-
Notifications
You must be signed in to change notification settings - Fork 0
Home
The Common API specifications focus on the respective business logic. In order for TPPs and FIs to implement these APIs in a standardized way, the secure implementation must be standardized too. Therefore, this repo describes all superior topics regarding security with focus on access control, which includes:
- Consent Management
- Strong Customer Authentication (SCA)
![321859308-5dff5dc6-b2f4-41a9-8e66-a229542f03f7](https://private-user-images.githubusercontent.com/49768081/324344064-a060ebf4-f250-4fea-b9c3-5bb9877249c8.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3MzkxMjE0MjIsIm5iZiI6MTczOTEyMTEyMiwicGF0aCI6Ii80OTc2ODA4MS8zMjQzNDQwNjQtYTA2MGViZjQtZjI1MC00ZmVhLWI5YzMtNWJiOTg3NzI0OWM4LnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNTAyMDklMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjUwMjA5VDE3MTIwMlomWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPWVhMzIzN2IyMDUxYjBjMDc0OGI2M2RjYzE1MzRlZjE2YzY4NWUzZjE0NTQyZjc0MTIyMWE1N2MxNTZmZTFkMzkmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0In0.Q-3q9hLfRbmEqLbp0h9JbrnzJtlDdvmfcL7tbVdWTjE)
The OpenID Foundation's FAPI Working Group already covers the baseline for secure implementations in the context of FIs. It consists of well-established standards and recommendations. The secure implementation of Common API use cases builds upon the basic API security principles and the FAPI 2.0 security profile. Swiss market-related specifics are covered in the FAPI 2.0 Swiss Profile. The following figure gives an overview of this repository.
![Bildschirmfoto 2024-04-23 um 07 28 32](https://private-user-images.githubusercontent.com/49768081/324698049-34fef0cd-a60b-47db-973f-95eb673eec04.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3MzkxMjE0MjIsIm5iZiI6MTczOTEyMTEyMiwicGF0aCI6Ii80OTc2ODA4MS8zMjQ2OTgwNDktMzRmZWYwY2QtYTYwYi00N2RiLTk3M2YtOTVlYjY3M2VlYzA0LnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNTAyMDklMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjUwMjA5VDE3MTIwMlomWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPWI4ZDU1YjUwZTg1ZGEzNmRhOTBhODU0N2UxMjQzNzhjZjliN2Q5YTZmZjhkMzZlMTcyYTg2MmU0ZTQ5NzNmMWMmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0In0.HFyaWsx06srqLtkWyAK3_9eH_ilEqvXnrUzkneMsPHs)
Please use the menu to the right to navigate through the available content.
SFTI | ca-security
Wiki
API Security & Consent Management
- Foundations and assumptions
- Basic API Security Principles
- FAPI 2.0 Swiss Security Profile
- Consent Management
- Implementation example Multibanking
- Strong Customer Authentication (SCA)
- Glossary and terminology
Version Management
Implementation Guidelines