Thanks to everyone’s support, FAPI Part 2 has become an Implementer’s Draft. We were concerned that we might not reach quorum because more people than expected were on vacation, but we managed to meet the quorum and it was duly approved as an Implementer’s Draft.
I would like to express my sincere gratitude to everyone who helped.
With this, both FAPI Parts 1 and 2 are now available.
The top 9 banks in the UK are currently coding profiles based on this, aiming for a cutover on January 13. 1 but the overall framework is now settled. One area where I currently expect revisions will probably be needed is the JWS cryptographic suite. At present, it specifies PS256 and ES256, but I anticipate cases in which the HSMs (Hardware Security Modules) used by banks support only RS256. If so, based on that feedback, I expect wording will be added to permit the use of RS256 when an HSM supports only RS256 or below.
Related posts
Public Review of “Financial API – Part 1: Read Only API Security Profile” Has Begun
The OpenID Foundation’s Financial API (FAPI) Working Group has recommended commencing a public review prior to the vote to approve Financial API – Part 1: Read Only API…
Financial API — Please Vote on the Read-Only Security Profile!
The OpenID Foundation in the United States is currently holding an Implementer's Draft vote, open until February 10, on “Financial API Part 1 -- Read only…
? It’s finally here! The final specification review for FAPI 2.0 Message Signing has begun!
Announced May 29, 2025 - A new member of the OpenID family is ready to join us! ? What's happening? We have exciting news from the…
