-
Notifications
You must be signed in to change notification settings - Fork 0
FAPI_Meeting_Notes_2026 01 28_Atlantic
Nat Sakimura edited this page Jul 10, 2026
·
1 revision
- Date: 2026-01-28
- Time: 14:00 UTC
- Location: Zoom
- Nat Sakimura (Chair)
- Dave Tonge (Co-chair, absent)
- Mike Leszcz (OIDF)
- Imran Ulghar (Open Banking Limited)
- Christopher Robbertse (Open Banking Limited)
- Hideki Ikeda (Authlete)
- Kosuke Koiwai (KDDI)
- Matthew Murphy (Mastercard)
- George Fletcher (Practical Identity)
- Annette Foster (Open Banking Limited)
- Lukasz Jaromin (Raidiam)
- Peter Stanley (Open Banking Limited)
- Robert Gallagher (Mastercard)
- Mike Leszcz presented the standard NoteWell and Trust Policy notices
- All policies referenced in NoteWell can be found at https://openid.net/policies
- Draft agenda re-circulated 70 minutes before the meeting
- Agenda adopted as presented with no additions
- Roll Call (Nat)
- Adoption of Agenda (Nat)
- Events (Mike L.)
- External Orgs & Liaisons (Mike L.)
- PRs (Nat)
- Issues (Nat)
- 6.1 #648 Define requirements for OpenAPI FAPI securityScheme type
- AOB (Nat)
- All Q1 through Q3 2026 events have been added to OIDF Google Calendar
- Events are listed on the OIDF website under Calendar
- Board members have internal meetings Q1-Q3 on their personal calendars
- Q4 meetings and industry events will be added to calendars this week
- Cross-referencing with Heather Flanagan's event list for completeness
- February 2 - FIDO Paris Seminar - Paris
- February 3 - FIDO Alliance Member Plenary - Paris
- February 9-12 - TIIME Unconference - Amsterdam
- March 9-13 - ISO/IEC JTC 1/SC 27 WG Meeting - Nürnberg, Germany
- March 14-20 - IETF 125 - Shenzhen, China
- March 16-17 - ISO/IEC JTC 1/SC 27 Plenary - Nürnberg, Germany
- March 16-19 - FDX Global Summit 2026 - Washington, DC
- April 27 - OIDF Workshop prior to IIW Spring 2026 - Mountain View
- April 28-30 - IIW Spring 2026 - Mountain View
- May 12-15 - ID4Africa - Abidjan
- May 19-22 - EIC 2026 - Berlin
- May 27-29 - OAuth Security Workshop (OSW) - Leipzig, Germany
- June 2 - FIDO Authenticate APAC 2026 - Singapore
- June 15-18 - Identiverse - Las Vegas
- June 22-24 - Dice 2026 - Copenhagen
- July 18-24 - IETF 126 - Vienna
- September 1-3 - Global Digital Collaboration Conference 2026 - Geneva
- September 14-17 - ISO/IEC JTC1/SC 17 Plenary - Chengdu, China
Note: Please send any 2026 events to be added to the calendar to mike.leszcz@oidf.org
- Regulation Timeline: CMF plans to have regulation in place by August 2026
- Implementation: Anticipate a few FAPI2 certifications in 2026
- Ecosystem Launch: Full ecosystem expected to go live in earnest in early 2027
- Implementation Partner: Minsait is CMF's implementation partner and may join the Foundation in place of CMF to provide directed funding
- Membership Status: As of week of January 19th, Minsait confirmed membership is in process to provide directed funding
- Follow-up Activity: Domingos and Mike L had follow-up call week of January 19th to address questions regarding the CMF FAPI Profile
- Shared Signals: CMF is now considering adopting Shared Signals
- Next Steps: Next call to include a Shared Signals Working Group co-chair and Thomas from the certification team
- Current Status: UAE originally adopted FAPI2 Implementer's Draft to go live prior to final
- Transition Planning: Domingos and Mike L had follow-up call week of January 19th with UAE and Ozone (implementation partner) to address transition from FAPI2 ID to FAPI2 Final
