openid / openid/fapi

how do we handle FAPI1 private_key_jwt aud changes in certification tools

Open
#848 5 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

component: Certification migrated-from-bitbucket priority: major type: bug
Dominant language
HTML
Stars
3
Forks
3
PR merge metrics
No merged PRs in 30d

Description

Originally submitted by josephheenan (Joseph Heenan) on 2026-06-10

As discussed in https://github.com/openid/fapi/issues/714 the IETF updates will result in a change to the requirements on aud values.

The working group needs to decide what approach it takes, as this could require the ecosystems that use our FAPI1 tests to do a migration, even if they're not vulnerable.


Bitbucket status: new

Bitbucket origin: issue 860

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the linked FAPI issue 714 and review how the current FAPI1 certification tools handle private_key_jwt aud values. The working group must first decide the required approach and migration impact; done means an agreed direction that can be translated into certification-tool changes.

Written by the indexing model from the issue text.

Assessment

Domain
api, authentication, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.