Financial Grade APIs Using OAuth and OpenID Connect

Financial Grade APIs Using OAuth and OpenID Connect

How OAuth and OpenID Connect can be used to conform to open banking regulations, PSD2 and GDPR.

Key Insights

In this whitepaper, we describe various aspects of OAuth and OpenID Connect — including proof-of-possession, issuer identification, and phantom tokens — that can be used to conform to the revised Directive on Payment Services (PSD2) and the General Data Protection Regulation (GDPR). Though these regulations are mandated by the European Union (EU), the applicability of the techniques described in this paper transcends regulatory regimes, and readers elsewhere building APIs that expose high-worth data will also find this paper useful.

Much of the content is industry agnostic, but various banking and finance examples are provided. Some of the techniques will be described in the context of PSD2 and GDPR, but an in-depth knowledge of these regulations is not required.

Table of contents

  • Introduction & Overview — 1

  • Securely Binding Token Obtainment to Presentation — 3

  • Certificate-bound Access Tokens — 5

  • Using a Proof Key to Protect Authorization Codes — 7

  • Pushing Request Parameters in the Back Channel — 11

  • Protecting Integrity of Requests and Responses — 12

  • Issuer Identification — 14

  • Strong Authentication — 17

  • Dynamic Registration Vis-à-vis PSD2 — 18

  • Pairwise Pseudonymous Identifiers — 19

  • Limiting the Regulatory Space — 20

  • Summary — 22

Related resources