- Impact Assessment: Minimal impact on ecosystem partners (primarily TTPs) as well as conformance tests
- Communication Strategy: UAE and Ozone believe the heavy lift is communicating to the TTPs and are coordinating those efforts currently
- Timeline: Transition anticipated for Q2 2026
- Implementation Partner: PMA (Peruvian Monetary Authority) is adopting FAPI2 as part of Peru's Open Banking initiative
- Partnership: Peru has partnered with Minsait, who is also supporting CMF in Chile
- Benefits: This creates opportunities for interoperability and knowledge transfer between ecosystems
- Profile Development: PMA is working on definition of the FAPI2 profile
- Technical Support: Domingos and others have provided significant input to date
- Next Steps: PMA will share draft profile soon for review and comments
- Authorization API 1.0 Final Specification: Vote announcement published at https://openid.net/authorization-api-1-0-final-specification-approved/
- OpenID Federation 1.0 Final Specification: Vote announcement at https://openid.net/notice-of-vote-to-approve-proposed-openid-federation-1-0-final-specification/
- Member Action Required: Members encouraged to vote when polls go live
- Specification: Proposed OpenID Connect Relying Party Metadata Choices 1.0 Final Specification
- Review Started: Friday, January 9, 2026
- Voting Start: Scheduled for Wednesday, March 11, 2026
Note: Mike Leszcz dropped from the call after this section to attend another meeting.
The following pull requests were reviewed:
- Link: https://bitbucket.org/openid/fapi/pull-requests/560
- The PR adds a key management section that refers to NIST etc.
- If needed, a change can be made with a new issue and PR.
- Merged
- Link: https://bitbucket.org/openid/fapi/pull-requests/540
- The PR adds:
- DPoP vs MTLS section
- Oversized header consideration
- Has one approval. Good to have another. Please review.
- Link: https://bitbucket.org/openid/fapi/pull-requests/541
- Another approval or change request needed.
- Link: https://bitbucket.org/openid/fapi/pull-requests/561
- Editorial change to correct a misplaced Note.
- Several approval came in during the call.
- To be merged.
- Link: https://bitbucket.org/openid/fapi/pull-requests/545
- Extensive discussion conducted.
- It was pointed out by several people that "SHOULD reject the response" is inappropriate as it is a MUST in the underlying spec.
- At the same time, it was also pointed out that a normative requirement (=MUST and MUST NOT) is not appropriate in the advice document, and it was argued that it should not be added to the document.
- Tending to take the latter view.
- Link: https://bitbucket.org/openid/fapi/pull-requests/529
- Discussion and review conducted
Issue #648: Define requirements for OpenAPI FAPI securityScheme type
- Link: https://github.com/openid/fapi/issues/648
- Substantial discussion conducted.
- It was pointed out that as it stands, it is not possible to express FAPI in OpenAPI 3.2.
- Some participant argued that it is not in the scope of the FAPI WG and the WG lacks the expertise, while about the equal number of participant argued that it is often needed and FAPI WG is the most appropriate body to advocate for the extension of the OpenAPI.
- Since it would involve the toolings, it was agreed that it should get into the core, if it was to be done.
- The topic is to be discussed in the subsequent calls.
