AuthZEN is a new OpenID Foundation specification that standardizes fine-grained authorization through a JSON-based decision API. It decouples policy enforcement points from policy decision points, allowing organizations to use any authorization model (RBAC, ABAC, ReBAC, etc.) behind a consistent interface. This approach reduces vendor lock-in, enables dynamic context-aware decisions for zero-trust architectures, and simplifies authorization across microservices, API gateways, and data systems. AuthZEN aims to bring the same level of standardization to authorization that OAuth and OpenID Connect brought to authentication.

7m read timeFrom nordicapis.com
Post cover image
Table of contents
The Problem AuthZEN SolvesHow AuthZEN WorksWhere AuthZEN Fits in Modern ArchitecturesHow AuthZEN Could Change Enterprise AuthorizationAuthZEN Improves Enterprise AuthorizationAI Summary
1 Comment

Sort: