Public-sector API operators rarely know the clients they authorize. Across a federation of hundreds of agencies with decentralized administrative processes, access decisions can no longer rest on acquaintance or bilateral agreements. What takes their place is a rule-based approach: decisions grounded in validated attributes, evaluable locally without a runtime dependency on a central platform.
In the project Federal API Authorization Infrastructure, Saxony-Anhalt and FITKO are developing, on behalf of the German IT Planning Council, uniform security requirements and a target architecture built on OAuth 2.0, OpenID Connect, the FAPI 2.0 Security Profile, and AuthZEN. The talk covers the architectural principles we commit to, the decisions and trade-offs behind them — sender-constrained tokens, client authentication, attribute-based authorization, onboarding via signed software statements — and how base services and connecting systems can derive reusable building blocks and realistic migration paths from them. We will share early results from our proof of concept and concrete options for action for operators, developers, and security officers.
High impact blog posts and eBooks on API business models, and tech advice
Connect with market leading platform creators at our events
Join a helpful community of API practitioners
Can't make it to the event? Signup to the Nordic APIs newsletter for quality content. High impact blog posts on API business models and tech advice.
By clicking below, you agree that we process your information per the terms in our Privacy Policy.
Become a part of our global community of API practitioners and enthusiasts. Share your insights on the blog, speak at an event or exhibit at our conferences and create new business relationships with decision makers and top influencers responsible for API solutions.