FAPI Working Group - Overview

FAPI security profile is a general-purpose, high-security OAuth 2 profile used for API protection. It has been adopted by many ecosystems in many countries to support open data, open banking and identity initiatives.
FAPI Working Group
OVERVIEW
CHARTER
SPECIFICATIONS
FAPI Working Group
REPOSITORY
WG News
FAPI 2.0 is now approved as FINAL specification (2025-02-19)
- FAPI 2.0 Security Profile – A secured OAuth profile that aims to provide specific implementation guidelines for security and interoperability. Formally verified under FAPI 2.0 Attacker Model.
- FAPI 2.0 Attacker Model – An attacker model that informs the decisions on security mechanisms employed by the FAPI security profiles.
Papers and Presentations
“Open Banking, Open Data, and the Financial Grade API,” March 2022
A primer for markets looking at enabling Open Banking and Open Data, covering the origins of “user-consent” based data sharing, global adoption, key standards, implementation considerations, and application across industry verticals.
“Open Banking and Open Data: Ready to Cross Borders?”, July 2022, working draft
The whitepaper offers an overview of the global open data landscape and makes a hypothesis that the next stage of open data development will be focused on global interoperability.
“Financial-grade API (FAPI) Profiles”, July 2022
This paper provides a comparison of available FAPI profiles and recommendations for new markets looking to implement FAPI as their security profile.
- Overview of the FAPI Profiles April 20, 2021
Meeting Notes
Working Group Chairs
- Nat Sakimura (NAT Consulting)
- Anoop Saxena (Intuit)
- Dave Tonge (Moneyhub)
- Dima Postnikov
The chairs can be reached at openid-specs-fapi-owner@lists.openid.net
Participation
To monitor progress and connect with working group members, join the mailing list.

Meeting Schedule
Regular Meetings
- Pacific zone call: Bi-weekly Thursday Call @ 11pm UTC
- Atlantic zone call: Weekly Wednesday Call @ 2pm UTC
- Zoom software is available on Mac, PC, iPhone, and Android Phone.
- Join Meeting
- Meeting Minutes
Frequently asked Questions
The FAPI Working Group is a working group at the OpenID Foundation. FAPI was previously known as the Financial-grade API but there was consensus within the working group to update the name to just FAPI to reflect that the specification is appropriate for many high-value use-cases requiring a more secure model beyond just financial services.
The group has expert members from the Identity and Access Management sector. The working group was initially formed to help develop security profiles and API standards for financial APIs. Over time the group has focussed its efforts on security profiles that while applicable for financial APIs, can be used in other industries and ecosystems.
The security profiles developed by the working group are based on the OAuth 2.0 and OpenID Connect suite of standards. OAuth 2.0 is an authorization framework which can be used for both low and high value operations. The standards produced by the FAPI WG contain much less optionality than the general OAuth 2.0 framework and require implementers to use modern security best practices.
The major benefits of the FAPI specifications are:
- Clear point-by-point specifications that implementers can use as a “check list”
- Exhaustive conformance tests to allow implementers to ensure their software is secure and interoperable
- Standards based approach to securing complex interactions (e.g. decoupled authZ flows via CIBA, grant management, pushed request objects).
The FAPI WG does not work on data models or standards for financial or other APIs. These are ecosystem specific.
Please reference the normative changes documentation: https://bitbucket.org/openid/fapi/src/master/FAPI_1.0/changes-between-id2-and-final.md
FAPI 2.0 has a broader scope than FAPI 1.0. It aims for complete interoperability at the interface between client and authorization server as well as interoperable security mechanisms at the interface between client and resource server.
As a consequence, FAPI 2.0 provides mechanisms for obtaining fine-grained and transactional authorization for API access and security mechanisms for replay detection and non-repudiation on both interfaces in addition to the mechanisms already defined in FAPI 1.0 focusing on the security of the authorization flow.
The working group also evolved the profile to be easier to use for developers based on the results of an analysis of various open banking implementations, the recommendations of the latest OAuth Security BCP, and a comprehensive security threat model.
Both FAPI 1.0 as well as FAPI 2.0 define two compliance levels, but the FAPI 2.0 levels are aligned with different protection levels (baseline vs advanced) rather than API access modes (read vs read-write) in FAPI 1.0. The baseline level aims to be secure against all threats captured in the security threat model, the advanced level adds non-repudiation.
FAPI 2.0 provides a higher degree of interoperability and is easier to use while maintaining a comparable security level. FAPI 2.0 aims at on-the-wire compatibility between compliant implementations and to this end removes optional and alternative features.
The specifications are under development and are currently in ‘draft’ status.
The OpenID Foundation process for specification development is involves publishing one (or more) Implementers Drafts that have public review periods and are approved by the membership, then another review period / vote for ‘Final’ status.
For FAPI 1.0, the dates were:
First Implementers Draft: July 2017
Second Implementers Draft: October 2018
Conformance testing launched: April 2019
Final: March 2021
The working group intends to move FAPI 2.0 forward at a faster pace.
You are very welcome to join the working group and propose changes.
Anyone can join the WG and contribute to the specifications after the submission of an IPR Agreement.
FAPI 2.0 conformance tests were launched in March 2023. The first set of FAPI 2.0 self-certifications have been published and can now be viewed on the Certification Listings.
We congratulate Authlete, Cloudentity, ConnectID, Ping Identity, and Raidiam for achieving compliance with the current FAPI 2.0 certifications and for being thought leaders on the leading edge of this important work. We are grateful to ConnectID in Australia who adopted FAPI 2.0 for their ecosystem and funded the FAPI 2.0 conformance test suite development.
Here are some examples of ecosystems that have implemented FAPI 1.0:
| Open Banking, UK | Consumer Data Rights, Australia |