swissfintechinnovations / ca-security

Apache License 2.0
0 stars 0 forks source link

RAR vs. PAR #2

Open michschl opened 2 months ago

michschl commented 2 months ago

Check wether or not RAR is needed or if the Swiss standard should only allow PAR

michschl commented 2 months ago

Started on 23.06.24 with documentation research.

michschl commented 2 months ago
mibrand commented 1 month ago

For the regular consent flow RAR should not be allowed. Instead it should be used only in those cases where fine-granular authorization is required, e.g. authorization of a payment or a trade. The business API owner shall decide in which cases RAR shall or may be used.