Skip to main content
This page is for Authlete 2.x. For current (3.0) documentation, see this page.
how-to-use-fapi-feature_1 FAPI Profile

Overview

This document explains how to use Financial-grade API (FAPI) feature in Authlete.
FAPI feature is available since Authlete 2.0.
If you are using Authlete 2.2+, refer to Financial-grade API (FAPI) Basics.

Introduction

FAPI defines two types of security profiles. One is read-only API profile (specified in FAPI part1) and the other one is read-and-write API profile (specified in FAPI part2). Requirements for authorization servers in both profiles are different, thus the behavior of authorization servers varies depending on which security profile it is based on. To enable FAPI feature in Authlete, you need to configure your service and client so that they satisfy the requirements in either of the profiles above. Additionally, request parameters that your client sends to your service (authorization server) also need to be configured appropriately because Authlete determines whether FAPI feature is enabled or not at runtime. This means FAPI feature is not enabled in Authlete when request parameters are not configured properly even if the configurations of your service and client meet FAPI requirements. The following steps briefly explain how Authlete determines whether to enable FAPI or not at runtime:
  1. Extract scopes that are contained in the request or associated with the request
  2. Check the scope attributes (see Appendix 1) associated with each scope as follows:
In the following sections, we will see more details of how to configure a service, a client and request parameters for both profiles.

Service configurations

This section explains how to configure a service to support FAPI profiles.

Configurations for read-only API profile

Configure a service as below.

Configurations for read-and-write API profile

To support read-and-write API profile, you need to configure a service according to the configurations for read-only API profile and the following additional configurations. (Some configurations for read-only API profile are overridden.)

Client configurations

This section explains how to configure a client to support FAPI profiles.

Configurations for read-only API profile

Configure a client as below.

Configurations for read-and-write API profile

To support read-and-write API profile, you need to configure a client according to the configurations for read-only API profile and the following additional configurations. (Some configurations for read-only API profile are overridden.)

Request

This section explains how to configure request parameters (for authorization endpoint and token endpoint) to support FAPI profiles.

Authorization request

Authorization request for read-only API profile

Requirements for request parameters Example

Authorization request for read-and-write API profile

Requirements for request parameters To support read-and-write API profile, you need to configure request parameters according to the requirements for read-only API profile and the following additional requirements. (Some requirements for read-only API profile are overridden.) Example claims structure:
Example

Token request

Token request for read-only API profile

Requirements for request parameters Example

Token request for read-and-write API profile

Requirements for request parameters To support read-and-write API profile, you need to configure request parameters according to the requirements for read-only API profile and the following additional requirements. (Some requirements for read-only API profile are overridden.) Client certificate The client needs to present a client certificate to the token endpoint as ‘TLS Client Certificate Bound Access Tokens’ is enabled for the client. Example

Appendix

1. Scope attributes

See this article.

2. JARM

See this article.

3. Requirements for key size

FAPI Part1 says
Financial Services – Financial API - Part 1, 5.2.2. Authorization Server The authorization server,
  …
  5. shall require a key of size 2048 bits or larger if RSA
    algorithms are used for the client authentication;
  6. shall require a key of size 160 bits or larger if elliptic
    curve algorithms are used for the client authentication;
Then, a public key for signing a client assertion (JWS) and a private key for verifying the signature must satisfy the following requirements.

4. Requirements for request objects

FAPI Part2 says
Financial Services – Financial API - Part 2, 5.2.2. Authorization Server The authorization server,
  …
  1. shall require the request or request_uri parameter to be passed as a JWS signed JWT as in clause 6 of [OIDC];
  …
  10. shall require that all parameters are present inside the signed request object passed in the request or request_uri parameter;
  …
  13. shall require the request object to contain an exp claim;
  …
  15. shall require the aud claim in the request object to be, or to be an array containing, the OP’s Issuer Identifier URL;
Additionally, the following requirements for JWS signature must be satisfied.
Financial Services – Financial API - Part 2, 8.6 JWS algorithm considerations Both clients and authorization servers:
    1. shall use PS256 or ES256 algorithms;
    2. should not use algorithms that use RSASSA-PKCS1-v1_5 (e.g. RS256);
    3. shall not use none;
In sum, in order to support read-and-write API profile, request objects
  • Must be signed with the algorithm specified as ‘Request Object Signature Algorithm’.
  • Must include all the request parameters.
  • Must include the ‘exp’ claim
  • Must include the ‘aud’ claim and the value must be the value of ‘Token Issuer Identifier’.
The following example shows the payload of a request object that satisfies the requirements.