Skip to main content

API security profile requirements for open finance initiatives

Open finance ecosystems require you to share customer financial data with authorized third-party providers (TPPs), and to prove that you do it securely. This article explains the OAuth and API security requirements you must meet.

What open finance ecosystems require

To take part in an open finance ecosystem, you must satisfy two sets of requirements.

  • Protect customer financial data. Put information security measures in place that prevent unauthorized access, disclosure, alteration, and destruction.

  • Give TPPs secure, token-based access. Your authorization server must issue and validate tokens using OAuth 2.0, OpenID Connect, and the extensions your ecosystem mandates. A TPP integrates with many providers at once. Supporting the same standards as everyone else is what makes that integration work.

How FAPI fits in

Most open finance specifications build on Financial-grade API (FAPI), a hardened OAuth profile for APIs that expose sensitive data.

FAPI is stricter than plain OAuth and OpenID Connect. Depending on the profile, it requires standards such as:

Security profile by ecosystem

Each ecosystem builds on an API security profile and adds its own rules on top. The table below separates what each ecosystem requires from the conformance certification SecureAuth holds for it, with the implementer name and date. For the full list of certified conformance profiles, see Certifications.

EcosystemWhat the ecosystem requiresCertification held
UK Open BankingFAPI 1.0 AdvancedUK-OB Adv. OP, certified by Cloudentity, 19 August 2022
Australia Consumer Data Right (CDR)FAPI 1.0 AdvancedAU-CDR Adv. OP, certified by Cloudentity, 19 August and 10 October 2022
Brazil Open BankingFAPI 1.0 Advanced, with the Open Finance Brasil profileBR-OB Adv. OP, certified by Cloudentity, 19 August to 10 October 2022
Brazil Open InsuranceFAPI 1.0 Advanced, with the Open Insurance Brasil profileBR-OPIN Adv. OP, certified by Cloudentity, 20 December 2022, and DCR on 2 January 2023
Saudi Arabia Open BankingFAPI 1.0 AdvancedKSA-OB Adv. OP, certified by Cloudentity, 1 May 2023
Financial Data Exchange (FDX)FDX 5.2 security profileNo certification suite is published for FDX
Australia ConnectIDFAPI 2.0, with the final ConnectID profileFAPI 2.0 ConnectID Third Implementer's Draft, certified by Cloudentity, 6 May 2023

FDX aligns with FAPI but is a separate specification, and the OpenID Foundation does not publish a certification suite for it.

SecureAuth's FAPI 2.0 certifications provide a standards baseline for FAPI 2.0 based deployments. Ecosystem specific requirements and certification are assessed separately.

How SecureAuth meets these requirements

SecureAuth provides authorization servers, a policy engine, and API gateway authorizers. You can add authorization to your applications using your existing authentication providers, API gateways, and service meshes.

SecureAuth is certified against the FAPI 2.0 Security Profile and FAPI 2.0 Message Signing final specifications. The FAPI 1.0 Advanced and Open Banking certifications in the table above were earned by Cloudentity before SecureAuth acquired it. As these specifications change, SecureAuth updates the platform to match.

For the full list of supported standards and certifications, see Open Standards and Certifications.