Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking and Finance Review

Global Banking & Finance Review

Company

    GBAF Logo
    • About Us
    • Profile
    • Privacy & Cookie Policy
    • Terms of Use
    • Contact Us
    • Advertising
    • Submit Post
    • Latest News
    • Research Reports
    • Press Release
    • Awards▾
      • About the Awards
      • Awards TimeTable
      • Submit Nominations
      • Testimonials
      • Media Room
      • Award Winners
      • FAQ
    • Magazines▾
      • Global Banking & Finance Review Magazine Issue 79
      • Global Banking & Finance Review Magazine Issue 78
      • Global Banking & Finance Review Magazine Issue 77
      • Global Banking & Finance Review Magazine Issue 76
      • Global Banking & Finance Review Magazine Issue 75
      • Global Banking & Finance Review Magazine Issue 73
      • Global Banking & Finance Review Magazine Issue 71
      • Global Banking & Finance Review Magazine Issue 70
      • Global Banking & Finance Review Magazine Issue 69
      • Global Banking & Finance Review Magazine Issue 66
    Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

    Global Banking & Finance Review® is a leading financial portal and online magazine offering News, Analysis, Opinion, Reviews, Interviews & Videos from the world of Banking, Finance, Business, Trading, Technology, Investing, Brokerage, Foreign Exchange, Tax & Legal, Islamic Finance, Asset & Wealth Management.
    Copyright © 2010-2025 GBAF Publications Ltd - All Rights Reserved.

    Editorial & Advertiser disclosure

    Global Banking and Finance Review is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    Home > Finance > Six Things You Should Know About the Financial-grade API (FAPI) specification
    Finance

    Six Things You Should Know About the Financial-grade API (FAPI) specification

    Six Things You Should Know About the Financial-grade API (FAPI) specification

    Published by Jessica Weisman-Pitts

    Posted on April 12, 2022

    Featured image for article about Finance

    By Rory Blundell, CEO at Gravitee

    There has been a global move to digital infrastructure for all kinds of diverse global systems, covering everything from banking and finance to health, intellectual property, and supply chain management.

    APIs are both ‘the glue’ and ‘the product’ in these systems: on a technical level, they enable systems to be connected together (glue), and, at a business level, they provide the opportunity to generate revenue as products and services that can be delivered as a part of a platform economy (product).

    APIs are awesome, but make sure that security is top of mind

    While APIs and platform economies are incredibly valuable, teams must remain keen on ensuring a strict security posture. Exposing large amounts of services and APIs means that the potential attack surface area when sharing data and digital services between various stakeholders expands.

    Security breaches are becoming more prevalent, more costly, and are eroding trust in using the emerging digital systems that are expected to become our global infrastructure in the future. They also come in more forms: data leaks and exposures, website hacks and denial of service, ransomware, and so on. Because APIs connect so many systems, they are often an entry route for hackers, if they are not properly controlled and robustly built.

    This is especially relevant to organizations operating within banking and finance, as new trends push vendors towards needing to modernize and expose services via APIs while still remaining compliant and keeping PII safe and secure.

    Introducing FAPI: six things to know

    The Financial-grade API (FAPI) specification was introduced by the OpenID Foundation to act as a defense against security risks and vulnerabilities that could be exploited via APIs. FAPI creates and requires an additional security level between banking APIs and third-party applications to ensure that, when sensitive data or digital services are being connected, there are no leaks and vulnerabilities that could expose sensitive information.

    1. What exactly is FAPI?

    FAPI is an industry-led specification that uses enhanced OAuth 2.0 and OpenID Connect (OIDC) processes to ensure greater security between APIs and third-party front-end applications.

    1. Why is FAPI Important?

    While the combination of OAuth 2.0 and OIDC provides a strong security baseline, it still contains several loopholes and vulnerabilities. FAPI strengthens security by mandating the use of specific, safe processes. The standardization of these processes improves interoperability and allows for the acceleration of secure digital systems to enable open banking.

    1. What is open banking?

    Open banking (that is, the process of opening data, like customer account information, and services, like payments, from banks and financial institutions for third-party use) is a key use case for FAPI. Open banking APIs share a wealth of information with other users in the financial ecosystem, such as developers, fintech vendors, and partners. FAPI standardizes the security measures used in these exchanges of information and services to ensure that any exchange between systems is secure. Additionally, the FAPI framework adheres to local open banking regulatory requirements, such as Europe’s PSD2 compliance and the UK’s OBIE regulations.

    1. How Does FAPI Work?

    FAPI addresses shortcomings in OAuth 2.0 and OIDC to build a more robust security framework. OIDC authenticates users via the OAuth authorization server, providing a layer of consent for the client. The server requests user consent to confirm the client can access the resource they’ve requested. Once consent is given, the client is granted an access token allowing them to view their requested resource. FAPI builds upon this by mandating the use of specific and safe processes. With FAPI specifications in place, additional features are offered such as:

    • Enforced mutual TLS authentication
    • Pushed authorization requests
    • Enforced asymmetric metric cryptography keys
    • Certificate-bound access tokens
    1. When Should You Use FAPI?

