-
Notifications
You must be signed in to change notification settings - Fork 0
FAPI_Meeting_Notes_2026 06 17_Atlantic
Date: 2026-06-17
Time: 14:00 UTC
Chair: Nat Sakimura (NAT.Consulting / Authlete)
Co-Chair: Dave Tonge (Moneyhub)
Notes prepared by: Claude / OIDF Secretariat
| Name | Affiliation |
|---|---|
| Nat Sakimura | NAT.Consulting / Authlete (Chair) |
| Dave Tonge | Moneyhub (Co-Chair) |
| Filip Skokan | Independent |
| Christopher Robbertse | Open Banking Limited (OBL) |
| Kosuke Koiwai | KDDI |
| Matthew Murphy | Mastercard |
| Bjorn Hjelm | Yubico |
| Hideki Ikeda | Authlete |
Apologies / Absent: Mike Leszcz (conflict), Joseph Heenan (absent), Peter Stanley (absent)
The OIDF Note Well applies to all contributions made during this call. Participants are reminded that all contributions are subject to the OpenID Foundation IPR Policy.
The standing agenda was circulated by Nat Sakimura via the meeting reminder approximately 30 minutes before the call and also posted to the chat window:
- Roll Call (Nat)
- Adoption of Agenda (Nat)
- Events (Mike L.)
- External Orgs & Liaisons (Mike L.)
- PRs (Dave)
- Issues (Dave)
- AOB (Nat)
Nat noted that there had been active mailing-list discussion around CIBA since the previous week and indicated this could be touched on under Issues. The agenda was adopted as proposed with no further additions.
Mike Leszcz sent his regrets and was not present. Nat reported there was nothing materially new to relay on his behalf.
Nat also noted that Joseph Heenan was expected to provide an update on his visit with Open Finance Brazil earlier in the week, but as Joseph was absent, no update was available.
No other events were raised by attendees.
No substantive updates were raised by Nat or by any attendees.
No other liaison updates were noted.
Dave confirmed there are no new PRs. The only outstanding item is one long-standing stale PR in the Bitbucket repository.
Dave and Nat discussed how best to handle it ahead of the planned Bitbucket-to-GitHub repository migration. Nat proposed the following approach:
- Accept the stale PR as-is.
- Immediately address any remaining editorial concern — specifically that the PR text contains normative language ("must" or similar requirements language) that is inappropriate in a notes context — by rewording it.
- This would allow the PR queue to be cleared before migration.
Dave agreed. Nat indicated he would work on this the following day.
Reference: FAPI Bitbucket Pull Requests
7.1 Issue #648 — Define Requirements for OpenAPI / FAPI Security Scheme
Dave reported there had been recent activity on this issue. Anoop has taken ownership of it, having been assigned approximately five days prior (i.e. the previous Friday's Pacific call). Nat confirmed there have been no further updates since the assignment — only three business days had elapsed.
No action required at this time; issue is being progressed by Anoop.
Reference: Issue #648
7.2 Issue #848 — How Do We Handle FAPI 1 private_key_jwt aud Changes in Certification Tools?
Dave introduced this issue, created by Joseph Heenan. It concerns how the certification tooling should handle private_key_jwt audience (aud) validation requirements under FAPI 1, where the audience value is underspecified and implementations vary.
Nat noted there had been extensive mailing-list discussion between Peter Stanley and Joseph Heenan in the week preceding this call. However, as both Joseph and Peter are absent, Nat proposed punting the substantive discussion to the following week's call.
Dave agreed and indicated he would leave a comment on the issue noting that ecosystem feedback would be valuable — particularly from implementers who are currently using FAPI 1, as this issue most directly impacts them.
Reference: Issue #848
Note: Issue #714, flagged in the Bitbucket tracker as related to #848, was briefly mentioned. Dave indicated it did not need a separate review at this time given the relationship.
7.3 Issue #229 — FAPI CIBA and ID Tokens
Dave reported that Peter Stanley had left a note on this issue in the previous week. The issue originally raised the question of whether FAPI CIBA should be modified to operate without requiring OpenID Connect ID tokens.
Dave summarised the current position:
- The working group had previously proposed closing this as "won't fix".
- The rationale is that reworking FAPI CIBA to remove the dependency on OpenID Connect / ID tokens would represent a disproportionate effort with no clear demand from the ecosystem.
- Peter's comment acknowledged that the ACR claim can be carried in the ID token, which addresses the concern about annual attestation requirements in some jurisdictions.
- FAPI CIBA is not widely deployed, which further supports the won't-fix disposition.
Dave confirmed that marking it "won't fix" does not change the existing specification; it simply records the working group's decision not to pursue this particular change.
No objections were raised. The issue is expected to be formally closed as won't fix.
Reference: Issue #229
Nat raised the broader concern that many open issues in the tracker are now stale or irrelevant, particularly in the context of the Bitbucket-to-GitHub migration. He suggested the chairs dedicate time outside of the regular call to triage old issues and close those that no longer require action.
Dave agreed this would be a better use of time than going through them one-by-one on the call. He took an action to review and close stale issues assigned to him, and noted that Dima Postnikov might also assist with triage.
No additional items were raised.
| # | Action | Owner | Due |
|---|---|---|---|
| 1 | Accept stale PR and reword normative-language text before Bitbucket-to-GitHub migration | Nat Sakimura | 2026-06-18 |
| 2 | Leave a comment on Issue #848 requesting ecosystem feedback, especially from FAPI 1 implementers | Dave Tonge | Next call |
| 3 | Review and close stale Bitbucket issues assigned to co-chair ahead of migration | Dave Tonge | Rolling |
| 4 | Revisit Issue #848 (private_key_jwt aud) with Peter Stanley and Joseph Heenan present |
Nat / Dave | 2026-06-24 call |
| 5 | Confirm disposition of Issue #229 (FAPI CIBA / ID tokens) as "won't fix" and close | Dave Tonge | Next call |
| Resource | URL |
|---|---|
| FAPI Bitbucket Pull Requests | https://bitbucket.org/openid/fapi/pull-requests/ |
| Issue #648 — OpenAPI / FAPI Security Scheme | https://github.com/openid/fapi/issues/648 |
Issue #848 — FAPI 1 private_key_jwt aud
|
https://github.com/openid/fapi/issues/848 |
| Issue #229 — FAPI CIBA and ID Tokens | https://github.com/openid/fapi/issues/229 |
FAPI WG Atlantic Call — 2026-06-24, 14:00 UTC
Expected agenda items:
- Issue #848:
private_key_jwtauddiscussion (with Peter Stanley and Joseph Heenan) - Confirmation of Issue #229 closure
- Progress update on stale issue triage
These notes are draft and subject to adoption at the next meeting.