-
Notifications
You must be signed in to change notification settings - Fork 0
FAPI_Meeting_Notes_2026 04 15_Atlantic
- Date: Wednesday, April 15, 2026
- Time: 14:00 UTC
| Name | Organization |
|---|---|
| Nat Sakimura (Chair) | NAT Consulting |
| Dave Tonge (Co-Chair) | Moneyhub |
| Joseph Heenan | OIDF / Authlete |
| Brian Campbell | Ping Identity |
| Robert Gallagher | Mastercard |
| Matthew Murphy | Mastercard |
| Mike Leszcz | OIDF |
| Hideki Ikeda | Authlete |
| Kosuke Koiwai | KDDI |
| George Fletcher | Practical Identity |
The chair presented the OpenID Foundation Note Well, covering antitrust policies, the Contribution Agreement, and the Participation Agreement.
Attendees were asked to enter their names in the chat. Roll call confirmed the participants listed above.
The agenda was adopted as circulated. No additions were proposed.
Agenda items:
- Note Well
- Roll Call
- Adoption of Agenda
- Events
- External Orgs & Liaisons
- PRs
- Issues - 7.1 Issues assigned to Dima - 7.2 FAPI 2 Security Profile Issues - 7.3 Other Issues
- AOB - 8.1 Co-chair changes
Mike Leszcz noted no material updates this week. He highlighted the upcoming OIDF Workshop prior to IIW Spring 2026 (April 27, Mountain View), urging attendees to register soon as the deadline closes approximately 7 days before the event. The registration link was posted in the chat.
The full events calendar shared in the chat is reproduced below:
| Date | Event | Location |
|---|---|---|
| April 14 | OECD Working Party on Digital Security | Paris |
| April 22–23 | IAM Tech Day | São Paulo |
| April 27 | OIDF Workshop prior to IIW Spring 2026 | Mountain View |
| April 28–30 | IIW Spring 2026 | Mountain View |
| May 12–15 | ID4Africa | Abidjan |
| May 19–22 | EIC 2026 | Berlin |
| May 27–29 | OAuth Security Workshop (OSW) | Leipzig, Germany |
| June 2 | FIDO Authenticate APAC 2026 | Singapore |
| June 9–10 | Identity Week Europe | Amsterdam |
| June 15–18 | Identiverse | Las Vegas |
| June 22–24 | DICE 2026 | Copenhagen |
| July 18–24 | IETF 126 | Vienna |
| August 26 | OIDF-J OpenID Summit 2026 Special Edition | Tokyo |
| September 1–3 | Global Digital Collaboration Conference 2026 | Geneva |
| September 14–17 | ISO/IEC JTC1/SC 17 Plenary | Chengdu, China |
| October 19–21 | FIDO Authenticate 2026 | Carlsbad, CA |
| November 2 | OIDF Workshop prior to IIW Fall 2026 | Mountain View |
| November 3–5 | IIW Fall 2026 | Mountain View |
| November 14–20 | IETF 127 | San Francisco |
| December 7–9 | Gartner IAM US | Las Vegas |
To add 2026 events to the calendar, contact: mike.leszcz@oidf.org
Mike Leszcz reported two ecosystem engagement updates:
Saudi Arabia (KSA) — FAPI2 KSA Profile: Mike and Joseph Dominguez held a call with the SAMA and Ozone teams to ensure alignment on the FAPI 2 KSA profile. The call was productive. SAMA has committed to making required updates. Once documented, those updates will inform the next steps for the FAPI2 KSA conformance test, which OIDF hopes to roll out within the next month.
Peru — Open Banking Outreach Workshop: OIDF is supporting Peru's open banking journey. Peru is hosting an ecosystem outreach workshop at the end of May (dates still fluid). OIDF will provide an OpenID Foundation overview, a deep dive into open banking/open data specifications, conformance and certification value, and a snapshot of ecosystem adoption of OpenID specifications. Details and a registration link will be shared once confirmed.
Colombia — Event Update (in response to Nat's question): The originally scheduled Colombia event dates have shifted. The current suggestion is to hold the event the week prior to Identiverse (week of June 8), following staff changes at the host organization. OIDF board member Authlete, in partnership with Capgemini, is hosting the event in Colombia for South American regulators, with a focus on OpenID specifications in open finance and open data. Joseph Heenan and Joseph Dominguez plan to attend in person. Confirmation of the date is still pending.
