How to use this reference
Map the ownership of token validation, issuer trust, client authentication, and resource-access decisions across an owned API integration. Keep protocol conformance distinct from application-specific authorization.
Before reading
- OAuth roles and authorization-code flows
- Public-key client authentication and token validation
Context and limits
- Public clients are outside this profile’s scope.
- Security claims depend on the stated model and complete implementation; this record is not certification.
Sources and provenance
- FAPI 2.0 Security Profile OpenID Foundation · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.