financial-grade API (FAPI)

GPTKB entity

Statements (30)
Predicate Object
gptkbp:instanceOf security profile
OAuth 2.0 profile
gptkbp:basedOn gptkb:OAuth_2.0
gptkb:OpenID_Connect
gptkbp:category gptkb:financial_technology
API security
gptkbp:developedBy gptkb:OpenID_Foundation
gptkbp:firstPublished 2017
gptkbp:focusesOn integrity
confidentiality
high security
non-repudiation
https://www.w3.org/2000/01/rdf-schema#label financial-grade API (FAPI)
gptkbp:includes FAPI Part 1: Read-Only API Security Profile
FAPI Part 2: Read and Write API Security Profile
gptkbp:publishedBy gptkb:OpenID_Foundation
gptkbp:requires gptkb:PKCE
mutual TLS
strong client authentication
JWT access tokens
secure token handling
gptkbp:specifies security requirements
best practices for APIs
gptkbp:usedFor secure API access
financial data protection
gptkbp:usedIn gptkb:PSD2
Open Banking
gptkbp:website https://openid.net/wg/fapi/
gptkbp:bfsParent gptkb:OAuth_2.0_Pushed_Authorization_Requests
gptkbp:bfsLayer 8