    FAPI isn’t solely for open banking. Any business dealing with sensitive customer information would benefit from the implementation of the FAPI framework. Telecommunications, healthcare, insurance industries, and the aforementioned intellectual property and supply chain management are just a few of the industry sectors that deal daily with sensitive information that could be targeted for data breaches.

    1. Why Is FAPI Certification Important?

    FAPI offers a self-certification program for vendors and builders of applications, allowing them to conduct their own conformance testing to ensure their products align with FAPI standards and specifications. Obtaining certification assures users that their sensitive data will be in good hands while also allowing businesses to stay competitive and comply with legal obligations.

    About the author

    Rory Blundell is the CEO of Gravitee, a leading API Management and modernization vendor.

    Blundell joined Gravitee in March 2020 as Chief Revenue Officer, before becoming Chief Executive Officer in September, 2020. Prior to joining Gravitee, Rory led SnapLogic’s EMEA expansion from a technical sales perspective. Rory was also the CEO and Founder of Velinko, a UK software and consulting company for the legal and accounting industries.

    He has recently overseen expansion into the USA and APAC markets, and bringing new customers including TIDE, Sodexo, the University of Helsinki, SDFE and CiputraLife onto the Gravitee platform.

    Related Posts
    ECB keeps rates steady, nudges up growth forecast
    ECB keeps rates steady, nudges up growth forecast
    Lufthansa looks to US flyers opting for premium to boost sales
    Lufthansa looks to US flyers opting for premium to boost sales
    Bank of England policymakers' views on December rate cut
    Bank of England policymakers' views on December rate cut
    EU leaders agree to work on using Russian assets for loan for Ukraine -Polish PM
    EU leaders agree to work on using Russian assets for loan for Ukraine -Polish PM
    ECB holds rates steady and turns more positive on the economy
    ECB holds rates steady and turns more positive on the economy
    Orlen to buy butadiene plant builder from Synthos for $193 million
    Orlen to buy butadiene plant builder from Synthos for $193 million
    British regulator cracks down on home, travel insurers
    British regulator cracks down on home, travel insurers
    France's EDF raises maximum cost estimate for six reactors to 72.8 billion euros
    France's EDF raises maximum cost estimate for six reactors to 72.8 billion euros
    Lululemon surges on Elliott's $1 billion bet ahead of leadership change
    Lululemon surges on Elliott's $1 billion bet ahead of leadership change
    Austria's RBI says Russian unit will book nearly $400 million provisions in Rasperia lawsuit
    Austria's RBI says Russian unit will book nearly $400 million provisions in Rasperia lawsuit
    EU leaders think it is fair to use Russian assets for Ukraine, Polish PM says
    EU leaders think it is fair to use Russian assets for Ukraine, Polish PM says
    Germany, Spain urge EU to back Mercosur trade pact, but France resists
    Germany, Spain urge EU to back Mercosur trade pact, but France resists

    Why waste money on news and opinions when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    Previous Finance PostHyperautomation — the new route to resilience for finance firms
    Next Finance PostWhy finance teams are dreading going back to the office

    More from Finance

    Explore more articles in the Finance category

    Zara turns to AI to generate fashion imagery using real-life models

    Zara turns to AI to generate fashion imagery using real-life models

    BNP Paribas in exclusive talks to buy Mercedes-Benz's car-leasing unit in $1.2 billion deal

    BNP Paribas in exclusive talks to buy Mercedes-Benz's car-leasing unit in $1.2 billion deal

    Exclusive-Lufthansa projects 6% long-haul flight growth in 2026 as pursues turnaround

    Exclusive-Lufthansa projects 6% long-haul flight growth in 2026 as pursues turnaround

    Bank of England cuts rates in tight vote, sterling rises

    Bank of England cuts rates in tight vote, sterling rises

    Russia says commission on Ukraine war damages has no legal force for Moscow

    Russia says commission on Ukraine war damages has no legal force for Moscow

    Russia's central bank says it will sue European banks in Russian court over frozen assets

    Russia's central bank says it will sue European banks in Russian court over frozen assets

    Bank of England cuts rates after tight vote but signals caution about further moves

    Bank of England cuts rates after tight vote but signals caution about further moves

    Lucasfilm wins bid to throw out UK lawsuit over 'resurrection' of 'Star Wars' character

    Lucasfilm wins bid to throw out UK lawsuit over 'resurrection' of 'Star Wars' character

    Volkswagen pushing ahead with German cost-cutting, brand boss says

    Volkswagen pushing ahead with German cost-cutting, brand boss says

    New Czech government looking at several CEZ buyout options, minister says

    New Czech government looking at several CEZ buyout options, minister says

    Germany launches 30 billion euro fund to mobilise private investment

    Germany launches 30 billion euro fund to mobilise private investment

    Rheinmetall, ICEYE partner on $2 billion German army order for space sector

    Rheinmetall, ICEYE partner on $2 billion German army order for space sector

    View All Finance Posts