Who Needs That FAPI Thing, Anyway?
A talk given by Michal Trojanowski from Curity at the Nordic APIs 2024 Platform Summit.
The FAPI security profile from the Open ID Foundation is very often associated with financial applications. The truth is, that it describes security enhancements that can benefit any industry. In fact, the working group changed its name from Financial-grade API to FAPI so that it is not so directly connected with finance. In this talk, Michal demystifies the FAPI security profile. He explains the vulnerabilities OAuth apps face and how enhancements introduced in the profile allow us to address them. He also shows that you can easily benefit from the profile regardless of the industry you work in.