Standardized, Fine-Grained Authorization Using OAuth 2 Grant Management and Rich Authorization Requests

Published March 19, 2025

Since 2018, the OpenID Foundation's FAPI Working Group and the global community have been developing standards to support Open Banking and Open Data. In "Standardized and Fine-Grained Authorization with OAuth 2 Grant Management and Rich Authorization Requests," Dima Postnikov (OIDF Vice Chairman) and Gail Hodges (OIDF Executive Director) lay out how implementations around the world have contributed to improvements in the specifications over time and explain the FAPI WG recommendations related to OAuth2 Grant Management and Rich Authorization Requests (RAR) to enable fine-grained authorization.

Previously deployed ecosystems did not have an opportunity to use a standard-based approach in fine-grained authorization. This draft paper explains why the FAPI WG is encouraging new ecosystems to become early adopters of Grant Management and RAR.

What to do next:

OpenID Foundation

The OpenID Foundation (OIDF) is a global open standards body committed to helping people assert their identity wherever they choose. Founded in 2007, we are a community of technical experts leading the creation of open identity standards that are secure, interoperable, and privacy preserving. The Foundation’s OpenID Connect standard is now used by billions of people across millions of applications. In the last five years, the Financial Grade API has become the standard of choice for Open Banking and Open Data implementations, allowing people to access and share data across entities. Today, the OpenID Foundation’s standards are the connective tissue to enable people to assert their identity and access their data at scale, the scale of the internet, enabling “networks of networks” to interoperate globally. Individuals, companies, governments and non-profits are encouraged to join or participate. Find out more atopenid.net.

Tagged