-
Notifications
You must be signed in to change notification settings - Fork 0
FAPI_Meeting_Notes_2026 06 03_Atlantic
Date: 2026-06-03 14:00 UTC
Location: Zoom
| Name | Organisation |
|---|---|
| Nat Sakimura | NAT Consulting (Chair) |
| Joseph Heenan | OIDF & Authlete |
| Christopher Robbertse | Open Banking Limited |
| Matthew Murphy | Mastercard |
| George Fletcher | Practical Identity |
| Kosuke Koiwai | KDDI |
| Bjorn Hjelm | Yubico |
Editorial note: Dave Tonge (Co-chair) and Mike Leszcz (OIDF) both sent regrets for this call. As a result, Nat Sakimura ran the meeting solo, and several standing-agenda items normally led by Dave or Mike (PRs, Issues) were covered briefly by Nat instead.
Roll call was taken via the chat window; attendees listed above identified themselves there.
Nat Sakimura presented the standing agenda, circulated approximately 90 minutes prior to the call:
1. Roll Call (Dave/Nat)
2. Adoption of Agenda (Dave/Nat)
3. Events (Mike L.)
4. External Orgs & Liaisons (Mike L.)
5. PRs (Dave)
6. Issues (Dave)
7. AOB (Nat)
No objections or additions were raised; the agenda was adopted as proposed.
Mike Leszcz sent regrets for this call. Nat Sakimura noted that FIDO's meeting was taking place in Singapore at the time of the call, and read through the events calendar that Mike had circulated. No additional events were raised by attendees.
The full 2026 events calendar shared in chat is reproduced below. Mike Leszcz (mike.leszcz@oidf.org) is the point of contact for additions to the calendar.
June 9-10 – Identity Week Europe - Amsterdam
June 15-18 - Identiverse - Las Vegas
June 22-24 - Dice 2026 - Copenhagen
July 18-24 - IETF 126 - Vienna
August 26 – OIDF-J OpenID Summit 2026 Special Edition - Tokyo
September 1-3 - Global Digital Collaboration Conference 2026 - Geneva
September 14-17 - ISO/IEC JTC1/SC 17 Plenary - Chengdu, China
October 19-21 - FIDO Authenticate 2026 - Carlsbad, CA
November 2 - OIDF Workshop prior to IIW Fall 2026 - Mountain View
November 3-5 - IIW Fall 2026 - Mountain View
November 14-20 - IETF 127 - San Francisco
December 7-9 - Gartner IAM US - Las Vegas
SAMA (Saudi Arabia): The KSA FAPI2 Security Profile has been received for publishing. The goal is to have KSA tests completed within a week to enable testing, with certification expected to open the week of June 15th.
Joseph Heenan provided a certification team update:
- The FAPI 2.0 Client Credentials Grant certification has launched, but no actual submissions have been received yet. Submissions are expected from Authlete, Mastercard, and Raidiam, though none have come in so far.
- The certification team had hoped to have a couple of certifications completed and published before making a more public announcement about the profile's availability. The availability has been announced on the working group mailing list, but not yet more broadly.
- Nat agreed it would be good to have a couple of certifications finished before going public more broadly.
Conference report-backs (EIC and OSW, past two weeks):
- Joseph Heenan gave a talk on FAPI at OSW. He noted growing interest from banks in applying FAPI2 to internal infrastructure (beyond the traditional open banking/open insurance use cases), driven by the need to better secure client credentials and access tokens for agentic AI systems operating within their environments. He attributed unusually strong attendance at his FAPI session (roughly half the conference) to this AI-driven interest.
- Nat Sakimura reported hearing renewed interest in Grant Management at EIC, including informal questions (in the hallway, not in a public session) about deployment status — though it was unclear whether this interest was at the ecosystem level or for internal/enterprise use. Nat speculated this could be connected to the broader AI delegation and authorization-delegation discussions prominent at EIC, but was not certain of the connection.
- Bjorn Hjelm asked where the renewed interest in Grant Management was coming from, and whether it remained tied to the original collective-consent use case. Joseph Heenan responded that the use case stems from implementers previously building custom APIs for managing grants, which the Grant Management specification replaces with a standardized approach; he confirmed the example ecosystem trying this is Chile.
- Joseph Heenan added that certification tests for Grant Management are currently being developed, prompted by interest from (he believed) Chile and/or Colombia — he was not fully certain which. He had reviewed the issue list and spec status a few weeks prior and found no open issues and no work done since the last implementer's draft was published.
- Joseph Heenan flagged a naming/numbering inconsistency: the specification was originally published as the first implementer's draft of "FAPI Grant Management," then renamed to "OAuth Grant Management." The first implementer's draft under the new name was subsequently announced as the second implementer's draft, which is technically accurate given the lineage but has caused some confusion. He raised the question of whether anything should be done to clarify this now.
Dave Tonge sent regrets. Nat Sakimura briefly reviewed the PR list and found nothing new requiring discussion, noting PR #529 specifically as one to keep open. No objections were raised to carrying items forward.
