Skip to content

FAPI_Meeting_Notes_2026 03 25_Atlantic

Nat Sakimura edited this page Jul 10, 2026 · 1 revision

DRAFT

FAPI Working Group — Atlantic Call Meeting Notes

  • Date: 2026-03-25 14:00 UTC
  • Location: Zoom

1. Attendees

Name Organization
Nat Sakimura (Chair) NAT.Consulting
Dave Tonge (Co-Chair) Moneyhub
Mike Leszcz OIDF
Hideki Ikeda Authlete
Matthew Murphy Mastercard
Robert Gallagher Mastercard
Peter Stanley Open Banking Limited (OBL)
Bjorn Hjelm Yubico
Kosuke Koiwai KDDI
Dima Postnikov Scytáles
Christopher Robbertse Open Banking Limited (OBL)
Lukasz Jaromin Raidiam
George Fletcher Practical Identity
Brian Campbell Ping Identity

2. Note Well / Adoption of Agenda

Mike Leszcz read the OpenID Foundation Note Well, covering:

  • The Code of Conduct Policy
  • The antitrust policy
  • The requirement for a signed contribution agreement to participate in OpenID Foundation working groups
  • The requirement for a signed participation agreement to participate in OpenID Foundation community groups

All reference policies are available at openid.net/policies.

The standard agenda posted in chat was adopted without objection.

Previous meeting notes (2026-03-18 Atlantic call) were published immediately before this call: https://github.com/openid/fapi/wiki/FAPI_Meeting_Notes_2026-03-18_Atlantic


3. Events

Presented by Mike Leszcz (OIDF). No material updates from the prior week; events list reproduced below for the record.

Date Event Location
March 23–26 RSA Conference San Francisco, CA
April 14 OECD Working Party on Digital Security Paris
April 22–23 IAM Tech Day São Paulo
April 27 OIDF Hybrid Workshop (prior to IIW Spring 2026) Mountain View
April 28–30 IIW Spring 2026 Mountain View
May 12–15 ID4Africa Abidjan
May 19–22 EIC 2026 Berlin
May 27–29 OAuth Security Workshop (OSW) Leipzig, Germany
June 2 FIDO Authenticate APAC 2026 Singapore
June 15–18 Identiverse Las Vegas
June 22–24 DICE 2026 Copenhagen
July 18–24 IETF 126 Vienna
September 1–3 Global Digital Collaboration Conference 2026 Geneva
September 14–17 ISO/IEC JTC1/SC 17 Plenary Chengdu, China
October 19–21 FIDO Authenticate 2026 Carlsbad, CA
November 2 OIDF Workshop (prior to IIW Fall 2026) Mountain View
November 3–5 IIW Fall 2026 Mountain View
November 14–20 IETF 127 San Francisco
December 7–9 Gartner IAM US Las Vegas

OIDF Hybrid Workshop (April 27):

Registration is required to participate either in-person or virtually. The agenda will be published soon.

To add events to the 2026 calendar, contact mike.leszcz@oidf.org.


4. External Organisations & Liaisons

4.1 Ecosystem Update — Chile (CMF)

Mike Leszcz provided a brief update:

  • The Comisión para el Mercado Financiero (CMF) in Chile remains on track to go live in 2026.
  • Shared Signals adoption, originally scoped for Phase 1, has been deferred to Phase 2 (2027).
  • Chile is adopting FAPI 2 Final.
  • A call is scheduled for the following week with Mensate (implementation partner) and the CMF team to confirm their FAPI 2 profile and revised launch milestones.
  • Upon go-live, approximately 200 banks / financial institutions will be required to undergo the FAPI 2 self-certification process. The split between Phase 1 (2026) and Phase 2 (early 2027) will be confirmed at the next call.
  • OIDF has offered to engage Shared Signals co-chairs to support CMF's next steps in that area.

4.2 Member Reminders


5. Pull Requests

5.1 Open PRs

No open PRs requiring discussion at time of call.

