FAPI without (long lived) API access
Open
@dpostnikov is already working on this.
Since Jul 11, 2026.
component: Implementation & Deployment Advice
migrated-from-bitbucket
priority: minor
type: enhancement
- Dominant language
- HTML
- Stars
- 3
- Forks
- 3
- PR merge metrics
- No merged PRs in 30d
Description
Originally submitted by Dima Postnikov (Dima Postnikov) on 2025-07-09
FAPI can be used by ecosystems that don’t require API access for any of their participants. One example is: Identity ecosystems that need ID token exchange only.
Current FAPI text forces clines to support access and refresh tokens regardless, e.g.: Clients shall support refresh tokens and their rotation.
Can we make it conditional in FAPI 2.1 or errata?
Bitbucket status: open
Bitbucket origin: issue 749
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.