-
Notifications
You must be signed in to change notification settings - Fork 0
FAPI_Meeting_Notes_2026 03 25_Atlantic
- Date: 2026-03-25 14:00 UTC
- Location: Zoom
| Name | Organization |
|---|---|
| Nat Sakimura (Chair) | NAT.Consulting |
| Dave Tonge (Co-Chair) | Moneyhub |
| Mike Leszcz | OIDF |
| Hideki Ikeda | Authlete |
| Matthew Murphy | Mastercard |
| Robert Gallagher | Mastercard |
| Peter Stanley | Open Banking Limited (OBL) |
| Bjorn Hjelm | Yubico |
| Kosuke Koiwai | KDDI |
| Dima Postnikov | Scytáles |
| Christopher Robbertse | Open Banking Limited (OBL) |
| Lukasz Jaromin | Raidiam |
| George Fletcher | Practical Identity |
| Brian Campbell | Ping Identity |
Mike Leszcz read the OpenID Foundation Note Well, covering:
- The Code of Conduct Policy
- The antitrust policy
- The requirement for a signed contribution agreement to participate in OpenID Foundation working groups
- The requirement for a signed participation agreement to participate in OpenID Foundation community groups
All reference policies are available at openid.net/policies.
The standard agenda posted in chat was adopted without objection.
Previous meeting notes (2026-03-18 Atlantic call) were published immediately before this call: https://github.com/openid/fapi/wiki/FAPI_Meeting_Notes_2026-03-18_Atlantic
Presented by Mike Leszcz (OIDF). No material updates from the prior week; events list reproduced below for the record.
| Date | Event | Location |
|---|---|---|
| March 23–26 | RSA Conference | San Francisco, CA |
| April 14 | OECD Working Party on Digital Security | Paris |
| April 22–23 | IAM Tech Day | São Paulo |
| April 27 | OIDF Hybrid Workshop (prior to IIW Spring 2026) | Mountain View |
| April 28–30 | IIW Spring 2026 | Mountain View |
| May 12–15 | ID4Africa | Abidjan |
| May 19–22 | EIC 2026 | Berlin |
| May 27–29 | OAuth Security Workshop (OSW) | Leipzig, Germany |
| June 2 | FIDO Authenticate APAC 2026 | Singapore |
| June 15–18 | Identiverse | Las Vegas |
| June 22–24 | DICE 2026 | Copenhagen |
| July 18–24 | IETF 126 | Vienna |
| September 1–3 | Global Digital Collaboration Conference 2026 | Geneva |
| September 14–17 | ISO/IEC JTC1/SC 17 Plenary | Chengdu, China |
| October 19–21 | FIDO Authenticate 2026 | Carlsbad, CA |
| November 2 | OIDF Workshop (prior to IIW Fall 2026) | Mountain View |
| November 3–5 | IIW Fall 2026 | Mountain View |
| November 14–20 | IETF 127 | San Francisco |
| December 7–9 | Gartner IAM US | Las Vegas |
OIDF Hybrid Workshop (April 27):
Registration is required to participate either in-person or virtually. The agenda will be published soon.
- Host: Cisco.
- Registration link: https://openid.net/registration-open-for-openid-foundation-hybrid-workshop-on-mon-27th-april-2026/
To add events to the 2026 calendar, contact mike.leszcz@oidf.org.
Mike Leszcz provided a brief update:
- The Comisión para el Mercado Financiero (CMF) in Chile remains on track to go live in 2026.
- Shared Signals adoption, originally scoped for Phase 1, has been deferred to Phase 2 (2027).
- Chile is adopting FAPI 2 Final.
- A call is scheduled for the following week with Mensate (implementation partner) and the CMF team to confirm their FAPI 2 profile and revised launch milestones.
- Upon go-live, approximately 200 banks / financial institutions will be required to undergo the FAPI 2 self-certification process. The split between Phase 1 (2026) and Phase 2 (early 2027) will be confirmed at the next call.
- OIDF has offered to engage Shared Signals co-chairs to support CMF's next steps in that area.
- OpenID Connect Relying Party Metadata Choices 1.0 Final Specification — member vote closes today (26 March 2026 at 12:00 PT). Quorum has been reached; additional votes appreciated. An abstain vote counts towards quorum.
- iGov Profile for OAuth 2.0 Implementer's Draft — public review concludes; member voting opens Sunday, 29 March 2026. See: https://openid.net/public-review-period-for-proposed-implementers-draft-of-igov-profile-for-oauth-2/
No open PRs requiring discussion at time of call.
5.2 PR #563 — BCP-195 / ChaCha20-Poly1305 (related to Issue #835)
- Nat noted a syntax issue in the current draft: the referencing syntax used for BCP-195 is not working correctly with xml2rfc and will require a follow-up PR to fix.
- Content-wise the PR is approved (Dima Postnikov and Dave Tonge have both approved).
- Resolution: Proceed to merge the technical change as implied by Issue #835; Nat to raise a separate PR to fix the xml2rfc referencing syntax.