Issue #837: FAPI2 Security Profile - ISO/IEC 26083-1
- Link: https://github.com/openid/fapi/issues/837
- Type: ISO/IEC JTC1 Pass comments
- Category: Newly submitted issue
- Nature: General and editorial updates on security profile
- Source: Collection of issues from ISO review process
- Classification: Marcus designated whether issues apply to Pass only or should be addressed as root items
- All issues are editorial in nature
-
Action Items:
- Working group members requested to review and comment as needed
- Nat to take up again next week and bring back to Pacific call where Mark will be present
- Goal to resolve in timely fashion
Issue #838: FAPI2 Attacker Model - ISO/IEC 26083-2
- Link: https://github.com/openid/fapi/issues/838
- Type: ISO/IEC JTC1 Pass comments
- Category: Newly submitted issue
- Nature: Collection of issues on the Attacker Model
- Classification: Marcus designated whether issues apply to Pass only or should be addressed as root items
- All issues are editorial in nature
-
Action Items:
- Working group members requested to review and comment as needed
- Nat to take up again next week and bring back to Pacific call where Mark will be present
- Goal to resolve in timely fashion
Issue #595: Create a resource server profile on top of FAPI 2
- Link: https://github.com/openid/fapi/issues/595
- Previous Discussion: Discussed in Pacific call last week
- Current Status: Upon Mark and Dima to bring to Ecosystem Working Group
- Next Meeting: Ecosystem Working Group meeting scheduled for Friday (or similar timeframe)
-
Action Items:
- Mark and Dima to present to Ecosystem Working Group and gather feedback
- Working group members encouraged to leave comments on the ticket if they have insights
Issue #404: Interoperability validation
- Link: https://github.com/openid/fapi/issues/404
- Assigned to: Lukasz Jaromin
- Status: Lukasz was not available to provide update during the meeting
- Action Item: Nat to ping Lukasz offline for update
Issue #835 (Follow-up from previous week)
- Raised by: Robert Gallagher (Mastercard)
- Context: Agreement reached in previous week's working group meeting
- Current Status: Passed over to Joseph (certification team)
- Question: How to track progress on certification team tickets
-
Nat's Response:
- Issue should be tracked in Certification team ticket system
- Nat hasn't had chance to talk to Joseph yet
- Will follow up with Joseph
-
Action Items:
- Nat to contact Joseph
- Robert also encouraged to try to get hold of Joseph
- No additional business items were declared
- Items deferred to next week's discussion as needed
- Date: Same time next week (February 4, 2026)
- Nat expressed looking forward to meeting everyone again
- Meeting concluded at approximately 52 minutes into the call
- Thanks expressed for constructive discussion
-
Mike Leszcz:
- Add Q4 2026 meetings and industry events to calendars this week
- Cross-reference with Heather Flanagan's event list
-
Chile/CMF:
- Schedule follow-up call including Shared Signals WG co-chair and Thomas (certification team) to discuss Shared Signals adoption
-
Peru:
- Await draft FAPI2 profile from PMA for review and comments
-
- All working group members to review ISO Pass comments and provide feedback
- Nat to bring issues back to Pacific call next week with Mark present
-
Issue #595:
- Mark and Dima to present resource server profile to Ecosystem Working Group
- Working group members to leave comments on ticket if they have insights
-
Issue #404:
- Nat to ping Lukasz Jaromin offline for update
-
Issue #835:
- Nat to contact Joseph regarding certification team tracking
- Robert Gallagher to also try contacting Joseph
- PR #560: https://bitbucket.org/openid/fapi/pull-requests/560
- PR #540: https://bitbucket.org/openid/fapi/pull-requests/540
- PR #541: https://bitbucket.org/openid/fapi/pull-requests/541
- PR #561: https://bitbucket.org/openid/fapi/pull-requests/561
- PR #545: https://bitbucket.org/openid/fapi/pull-requests/545
- PR #529: https://bitbucket.org/openid/fapi/pull-requests/529
- #648: https://github.com/openid/fapi/issues/648
- #837: https://github.com/openid/fapi/issues/837
- #838: https://github.com/openid/fapi/issues/838
- #595: https://github.com/openid/fapi/issues/595
- #404: https://github.com/openid/fapi/issues/404
- OIDF Policies: https://openid.net/policies
- Authorization API 1.0 Final: https://openid.net/authorization-api-1-0-final-specification-approved/
- OpenID Federation 1.0 Final: https://openid.net/notice-of-vote-to-approve-proposed-openid-federation-1-0-final-specification/