-
Notifications
You must be signed in to change notification settings - Fork 0
FAPI_Meeting_Notes_2026 02 25_Atlantic
Date: Wednesday, 25 February 2026
Chair: Nat Sakimura (Dave Tonge absent)
- Mike Leszcz (OIDF)
- Hideki Ikeda
- Nat Sakimura
- Imran Ulghar (Open Banking Ltd)
- Robert Gallagher (Mastercard)
- Filip Skokan
- Benny Mei (Bloomberg) — first call
- George Fletcher
- Łukasz Jaromin
- Bjorn Hjelm
- Annette Foster (Open Banking Ltd)
Mike Leszcz read the Note Well, referencing the OIDF code of conduct policy and antitrust policy. Noted that a signed contribution agreement is required to participate in working groups, and a signed participation agreement is required for community groups. All reference policies are available at openid.net/policies.
Nat confirmed the draft agenda as posted by Nat Sakimura in chat. No additional items were proposed. Agenda adopted.
Mike Leszcz noted no new updates from the previous week and shared the full events list in chat. Key highlight:
- OIDF Workshop prior to IIW Spring 2026 — Monday, April 27, Mountain View remains on track. The original host venue (Microsoft/PAM) is no longer available; OIDF is pivoting to an alternate host. Updates to follow.
Upcoming events (from chat):
| Date | Event | Location |
|---|---|---|
| 9–13 Mar | ISO/IEC JTC 1/SC 27 WG Meeting | Nürnberg, Germany |
| 14–20 Mar | IETF 125 | Shenzhen, China |
| 16–17 Mar | ISO/IEC JTC 1/SC 27 Plenary | Nürnberg, Germany |
| 16–19 Mar | FDX Global Summit 2026 | Washington, DC |
| 27 Apr | OIDF Workshop (prior to IIW) | Mountain View, CA |
| 28–30 Apr | IIW Spring 2026 | Mountain View, CA |
| 12–15 May | ID4Africa | Abidjan |
| 19–22 May | EIC 2026 | Berlin |
| 27–29 May | OAuth Security Workshop (OSW) | Leipzig, Germany |
| 2 Jun | FIDO Authenticate APAC 2026 | Singapore |
| 15–18 Jun | Identiverse | Las Vegas |
| 22–24 Jun | DICE 2026 | Copenhagen |
| 18–24 Jul | IETF 126 | Vienna |
| 1–3 Sep | Global Digital Collaboration Conference 2026 | Geneva |
| 14–17 Sep | ISO/IEC JTC1/SC 17 Plenary | Chengdu, China |
| 19–21 Oct | FIDO Authenticate 2026 | Carlsbad, CA |
| 2 Nov | OIDF Workshop (prior to IIW Fall) | Mountain View, CA |
| 3–5 Nov | IIW Fall 2026 | Mountain View, CA |
| 14–20 Nov | IETF 127 | San Francisco |
| 7–9 Dec | Gartner IAM US | Las Vegas |
Send any 2026 events to be added to the calendar to mike.leszcz@oidf.org.
Gail and Mark Haine met with the EC. Draft spec objectives and hierarchy document expected imminently. Initial review will focus on their VCI specs, with analysis of any gaps and implications for conformance test alignment.
Directed funding to support the new KSA FAPI 2.0 profile has been received (confirmed the day prior to this call). Mike Leszcz is now working with Joseph and Domingos on the development plan to get new tests into production. Anticipated timeline: within 30 days.
Ralph Bragg confirmed Erick Domingues (Raidiam) is the author of the UAE security profile. The UAE profile had already included the FAPI 2.0 final elements that were absent from FAPI 2.0 ID2. The main remaining work is removing duplication now that the profile is based on FAPI 2.0 Final.
Regulation targeted for August 2026. A few FAPI 2.0 certifications anticipated in 2026, with ecosystem going live in earnest in early 2027. Minstait (CMF's implementation partner) is in process of joining the Foundation to provide directed funding. CMF is also now considering adopting Shared Signals; the next call will include an SS WG co-chair and Thomas from the certification team.
2026 certifications confirmed.
Gail and Domingos held a follow-up call the week of 2 February covering interest in the Ecosystem Support CG and OIDF WGs. FAPI 2.0 adoption is well underway; an updated roadmap is expected at end of February.
Not yet live with the VP spec; anticipated in the next couple of months. VCI adoption is still being evaluated. Receiving EC funding support through ADHAR.
ETSI TS 119 472-2 and 119 472-3 (EAA PID Issuance Profile and related specs) are expected to publish this Friday. Bjorn Hjelm noted that OIDF has a liaison agreement with ETSI and can request access.
