Financial-grade API (FAPI) 1.0 Advanced

Version 1.0

FAPI 1.0 Advanced is the OpenID Foundation security profile that defines how to secure financial-grade APIs using OAuth 2.0 and OpenID Connect.

View Official Specification →

Key Features

  • OAuth 2.0 Advanced security profile
  • Signed request objects (JAR/PAR)
  • Sender-constrained access tokens (mTLS/DPoP)
  • JWT-Secured Authorisation Response Mode (JARM)
  • Protection against authorisation code injection
  • Conformance certification programme
  • Adopted by UK, Australia, Brazil, Saudi Arabia
  • Foundation for FAPI 2.0 evolution

About FAPI Advanced

The Financial-grade API (FAPI) 1.0 Advanced Profile is a security specification published by the OpenID Foundation's FAPI Working Group. It defines a highly secured OAuth 2.0 profile designed to protect financial-grade APIs from common attack vectors including authorisation code injection, token replay, and man-in-the-middle attacks.

FAPI Advanced builds on the FAPI 1.0 Baseline profile, adding requirements for signed request objects (JAR), proof of possession tokens, mutual TLS or DPoP for sender-constrained access tokens, and JARM (JWT-Secured Authorisation Response Mode). These security measures ensure that API access is protected even in adversarial network conditions.

The profile has been adopted as the security foundation for open banking standards worldwide, including the UK Open Banking Standard, Australia's CDR Information Security Profile, Brazil's Open Finance security profile, and Saudi Arabia's Open Banking Framework. It is also referenced in the Berlin Group's security guidance.

FAPI 2.0, the next generation of the specification, further simplifies the security model while maintaining the same level of protection. It is expected to supersede FAPI 1.0 in new implementations over the coming years.

Countries Using FAPI Advanced

7 countries currently implement this standard.

Related Standards

Looking to get started with open finance?

Fiskil helps financial institutions, fintechs, and enterprises around the world deliver a successful open finance program.

Fiskil logo

© Fiskil 2026. All rights reserved.

FAPI 1.0 Advanced | Financial-grade API Security Profil...