Maybe rename this to ax_resp, in case you want to use it more general later on? (Since there's also other info in AX)
Why only in the case of fas? Other providers might start to support this too?
Why not just always add it? In case it's not there, it doesn't harm.
Because it asks for something that not always required (ok it is for pagure but at one point I hope to un-bundle flask_fas_openid from pagure)
Because currently we have 2 authentications options: FAS and local accounts
:wheelchair: Looks good to me