Dave Tonge confirmed there are currently no actionable PRs. The group moved directly to issues.
Issue #583 — Using OIDC Federation and FAPI Together
Assigned to Dima at the previous call. No movement reported. The group will await Dima's response this week or next.
Issue #743 — Some FAPI2 SP Clauses
Also assigned to Dima. Awaiting a draft PR for the next iteration. No further discussion at this time.
Issue #738 — Deprecation of FAPI2 ID2 Tests
Dima confirmed the ID2 tests are no longer used and can be decommissioned. The group noted that UAE's confirmation is still outstanding. Joseph Heenan will check with Domingos to confirm whether UAE is also comfortable with decommissioning the ID2 tests. Once confirmed, Joseph will comment on the issue and it can be closed.
- Action: Joseph Heenan to check UAE's position with Dominguez and comment on the issue.
Issue #839 — FAPI 2.0 OSCAL Profile
Awaiting input from Damian. No progress to report.
Issue #434 — Certification Team Query: Error Messages
This issue concerns the FAPI 2 Implementation and Deployment Advice document (link), which was last updated in March. The issue was opened in 2021 and has not yet been addressed in that document. Joseph Heenan confirmed that the relevant guidance is not currently present. Dave Tonge volunteered to assign the issue to himself as a placeholder pending further work, while acknowledging a current time constraint.
- Action: Dave Tonge to self-assign Issue #434 and revisit when bandwidth allows.
Issue #831 — Browser Swapping Attacks
No progress. Continues to be tracked; still awaiting IETF developments.
Issue #843 — OAuth Security BCP Addition
Dave Tonge emailed Tim and Pedram and will follow up to chase a response.
- Action: Dave Tonge to chase Tim and Pedram on Issue #843.
Issue #844 — FAPI Not Currently Compliant with CNSA 2.0
Dave raised the broader question of whether a policy statement on post-quantum cryptography is needed and whether this falls within FAPI WG's remit. Discussion:
- Nat noted that the original intent was to document that FAPI's current requirements cannot be successfully deployed on US government cloud infrastructure (FedRAMP) due to CNSA 2.0 constraints. He observed that the iGov Working Group has been adopting post-quantum algorithms into the iGov profile, which was accepted as final the previous week.
- Dave noted that post-quantum changes would primarily affect signing and encryption algorithms, and that FAPI 1 was also considered in this context. His personal preference as a member is to focus post-quantum work on FAPI 2 rather than FAPI 1, to incentivize ecosystem migration.
- Joseph Heenan agreed that, given ecosystems will need to change TLS versions and algorithms anyway, migrating to FAPI 2 concurrently would not add significant additional disruption. He recommended explicitly communicating to Brazil, UK, and other FAPI 1 ecosystems that post-quantum support is currently planned only for FAPI 2, to solicit their feedback.
- Conclusion: No immediate action required. Dave Tonge left a comment on the issue to that effect. Priority remains low unless strong demand emerges from working group members.
Issue #736 — FAPI Post-Quantum Cryptography
Linked to the discussion on Issue #844 above. The component label will be updated to reflect FAPI 2 (rather than FAPI 1). The group's position — that post-quantum support will be addressed in FAPI 2 rather than FAPI 1 — was confirmed. Dave Tonge noted FAPI 1 is nominally intended to reach final status.
- Action: Dave Tonge to update the component label on Issue #736 to FAPI 2.
Issue #744 — Certification Team Query: Refresh Tokens in Client Credentials Grant
The working group's earlier direction was that refresh token handling in Client Credentials Grant should generate a warning (rather than a failure) in the conformance suite. Joseph Heenan will open a separate conformance suite issue to implement this, link it to Issue #744, and close Issue #744 on that basis.
- Action: Joseph Heenan to open a conformance suite issue for the warning change and close Issue #744.
Issue #837 — FAPI 2 Security Profile ISO/IEC 26083-1
Nat indicated he would check with Mark Verstege (presumably at the FAPI Pacific call). No further action at this time.
- Action: Nat Sakimura to check with Mark Verstege roboy regarding Issue #837.
Issue #732 — Allow OAuth 2.0 Attestation-Based Client Authentication
Waiting on the relevant IETF draft. Brian Campbell clarified the draft has not yet reached Working Group Last Call and is likely still weeks to months away. The group will continue to monitor and wait for the IETF OAuth Working Group process to conclude.