- Action — Nat: Send Bjorn the list of relevant ETSI spec numbers.
- Action — Bjorn: Request the ETSI specs through the OIDF liaison channel once the list is received.
- OpenID Federation 1.0 Final Specification approved: https://openid.net/openid-federation-1-0-final-specification-approved/
- Public Review for Proposed OpenID Connect Relying Party Metadata Choices 1.0 Final started 9 January 2026; voting scheduled to start 11 March 2026.
- Public Review for Proposed Implementer's Draft of iGov Profile for OAuth 2.0 started 11 February 2026; voting scheduled 29 March 2026: https://openid.net/public-review-period-for-proposed-implementers-draft-of-igov-profile-for-oauth-2/
- Public Review for Proposed OpenID Federation 1.1 Final Specifications started 17 February 2026; voting scheduled 4 May 2026: https://openid.net/public-review-period-for-proposed-openid-federation-1-1-final-specifications/
Members on the call were encouraged to monitor these reviews and vote when they open.
Dave Tonge was absent. Nat Sakimura chaired the PR review.
https://bitbucket.org/openid/fapi/pull-requests/540/diff
All comments resolved; approvals received. No dissent raised.
- Decision: Nat to merge after the call. ✅
https://bitbucket.org/openid/fapi/pull-requests/541
All comments resolved. No dissent raised.
- Decision: Nat to merge. ✅
https://bitbucket.org/openid/fapi/pull-requests/529
Ongoing discussions; no responses for approximately three weeks.
- Action — Nat: Contact the relevant contributor (Job) to determine how to move forward.
Issues list: https://github.com/openid/fapi/issues?q=is%3Aissue%20state%3Aopen
Damien not present on the call.
- Action — Nat: Ping Damien for any updates on the OSCAL profile.
Issue #835 — 5.2 Network Layer Protections
https://github.com/openid/fapi/issues/835
Robert Gallagher (Mastercard) was unaware that a PR was expected from him; the assignment was ambiguous. A blog post was already sent to Gail for chair review a couple of weeks ago. Nat confirmed receipt but has not yet had time to review.
- Decision: Nat will create the PR and self-assign.
- Action — Nat: Review the blog post submitted by Robert/Gail.
Issue #831 — Browser Swapping Attacks
https://github.com/openid/fapi/issues/831
Awaiting action from the Health Working Group. The all-WG face-to-face is expected in the second week of March; outcome from that meeting will inform next steps. No further action at this time.
Issue #744 — Certification Team Query: Refresh Tokens in Client Credentials Grant
https://github.com/openid/fapi/issues/744
No certification team representative present. Nat opened the issue for the record; noted that Joseph should be pinged to confirm test status.
- Action — Nat: Ping Joseph regarding the test status for client credentials / refresh token scenario.
Issue #734 — Recommendations Around Handling of Private Keys
https://github.com/openid/fapi/issues/734
Addressed via PR #560; a section on private key handling was added to the implementation advice.
- Decision: Nat to close/resolve the issue. ✅
Issue #730 — 5.2.3 Public Client Interpretation
https://github.com/openid/fapi/issues/730
Nat indicated intent to close, but will first ping Joseph to confirm that tests are working as intended.
- Action — Nat: Ping Joseph before closing.
Issue #740 — Request for a Tailored FAPI 2.0 Conformance Test (Machine-to-Machine / Client Credentials)
https://github.com/openid/fapi/issues/740 Related GitLab conformance suite issue: https://gitlab.com/openid/conformance-suite/-/issues/1561
Raised by Robert Gallagher. The related GitLab issue appears to have been merged approximately two months ago. Robert believed the matter was resolved based on Joseph's earlier commitment to work on it.
- Action — Robert Gallagher: Check with his Mastercard team to confirm whether implementation work was completed on their side, and report back to the group.
Issue #742 — Agent Payments Protocol (AP2) Impacts to FAPI
https://github.com/openid/fapi/issues/742
Approximately six months old with no activity since a brief discussion on the 17 September call, where the group agreed to track it as a task. No one present is currently working on AP2 in this context.
- Decision: Nat to keep the issue open but lower its priority.
Issue #741 — Is nbf a Mandatory Requirement for Request Objects?
https://github.com/openid/fapi/issues/741
Awaiting a DMAS action. Nat noted he would ping the relevant party (Dima).
-
Action — Nat: Ping Dima regarding the DMAS action on
nbfin request objects.
