Who Needs That FAPI Thing, Anyway?

A talk given by Michal Trojanowski from Curity at the Nordic APIs 2024 Platform Summit.

The FAPI security profile from the Open ID Foundation is very often associated with financial applications. The truth is, that it describes security enhancements that can benefit any industry. In fact, the working group changed its name from Financial-grade API to FAPI so that it is not so directly connected with finance. In this talk, Michal demystifies the FAPI security profile. He explains the vulnerabilities OAuth apps face and how enhancements introduced in the profile allow us to address them. He also shows that you can easily benefit from the profile regardless of the industry you work in.

More Live presentations videos

Panel Discussion: API Authorization
OAuth Well Played – Mods and Combos for the Cloud Native API Security Game
How to Build a Fortress with the Security of a Tent
The Swedish Chef Would Be Proud: Cooking up a Secure API in Minutes – Instructions Included
Ditch the Browser, Native API-Driven App Authentication with Passkeys
Browserless OAuth Flows in Mobile Apps Using a Hypermedia API
Addressing Top API Security Risks
Decentralized Identities Changes Everything, Even Your APIs
Military-Grade Security for APIs
OAuth and OpenID Connect - What's next?
Curity on ProgrammableWeb's Developers Rock Podcast
OAuth Tokens As Your Identity API
OAuth Claims Ontology: Using Claims in OAuth and How They Relate to Scopes
Jacob Has a Horse, Says Travis – a Tale of Truths In a Microservice Architecture
Scalable API Security Using OAuth
Financial Grade APIs Using OAuth and OpenID Connect
Security Is a Concern, Let’s Make It an Enabler
Securing APIs in a Cloud Native Environment Using OAuth
Securing APIs and Microservices with OAuth and OpenID Connect
OAuth and OpenID Connect for PSD2 and Third-Party Access