vulns.co
/
GKData.io MCP

OpenID Foundation · 1 min read

FAPI 2.0 Security Profile

Defines a high-security OAuth profile with coordinated requirements for confidential clients, authorization servers, and resource servers. Connects sender-constrained tokens and authorization-request integrity with the separate requirement to evaluate whether a token’s authority is sufficient for each protected resource.

Open the reference Technical StandardReviewed 2026-10-03

How to use this reference

Map the ownership of token validation, issuer trust, client authentication, and resource-access decisions across an owned API integration. Keep protocol conformance distinct from application-specific authorization.

Before reading

  • OAuth roles and authorization-code flows
  • Public-key client authentication and token validation

Context and limits

  • Public clients are outside this profile’s scope.
  • Security claims depend on the stated model and complete implementation; this record is not certification.

Sources and provenance

  1. FAPI 2.0 Security Profile OpenID Foundation · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software