-
Notifications
You must be signed in to change notification settings - Fork 0
FAPI_Meeting_Notes_2026 04 22_Atlantic
Date: Wednesday, 22 April 2026
Time: 14:00 UTC
Chair: Nat Sakimura (Dave Tonge absent)
All participants are reminded that OIDF intellectual property rules apply to this meeting.
Quorum was achieved.
| Name | Organization |
|---|---|
| Nat Sakimura | OIDF (Chair) |
| Hideki Ikeda | Authlete |
| Matthew Murphy | Mastercard |
| Robert Gallagher | Mastercard |
| Imran Ulghar | Open Banking Limited (OBL) |
| Peter Stanley | Open Banking Limited (OBL) |
| Christopher Robbertse | Open Banking Limited (OBL) |
| Dima Postnikov | (Individual) |
| Lukasz Jaromin | Raidiam |
| George Fletcher | Practical Identity |
| Craig Borysowich | IMedge (CA) |
| Filip Skokan | Okta |
| Bjorn Hjelm | Yubico |
| Joseph Heenan | OIDF / Authlete |
| Gail Hodges | OIDF |
- Roll Call
- Adoption of Agenda
- Events (standing in for Mike Leszcz)
- External Organisations & Liaisons
- PRs
- Issues
- AOB
The agenda was adopted with one addition: Imran Ulghar raised an item regarding the Anthropic MCP (Model Context Protocol) security incident, to be taken after Events.
Presented by Nat Sakimura, standing in for Mike Leszcz who was unable to attend.
Nat drew participants' attention to the following upcoming events. He noted that in-person registration for the OIDF Workshop on 27 April closes today, 22 April.
| Date | Event | Location |
|---|---|---|
| 22–23 April 2026 | IAM Tech Day | São Paulo, Brazil |
| 27 April 2026 | OIDF Workshop (prior to IIW Spring 2026) | Mountain View, CA |
| 28–30 April 2026 | IIW Spring 2026 | Mountain View, CA |
| 12–15 May 2026 | ID4Africa | Abidjan, Côte d'Ivoire |
| 19–22 May 2026 | EIC 2026 | Berlin, Germany |
| 27–29 May 2026 | OAuth Security Workshop (OSW) | Leipzig, Germany |
| 2 June 2026 | FIDO Authenticate APAC 2026 | Singapore |
| 9–10 June 2026 | Identity Week Europe | Amsterdam, Netherlands |
| 15–18 June 2026 | Identiverse | Las Vegas, NV |
| 22–24 June 2026 | Dice 2026 | Copenhagen, Denmark |
| 18–24 July 2026 | IETF 126 | Vienna, Austria |
| 26 August 2026 | OIDF-J OpenID Summit 2026 Special Edition | Tokyo, Japan |
| 1–3 September 2026 | Global Digital Collaboration Conference 2026 | Geneva, Switzerland |
| 14–17 September 2026 | ISO/IEC JTC1/SC 17 Plenary | Chengdu, China |
| 19–21 October 2026 | FIDO Authenticate 2026 | Carlsbad, CA |
| 2 November 2026 | OIDF Workshop (prior to IIW Fall 2026) | Mountain View, CA |
| 3–5 November 2026 | IIW Fall 2026 | Mountain View, CA |
| 14–20 November 2026 | IETF 127 | San Francisco, CA |
| 7–9 December 2026 | Gartner IAM US | Las Vegas, NV |
| February 2027 | OIDF Conference | London, UK |
To submit 2026 events for the OIDF calendar, contact: mike.leszcz@oidf.org
- Peru: The regulator recently signed the Ecosystem Support Community Group Participation Agreement. Mike Leszcz and Domingos are supporting an ecosystem outreach workshop at the end of May.
Dima Postnikov noted that OIDF is planning a major conference in London in early February 2027, with a significant focus on ecosystems. A content committee has been formed. Details and agenda are still to come.
- OpenID Federation 1.1 Final Specifications: Voting opened Tuesday, 21 April 2026.
- OpenID Connect Advanced Syntax for Claims (ASC) 1.0 — Implementer's Draft: Public review period started Monday, 16 March 2026. Voting is scheduled to start Friday, 1 May 2026.
Raised by Imran Ulghar (OBL).
Imran brought to the group's attention a significant security threat involving Anthropic's Claude Mythos model, which became public in April 2026. Key points raised:
- The AI system identified a 17-year-old security vulnerability and, when directed by researchers to test whether it could escape a heavily restricted sandbox environment, successfully did so — autonomously chaining multiple attack vectors and exploiting a zero-day vulnerability to achieve this.
- The concern raised was that capable AI systems could autonomously discover novel zero-day vulnerabilities across widely deployed technical stacks, potentially including systems deployed FAPI.
- Imran suggested the group consider two potential responses:
- Examining whether FAPI 2.0 baseline, attacker model, and security profile remain robust against AI-augmented attack discovery.
- Preparing some form of advisory for FAPI implementers.
George Fletcher noted that the FAPI protocol itself has had a formal methods proof performed against it, covering defined attacker models, and that this should provide confidence at the protocol layer. However, he acknowledged that implementation vulnerabilities are a different matter and that having an AI model attempt to validate (or invalidate) the formal proof would be interesting.
