

  • Recommended: TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 (and ECDHE variants)
  • Deprecated: DHE_RSA, DHE_PSK, and RSA_PSK versions of ChaCha20-Poly1305

Matthew Murphy (Mastercard) confirmed this approach would work for their use case and aligns with their maintained cipher list.

Concerns Raised: Nat expressed concern that a pure block-list approach might allow completely new, unverified algorithms to pass. Filip clarified that the conformance suite uses the latest Java Cryptography suite, so any supported algorithms are already vetted.

Resolution:

  • Proposed approach: Allow any cipher supported by Java Crypto Library that is not deprecated by IANA Registry
  • Nat will communicate this to Joseph Heenan for certification suite implementation
  • Issue will be tracked through the certification suite issue list

Action Items:

  • Nat to communicate proposed solution to Joseph Heenan
  • Track implementation in certification suite issue list

6.2 Issue #778 – Key Length Updates (ISO Review Comments)

Link: https://github.com/openid/fapi/issues/778

Background: ISO/IEC JTC 1 review comments requesting an update to the keylength by refering more up-to-date external document such as NIST one.

UK Ecosystem Feedback (from TDA meeting ~1 hour prior):

Chris Robbertse (Open Banking) reported fresh feedback from the Technical Design Authority meeting with CMA9 banks and TPPs:

  1. Higher key length is supportable across CMA9 and engaged TPPs

  2. Preference for BCP-195 reference: The UK ecosystem would prefer FAPI specification reference BCP-195 rather than directly referencing NIST:

    • BCP-195 already references NIST internally
    • Provides a singular reference point with established update processes
    • Aligns with the proposed approach for algorithms
  3. Processing time impact acknowledged: Higher key lengths will impact processing times, but this is not raised as a blocking issue – just flagged for awareness. No hard metrics available at this time.

  4. Current UK focus: RSA algorithms only (2048 to 3072 transition). ECC is not an immediate concern.

  5. Deprecation timeline: UK ecosystem has been primed to expect 2048-bit deprecation within approximately 4 years.

ECC Discussion:

Nat noted that BCP-195 currently states ECC less than 224 bits must not be used. The current FAPI text just requires ECC over 160 bits, so it would be a change that might impact implementations. Chris confirmed this ECC change does not affect UK (RSA-only ecosystem).

Resolution:

  • This was the last outstanding ISO comment
  • Nat and Hodari will draft updated text reflecting BCP-195 reference approach
  • Text to be shared with working group before submission to ISO

Action Items:

  • Nat and Hodari to draft updated key length text referencing BCP-195
  • Share draft with working group for review
  • Submit to ISO after approval

6.3 Issue #734 – Private Key Handling Recommendations

Link: https://github.com/openid/fapi/issues/734

Related to PR #560. Members asked to review and approve the PR or provide suggestions.

6.4 Issue #594 – JWT/JWK Concerns

Link: https://github.com/openid/fapi/issues/594

Brian and Dave have been discussing. Also related to the IETF draft:

6.5 Issue #595 – Resource Server Profile

Link: https://github.com/openid/fapi/issues/595

Dave pinged Mark on January 7th but no response yet. Nat will follow up with Mark offline.

6.6 Issue #583 – Using OIDC Federation and FAPI Together

Link: https://github.com/openid/fapi/issues/583

Being discussed between Joseph, Dave, and Diemer. All three absent today; deferred to next call.

6.7 Issue #648 – OpenAPI/FAPI Requirements

Link: https://github.com/openid/fapi/issues/648

Discussion: Chris Robbertse raised the proposal to add FAPI support to OpenAPI specification. Previous discussions noted that OpenAPI has limitations in expressing all FAPI requirements, though basic OAuth support was added through previous engagement.

Current Status: Issue has been dormant since 2024.

Proposal: Chris requested bringing this to next week's meeting for a decision:

  • Either identify someone to lead engagement with OpenAPI specification organization
  • Or close the issue as no action

Resolution: Item to be added to next week's agenda for decision on continuation or closure.

Action Items:

  • Add to next week's agenda
  • Members to have internal conversations about available resources to lead this effort

7. Any Other Business

No additional items raised.


8. Next Meeting

Next call scheduled for the following week at the regular time.


Action Item Summary

Action Owner Status
Communicate Issue #835 TLS cipher suite solution to Joseph Heenan Nat Pending
Track TLS cipher implementation in certification suite Nat/Joseph Pending
Draft key length text referencing BCP-195 for ISO submission Nat, Hodari Pending
Share key length draft with working group Nat, Hodari Pending
Follow up with Mark on Issue #595 (Resource Server Profile) Nat Pending
Lead UK FCA response drafting Dave Tonge Pending
Add OpenAPI/FAPI issue (#648) to next week's agenda Nat Pending
Members assess resources for OpenAPI engagement All Pending
Review PRs #560, #541, #540, #545 All Ongoing

Links Referenced in Meeting

PRs:

Issues:

External:


Meeting adjourned at approximately 14:45 UTC

Clone this wiki locally