Errata Corrections to JWT Secured Authorization Response Mode for OAuth 2.0 (JARM) Approved
Errata to the following specification have been approved by a vote of the OpenID Foundation members: JWT Secured Authorization Response Mode for OAuth 2.0 (JARM) – This specification was created to bring some of the security features defined as part of OpenID Connect to OAuth 2.0 An Errata version of a specification incorporates corrections identified after the Final Specification […]
UN’s DPI Day: Elizabeth Garber on standards as safeguards
The OpenID Foundation’s Strategy and Marketing Director, Elizabeth Garber, attended DPI (Digital Public Infrastructure) Day as a member of the 2025 DPI Safeguards Working Group, which operates within the United Nations Development Programme and the Office for Digital and Emerging Technologies. Her extensive background with multi-stakeholder communities like SIDI Hub, which advances safe, interoperable identity […]
Notice of Vote to Approve Proposed Errata Corrections to JWT Secured Authorization Response Mode for OAuth 2.0 (JARM)
This is a notice of an upcoming vote to approve proposed errata corrections to JWT Secured Authorization Response Mode for OAuth 2.0 (JARM). The official voting period will be between Monday, July 28, 2025 and Monday, August 4, 2025, once the 45 day review of the specification has been completed. For the convenience of members who […]
FAPI 2.0 Security Profile and FAPI 2.0 Message Signing: Final Conformance Tests and Certifications Now Available

The OpenID Foundation is pleased to announce the availability of conformance tests and certifications for the final versions of the FAPI 2.0 Security Profile and FAPI 2.0 Message Signing specifications for both authorization servers and OAuth clients. FAPI 2.0 Security Profile was approved as a Final specification in February 2025, and FAPI 2.0 Message Signing […]
Public Review Period for Proposed Three Shared Signals Final Specifications
The OpenID Shared Signals Working Group recommends approval of the following three specifications as OpenID Final Specifications: OpenID Shared Signals Framework OpenID CAEP OpenID RISC A Final Specification provides intellectual property protections to implementers of the specification and is not subject to further revision. This note starts the 60-day public review period for the specification draft in […]
Public Review of JWT Secured Authorization Response Mode for OAuth 2.0 (JARM)
The OpenID FAPI working group recommends the approval of Errata corrections to the following specification: First Errata Set for JWT Secured Authorization Response Mode for OAuth 2.0 (JARM) An Errata version of a specification incorporates corrections identified after the Final Specification was published. This would be the first set of errata corrections for JWT Secured Authorization […]
Public Review Period for Proposed FAPI 2.0 Message Signing Final Specification
This blog post was updated on August 27, 2025 to update the final specification voting schedule below The OpenID FAPI working group recommends the approval of the following specification as an OpenID Final Specification: FAPI 2.0 Message Signing A Final Specification provides intellectual property protections to implementers of the specification and is not subject to further […]
OpenID Foundation presents at Financial Data Exchange Summit
The OpenID Foundation’s Gail Hodges and Joseph Heenan presented a talk on “If, when, and why to implement the FDX ‘blue’ security profile with FAPI 2.0” on Tuesday April 22nd for the benefit of North American attendees at the Financial Data Exchange’s Spring Global Summit held at the Gaylord National Harbor. This talk is especially […]
Implementer’s Guide: FAPI 2.0 Final vs. Implementer’s Draft 2.0
Author: Dima Postnikov, Vice-Chair of OpenID Foundation and FAPI WG Member Contributors: Gail Hodges, Nat Sakimura, Ralph Bragg, Filip Skokan, Joseph Heenan. This article is also accessible on Medium. Introduction In a significant milestone for the global Open Banking and Open Data community, on February 22nd, the OpenID Foundation published and approved the new and […]
Standardized, Fine-Grained Authorization Using OAuth 2 Grant Management and Rich Authorization Requests
Since 2018, the OpenID Foundation’s FAPI Working Group and the global community have been developing standards to support Open Banking and Open Data. In “Standardized and Fine-Grained Authorization with OAuth 2 Grant Management and Rich Authorization Requests,” Dima Postnikov (OIDF Vice Chairman) and Gail Hodges (OIDF Executive Director) lay out how implementations around the world […]