What is the Financial-grade API (FAPI) WG?
- 2019-04-03 New bi-weekly issues call starting today on the Atlantic time schedule.
- 2019-04-01 FAPI Conformance tests and Self-certifications are now available. To see the list of results, click here.
In many cases, Fintech services such as aggregation services use screen scraping and stores user passwords. This model is both brittle and insecure. To cope with the brittleness, it should utilize an API model with structured data and to cope with insecurity, it should utilize a token model such as OAuth [RFC6749, RFC6750].
This working group aims to rectify the situation by developing a REST/JSON model protected by OAuth. Specifically, the FAPI WG aims to provide JSON data schemas, security and privacy recommendations and protocols to:
- enable applications to utilize the data stored in the financial account,
- enable applications to interact with the financial account, and
- enable users to control security and privacy settings.
Both commercial and investment banking account as well as insurance, and credit card accounts are to be considered.
Working Group Chairs
- Nat Sakimura (NAT Consulting), Anoop Saxena (Intuit), Anthony Nadalin, Dave Tonge (Moneyhub)
The chairs can be reached at <email@example.com>.
List of Specifications and status
- FAPI 1.0 — Part 1: Baseline API Security Profile (Draft towards the final specification.).
- FAPI 1.0 — Part 2: Advanced Security Profile (Draft towards the final specification).
- FAPI 1.0 — JWT Secured Authorization Response Mode for OAuth 2.0 (JARM) (Implementer’s Draft).
- FAPI 1.0 — CIBA Profile (Implementers Draft).
- FAPI 2.0 — Grant Management for OAuth 2.0 (Draft)
Followings are skeletons of the future works. The structure may well be changed.
- FAPI 1.0 — Lodging Intent ===> Now OAuth PAR + OAuth RAR
- FAPI 2.0 — Part 1: Baseline Security Profile
- FAPI 2.0 — Part 2: Advanced Security Profile
The current thought around it can be found in this presentation.
The easiest way to participate is to join the mailing list at http://lists.openid.net/mailman/listinfo/openid-specs-fapi.
Please note that while anyone can join the mailing list as a read-only recipient, posting to the mailing list or actively contributing to the specification itself requires the submission of an IPR Agreement. More information is available at http://openid.net/intellectual-property. Make sure to specify the working group as FAPI WG.
- Regular Meetings
- Pacific zone call: Bi-weekly Tuesday Call @ 11pm UTC
- Atlantic zone call: Weekly Wednesday Call @ 2pm UTC
- See the calendar below for the details.
- Location: https://global.gotomeeting.com/join/321819862
- GoToMeeting software is available on Mac, PC, iPhone, and Android Phone.
- Using VoIP option of GoToMeeting is preferred. If you have to absolutely use a plain old telephone for some reason, here is the phone number:
United States: +1 (224) 501-3316 United Kingdom: +44 (0) 20 3713 5011
- Meeting minutes are available at: https://bitbucket.org/openid/fapi/wiki/browse/