API Evangelist
Read post

Show Your Work: Governing an API Standard with ADRs and Attacker Models

Germany's federal API authorization blueprint stands out not for its technology choices but for its governance methodology. Every architectural decision is captured in one of 23 Architecture Decision Records (ADRs), each documenting the problem, options considered, trade-offs, and reasoning — including rejected alternatives. Security requirements are derived from explicit attacker models rather than asserted as controls, with formal proofs for the high-assurance profile. The entire project lives on a public code platform under an open license, with a formal public consultation process. Crucially, approving the specification and making it mandatory were treated as separate steps, with the latter involving a dedicated project group, timelines, exemptions, and support measures. The author argues this method — documented decisions, threat-derived requirements, public transparency, and phased adoption — is more valuable and transferable than any specific technology choice like DPoP or FAPI.

    #security#oauth
Today•6m read time•From apievangelist.com
Post cover image
45 Impressions
API Evangelist's image
API Evangelist

API Evangelist's publication is a resource for developers, architects, and technology leaders seekin...

102 Followers

•

1.1K Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard