New Livestream: How Banks Protect Their Apps with FAPI 2.0.

Register Now!
Livestream

How Banks Protect Their Apps with FAPI 2.0

September 24, 2026

10:00 EDT / 16:00 CEST / 14:00 UTC

Register Now

Overview

FAPI is a security profile that protects APIs in high-value scenarios that require heightened security. To be considered FAPI 2.0 compliant, an implementation must adopt the right set of OAuth best current practices. FAPI 2.0 is where identity stops being a checkbox and becomes the control plane for high-value transactions. Banks figured this out first, but the profile applies anywhere the cost of a compromised token is measured in more than a password reset.


This session pairs the concepts with a working implementation on both sides – identity provider and client. Attendees may leave convinced their organization needs FAPI compliance. If not, they will leave with at least one change that meaningfully hardens their application landscape.

What You'll Learn

  • Why FAPI 2.0 exists: The threat model behind financial-grade security and why OAuth 2.0, correctly configured, still isn't enough when a stolen token can move money.
  • What FAPI 2.0 requires:
    • Sender-constrained access tokens: How DPoP and mTLS bind a token to the client that requested it, making a leaked token useless to an attacker.
    • Confidential clients only: Why FAPI 2.0 excludes public clients, and what that means for your application architecture.
    • private_key_jwt over client secrets: Asymmetric client authentication in practice with no shared secrets to leak, rotate, or accidentally commit.
    • Least privilege for access tokens: Scoping tokens tightly so a compromise is contained by design.
    • Live implementation: Each concept demonstrated end-to-end on both the identity provider and the client, not slideware.

Speakers

  • Roland Guijt

    Developer Educator, Duende Software

    Background frame
    Roland Gujit