Nat Sakimura observed that the formal methods proof rests on its own set of assumptions (e.g., that TLS is functioning correctly). If underlying components such as OS-level TLS libraries are compromised, those assumptions break. He also noted that the Foundation has previously been informed of implementation flaws in OpenID Connect and attempted to reach implementers for remediation before public disclosure, but that this process has not been formalised.
Dima Postnikov suggested that the Ecosystem Support Community Group could serve as a venue for broader cross-standards discussion of this topic, in addition to FAPI WG.
Resolution: Nat asked Dima to raise the issue within the Ecosystem Support Community Group. Dima agreed, and invited Imran to present the topic at an upcoming Community Group call. Imran accepted.
No active PRs were reported. Nat noted he would follow up with Joseph Heenan.
Issue #738 — Deprecation of FAPI 2 ID2 Tests
- Bitbucket: https://github.com/openid/fapi/issues/738
- Dima Postnikov reported that ConnectID (Australia) has confirmed they are comfortable with the FAPI 2 Implementer's Draft 2 (ID2) conformance tests being decommissioned. He will add a comment to the issue accordingly.
- Nat noted the group is still awaiting confirmation from the UAE ecosystem. Domingos has made the outreach but has not yet received a response.
- Lukasz Jaromin (Raidiam) offered to check whether Raidiam has additional pathways to the UAE to expedite confirmation.
Issue #648 — OpenAPI / FAPI Security Scheme
- Bitbucket: https://github.com/openid/fapi/issues/648
- Nat noted this issue is somewhat stalled, partly due to limited pushing from his side. He shared that there are interested parties and that he has an informal Slack channel for coordination; he has now invited Lukasz to it.
- Lukasz reported interest from an external contributor ("Clyde" / "Plaid") who has been following the issue and may be willing to contribute, though that party is not an OIDF member.
- Peter Stanley (OBL) noted that Christopher Robbertse (OBL) has been following this and will provide an update; he will also chase Chris directly.
- Action: Peter Stanley to follow up with Christopher Robbertse for an update. Topic to be revisited at a future session.
Issue #583 — OpenID Federation and FAPI
- Bitbucket: https://github.com/openid/fapi/issues/583
- Lukasz raised this issue, originally filed by Joseph Heenan approximately three years ago, which was last active in January 2026.
- The issue concerns how OpenID Federation should interact with FAPI, specifically the question of whether explicit (manual) client registration or automatic (federation-driven) client registration should be used when deploying FAPI with Federation.
- Joseph Heenan explained his original concern: from an interoperability standpoint, FAPI should say something normative about the registration approach. He noted that explicit registration via DCR (Dynamic Client Registration) retains a management access token enabling clearer lifecycle control, which could become particularly relevant in future post-quantum algorithm migration scenarios.
- Dima Postnikov noted there is ecosystem interest in this analysis, and suggested he and Lukasz review the gap between existing registration mechanisms and what Federation provides.
- Bjorn Hjelm confirmed his understanding: this is about substituting Federation for conventional client registration.
- Action: Lukasz Jaromin to coordinate with Dima Postnikov offline on a gap analysis for this issue.
- Peter Stanley asked for an update on a dedicated call for the CIBA issue, which had been promised in a previous session.
- Nat confirmed that Dave Tonge is responsible for organising this, but has been very busy. The plan is to use the existing Atlantic time slot for a dedicated CIBA session (not a separate call), subject to sufficient notice and pre-announcement.
- Peter Stanley confirmed he would watch the agenda for that item.
- Action: Nat Sakimura to communicate with Dave Tonge about scheduling the CIBA-focused session on the agenda with adequate notice.
Raised by Robert Gallagher (Mastercard); update provided by Joseph Heenan.
- Conformance Suite tracking issue: https://gitlab.com/openid/conformance-suite/-/work_items/1757
- A production deployment of the conformance suite is planned within the next one to two days. Once deployed, changes to the client credentials (machine-to-machine) certification tests will be live.
- Following deployment, a notification will be sent to the FAPI WG mailing list confirming that certification submissions can begin.
- Joseph shared his screen to demonstrate the existing FAPI 2 certification results page. The existing table covers the four combinations of client authentication method (MTLS / private key JWT) and sender-constraining mechanism (MTLS / DPoP) for the authorisation code flow, plus JAR/OpenID Connect variants not applicable to client credentials.
- The certification team's proposal is to add a new table at the bottom of the page for client credentials certifications, covering only the four client authentication × sender-constraining combinations (JAR/OpenID Connect columns are not relevant for this flow).
- Hideki Ikeda asked in chat whether conformance tests will also be updated for FAPI 1 and FAPI 2 errata; this was noted but not fully resolved in the session.
Raised by Peter Stanley (OBL) and Gail Hodges (OIDF); extended discussion.
- Peter Stanley sought clarity on what the planned FAPI 1 Errata 1 will contain, and how any changes flowing from underlying specifications (particularly RFC 7523bis regarding private key JWT audience restrictions) will interact with conformance tests.
