SlideShare ist ein Scribd-Unternehmen logo
1 von 30
Downloaden Sie, um offline zu lesen
Identity APIs and the Road to
Digital Transformation
T. Inthirakumaaran, Software Engineer, WSO2
Sachini Wettasinghe, Software Engineer, WSO2
Evolution of IAM
Story of Julie joining XYZ Corp
XYZ corporationJulie
Siloed IAM - Application Bounded
4
HR Application Payroll Application License Application
Julie J.Julie Juliee
XYZ Corp
Challenges with Siloed IAM -Application
Bounded
● Identity mismatch
● Redundancy
● DifïŹculty in maintenance
● Very low user friendliness
Siloed IAM - Centralized but Proprietary
Payroll
Application Identity Provider
HR
Application
License
Application
XYZ Corp ABC Org
CRM
Application
xyz
Proprietary
xyz
Proprietary
xyz
Proprietary
Julie
Challenges with Siloed IAM - Centralized but
Proprietary
● Identity mismanagement between silos
● SSO between silos is hard
● Integration between organization or departments are difïŹcult or
impossible
How to ïŹx this?
Introduction of Standards and Identity APIs
Payroll
Application Identity Provider
HR
Application
License
Application
XYZ Corp ABC Org
CRM
Application
SAML SSO /
SCIM / XACML
OpenID Connect
/ SCIM / XACML
WS-Fed / SCIM
/ XACML
OpenID Connect
/ SCIM / XACML
Julie
Importance of Standard Identity APIs
● Integration
● User friendliness increased
● Less Vulnerabilities
11
Business Success
Seamless Experience
Customer Satisfaction
Identity Integrations
Identity APIs
Authorization APIs
● APIs that controls user or administrator permission/access
rights to resources.
● OAuth 2.0
○ Authorization Code Grant
○ SAML Bearer Grant
○ JWT Grant
○ Client Credentials Grant
Will this be
enough?
New Drift → Customer is King
● CIAM
● Industry become customer
centric
● Seamless integration between
devices (Omni channel)
● Privacy concerns GDPR &
PSD2
● Party to Party delegation
CIAM at a Glance
Self Care
Portal
Identity
Provider
Retail
Application
Cloud
OIDC
OpenID
Connect / SCIM
/ XACML
Customer
CRM
SCIM
XYZ Corp
Evolution of IAM by KuppingerCole
Source https://www.kuppingercole.com/report/lc79012
Modern Identity APIs
Modern API categories
Authorization APIs03
Identity & User Management APIs01
Authentication APIs02
Audit & Compliance APIs04
DevOps APIs07
WorkïŹ‚ow & Orchestration APIs05
API Developer Support08
API security06
Identity & User Management APIs
Self Care
Portal
Identity
Provider
AA Org CC Org
Identity
Provider
BB Org
Identity
Provider
SCIM
SCIM SCIM
Inbound Outbound
Inbound
Authz Code Grant Flow
Application (OAuth
Client)
OAuth
Authorization
Server
2
3
4
1
5
6
7
8
OAuth
Resource
Server
Introspect
Authenticate + Consent
Authz Code
302
Access
Token Rq
Access Token
Access Token
Access Token
Resource
Request
Prerequisite
Client application
registered with the
Authz Server
manually or via
Dynamic Client
Registration
Resource
Owner
Authentication APIs
● Authentication method support via APIs within the range of
username/password to biometrics and anything in between.
● SSO and session management.
● Authentication with OIDC - OpenID Connect
OIDC Flow
Application (OAuth
Client)
OAuth Authorization
Server
Resource
Owner
2
3
4
1
5
6
9
OAuth
Resource
Server
Introspect
Authenticate + Consent
Authz Code
302
Access
Token Rq
Access Token
ID Token
User Info
Request
7
Access Token
Access Token
8
Access Token
Resource
Request
scope=openid
WorkïŹ‚ow & Orchestration APIs
● User Self Registration
● User Consent Management
User Consent Management
Change
Consent
Self Care Portal
Consent Mgt API
Identity Provider
ConsentStorages
End-user
Audit & Compliance APIs
And there’s more..
● DevOps APIs
○ Tools, automation, and continuous integrations.
● API security
○ Encryption, rate limiting, content ïŹltering, and schema
validation.
● API Developer Support
○ Documentation, tutorials, and community support.
WSO2 as an overall Leader
● Only open source IAM vendor in leader category.
Source https://www.kuppingercole.com/report/lc79012
Conclusion
● Evolution of IAM and Identity APIs
● Identity APIs and their importance
● How they support digital transformation/CIAM initiatives
● WSO2 Identity Server as an Identity API platform
Questions?
THANK YOU
wso2.com