Issue #727 — MCP Servers: Scope and RAR
https://github.com/openid/fapi/issues/727
This approximately one-year-old issue (raised shortly after MCP emerged) generated substantive discussion. Key points:
Background (from meeting notes of 10 April 2025, pasted into the issue by Nat): The issue was opened to examine whether MCP-based deployments using FAPI should prefer scopes or Rich Authorization Requests (RAR), and what the FAPI WG's appropriate guidance is.
Discussion:
- Łukasz Jaromin noted he is currently reviewing the IAM WG white paper / NIST RFI response and observed that over-permissioning (e.g., using full browser access rather than constrained tokens) is flagged as a concern. He argued that RAR should be included among NIST recommendations where finer-grained permissions are available.
- George Fletcher observed that there is no well-defined authorization model in the MCP world. In enterprise deployments, authorization tends to be deployment-specific. For publicly exposed MCP services, a common delegated authorization approach is lacking. RAR could be useful if the MCP server can accept RAR claims from a trusted authorization server — but in practice, the underlying ecosystems often do not support RAR or finer-grained permissions at all. George noted that most MCP servers do not require FAPI; FAPI, if used at all, is typically between the MCP server and a downstream API, creating a potential security mismatch if the agent-to-MCP leg is less secure than the MCP-to-API FAPI leg.
- Łukasz Jaromin framed the core question as: given that FAPI is in use, should an agent use RAR (as the FAPI spec already recommends when scopes are insufficient)? He suggested the broader question of when to use FAPI for agentic AI deserves treatment in the AI/IAM community group context.
- George Fletcher suggested that there may not be any FAPI spec work required here — it is more likely an implementation guidance question. He proposed identifying concrete ecosystems that currently require FAPI and want to expose capabilities via MCP servers as the right starting point, because those deployments are more likely to have finer-grained permission support already. He also proposed the topic be raised in the AI community group's main working session (10–15 minutes to present the problem space).
- Bjorn Hjelm agreed and suggested opening an issue in the AI community group's repository referencing the FAPI issue.
- Łukasz Jaromin noted the threat modeling subgroup may also be a relevant venue; contributing use cases about regulated-industry agentic deployments (where FAPI applies and security property preservation across transport protocol transitions is a concern) would be valuable for the NIST response.
- George Fletcher emphasised the security risk when traversing multiple transport protocols — transformation from one protocol to another can cause security properties to be dropped, and this is a key concern for the NIST-level discussion.
Actions:
- Action — Nat: Summarise today's discussion in Issue #727.
- Action — Bjorn Hjelm: Bring the topic to the AI/IAM community group and open a referencing issue in their repository. (George Fletcher offered; Bjorn volunteered to take this on.)
- Action — Łukasz Jaromin: Add comments to the NIST RFI response (via the AI/IAM WG) covering RAR and fine-grained permissions in the context of agentic AI and regulated ecosystems.
Benny Mei introduced themselves as a first-time attendee from Bloomberg, having signed the contribution agreement a couple of weeks ago and now exploring different working groups. Nat welcomed Benny to the working group.
Nat noted he will follow up with Christopher via back-channel regarding an OpenAPI-related arrangement.
| # | Action | Owner | Due |
|---|---|---|---|
| 1 | Send Bjorn the list of relevant ETSI TS 119 472-x spec numbers | Nat Sakimura | ASAP |
| 2 | Request ETSI specs through the OIDF liaison channel | Bjorn Hjelm | After receiving list |
| 3 | Contact Job to determine how to move forward on PR #529 | Nat Sakimura | Next call |
| 4 | Ping Damien for OSCAL profile updates | Nat Sakimura | ASAP |
| 5 | Create PR for Issue #835 (network layer protections) and self-assign | Nat Sakimura | Next call |
| 6 | Review Mastercard/Gail blog post on Issue #835 | Nat Sakimura | ASAP |
| 7 | Ping Joseph re test status for Issue #744 (client credentials / refresh tokens) | Nat Sakimura | ASAP |
| 8 | Ping Joseph before closing Issue #730 (public client interpretation) | Nat Sakimura | ASAP |
| 9 | Check with Mastercard team on M2M conformance work (Issue #740 / GitLab #1561); report back | Robert Gallagher | Next call |
| 10 | Ping Dima regarding DMAS action on Issue #741 (nbf in request objects) |
Nat Sakimura | ASAP |
| 11 | Summarise MCP/RAR discussion into Issue #727 | Nat Sakimura | ASAP |
| 12 | Bring Issue #727 topic to AI/IAM community group; open referencing issue | Bjorn Hjelm | Next call |
| 13 | Add NIST RFI comments on RAR / fine-grained permissions for agentic AI | Łukasz Jaromin | Per NIST deadline |
Next call: Wednesday, 4 March 2026