AuthZEN is a new OpenID Foundation specification that standardizes fine-grained authorization through a JSON-based decision API. It decouples policy enforcement points from policy decision points, allowing organizations to use any authorization model (RBAC, ABAC, ReBAC, etc.) behind a consistent interface. This approach reduces vendor lock-in, enables dynamic context-aware decisions for zero-trust architectures, and simplifies authorization across microservices, API gateways, and data systems. AuthZEN aims to bring the same level of standardization to authorization that OAuth and OpenID Connect brought to authentication.
Table of contents
The Problem AuthZEN SolvesHow AuthZEN WorksWhere AuthZEN Fits in Modern ArchitecturesHow AuthZEN Could Change Enterprise AuthorizationAuthZEN Improves Enterprise AuthorizationAI Summary1 Comment
Sort: