Technology

AuthHub is built on open standards and proven distributed systems. Every protocol is implemented to specification and validated against the OpenID Foundation conformance suite.

OpenID Foundation Conformance Tested

AuthHub has passed hundreds of tests across the OpenID Foundation conformance suite — covering AuthZEN authorization decisions, shared signals event streaming, and OpenID Connect authentication. Every endpoint is validated against the official interoperability test harness used for certification worldwide.

AuthZEN 1.0 — Hundreds of tests SSF/CAEP — All tests OIDC Core — Conformance tested

Standards & Protocols

Every protocol is implemented to specification — no proprietary extensions, no vendor lock-in.

StandardCategoryStatus
OpenID Connect Core 1.0IdentityLive
OpenID Connect Discovery 1.0IdentityLive
OAuth 2.0 DPoP (RFC 9449)IdentityLive
OAuth 2.0 Token Exchange (RFC 8693)IdentityLive
XAA / Cross-App Access (ID-JAG)IdentityLive
PKCE (RFC 7636)IdentityLive
Client ID Metadata Document (CIMD)IdentityLive
Protected Resource Metadata (RFC 9728)IdentityLive
AuthZEN 1.0 Authorization APIAuthorizationLive
Google Zanzibar / ReBAC (SpiceDB)AuthorizationLive
Shared Signals Framework (SSF) 1.0Security EventsLive
Continuous Access Evaluation Profile (CAEP) 1.0Security EventsLive
Security Event Tokens (RFC 8417)Security EventsLive
SCIM 2.0 ProvisioningIntegrationLive
NHS CIS2 Identity FederationIntegrationLive
JSON Web Token (RFC 7519)Tokens & KeysLive
JSON Web Key Set (RFC 7517)Tokens & KeysLive
JWK Thumbprint (RFC 7638)Tokens & KeysLive
Protocol Buffers (gRPC/Connect)TransportLive

Conformance Test Results

Validated against the OpenID Foundation conformance suite (v5.2.0) — the same test harness used for official certification worldwide.

Test SuiteTestsResult
AuthZEN 1.0 — Evaluation (Interop + PDP Server)40+Passed
AuthZEN 1.0 — Subject Search (Interop + PDP Server)20+Passed
AuthZEN 1.0 — Action Search (Interop + PDP Server)20+Passed
AuthZEN 1.0 — Resource Search (Interop)20+Passed
AuthZEN 1.0 — Batch Evaluations (Interop)10+Passed
Shared Signals Framework (SSF/CAEP) TransmitterAllPassed
OpenID Connect Core (Authorization Code Flow)MostPassed

Architecture

Distributed systems built for sub-10ms authorization decisions at scale.

Google Zanzibar ReBAC

Relationship-based access control via SpiceDB — consistent, scalable permission checks at sub-10ms latency.

Multi-Tenant Namespace Isolation

Per-tenant cryptographic namespace prefixes ensure complete data separation in a shared authorization engine.

Three-Clock Governance

Event-time detection, attestation-time signatures, execution-time admissibility — zero temporal drift.

Circuit Breakers (Redis-backed)

Distributed circuit breakers on SpiceDB, ODS API, JWKS fetching, and webhook delivery prevent cascade failures.

Kafka/Redpanda Event Streaming

Audit events, governance signals, and webhook delivery via Kafka-compatible event bus with consumer group isolation.

Prometheus + Grafana Observability

Application metrics, SpiceDB latency histograms, and infrastructure dashboards with alerting.

Security Model

Zero-trust by default. Every token is bound, every decision is audited, every key is rotated.

DPoP Sender-Constrained Tokens

Tokens cryptographically bound to client key pairs — stolen tokens are useless without the private key. Fail-closed mode for NHS clinical safety.

XAA / Cross-App Access

Enterprise IdP-mediated agent authorization. AI agents and MCP tools access resources without per-user consent prompts or static secrets.

Break-Glass Emergency Access (AARP)

Time-limited clinical override with full audit trail, dual-clinician authorisation, and automatic revocation.

HSM-Ready Key Management

AES-256-GCM encrypted key storage with automated rotation, propagation delay, and 7-day retention. Thales Luna HSM integration planned.

GDPR Right to Erasure

Complete data erasure with erasure locks preventing re-creation. NHS 7-year immutable audit trail maintained.

AI Agent Governance

Registered agents with scope bounds, rate limits, human-in-the-loop approval, and delegated authorization via SpiceDB caveats.

NHS-Specific Capabilities

Purpose-built for the UK National Health Service — ODS codes, clinical safety, and DSPT compliance out of the box.

NHS CIS2 Federation

Native integration with Care Identity Service 2 for Smartcard and Windows Hello authentication.

NHS DSPT Alignment

Data Security and Protection Toolkit — policies, DPIA, risk register, and annual spot-check documentation maintained.

ODS Organisation Codes

Automatic ODS hierarchy resolution with FHIR API integration for trust/ICB/PCN validation.

Clinical Data Protection

Sensitive resource tagging, VIP patient protection, psychiatric note isolation, and Caldicott guardian overrides.

Break-Glass for Clinical Safety

Emergency override mechanism for A&E, cardiac arrest, and safeguarding scenarios with mandatory justification.

Want to see it in action?

Explore the interactive demos or start integrating with AuthHub today.