AuthZEN-Compliant Authorization

Technology logo

Native implementation of the OpenID AuthZEN API specification

OpenID AuthZEN

Authentication has been a solved problem for some time. We have mature specifications such as SAML, OAuth 2.0, and OpenID Connect, which have given rise to many developer services that provide out-of-the-box standards-compliant authentication.

Authorization, however, has not yet had its "OIDC moment". OpenID AuthZEN aims to provide the answer.

Why OpenID?

The OpenID Foundation was founded to drive interoperability in the identity & access space. The OpenID Connect (OIDC) specification has become the ubiquitous protocol for signing into any website on the internet. It is fitting that OpenID is the home for the effort that will bring this level of interoperability to the authorization world.

How is Aserto involved?

Aserto was one of the co-proposers of the working group to the OpenID Foundation board in October 2023. We've actively participated as co-chair of the WG, co-editor of the PEP-PDP spec, and primary authors of the AuthZEN interop scenario, which was first demonstrated by 12 interoperable implementations in May 2024 at the Identiverse conference.

How can you participate?

OpenID is an open standards organization. To join the AuthZEN WG calls, you can sign an IPR agreement on the OpenID website, and join the video calls. The call-in information is posted on the AuthZEN WG page.

Resources

Built for developers with

David Kerber

VP of Technology

"Authorization involves really hard problems that I want experts to solve. We like to focus our internal engineering efforts on our customers and their problems. Aserto allows us to do just that, at a small fraction of the cost it would take to build and maintain it ourselves, not to mention the opportunity cost."

Mathias Biilmann Christensen

Co-founder & CEO, Netlify

"As millions of developers and businesses are adopting a Jamstack approach, most modern web applications involve multiple APIs and services. Aserto's promise of separating policies from code could radically simplify the implementation of authorization across the front-end UI and the larger world of back-end functions and endpoints."

Tom Preston-Werner

Co-founder, GitHub

"Building & managing an authorization/RBAC system is a huge pain, especially at enterprise scale. So stop! Aserto has a distributed, millisecond latency, 100% availability API for that. I'm excited to help as an angel investor!"

Lottie

Authorization, the AuthZEN way!