5.2 PR #563 — BCP-195 / ChaCha20-Poly1305 (related to Issue #835)

  • Nat noted a syntax issue in the current draft: the referencing syntax used for BCP-195 is not working correctly with xml2rfc and will require a follow-up PR to fix.
  • Content-wise the PR is approved (Dima Postnikov and Dave Tonge have both approved).
  • Resolution: Proceed to merge the technical change as implied by Issue #835; Nat to raise a separate PR to fix the xml2rfc referencing syntax.
  • PR link: https://bitbucket.org/openid/fapi/pull-requests/563

6. Issues

6.1 Issue #744 — Certification Team Query: Refresh Tokens in Client Credentials Grant

  • Nat sent the proposed resolution to the mailing list before the call.
  • Proposed resolution: Issue a warning regarding refresh tokens being returned in the Client Credentials Grant.
  • Dima Postnikov noted that issuing a warning makes sense.
  • No objections raised on the call.
  • Resolution: Adopt the proposed resolution (warning) as discussed. Nat to confirm on the mailing list.
  • Issue link: https://github.com/openid/fapi/issues/744

6.2 Issue #842 — Approval to Launch Client Credentials Grant Certification

  • Nat sent the approval email to the mailing list just before the call (having omitted to send it previously).
  • Decision: If no objections are raised on the mailing list by end of week (27 March 2026), Nat will communicate to Joseph Heenan and the certification team that they may proceed with launching the FAPI 2 Client Credentials Grant certification.
  • No objections were raised on the call.
  • Issue link: https://github.com/openid/fapi/issues/842

6.3 Issue #845 — Publishing Updated Draft of FAPI CIBA

  • A dedicated call is needed to work through the outstanding CIBA items.
  • Nat suggested the week following this call, if Dave is available.
  • Action: Dave Tonge to confirm availability for a dedicated CIBA call and share a date with participants.
  • Issue link: https://github.com/openid/fapi/issues/845

6.4 Issue #778 — FAPI 1 ISO/IEC 25791-1 Review Comments: Key Lengths

  • A PR exists and is ready to merge.
  • Nat noted a broader observation: current recommendations suggest RSA keys of 3,072 bits or more, and ECC keys of 256 bits or more. Ecosystem operators should consider this as a migration planning target.
  • BCP-195 may be updated in line with these figures in the near future.
  • Resolution: Merge the existing PR. Nat to raise a follow-up PR for xml2rfc referencing syntax if needed.
  • Issue link: https://github.com/openid/fapi/issues/778

6.5 Issue #844 — FAPI Not Currently Compliant with CNSA 2.0

  • Filed on 16 March 2026 following discussion at the IETF OAuth Working Group.
  • CNSA 2.0 (Commercial National Security Algorithm Suite 2.0, published by the NSA) disallows SHA-256 in favour of SHA-384 or SHA-512 for certain use cases, which may mean FAPI cannot be used in environments mandating CNSA 2.0 compliance. PKCE currently requires SHA-256.
  • Filip Skokan presented this at the IETF OAuth WG; there is a related draft addressing additional hash algorithm support for PKCE.
  • Brian Campbell clarified that as he understood it, the CNSA prohibition on SHA-256 is not strictly a post-quantum concern in the way it was originally framed on this issue — the real points of contention in the OAuth WG were around hash algorithm negotiation mechanisms and metadata, and whether ecosystem-specific configuration would be sufficient rather than a formal signalling mechanism.
  • The group noted (consistent with last week's discussion) that:
    • There is no imminent technical danger from SHA-256 use in PKCE.
    • Addressing SHA-256 in isolation does not constitute a complete PQC response.
    • Any PQC transition must be considered holistically.
  • Nat clarified that CNSA 2.0 stands for "Commercial National Security Algorithm Suite 2.0" and appears related to post-quantum computing preparedness per its associated FAQ document.
  • No call for adoption of Filip's draft has been issued yet in the IETF OAuth WG; it may resurface.
  • Next steps:
    • Dave Tonge has left a comment on the issue noting the need for a broader FAPI position on PQC.
    • Invite Filip Skokan to a future call to present and explain the issue in detail.
    • Consider developing a brief FAPI policy statement on post-quantum cryptography to provide a considered response to ecosystem queries.
  • Issue link: https://github.com/openid/fapi/issues/844
  • Reference: NSA Cybersecurity Information Sheet — The Commercial National Security Algorithm Suite 2.0 and Quantum Computing FAQ