- PR link: https://bitbucket.org/openid/fapi/pull-requests/563
6.1 Issue #744 — Certification Team Query: Refresh Tokens in Client Credentials Grant
- Nat sent the proposed resolution to the mailing list before the call.
- Proposed resolution: Issue a warning regarding refresh tokens being returned in the Client Credentials Grant.
- Dima Postnikov noted that issuing a warning makes sense.
- No objections raised on the call.
- Resolution: Adopt the proposed resolution (warning) as discussed. Nat to confirm on the mailing list.
- Issue link: https://github.com/openid/fapi/issues/744
6.2 Issue #842 — Approval to Launch Client Credentials Grant Certification
- Nat sent the approval email to the mailing list just before the call (having omitted to send it previously).
- Decision: If no objections are raised on the mailing list by end of week (27 March 2026), Nat will communicate to Joseph Heenan and the certification team that they may proceed with launching the FAPI 2 Client Credentials Grant certification.
- No objections were raised on the call.
- Issue link: https://github.com/openid/fapi/issues/842
6.3 Issue #845 — Publishing Updated Draft of FAPI CIBA
- A dedicated call is needed to work through the outstanding CIBA items.
- Nat suggested the week following this call, if Dave is available.
- Action: Dave Tonge to confirm availability for a dedicated CIBA call and share a date with participants.
- Issue link: https://github.com/openid/fapi/issues/845
6.4 Issue #778 — FAPI 1 ISO/IEC 25791-1 Review Comments: Key Lengths
- A PR exists and is ready to merge.
- Nat noted a broader observation: current recommendations suggest RSA keys of 3,072 bits or more, and ECC keys of 256 bits or more. Ecosystem operators should consider this as a migration planning target.
- BCP-195 may be updated in line with these figures in the near future.
- Resolution: Merge the existing PR. Nat to raise a follow-up PR for xml2rfc referencing syntax if needed.
- Issue link: https://github.com/openid/fapi/issues/778
6.5 Issue #844 — FAPI Not Currently Compliant with CNSA 2.0
- Filed on 16 March 2026 following discussion at the IETF OAuth Working Group.
- CNSA 2.0 (Commercial National Security Algorithm Suite 2.0, published by the NSA) disallows SHA-256 in favour of SHA-384 or SHA-512 for certain use cases, which may mean FAPI cannot be used in environments mandating CNSA 2.0 compliance. PKCE currently requires SHA-256.
- Filip Skokan presented this at the IETF OAuth WG; there is a related draft addressing additional hash algorithm support for PKCE.
- Brian Campbell clarified that as he understood it, the CNSA prohibition on SHA-256 is not strictly a post-quantum concern in the way it was originally framed on this issue — the real points of contention in the OAuth WG were around hash algorithm negotiation mechanisms and metadata, and whether ecosystem-specific configuration would be sufficient rather than a formal signalling mechanism.
- The group noted (consistent with last week's discussion) that:
- There is no imminent technical danger from SHA-256 use in PKCE.
- Addressing SHA-256 in isolation does not constitute a complete PQC response.
- Any PQC transition must be considered holistically.
- Nat clarified that CNSA 2.0 stands for "Commercial National Security Algorithm Suite 2.0" and appears related to post-quantum computing preparedness per its associated FAQ document.
- No call for adoption of Filip's draft has been issued yet in the IETF OAuth WG; it may resurface.
-
Next steps:
- Dave Tonge has left a comment on the issue noting the need for a broader FAPI position on PQC.
- Invite Filip Skokan to a future call to present and explain the issue in detail.
- Consider developing a brief FAPI policy statement on post-quantum cryptography to provide a considered response to ecosystem queries.
- Issue link: https://github.com/openid/fapi/issues/844
- Reference: NSA Cybersecurity Information Sheet — The Commercial National Security Algorithm Suite 2.0 and Quantum Computing FAQ
6.6 Issue #843 — OAuth Security BCP Addition
- Joseph Heenan noted that an updated OAuth Security BCP (Best Current Practice) document is in progress, and FAPI should address each attack mentioned in that document in some way.
- One attack — the private key exfiltration issue — is already addressed in FAPI.
- The remaining new attacks require analysis.
- Pedram and Tim are among the document's authors and have familiarity with FAPI.
- Action: Dave Tonge to contact Pedram and Tim (OAuth Security BCP authors), request an analysis of newly added attacks against FAPI coverage, and invite them to present to the WG.
- Dima Postnikov suggested inviting them to present to the FAPI WG call; Dave agreed.
- Issue link: https://github.com/openid/fapi/issues/843
6.7 Issue #835 — §5.2 Network Layer Protections (ChaCha20-Poly1305 / BCP-195)
- Robert Gallagher (Mastercard) confirmed that the implementation testing is progressing: two organisations have completed testing, a third is pending, and the cipher suite will move to production once complete.
- PR #563 addresses this technically (see §5.2 above).
- Resolution: Merge PR #563 once the xml2rfc syntax is fixed; issue can then be closed.
- Issue link: https://github.com/openid/fapi/issues/835
6.8 Issue #727 — MCP Servers, Scope, and Rich Authorization Requests (RAR)
- Bjorn Hjelm has opened a corresponding issue in the AI Identity Management Community Group GitHub repository, as requested by Nat.
