08 Apr 2025
Dynamic Client Registration in Open Banking: UK, Brasil, and FDX Compared
Dynamic Client Registration (DCR) is a key component of Open Banking infrastructure, allowing fintechs and banks to onboard securely and automatically. But not all implementations are created equal. Here's how the UK, Brazil, and FDX differ.
Read more →
08 Apr 2025
Understanding Optional SSAs in FDX: DCR with and without Software Statements
In the world of Dynamic Client Registration (DCR), one acronym tends to trip up even experienced implementers: SSA.
While Open Banking specs like the UK's and Brazil's mandate Software Statement Assertions, the FDX spec takes a
different approach—SSAs are optional.
Read more →
28 Mar 2025
The End of the Implicit Flow: Why OAuth 2.1 Matters for Modern Apps
28 March 2025 • by Opendata Consult Ltd
In the world of web security, it's not often that deprecating a feature is cause for celebration. But with OAuth 2.1, that's exactly what's happening. The removal of the implicit flow is one of the most significant and welcome changes in the evolution of OAuth — especially for those building modern, secure fintech apps.
Read more →
24 Mar 2025
OAuth has come a long way since its early days. In this article, we explore its evolution from OAuth 1.0 to OAuth 2.0, the rise of FAPI, and what fintech developers need to know about securing APIs in the age of Open Banking and decentralised identity.
Read more →