---
term: "FAPI 2.0 Security Profile"
category: "Authentication and security"
url: https://agenticopenfinance.com/glossary/fapi-2
source: AgenticOpenFinance glossary
---

# FAPI 2.0 Security Profile

> An OpenID Foundation profile of OAuth for high-value APIs, such as open banking, with stricter security.

The FAPI 2.0 Security Profile is an OpenID Foundation specification that profiles OAuth for APIs protecting high-value data and actions, such as those used in open banking. It narrows OAuth's options to a secure set, for example requiring sender-constrained access tokens and protecting authorisation requests against tampering, and it comes with an attacker model. Several open banking and open finance ecosystems require it, and it is a sound baseline for agent-facing financial APIs.

Related terms: [OAuth 2.0](https://agenticopenfinance.com/glossary/oauth-2.md), [DPoP](https://agenticopenfinance.com/glossary/dpop.md), [Access token](https://agenticopenfinance.com/glossary/access-token.md), [Open banking](https://agenticopenfinance.com/glossary/open-banking.md)
