The OpenID Foundation in the United States is currently holding an Implementer’s Draft vote, open until February 10, on
“Financial API Part 1 — Read only security profile” 1.
Any member in the United States can vote using this link2.
Standards such as the UK’s Open Banking Standard and the U.S. Durable Data API specify the use of OAuth to protect APIs. In practice, however, as its title, “The OAuth Authorization Framework,” indicates, OAuth is a “framework,” and applying it in the real world requires “profiling”—precisely defining the values of individual options. By providing this kind of framework, OAuth can accommodate use cases ranging from those with relatively relaxed requirements to those demanding stronger security. Most OAuth implementations in circulation, however, are profiled for “relaxed” use cases and are unsuitable for use cases that require stronger security.
The OpenID Foundation therefore formed the “Financial API (FAPI) Work Group” last year and has been developing profiles for the financial sector. The specification has now reached the Implementers Draft stage.3 The document being put to a certification vote is “Part 1: Read Only Security Profile,” a proposed specification for the risk level associated with read-only access to financial data. A profile supporting write operations is also being drafted as Part 2.
Voting is open until February 10.
Casting a vote is unrelated to making an IPR Contribution, so you can vote with confidence.
If you are not yet a member, you can register from the registration page4.
To register, first log in with an OpenID you already have (Google, Yahoo!, etc.), and then proceed to payment of the membership fee.
- http://openid.net/specs/openid-financial-api-part-1.html
- https://openid.net/foundation/members/polls/106
- OpenID Foundation specifications advance through 3 stages: Draft → Implementers Draft → Final.
- https://openid.net/foundation/members/registration
Related posts
Financial-grade API (FAPI) Security Profile Parts 1 and 2, and JWT Secured Authorization Response Mode (JARM), Have Entered Public Review Prior to the Implementer’s Draft Vote.
The OpenID Financial-grade API Working Group has recommended that the following draft specifications be approved as OpenID Implementer's Drafts. Financial-grade API - Part 1: Read-Only API…
Public Review of “Financial API – Part 1: Read Only API Security Profile” Has Begun
The OpenID Foundation’s Financial API (FAPI) Working Group has recommended commencing a public review prior to the vote to approve Financial API – Part 1: Read Only API…
Please Vote on the Implementer’s Draft for FAPI Part 2
The OpenID Financial API (FAPI) Working Group has recommended that “Financial API – Part 2: Read and Write API Security Profile” be approved as an OpenID…
