The AuthZEN Working Group was established through the OpenID Foundation to tackle the complexities of authorization, promote decoupling and externalizing authorization logic from applications, and simplify the implementation of a robust authorization layer that can be edited and audited with ease within diverse application environments.
The group consists of several identity practitioners, including myself, who have concluded that companies have reached a certain degree of maturity when it comes to authentication. Now, it is time to tackle authorization.
We reached this conclusion due to the increasing number of users, unprotected data, and applications within organizations, which has amplified the risk of attacks. The increase has led to the need for dynamic, runtime, and fine-grained authorization. We aim to unify and standardize the way authorization decisions are enforced across varying platforms, with an initial focus on a specification that ensures interoperability and integration between policy enforcement points and decision points.
It is important to know that the working group is not defining yet another authorization architecture or runtime policy language.
Instead, AuthZEN wants to achieve three key objectives, which are:
- Set a standard for a policy enforcement point-policy decision point (PEP-PDP) interaction
- Identify and document common usage patterns and recommended best practices
- Create a standard for communicating access policies to policy decision points
Standards in authorization
When you first think about standards and authorization, the National Institute of Standards and Technology (NIST) comes to mind. NIST formalized what attribute-based access control (ABAC) means and helped clarify what authorization was when many vendors and analysts were using different terms for the same thing. In doing this, NIST also set in stone the P*P architecture, which we use at Axiomatics and within the Organization for the Advancement of Structured Information Standards eXtensible Access Control Markup Language (OASIS XACML). Despite setting these standards NIST and providing a reference implementation called next generation access control (NGAC), they left the door open to other standard PEP-PDP interactions.
AuthZEN aims to bridge the different options available out there: from XACML to Abbreviated Language for Authorization (ALFA) to NGAC to vendor-specific alternatives like Oso and Cerbos.
Design patterns in authorization
The group also aims to define design patterns that take performance and scale into account on top of other considerations such as the interaction or interoperability with OAuth and OpenID Connect.
Design patterns explain how to best use a PEP and PDP approach when possible. They also address the ability to roll out fine-grained authorization through a token-based architecture. For instance, an IdP could call out to a PDP during the token issuance process and ask which claims can be injected into the token-to-be.
Another design pattern is entitlement provisioning. This is particularly relevant for COTS or SaaS that have built-in authorization models but no options to delegate to a PDP. In that case, the pattern consists in converting or translating the authorization configuration (policies) maintained centrally into a format understood by the target commercial off-the-self (COTS) or software-as-a-service (SaaS) and then provisioning it to said COTS/SaaS via their administration APIs.
Using different design patterns allows us to achieve more comprehensive and consistent authorization across a broader range of applications, APIs, and data.
Education around authorization
Arguably the most important of these is the awareness around authorization. Most people have an understanding of what authentication is, but they don’t know or understand that the next step in that process is authorization. Through AuthZEN, we plan to create educational materials and promote the awareness of authorization — not only that, but we look at how we can make authorization easier for organizations to deploy and operate across their application estate.
The future of authorization with AuthZEN
We have recently achieved conformance with the AuthZEN request/response protocol, which included a defined interop scenario in the form of a Todo application. This is a significant step in bringing interoperability and standardization to the authorization market. Participating companies included 3Edges, Aserto, Axiomatics, Cerbos, SGNL, and Strata, all of which achieved success in this testing.
An implementer’s draft was announced late last year, and members of the AuthZEN working group are getting together at Gartner IAM London 2025 to run through the latest interop scenario. The interop will include for the first time new participants and specifically API gateways including Layer 7, Kong, and Envoy.
As we look to the future, people can expect to see an interop guide that will help vendors and other companies alike adopt the PEP-PDP interface, and along with the interop, they will be able to certify that they are AuthZEN-compliant. We also hope to provide software development kits (SDKs) that can be used to write PEPs and work against the AuthZEN PEP-PDP interface.
We also inspire for AuthZEN to be the trigger shot — to be the OAuth of authorization. We hope to achieve this vision by having developer tooling, standards, and education around authorization.
The AuthZEN Working Group has published a roadmap for the first half of 2025 which all are welcome to consult and comment on. Lastly, my co-chair and I will be presenting the latest results and vision at Gartner IAM London 2025, the European Identity Conference 2025, and Identiverse.
Be a part of the future of AuthZEN
The AuthZEN Working Group meets weekly on Tuesdays, alternating between 11 am PT or 3pm PT and is open to all organizations committed to the goal of improving interoperability and standardization in authorization.
However, foundation membership is encouraged to support the work of the OpenID Foundation.