Weitere Àhnliche Inhalte

Mehr von WSO2

Mehr von WSO2 (20)

WSO2CON 2024 - OSU & WSO2: A Decade Journey in Integration & Innovation
WSO2CON 2024 - OSU & WSO2: A Decade Journey in Integration & InnovationWSO2CON 2024 - OSU & WSO2: A Decade Journey in Integration & Innovation
WSO2CON 2024 - OSU & WSO2: A Decade Journey in Integration & Innovation
 
WSO2CON 2024 - Freedom First—Unleashing Developer Potential with Open Source
WSO2CON 2024 - Freedom First—Unleashing Developer Potential with Open SourceWSO2CON 2024 - Freedom First—Unleashing Developer Potential with Open Source
WSO2CON 2024 - Freedom First—Unleashing Developer Potential with Open Source
 
WSO2CON 2024 Slides - Open Source to SaaS
WSO2CON 2024 Slides - Open Source to SaaSWSO2CON 2024 Slides - Open Source to SaaS
WSO2CON 2024 Slides - Open Source to SaaS
 
WSO2CON 2024 - Does Open Source Still Matter?
WSO2CON 2024 - Does Open Source Still Matter?WSO2CON 2024 - Does Open Source Still Matter?
WSO2CON 2024 - Does Open Source Still Matter?
 
WSO2CON 2024 - IoT Needs CIAM: The Importance of Centralized IAM in a Growing...
WSO2CON 2024 - IoT Needs CIAM: The Importance of Centralized IAM in a Growing...WSO2CON 2024 - IoT Needs CIAM: The Importance of Centralized IAM in a Growing...
WSO2CON 2024 - IoT Needs CIAM: The Importance of Centralized IAM in a Growing...
 
WSO2CON 2024 - Architecting AI in the Enterprise: APIs and Applications
WSO2CON 2024 - Architecting AI in the Enterprise: APIs and ApplicationsWSO2CON 2024 - Architecting AI in the Enterprise: APIs and Applications
WSO2CON 2024 - Architecting AI in the Enterprise: APIs and Applications
 
WSO2CON 2024 - WSO2's Digital Transformation Journey with Choreo: A Platforml...
WSO2CON 2024 - WSO2's Digital Transformation Journey with Choreo: A Platforml...WSO2CON 2024 - WSO2's Digital Transformation Journey with Choreo: A Platforml...
WSO2CON 2024 - WSO2's Digital Transformation Journey with Choreo: A Platforml...
 
WSO2CON 2024 - Software Engineering for Digital Businesses
WSO2CON 2024 - Software Engineering for Digital BusinessesWSO2CON 2024 - Software Engineering for Digital Businesses
WSO2CON 2024 - Software Engineering for Digital Businesses
 
WSO2CON 2024 - Navigating API Complexity: REST, GraphQL, gRPC, Websocket, Web...
WSO2CON 2024 - Navigating API Complexity: REST, GraphQL, gRPC, Websocket, Web...WSO2CON 2024 - Navigating API Complexity: REST, GraphQL, gRPC, Websocket, Web...
WSO2CON 2024 - Navigating API Complexity: REST, GraphQL, gRPC, Websocket, Web...
 