- Bjorn noted that he did not attend the AI/IAM Community Group meeting the previous week (the group meets every other week) but will raise it this week.
- Decision: Keep the issue open in the FAPI repository to monitor the Community Group's conclusions. The issue may be recategorised.
- Issue link: https://github.com/openid/fapi/issues/727
6.9 Issue #741 — Is nbf a Mandatory Requirement for Request Objects?
- Dima Postnikov indicated he would double-check the status.
- Resolution: Leave open pending update.
- Issue link: https://github.com/openid/fapi/issues/741
6.10 Issue #742 — Agent Payments Protocol (AP2) Impacts to FAPI
- Dave Tonge noted that this is related to the MCP/agentic payments space (Issue #727).
- Bjorn Hjelm provided the following update from the FIDO Alliance Payment Working Group call that week:
- The FIDO Payment WG is focused on verifiable credentials, specifically including transaction information in VCs at issuance — referred to internally as DPC (Digital Payment Credentials).
- Google offered to donate their AP2 work to FIDO at this week's call.
- The AI/IAM Community Group is focused on defining taxonomy and use cases, not specifically on AP2.
- Decision: Keep the issue open as a low-priority tracking item to monitor developments in the agentic payments space. Bjorn to add comments with the above update.
- Issue link: https://github.com/openid/fapi/issues/742
6.11 Issue #839 — FAPI 2.0 OSCAL Profile
- Action from prior meeting: Damien to develop specific FAPI-relevant examples for an OSCAL profile.
- Dima Postnikov raised this at the Ecosystem Support Community Group — there was no immediate driver or need identified.
- Actions: Dave Tonge to follow up with Damien on the FAPI-specific examples.
- Issue link: https://github.com/openid/fapi/issues/839
6.12 Issue #733 — JARM Downgrade
- The associated PR was declined. No response has been received from the issue reporter (Yaron).
- Action: Dave Tonge to leave a note on the issue stating that if no response is received, the issue will be closed.
- Issue link: https://github.com/openid/fapi/issues/733
6.13 Issue #838 — FAPI 2 Attacker Model: ISO/IEC 26083-2
- Nat reviewed issues #837 and #838 relating to ISO/IEC 26083 editorial review comments.
- Most comments are minor editorial items (e.g., missing spaces).
- Nat noted that JTC 1 style pass is significantly more lenient than strict ISO style pass; full compliance with every ISO editorial comment is therefore not strictly required.
- Decision: Acknowledge the review comments without necessarily implementing all of them. Dave Tonge to leave a note for Mark to that effect.
- Issue link: https://github.com/openid/fapi/issues/838
6.14 Issue #837 — FAPI 2 Security Profile: ISO/IEC 26083-1
- Same context as Issue #838 above.
- Decision: Acknowledge editorial review comments; implement only those the team considers worthwhile. Editorial PRs may be raised as needed.
- Issue link: https://github.com/openid/fapi/issues/837
No items raised. Meeting closed.
| # | Owner | Action | Due |
|---|---|---|---|
| 1 | Nat Sakimura | Confirm Issue #744 resolution (refresh token warning) on mailing list | By end of week |
| 2 | Nat Sakimura | Communicate approval to Joseph Heenan / certification team for FAPI 2 Client Credentials Grant certification (Issue #842), if no mailing list objections | By end of week (27 March 2026) |
| 3 | Dave Tonge | Confirm availability and schedule dedicated CIBA call (Issue #845) | ASAP |
| 4 | Nat Sakimura | Raise follow-up PR to fix xml2rfc BCP referencing syntax (related to PR #563 / Issue #835) | TBD |
| 5 | Dave Tonge | Invite Filip Skokan to a future FAPI WG call to present and clarify CNSA 2.0 / SHA-256 issue (Issue #844) | Next call if possible |
| 6 | Dave Tonge | Draft / propose a FAPI position statement on post-quantum cryptography (Issue #844) | TBD |
| 7 | Dave Tonge | Contact Pedram and Tim (OAuth Security BCP authors) re: analysis of new attacks vs. FAPI coverage; invite to present (Issue #843) | TBD |
| 8 | Bjorn Hjelm | Raise Issue #727 (MCP Servers / RAR) at the AI/IAM Community Group meeting this week | This week |
| 9 | Bjorn Hjelm | Add comments to Issue #742 with FIDO Alliance Payment WG updates (AP2 / DPC / Google donation) | This week |
| 10 | Dave Tonge | Follow up with Damien on FAPI-specific OSCAL examples (Issue #839) | TBD |
| 11 | Dave Tonge | Leave note on Issue #733 (JARM Downgrade): close if no response from Yaron | This week |
| 12 | Dave Tonge | Leave note for Mark on Issues #837/#850: acknowledge ISO/IEC 26083 editorial comments without necessarily implementing all | This week |
Next FAPI WG Atlantic call: Wednesday, 1 April 2026 (same time)
Note: A dedicated CIBA call is also being scheduled — see Action Item #3.