API security profile requirements for open finance initiatives
Open finance ecosystems require you to share customer financial data with authorized third-party providers (TPPs), and to prove that you do it securely. This article explains the OAuth and API security requirements you must meet.
What open finance ecosystems require
To take part in an open finance ecosystem, you must satisfy two sets of requirements.
-
Protect customer financial data. Put information security measures in place that prevent unauthorized access, disclosure, alteration, and destruction.
-
Give TPPs secure, token-based access. Your authorization server must issue and validate tokens using OAuth 2.0, OpenID Connect, and the extensions your ecosystem mandates. A TPP integrates with many providers at once. Supporting the same standards as everyone else is what makes that integration work.
How FAPI fits in
Most open finance specifications build on Financial-grade API (FAPI), a hardened OAuth profile for APIs that expose sensitive data.
FAPI is stricter than plain OAuth and OpenID Connect. Depending on the profile, it requires standards such as:
Security profile by ecosystem
Each ecosystem builds on an API security profile and adds its own rules on top. The table below separates what each ecosystem requires from the conformance certification SecureAuth holds for it, with the implementer name and date. For the full list of certified conformance profiles, see Certifications.
| Ecosystem | What the ecosystem requires | Certification held |
|---|---|---|
| UK Open Banking | FAPI 1.0 Advanced | UK-OB Adv. OP, certified by Cloudentity, 19 August 2022 |
| Australia Consumer Data Right (CDR) | FAPI 1.0 Advanced | AU-CDR Adv. OP, certified by Cloudentity, 19 August and 10 October 2022 |
| Brazil Open Banking | FAPI 1.0 Advanced, with the Open Finance Brasil profile | BR-OB Adv. OP, certified by Cloudentity, 19 August to 10 October 2022 |
| Brazil Open Insurance | FAPI 1.0 Advanced, with the Open Insurance Brasil profile | BR-OPIN Adv. OP, certified by Cloudentity, 20 December 2022, and DCR on 2 January 2023 |
| Saudi Arabia Open Banking | FAPI 1.0 Advanced | KSA-OB Adv. OP, certified by Cloudentity, 1 May 2023 |
| Financial Data Exchange (FDX) | FDX 5.2 security profile | No certification suite is published for FDX |
| Australia ConnectID | FAPI 2.0, with the final ConnectID profile | FAPI 2.0 ConnectID Third Implementer's Draft, certified by Cloudentity, 6 May 2023 |
FDX aligns with FAPI but is a separate specification, and the OpenID Foundation does not publish a certification suite for it.
SecureAuth's FAPI 2.0 certifications provide a standards baseline for FAPI 2.0 based deployments. Ecosystem specific requirements and certification are assessed separately.
How SecureAuth meets these requirements
SecureAuth provides authorization servers, a policy engine, and API gateway authorizers. You can add authorization to your applications using your existing authentication providers, API gateways, and service meshes.
SecureAuth is certified against the FAPI 2.0 Security Profile and FAPI 2.0 Message Signing final specifications. The FAPI 1.0 Advanced and Open Banking certifications in the table above were earned by Cloudentity before SecureAuth acquired it. As these specifications change, SecureAuth updates the platform to match.
For the full list of supported standards and certifications, see Open Standards and Certifications.