6.6 Issue #843 — OAuth Security BCP Addition

  • Joseph Heenan noted that an updated OAuth Security BCP (Best Current Practice) document is in progress, and FAPI should address each attack mentioned in that document in some way.
  • One attack — the private key exfiltration issue — is already addressed in FAPI.
  • The remaining new attacks require analysis.
  • Pedram and Tim are among the document's authors and have familiarity with FAPI.
  • Action: Dave Tonge to contact Pedram and Tim (OAuth Security BCP authors), request an analysis of newly added attacks against FAPI coverage, and invite them to present to the WG.
  • Dima Postnikov suggested inviting them to present to the FAPI WG call; Dave agreed.
  • Issue link: https://github.com/openid/fapi/issues/843

6.7 Issue #835 — §5.2 Network Layer Protections (ChaCha20-Poly1305 / BCP-195)

  • Robert Gallagher (Mastercard) confirmed that the implementation testing is progressing: two organisations have completed testing, a third is pending, and the cipher suite will move to production once complete.
  • PR #563 addresses this technically (see §5.2 above).
  • Resolution: Merge PR #563 once the xml2rfc syntax is fixed; issue can then be closed.
  • Issue link: https://github.com/openid/fapi/issues/835

6.8 Issue #727 — MCP Servers, Scope, and Rich Authorization Requests (RAR)

  • Bjorn Hjelm has opened a corresponding issue in the AI Identity Management Community Group GitHub repository, as requested by Nat.
  • Bjorn noted that he did not attend the AI/IAM Community Group meeting the previous week (the group meets every other week) but will raise it this week.
  • Decision: Keep the issue open in the FAPI repository to monitor the Community Group's conclusions. The issue may be recategorised.
  • Issue link: https://github.com/openid/fapi/issues/727

6.9 Issue #741 — Is nbf a Mandatory Requirement for Request Objects?

6.10 Issue #742 — Agent Payments Protocol (AP2) Impacts to FAPI

  • Dave Tonge noted that this is related to the MCP/agentic payments space (Issue #727).
  • Bjorn Hjelm provided the following update from the FIDO Alliance Payment Working Group call that week:
    • The FIDO Payment WG is focused on verifiable credentials, specifically including transaction information in VCs at issuance — referred to internally as DPC (Digital Payment Credentials).
    • Google offered to donate their AP2 work to FIDO at this week's call.
    • The AI/IAM Community Group is focused on defining taxonomy and use cases, not specifically on AP2.
  • Decision: Keep the issue open as a low-priority tracking item to monitor developments in the agentic payments space. Bjorn to add comments with the above update.
  • Issue link: https://github.com/openid/fapi/issues/742

6.11 Issue #839 — FAPI 2.0 OSCAL Profile

  • Action from prior meeting: Damien to develop specific FAPI-relevant examples for an OSCAL profile.
  • Dima Postnikov raised this at the Ecosystem Support Community Group — there was no immediate driver or need identified.
  • Actions: Dave Tonge to follow up with Damien on the FAPI-specific examples.
  • Issue link: https://github.com/openid/fapi/issues/839

6.12 Issue #733 — JARM Downgrade

  • The associated PR was declined. No response has been received from the issue reporter (Yaron).
  • Action: Dave Tonge to leave a note on the issue stating that if no response is received, the issue will be closed.
  • Issue link: https://github.com/openid/fapi/issues/733

6.13 Issue #838 — FAPI 2 Attacker Model: ISO/IEC 26083-2

  • Nat reviewed issues #837 and #838 relating to ISO/IEC 26083 editorial review comments.
  • Most comments are minor editorial items (e.g., missing spaces).
  • Nat noted that JTC 1 style pass is significantly more lenient than strict ISO style pass; full compliance with every ISO editorial comment is therefore not strictly required.
  • Decision: Acknowledge the review comments without necessarily implementing all of them. Dave Tonge to leave a note for Mark to that effect.
  • Issue link: https://github.com/openid/fapi/issues/838

6.14 Issue #837 — FAPI 2 Security Profile: ISO/IEC 26083-1

  • Same context as Issue #838 above.
  • Decision: Acknowledge editorial review comments; implement only those the team considers worthwhile. Editorial PRs may be raised as needed.
  • Issue link: https://github.com/openid/fapi/issues/837

7. Any Other Business

No items raised. Meeting closed.


