The OpenID Foundation in the United States is currently holding an Implementer’s Draft vote, open until February 10, on
“Financial API Part 1 — Read only security profile” 1.
Any member in the United States can vote using this link2.
Standards such as the UK’s Open Banking Standard and the U.S. Durable Data API specify the use of OAuth to protect APIs. In practice, however, as its title, “The OAuth Authorization Framework,” indicates, OAuth is a “framework,” and applying it in the real world requires “profiling”—precisely defining the values of individual options. By providing this kind of framework, OAuth can accommodate use cases ranging from those with relatively relaxed requirements to those demanding stronger security. Most OAuth implementations in circulation, however, are profiled for “relaxed” use cases and are unsuitable for use cases that require stronger security.
The OpenID Foundation therefore formed the “Financial API (FAPI) Work Group” last year and has been developing profiles for the financial sector. The specification has now reached the Implementers Draft stage.3 The document being put to a certification vote is “Part 1: Read Only Security Profile,” a proposed specification for the risk level associated with read-only access to financial data. A profile supporting write operations is also being drafted as Part 2.
Voting is open until February 10.
Casting a vote is unrelated to making an IPR Contribution, so you can vote with confidence.
If you are not yet a member, you can register from the registration page4.
To register, first log in with an OpenID you already have (Google, Yahoo!, etc.), and then proceed to payment of the membership fee.
Footnotes
- http://openid.net/specs/openid-financial-api-part-1.html
- https://openid.net/foundation/members/polls/106
- OpenID Foundation specifications advance through 3 stages: Draft → Implementers Draft → Final.
- https://openid.net/foundation/members/registration
Related posts

OpenAI Launches Sign in with ChatGPT (Based on OpenID Connect)
(Work in progress; last updated 2026-10-02 12:39 JST) On September 29, at DevDay 2026, OpenAI officially announced Sign in with ChatGPT (SIWC). I would like to…
【Announcement】Is That QR Code Safe? Threats and Countermeasures in Cross-Device Authentication and Authorization Flows【YouTube Live】
On August 22 (Thursday), starting at 20 hours, we will host a YouTube Live stream titled “Is That QR Code Safe? Threats and Countermeasures in Cross-Device…
Authlete Features for OAuth/OIDC Profiling: A Summary
As many of you may know, I serve as an outside director of Authlete Despite that, I had not kept up with the latest developments, so…
