|
Work item:
|
X.f2sp
|
|
Subject/title:
|
FAPI 2.0 security profile
|
|
Status:
|
Under study
|
|
Approval process:
|
TAP
|
|
Type of work item:
|
Recommendation
|
|
Version:
|
New
|
|
Equivalent number:
|
-
|
|
Timing:
|
2026-04 (Medium priority)
|
|
Liaison:
|
OpenID Foundation
|
|
Supporting members:
|
NEC Corpration, Thales Cybersecurity and Digital Identity
|
|
Summary:
|
The FAPI 2.0 Security Profile is an API security profile based on the OAuth 2.0 Authorization Framework that aims to reach the security that is suitable for protecting APIs in high-value scenarios. It follows the recommendations in the OAuth Security BCP profile.
The document specifies the process for a client to obtain sender-constrained tokens from an authorization server and use them securely with resource servers.
|
|
Comment:
|
-
|
|
Reference(s):
|
|
|
Historic references:
|
|
Contact(s):
|
|
| ITU-T A.5 justification(s): |
|
|
|
|
First registration in the WP:
2025-12-11 21:14:49
|
|
Last update:
2025-12-11 21:17:24
|