Issue #555 — Tracking Implementers of FAPI 1.0 and FAPI 2.0
This is a tracking issue last updated in 2023. The group agreed to send an email to the mailing list asking implementers to update their status on the ticket.
- Action: Dave Tonge to send an email to the mailing list asking implementers to update Issue #555.
Nat Sakimura announced that Tony Nadaline has kindly agreed to step down as Co-Chair of the FAPI Working Group. The group was informed of this change.
Nat provided an update on the FAPI 1 Part 2 submission to the publication pipeline (GitHub PR: openid/publication#173), submitted around April 4th. Several automated checks failed:
- Abstract requirement: FAPI 1 documents do not include abstracts (consistent with existing published finals). Nat indicated this should be accepted as-is, since retroactively adding abstracts after publication would be inappropriate.
- Non-versioned HTML: The check failure related to a non-versioned HTML file was resolved by Joseph Heenan, who updated the PR to remove the unversioned file. This resolved most of the failures.
- Publication tooling: Joseph Heenan clarified he does not hold decision-making authority over the publication rules. He updated the tooling (which had become "cranky") to align with the rules as published on the OpenID website. If those rules need to change, the published rules should be updated so that everything remains consistent. Nat noted that the rules, as currently documented, were a record of the previous secretary's (Mike Jones) practice and had not been formally approved.
ISO/IEC JTC1 submission and alignment: Nat explained the intent to align FAPI documents with ISO Directives Part 2 for TC68 fast-track submission via JTC1 (the Joint Technical Committee of ISO and IEC). He noted that JTC1 rules are more relaxed than ISO proper — there is no strict 3-year cancellation deadline, though a 5-year revision cycle applies. He expressed a desire to complete the ISO submission process for both FAPI 1 and FAPI 2 promptly.
Brian Campbell's objection (recorded per his request): Brian Campbell formally objected to the characterization that the working group as a whole had agreed to or endorsed the ISO alignment effort. His objections, stated clearly for the record, were:
- He never signed on to targeting ISO/IEC submission as a working group goal.
- ISO compliance requirements were introduced late in the publication process, creating churn and problems in documentation that made the documents worse.
- He sees no value in the ISO submission effort, particularly given that the documents are freely available while ISO would publish them behind a paywall.
- The "we" framing used to describe past decisions overstates the level of working group consensus.
Nat acknowledged Brian's objection and stated it is recorded in the meeting notes.
NOTE: The claim "ISO compliance requirements were introduced late" is factually incorrect. It was unaniously approved on 2016-06-06 FAPI meeting as recorded in the meeting notes. The very first published draft (December, 2016) was already aligned to ISO Directive Part 2.
Robert Gallagher asked for an update on conformance testing for the Client Credentials Grant and specifically on finding a third tester. Joseph Heenan reported:
-
A third set of tests on the Client Credentials Grant has been completed (the third implementation was a development system from Raidiam, likely from Brazil).
-
The tests are considered ready to launch for certification.
-
Joseph will verify that the updated version has been deployed to the production conformance system and that the certification display page work is complete. He will follow up and confirm.
-
Action: Joseph Heenan to verify production deployment of FAPI 2 Client Credentials Grant conformance tests and confirm launch readiness; notify the working group once live.
| # | Action | Owner | Due |
|---|---|---|---|
| 1 | Check UAE's position on decommissioning FAPI2 ID2 tests (Issue #738); comment on issue when confirmed | Joseph Heenan | Next call |
| 2 | Self-assign Issue #434 (Error Messages / Implementation Advice) | Dave Tonge | Immediate |
| 3 | Chase Tim and Pedram on Issue #843 (OAuth Security BCP Addition) | Dave Tonge | This week |
| 4 | Update component label on Issue #736 to FAPI 2 | Dave Tonge | Immediate |
| 5 | Open conformance suite issue for refresh token warning change; close Issue #744 | Joseph Heenan | Next call |
| 6 | Check with Mark Proboy regarding Issue #837 (ISO/IEC 26083-1) | Nat Sakimura | FAPI Pacific call |
| 7 | Send email to mailing list asking implementers to update Issue #555 | Dave Tonge | This week |
| 8 | Verify production deployment of FAPI 2 Client Credentials Grant conformance tests; notify WG when live | Joseph Heenan | ASAP |
The next FAPI WG Atlantic call will be held on Wednesday, April 22, 2026 at the usual time.