With Dave Tonge absent, Nat Sakimura worked through the open issues list directly: https://github.com/openid/fapi/issues?q=is%3Aissue%20state%3Aopen
Filtered list: https://github.com/openid/fapi/issues?q=is%3Aissue%20state%3Aopen%20label%3A%22component%3A%20Grant%20Management%22
Issue #847 — Discussed in connection with the renewed Grant Management interest above (see Section 4). No action items currently available; left open pending further developments.
Issue #457 — Create JSON schema for Grant Management specification. No objections to closing were received, and Nat closed the issue.
Issue #420 — Multi-party consents. Extended discussion:
- The issue proposes using a CIBA-style (asynchronous authorization) approach to collect multiple consent approvals, rather than the CIBA protocol itself. Joseph Heenan confirmed this reading.
- Joseph Heenan recalled that this pattern shows up in UK Open Banking standards for business payments requiring more than one approver (e.g. payments above a threshold requiring two levels of approval), though he could not recall the mechanics precisely. His understanding is that the initial payment is initiated via standard OAuth/FAPI, but the additional approval steps use a separate proprietary mechanism, with a polling endpoint to check approval status — though he flagged he was not fully certain of the details.
- Joseph Heenan also noted that a similar dual-consent requirement comes up in Brazil for joint accounts requiring dual consent for data sharing, again believing this is not handled at the OAuth layer, but without certainty on the details.
- Nat Sakimura asked Christopher Robbertse if he was familiar with the current status of the UK mechanism. Christopher said he was not certain of the current status and would follow up with a colleague, Pete, who works on a related project with Raidiam and could advise further.
- Nat speculated the issue might also have some relationship to Grant Management, particularly for recursive consent scenarios, but was not confident in this connection.
- Action: Nat will ping Dima Postnikov (issue assignee) regarding next steps. Christopher Robbertse to follow up with Pete (at Open Banking Limited/Raidiam context) on the current status of the UK multi-approver mechanism. Issue left open.
Nat noted that most CIBA issues had already been addressed in a session with Dave a couple of weeks prior, and the group skipped this component for today's call.
Filtered list: https://github.com/openid/fapi/issues?q=is%3Aissue%20state%3Aopen%20label%3A%22component%3A%20HTTP%20Signing%22
Nat noted he is not deeply familiar with HTTP Signing topics personally but has been hearing increasing discussion of the topic recently, and asked attendees to review the open items. Most issues in this component had already been addressed in prior weeks; the one outstanding item flagged was:
Issue #706 — Signature-Req and Signature-Input-Req are... — Nat observed there has been substantial discussion between Justin (Richer) and Taka, and it appears a conclusion has been reached; Nat needs to verify whether that conclusion has actually been applied to the spec text.
- Action: Nat to verify whether the Justin/Taka resolution on Issue #706 has been applied to the document.
- FAPI 2 issues were noted as mostly addressed already, having been acted upon during the prior month's call.
- A number of issues remain outstanding under Implementation & Deployment Advice. Nat noted that, with Dave currently very busy, the working group needs additional editors for this document to make further progress, and asked for volunteers. No one volunteered on the call.
- Action: Nat to send a request to the mailing list for additional editors on the Implementation & Deployment Advice document, after first consulting with Dave Tonge.
Editorial note: Joseph Heenan needed to leave the call at the half-hour mark for another commitment. The HTTP Signing and Implementation & Deployment Advice discussions that follow in the transcript occurred after Joseph had dropped off the call.
Nat Sakimura asked if there was anything further to discuss. No additional business was raised. Nat proposed closing the call to allow time to continue reviewing issues independently.
| # | Action | Owner | Notes |
|---|---|---|---|
| 1 | Follow up with Pete (Raidiam-related project) on the current status of the UK multi-party/dual-consent mechanism for business payments | Christopher Robbertse | Relates to Issue #420 |
| 2 | Ping Dima Postnikov regarding Issue #420 (Multi-party consents), as he is the assigned owner | Nat Sakimura | |
| 3 | Verify whether the Justin Richer / Taka discussion resolution has been applied to Issue #706 (HTTP Signing) | Nat Sakimura | |
| 4 | Send a request to the mailing list for additional editors on the Implementation & Deployment Advice document, after consulting with Dave Tonge | Nat Sakimura |
| Reference | URL |
|---|---|
| Open/new issues (all) | https://github.com/openid/fapi/issues?q=is%3Aissue%20state%3Aopen |
| Grant Management issues | https://github.com/openid/fapi/issues?q=is%3Aissue%20state%3Aopen%20label%3A%22component%3A%20Grant%20Management%22 |
| Issue #457 — JSON schema for Grant Management | https://github.com/openid/fapi/issues/457 |
| Issue #420 — Multi-party consents | https://github.com/openid/fapi/issues/420 |
| HTTP Signing issues | https://github.com/openid/fapi/issues?q=is%3Aissue%20state%3Aopen%20label%3A%22component%3A%20HTTP%20Signing%22 |
| Issue #706 — Signature-Req and Signature-Input-Req | https://github.com/openid/fapi/issues/706 |
| Implementation & Deployment Advice issues | https://github.com/openid/fapi/issues?q=is%3Aissue%20state%3Aopen%20label%3A%22component%3A%20Implementation%20%26%20Deployment%20Advice%22 |
FAPI WG Atlantic call — June 10, 2026 (standing weekly cadence).