WSO2CON 2024 - Designing Event-Driven Enterprises: Stories of Transformation
WSO2CON 2024 - Designing Event-Driven Enterprises: Stories of TransformationWSO2CON 2024 - Designing Event-Driven Enterprises: Stories of Transformation
WSO2CON 2024 - Designing Event-Driven Enterprises: Stories of Transformation
 
WSO2CON 2024 - Not Just Microservices: Rightsize Your Services!
WSO2CON 2024 - Not Just Microservices: Rightsize Your Services!WSO2CON 2024 - Not Just Microservices: Rightsize Your Services!
WSO2CON 2024 - Not Just Microservices: Rightsize Your Services!
 
WSO2CON 2024 - Cloud Native Middleware: Domain-Driven Design, Cell-Based Arch...
WSO2CON 2024 - Cloud Native Middleware: Domain-Driven Design, Cell-Based Arch...WSO2CON 2024 - Cloud Native Middleware: Domain-Driven Design, Cell-Based Arch...
WSO2CON 2024 - Cloud Native Middleware: Domain-Driven Design, Cell-Based Arch...
 
WSO2CON 2024 - How to Run a Security Program
WSO2CON 2024 - How to Run a Security ProgramWSO2CON 2024 - How to Run a Security Program
WSO2CON 2024 - How to Run a Security Program
 
WSO2CON 2024 - Building the API First Enterprise – Running an API Program, fr...
WSO2CON 2024 - Building the API First Enterprise – Running an API Program, fr...WSO2CON 2024 - Building the API First Enterprise – Running an API Program, fr...
WSO2CON 2024 - Building the API First Enterprise – Running an API Program, fr...
 
WSO2CON 2024 - Lessons from the Field: Legacy Platforms – It's Time to Let Go...
WSO2CON 2024 - Lessons from the Field: Legacy Platforms – It's Time to Let Go...WSO2CON 2024 - Lessons from the Field: Legacy Platforms – It's Time to Let Go...
WSO2CON 2024 - Lessons from the Field: Legacy Platforms – It's Time to Let Go...
 
WSO2CON 2024 - API Management Usage at La Poste and Its Impact on Business an...
WSO2CON 2024 - API Management Usage at La Poste and Its Impact on Business an...WSO2CON 2024 - API Management Usage at La Poste and Its Impact on Business an...
WSO2CON 2024 - API Management Usage at La Poste and Its Impact on Business an...
 
WSO2CON 2024 - How CSI Piemonte Is Apifying the Public Administration
WSO2CON 2024 - How CSI Piemonte Is Apifying the Public AdministrationWSO2CON 2024 - How CSI Piemonte Is Apifying the Public Administration
WSO2CON 2024 - How CSI Piemonte Is Apifying the Public Administration
 
WSO2CON 2024 - How CSI Piemonte Is Apifying the Public Administration
WSO2CON 2024 - How CSI Piemonte Is Apifying the Public AdministrationWSO2CON 2024 - How CSI Piemonte Is Apifying the Public Administration
WSO2CON 2024 - How CSI Piemonte Is Apifying the Public Administration
 
WSO2CON 2024 - Building a Digital Government in Uganda
WSO2CON 2024 - Building a Digital Government in UgandaWSO2CON 2024 - Building a Digital Government in Uganda
WSO2CON 2024 - Building a Digital Government in Uganda
 
WSO2CON2024 - Why Should You Consider Ballerina for Your Next Integration
WSO2CON2024 - Why Should You Consider Ballerina for Your Next IntegrationWSO2CON2024 - Why Should You Consider Ballerina for Your Next Integration
WSO2CON2024 - Why Should You Consider Ballerina for Your Next Integration
 

KĂŒrzlich hochgeladen

Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 

KĂŒrzlich hochgeladen (20)

Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 
HTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesHTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation Strategies
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsTop 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
 