- Nat Sakimura confirmed the current position: the changes will be published as FAPI 1 Errata 1 (not FAPI 1.1). The errata includes changes already reflected in Bitbucket PRs, and will be pushed through the OIDF publication tool before a working group last call is initiated.
- The errata is expected to include:
- Removal of specific deprecated algorithm/cipher references, replaced by reference to BCP 195 / the IANA registry.
Clarifications around iss/aud as strings vs. arrays.
-
Joseph Heenan raised two open questions:
- The change to private key JWT audience restrictions (driven by RFC 7523bis progress in the OAuth/JOSE working groups) is outside FAPI's direct control, since FAPI 1 links to OpenID Connect without a pinned errata version. This means any future Connect errata on this topic will be automatically absorbed by FAPI 1.
- It is unclear whether the conformance suite should maintain tests for the pre-errata behaviour, and for how long. This affects ecosystems such as Brazil and the UK that may need transition time.
- Filip Skokan clarified that, as written, FAPI 1 links to OpenID Connect (not a specific errata-fixed version), so any future Connect errata — including changes to private key JWT audience restrictions — will automatically flow through to FAPI 1. Whether this constitutes a breaking change depends on decisions made by the Connect Working Group regarding RFC 7523bis.
- Brian Campbell raised a concern about the principle of introducing a breaking change via an errata, and questioned how implementers would be expected to interpret such a change.
- Filip Skokan and Joseph Heenan noted that the certification team acts in accordance with the working group's decisions on how to treat errata updates in underlying specs, and whether to maintain parallel tests for pre- and post-errata behaviour. This is ultimately a working group decision, not a certification team decision.
- Joseph also noted that the TLS cipher changes in the errata are in practice two previously recommended ciphers have effectively been dropped from production use due to denial-of-service vulnerabilities, and will not be breaking for banks or authorization servers.
- Resolution: The group agreed that this warrants a dedicated, well-attended discussion session. Given that IIW conflicts with next week's call, this topic is to be added to the agenda for the session in two weeks' time (6 May 2026).
Raised by Gail Hodges (OIDF).
- Gail noted there are two outstanding publication tasks: (1) publishing the FAPI 1 and FAPI 2 errata through the OIDF spec publishing tool, and (2) separately preparing the ISO versions of those specs, which require manual edits.
- She asked whether a small group (Nat, Dima, Joseph) could remain on the line at the end of the call for a brief coordination discussion.
- This was agreed; the main call was closed and the small group remained.
| # | Action | Owner | Due |
|---|---|---|---|
| 1 | Raise Anthropic Mythos security risks in Ecosystem Support Community Group and invite Imran to present | Dima Postnikov | Next ESCG call |
| 2 | Follow up with UAE ecosystem regarding ID2 test decommissioning (Issue #738) | Lukasz Jaromin (via Raidiam channels) | Next call |
| 3 | Comment on Issue #738 confirming ConnectID approval of ID2 decommissioning | Dima Postnikov | By next call |
| 4 | Follow up with Christopher Robbertse for update on OpenAPI / FAPI security scheme work (Issue #648) | Peter Stanley | By next call |
| 5 | Coordinate offline on gap analysis for Issue #583 (OpenID Federation + FAPI registration) | Lukasz Jaromin + Dima Postnikov | TBD |
| 6 | Communicate with Dave Tonge to schedule a dedicated CIBA session on the Atlantic call agenda | Nat Sakimura | ASAP |
| 7 | Deploy updated conformance suite to production; notify mailing list when client credentials certifications can be submitted | Joseph Heenan | Within 1–2 days of 22 April |
| 8 | Add FAPI 1 Errata / breaking change / conformance test policy discussion to agenda for 6 May 2026 session | Nat Sakimura | By 6 May 2026 |
| 9 | Invite interested parties to OpenAPI–FAPI Slack coordination channel | Nat Sakimura | Ongoing |
| Resource | URL |
|---|---|
| Issue #738 — FAPI 2 ID2 Test Deprecation | https://github.com/openid/fapi/issues/738 |
| Issue #648 — OpenAPI / FAPI Security Scheme | https://github.com/openid/fapi/issues/648 |
| Issue #583 — OpenID Federation and FAPI | https://github.com/openid/fapi/issues/583 |
| Conformance Suite Work Item #1757 | https://gitlab.com/openid/conformance-suite/-/work_items/1757 |
| OIDF Workshop 27 April — Registration | https://openid.net/registration-open-for-openid-foundation-hybrid-workshop-on-mon-27th-april-2026/ |
| OpenID Federation 1.1 Final — Voting | https://openid.net/public-review-period-for-proposed-openid-federation-1-1-final-specifications/ |
| OpenID Connect ASC 1.0 — Public Review | https://openid.net/public-review-period-for-proposed-implementers-draft-of-openid-connect-advanced-syntax-for-claims-1-0/ |
FAPI WG Atlantic Call — 29 April 2026 (note: IIW Spring 2026 conflict; reduced attendance expected)
FAPI WG Atlantic Call — 6 May 2026 — FAPI 1 Errata / breaking change / conformance test policy discussion to be scheduled.