FAPI 2.0 Security Profile
An OpenID Foundation profile of OAuth for high-value APIs, such as open banking, with stricter security.
The FAPI 2.0 Security Profile is an OpenID Foundation specification that profiles OAuth for APIs protecting high-value data and actions, such as those used in open banking. It narrows OAuth's options to a secure set, for example requiring sender-constrained access tokens and protecting authorisation requests against tampering, and it comes with an attacker model. Several open banking and open finance ecosystems require it, and it is a sound baseline for agent-facing financial APIs.
Agent Minute explains this term on 3 January 2027.
Related terms
OAuth 2.0The IETF framework that lets an application obtain limited access to a service on a user's behalf, without their password.DPoPAn OAuth mechanism that binds a token to a key the client holds, so a stolen token cannot be used alone.Access tokenA credential a client presents to access protected resources, representing a specific, limited authorisation.Open bankingCustomers letting authorised third parties access their payment account data and initiate payments through secure APIs.