[Openid-specs-fapi] Introduction and some questions

Monika Avalur Monika.Avalur at cyberark.com
Thu Jun 26 16:18:24 UTC 2025


Hi,

I am Monika Avalur working as a product manager in IAM space in CyberArk. I have been assigned to this working group and have been going through the specs for FAPI.

I wanted to understand if we plan of further providing guidance as part of FAPI on how the security varies for each entity. Ex: Human vs machine vs workload vs AI agent etc., as the security profile varies for each as well the way they authenticate and authorize.

FAPI talks mostly about confidential clients, but it doesn't say a lot of which protocol and which type of security profile to use for which entity. This guidance will help standardize security among a lot IAM vendors.

Thanks & Regards,
Monika

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-fapi/attachments/20250626/05bc9cbe/attachment.htm>


More information about the Openid-specs-fapi mailing list