openid / openid/fapi

FAPI 2.0 Purpose and FAPI WG Scope

Open
#425 11 comments 0 reactions 1 assignee View on GitHub

@davidgtonge is already working on this.

Since Jul 11, 2026.

component: Others migrated-from-bitbucket priority: minor type: proposal
Dominant language
HTML
Stars
3
Forks
3
PR merge metrics
No merged PRs in 30d

Description

Originally submitted by dgtonge (Dave Tonge) on 2021-06-23

There was some discussion on the call today about the purpose of FAPI 2.0 and how it fits with the WG Charter.

The current charter - https://openid.net/wg/fapi/charter/ is a little outdated, but is fairly broad in its remit. I don’t personally think that the charter prevents us from producing specifications based on OIDC / OAuth 2 that aid interoperability and security.

The purpose for FAPI 2.0 as expressed in our FAQ is:

  • complete interoperability at the interface between client and authorization server as well as interoperable security mechanisms at the interface between client and resource server.
  • easier to use than FAPI 1.0
  • alignment with OAuth Security BCP
  • clear attacker model

It would be good to get any feedback on this.


Bitbucket status: open

Bitbucket origin: issue 425

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.