FAPI 2.0
RU: FAPI 2.0
Financial-grade API 2.0: an OpenID Foundation security profile built on OAuth 2.0 and OIDC, designed for high-value APIs such as open banking. It mandates Pushed Authorization Requests, PKCE, mTLS or DPoP for sender-constraining tokens, and signed request objects to eliminate the attack surface that weaker OAuth profiles leave open.