| connectid-fapi-security-profile-03 | October 2025 | |
| Postnikov | Standards Track | [Page] |
This specification is a part of standards and specifications necessary to meet the requirements and obligations of the Australian Payments Plus ConnectID Scheme. There is a possibility that some of the elements of this document may be the subject to patent rights. Australian Payments Plus shall not be held responsible for identifying any or all such patent rights.¶
The ConnectID specifications consist of the following parts:¶
The ConnectID Security profile specifies additional security and interoperability requirements for ConnectID participants on top of requirements detailed in RFC6749, FAPI-2-Security, FAPI-2-Message-Signing and other referenced specifications.¶
The key words "shall", "shall not", "should", "should not", "may", and "can" in this document are to be interpreted as described in ISO Directive Part 2. These key words are not used as dictionary terms such that any occurrence of them shall be interpreted as key words and are not to be interpreted with their natural language meanings.¶
This document details ConnectID profile of FAPI Security profile ConnectID-FAPI.¶
This document is applicable to all participants engaging in ConnectID.¶
The following referenced documents are indispensable for the application of this document. For dated references, only the edition cited applies. For undated references, the latest edition of the referenced document (including any amendments) applies.¶
ConnectID-FAPI - ConnectID FAPI Security Profile¶
ConnectID-Id-Assurance ConnectID Identity Assurance Profile¶
ConnectID-Cert-Std - ConnectID Certificate Standards¶
ConnectID-Client-Reg - ConnectID Client Registration Profile¶
OAuth2-Purpose - Oauth 2 Purpose extension (individual draft)¶
ISODIR2 - ISO/IEC Directives Part 2¶
RFC6749 - The OAuth 2.0 Authorization Framework¶
RFC8705 - OAuth 2.0 Mutual TLS Client Authentication and Certificate Bound Access Tokens¶
OIDC - OpenID Connect Core 1.0 incorporating errata set 1¶
OIDD - OpenID Connect Discovery 1.0 incorporating errata set 1¶
FAPI-2-Security - FAPI 2.0 Security Profile¶
FAPI-2-Message-Signing - FAPI 2.0 Message Signing¶
RFC4122 - A Universally Unique IDentifier (UUID) URN Namespace¶
For the purpose of this document, the terms defined in RFC6749, OpenID Connect Core and other normative references apply.¶
The ConnectID Security profile specifies security and interoperability requirements for ConnectID participants in addition to requirements detailed in RFC6749, FAPI-2-Security, FAPI-2-Message-Signing and other referenced specifications.¶
A Confidential Client shall support the provisions for Confidential Clients in FAPI 2.0 Security Profile.¶
In addition, the Confidential Client:¶
private_key_jwt as a token endpoint authentication mechanism;¶
mtls_endpoint_aliases as per clause 5 RFC 8705 OAuth 2.0 Mutual-TLS Client Authentication and Certificate-Bound Access Tokens;¶
request_uri parameter as defined in Section 6.2 of OpenID Connect Core in the authentication request;¶
aud claim in the request object as the OP's Issuer Identifier URL;¶
exp claim in the request object that has a lifetime of no longer than 10 minutes; and¶
nbf claim in the request object.¶
x-fapi-interaction-id request header for token, PAR AS endpoints and any other Resource Server call, with its value being a unique RFC4122 UUID for each request, to help correlate log entries between the client and server, eg: x-fapi-interaction-id: c770aef3-6784-41f7-8e0e-ff5f97bddb3a.¶
x-fapi-interaction-id in the log entry for token, PAR AS endpoints and any other Resource Server call.¶
A Resource Server shall support the provisions for Resource Servers in FAPI 2.0 Security Profile.¶
In addition, the Resource Server:¶
For JWS, both clients and Authorization Servers:¶
We would like to thank Ralph Bragg, Joseph Heenan, Paul Ruskin, Amanda Wyllie, Tam Tran, Naveen Tiku and everyone who provided valuable feedback and contributions that helped to evolve this specification.¶
We would also like to thank OpenID Foundation, IETF and many others who have set up the foundations for secure and safe data sharing.¶
Copyright (c) 2025 ConnectID¶
Published: 28th July 2025¶
Published: 10th July 2025¶