W3C

Web Payments Working Group

13 February 2025

Attendees

Present
David Benoit, Fahad Saleem (Mastercard), Gustavo Kok (Netflix), Kenneth Diaz (Entersekt), Nick Telford-Reed, Praveena Subrahmanyam (Airbnb), Rogerio Matsui (Rakuten), Rouslan Solomakhin (Google), Sameer Tare (Mastercard), Sharanya Chandrasekaran (PayPal), Slobodan Pejić (Google), Stephen McGruer (Google), Vasilii Trofimchuk (Block)
Regrets
Gerard Oosthuizen, Ian Jacobs
Chair
Nick Telford-Reed
Scribe
nicktr, Nick Telford-Reed

Meeting minutes

Proposal to take up Faciliated Payments Link in WPWG Charter

nicktr: should we include faciliated payment link in our next charter?

jean-luc: can you say a little more about how it works?

smcgruer_[EST]: I think it makes a lot of sense to link to payment handlers. There is no connection currently in the spec

rouslan: We had feedback from TAG about accessibility - how can we make payment handlers works with payment links

Strawpoll: Should we include facilitated payment links in the scope of our next charter?

<praveenas> +1

<JeanLuc> +1

<vasilii> +0

<SameerT> 0

seeing no objections, we will carry payment links into the draft charter renewal

Relationship to Web Monetization proposal

rouslan: I am trying to guide the Igalia team who are doing experimentation in this space in Chromium.
… I have suggested that they should come to the working group to refresh our knowledge
… otherwise I don't think many people have the knowledge to make the decision
… I am waiting to hear

smcgruer_[EST]: Chrome has no official position on monetization

nicktr: I suggest we wait for a presentation before we consider this

Update on SPC browser based key implementation

smcgruer_[EST]: we talked a couple of weeks ago the prototype BBK
… this is now available in Chrome Canary
… and now includes the instantiation of a new BBK on a new instance of a browser that gets a synchronised passkey
… and we are getting great questions already from implementers

JeanLuc: is the BBK created also with a synchronised passkey?

smcgruer_[EST]: yes
… and it's currently only android

SameerT: is there a link on this that we can include in the minutes?

<Zakim> SameerT, you wanted to say Can we please get the link for BBK information as part of the notes?

<smcgruer_[EST]> w3c/secure-payment-confirmation#271 is the general issue

<smcgruer_[EST]> I will send an email to the group after the meeting with details on how to test BBKs in Chrome Canary on Android :)

nicktr: how many users are there on Canary?

smcgruer_[EST]: I don't think we say publicly, but it's a lot

Update on the isSecurePaymentConfirmationAvailable API

<smcgruer_[EST]> w3c/secure-payment-confirmation#233

smcgruer_[EST]: about a year about we specified a method for feature detection for SPC
… "isSecurePaymentConfirmationAvailable API"
… it is only a boolean TRUE/FALSE
… it is now available in Chrome Canary

<smcgruer_[EST]> https://w3c.github.io/secure-payment-confirmation/#sctn-secure-payment-confirmation-available-api

smcgruer_[EST]: and we should add an issue to consider whether it should be an ENUM rather than a boolean

SameerT: If I try to use this in 3DS challenge, can an iframe call this API?

smcgruer_[EST]: yes, if payment permission policy is enabled

smcgruer_[EST]: this is just "is SPC working" rather than "is the credential available"

JeanLuc: do you think we should look at digital credential API and its alignment with web payments?

rouslan: I think that is a great idea - are you able to bring some information to a future meeting?

JeanLuc: yes, I can
… we could also include attributes
… like age

<JeanLuc> https://openid.net/specs/openid-4-verifiable-presentations-1_0.html#section-5-8

fahad: the digital (payment) credential API work shares a lot with the web authentication - do you know which Chrome team are working on this?

smcgruer_[EST]: yes, and we are talking with them

nicktr: I think @rbyers is involved in both

JeanLuc: could we use something other that FIDO?

smcgruer_[EST]: That's a topic that Gerard is very interested in
… of course there is a lot of the work happening away from W3C like OpenID

JeanLuc: I shared a link from OpenID verifiable presentations

fahad: the DPC API already does all of that. There is a conflict with SPC.
… we did a demo with DPC and we presented it at FIDO last week
… we would demo to the next meeting?

<JeanLuc> https://openid.net/specs/openid-4-verifiable-presentations-1_0.html#section-5-8

<JeanLuc> https://github.com/eu-digital-identity-wallet/eudi-doc-architecture-and-reference-framework/blob/main/docs/architecture-and-reference-framework-main.md#4432-same-device-remote-presentation-flows

nicktr: that would great

next meeting

nicktr: our next meeting will be February 27th, 2025

ACTION: include demo from Mastercard on next agenda

Summary of action items

  1. include demo from Mastercard on next agenda
Minutes manually created (not a transcript), formatted by scribe.perl version 242 (Fri Dec 20 18:32:17 2024 UTC).