Open Banking Security
FAPI 2.0 Conformance

Open Banking Security OPENBANK-1: FAPI 2.0 Security Profile and OpenID Foundation Conformance

Conform to OpenID Foundation Financial-grade API (FAPI) 2.0 Security Profile per FAPI 2.0 Security Profile and FAPI 2.0 Message Signing specifications administered by the OpenID Foundation FAPI Working Group. FAPI 2.0 (final 2024) replaces FAPI 1.0 with simplified + stronger requirements + including mandatory PKCE + Pushed Authorisation Requests (PAR) + sender-constrained tokens + JARM. Conformance must (a) implement Authorisation Server and Client per FAPI 2.0 with all MUST and SHOULD requirements documented + (b) participate in OpenID Foundation FAPI conformance certification programme + maintain current conformance status, (c) align with national open banking schemes (UK OBL + Brazil + Australia CDR + Saudi SAMA + others) where applicable, (d) maintain regression testing on Authorisation Server + Client implementations during release cycles + (e) integrate with broader API security programme + with documented FAPI deviation rationale where deviations exist.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.