Identity APIs and the Road to Digital Transformation

  • 1. Identity APIs and the Road to Digital Transformation T. Inthirakumaaran, Software Engineer, WSO2 Sachini Wettasinghe, Software Engineer, WSO2
  • 3. Story of Julie joining XYZ Corp XYZ corporationJulie
  • 4. Siloed IAM - Application Bounded 4 HR Application Payroll Application License Application Julie J.Julie Juliee XYZ Corp
  • 5. Challenges with Siloed IAM -Application Bounded ● Identity mismatch ● Redundancy ● DifïŹculty in maintenance ● Very low user friendliness
  • 6. Siloed IAM - Centralized but Proprietary Payroll Application Identity Provider HR Application License Application XYZ Corp ABC Org CRM Application xyz Proprietary xyz Proprietary xyz Proprietary Julie
  • 7. Challenges with Siloed IAM - Centralized but Proprietary ● Identity mismanagement between silos ● SSO between silos is hard ● Integration between organization or departments are difïŹcult or impossible
  • 9. Introduction of Standards and Identity APIs Payroll Application Identity Provider HR Application License Application XYZ Corp ABC Org CRM Application SAML SSO / SCIM / XACML OpenID Connect / SCIM / XACML WS-Fed / SCIM / XACML OpenID Connect / SCIM / XACML Julie
  • 10. Importance of Standard Identity APIs ● Integration ● User friendliness increased ● Less Vulnerabilities
  • 11. 11 Business Success Seamless Experience Customer Satisfaction Identity Integrations Identity APIs
  • 12. Authorization APIs ● APIs that controls user or administrator permission/access rights to resources. ● OAuth 2.0 ○ Authorization Code Grant ○ SAML Bearer Grant ○ JWT Grant ○ Client Credentials Grant
  • 14. New Drift → Customer is King ● CIAM ● Industry become customer centric ● Seamless integration between devices (Omni channel) ● Privacy concerns GDPR & PSD2 ● Party to Party delegation
  • 15. CIAM at a Glance Self Care Portal Identity Provider Retail Application Cloud OIDC OpenID Connect / SCIM / XACML Customer CRM SCIM XYZ Corp
  • 16. Evolution of IAM by KuppingerCole Source https://www.kuppingercole.com/report/lc79012
  • 18. Modern API categories Authorization APIs03 Identity & User Management APIs01 Authentication APIs02 Audit & Compliance APIs04 DevOps APIs07 WorkïŹ‚ow & Orchestration APIs05 API Developer Support08 API security06
  • 19. Identity & User Management APIs Self Care Portal Identity Provider AA Org CC Org Identity Provider BB Org Identity Provider SCIM SCIM SCIM Inbound Outbound Inbound
  • 20. Authz Code Grant Flow Application (OAuth Client) OAuth Authorization Server 2 3 4 1 5 6 7 8 OAuth Resource Server Introspect Authenticate + Consent Authz Code 302 Access Token Rq Access Token Access Token Access Token Resource Request Prerequisite Client application registered with the Authz Server manually or via Dynamic Client Registration Resource Owner
  • 21. Authentication APIs ● Authentication method support via APIs within the range of username/password to biometrics and anything in between. ● SSO and session management. ● Authentication with OIDC - OpenID Connect
  • 22. OIDC Flow Application (OAuth Client) OAuth Authorization Server Resource Owner 2 3 4 1 5 6 9 OAuth Resource Server Introspect Authenticate + Consent Authz Code 302 Access Token Rq Access Token ID Token User Info Request 7 Access Token Access Token 8 Access Token Resource Request scope=openid
  • 23. WorkïŹ‚ow & Orchestration APIs ● User Self Registration ● User Consent Management
  • 24. User Consent Management Change Consent Self Care Portal Consent Mgt API Identity Provider ConsentStorages End-user
  • 26. And there’s more.. ● DevOps APIs ○ Tools, automation, and continuous integrations. ● API security ○ Encryption, rate limiting, content ïŹltering, and schema validation. ● API Developer Support ○ Documentation, tutorials, and community support.
  • 27. WSO2 as an overall Leader ● Only open source IAM vendor in leader category. Source https://www.kuppingercole.com/report/lc79012
  • 28. Conclusion ● Evolution of IAM and Identity APIs ● Identity APIs and their importance ● How they support digital transformation/CIAM initiatives ● WSO2 Identity Server as an Identity API platform