Skip to main content

Resources

Reference material for the standards SecureAuth is built on: OAuth 2.1, OpenID Connect, SAML, and the financial-grade API security profiles.

💡 Why this matters
These pages explain how the protocols work, not how to configure a specific feature. Use them when you need to understand a flow, choose a client authentication method, or answer a security review.

Choose your area:

  • OAuth and OpenID Connect - Flows, tokens, client authentication, and advanced profiles. The largest set of pages here, and where most readers start.

  • SAML - Single sign-on flows, key concepts, and how SAML compares with OAuth 2.0.

  • Industry standards - FAPI, open finance ecosystems, eIDAS, and the certifications SecureAuth holds.

  • Fundamentals - IAM concepts and terminology, and the open standards SecureAuth supports.

Certifications and security reviews​

SecureAuth is certified against the FAPI 2.0 Security Profile and FAPI 2.0 Message Signing final specifications. The SecureAuth SaaS platform was certified on 23 July 2026 and appears in the OpenID Foundation FAPI 2.0 certification directory.

SecureAuth also holds FAPI 1.0 Advanced certification, along with the UK Open Banking, Australia CDR, Brazil Open Banking, and Saudi Arabia Open Banking profiles.

If you are completing a security review or a procurement questionnaire, see Certifications for every certified conformance profile, and API security profile requirements for open finance initiatives for the profile each ecosystem uses.

Most-read pages​