[Openid-specs-fapi] Issue #540: Use of eKYC-IDA spec with CIBA/FAPI-CIBA (openid/fapi)

josephheenan issues-reply at bitbucket.org
Mon Sep 5 05:15:45 UTC 2022


New issue 540: Use of eKYC-IDA spec with CIBA/FAPI-CIBA
https://bitbucket.org/openid/fapi/issues/540/use-of-ekyc-ida-spec-with-ciba-fapi-ciba

Joseph Heenan:

The [CIBA spec](https://openid.net/specs/openid-client-initiated-backchannel-authentication-core-1_0-final.html) & [identity assurance specs](https://openid.bitbucket.io/ekyc/openid-connect-4-identity-assurance.html) don’t currently work together - the identity assurance defines extra members for the ‘claims’ request parameter defined in OpenID Connect Core, but CIBA doesn’t have the `claims` request parameter so there’s currently no way to request `verified_claims` using CIBA. There probably should be.

\(This perhaps isn’t entirely an obvious topic for the FAPI working group, though given CIBA is already final it’s also not obvious where it should be handled, apparently Nat suggested to my colleagues that FAPI-CIBA could be an appropriate place.\)



More information about the Openid-specs-fapi mailing list