8. Action Items

# Owner Action Due
1 Nat Sakimura Confirm Issue #744 resolution (refresh token warning) on mailing list By end of week
2 Nat Sakimura Communicate approval to Joseph Heenan / certification team for FAPI 2 Client Credentials Grant certification (Issue #842), if no mailing list objections By end of week (27 March 2026)
3 Dave Tonge Confirm availability and schedule dedicated CIBA call (Issue #845) ASAP
4 Nat Sakimura Raise follow-up PR to fix xml2rfc BCP referencing syntax (related to PR #563 / Issue #835) TBD
5 Dave Tonge Invite Filip Skokan to a future FAPI WG call to present and clarify CNSA 2.0 / SHA-256 issue (Issue #844) Next call if possible
6 Dave Tonge Draft / propose a FAPI position statement on post-quantum cryptography (Issue #844) TBD
7 Dave Tonge Contact Pedram and Tim (OAuth Security BCP authors) re: analysis of new attacks vs. FAPI coverage; invite to present (Issue #843) TBD
8 Bjorn Hjelm Raise Issue #727 (MCP Servers / RAR) at the AI/IAM Community Group meeting this week This week
9 Bjorn Hjelm Add comments to Issue #742 with FIDO Alliance Payment WG updates (AP2 / DPC / Google donation) This week
10 Dave Tonge Follow up with Damien on FAPI-specific OSCAL examples (Issue #839) TBD
11 Dave Tonge Leave note on Issue #733 (JARM Downgrade): close if no response from Yaron This week
12 Dave Tonge Leave note for Mark on Issues #837/#850: acknowledge ISO/IEC 26083 editorial comments without necessarily implementing all This week

9. Reference Links

Resource URL
Previous meeting notes (2026-03-18) https://github.com/openid/fapi/wiki/FAPI_Meeting_Notes_2026-03-18_Atlantic
OIDF Workshop April 27 registration https://openid.net/registration-open-for-openid-foundation-hybrid-workshop-on-mon-27th-april-2026/
iGov Implementer's Draft public review https://openid.net/public-review-period-for-proposed-implementers-draft-of-igov-profile-for-oauth-2/
Issue #744 — Refresh tokens in client credentials grant https://github.com/openid/fapi/issues/744
Issue #842 — Approval to launch client credentials certification https://github.com/openid/fapi/issues/842
Issue #845 — Publishing updated draft of FAPI CIBA https://github.com/openid/fapi/issues/845
Issue #778 — FAPI 1 ISO/IEC 25791-1 key length review comments https://github.com/openid/fapi/issues/778
Issue #844 — FAPI not compliant with CNSA 2.0 https://github.com/openid/fapi/issues/844
Issue #843 — OAuth Security BCP addition https://github.com/openid/fapi/issues/843
Issue #835 — §5.2 Network layer protections (ChaCha20-Poly1305) https://github.com/openid/fapi/issues/835
PR #563 — BCP-195 / ChaCha20-Poly1305 https://bitbucket.org/openid/fapi/pull-requests/563
Issue #727 — MCP servers, scope, and RAR https://github.com/openid/fapi/issues/727
Issue #741 — Is nbf mandatory for request objects? https://github.com/openid/fapi/issues/741
Issue #742 — Agent Payments Protocol (AP2) impacts https://github.com/openid/fapi/issues/742
Issue #839 — FAPI 2.0 OSCAL profile https://github.com/openid/fapi/issues/839
Issue #733 — JARM downgrade https://github.com/openid/fapi/issues/733
Issue #838 — FAPI 2 Attacker Model: ISO/IEC 26083-2 https://github.com/openid/fapi/issues/838
Issue #837 — FAPI 2 Security Profile: ISO/IEC 26083-1 https://github.com/openid/fapi/issues/837
NSA CNSA 2.0 and Quantum Computing FAQ NSA Cybersecurity Information Sheet
OIDF policies https://openid.net/policies

10. Next Meeting

Next FAPI WG Atlantic call: Wednesday, 1 April 2026 (same time)

Note: A dedicated CIBA call is also being scheduled — see Action Item #3.

Clone this wiki locally