AuthHub is built on open standards and proven distributed systems. Every protocol is implemented to specification and validated against the OpenID Foundation conformance suite.
AuthHub has passed hundreds of tests across the OpenID Foundation conformance suite — covering AuthZEN authorization decisions, shared signals event streaming, and OpenID Connect authentication. Every endpoint is validated against the official interoperability test harness used for certification worldwide.
Every protocol is implemented to specification — no proprietary extensions, no vendor lock-in.
| Standard | Category | Status |
|---|---|---|
| OpenID Connect Core 1.0 | Identity | Live |
| OpenID Connect Discovery 1.0 | Identity | Live |
| OAuth 2.0 DPoP (RFC 9449) | Identity | Live |
| OAuth 2.0 Token Exchange (RFC 8693) | Identity | Live |
| XAA / Cross-App Access (ID-JAG) | Identity | Live |
| PKCE (RFC 7636) | Identity | Live |
| Client ID Metadata Document (CIMD) | Identity | Live |
| Protected Resource Metadata (RFC 9728) | Identity | Live |
| AuthZEN 1.0 Authorization API | Authorization | Live |
| Google Zanzibar / ReBAC (SpiceDB) | Authorization | Live |
| Shared Signals Framework (SSF) 1.0 | Security Events | Live |
| Continuous Access Evaluation Profile (CAEP) 1.0 | Security Events | Live |
| Security Event Tokens (RFC 8417) | Security Events | Live |
| SCIM 2.0 Provisioning | Integration | Live |
| NHS CIS2 Identity Federation | Integration | Live |
| JSON Web Token (RFC 7519) | Tokens & Keys | Live |
| JSON Web Key Set (RFC 7517) | Tokens & Keys | Live |
| JWK Thumbprint (RFC 7638) | Tokens & Keys | Live |
| Protocol Buffers (gRPC/Connect) | Transport | Live |
Validated against the OpenID Foundation conformance suite (v5.2.0) — the same test harness used for official certification worldwide.
| Test Suite | Tests | Result |
|---|---|---|
| AuthZEN 1.0 — Evaluation (Interop + PDP Server) | 40+ | Passed |
| AuthZEN 1.0 — Subject Search (Interop + PDP Server) | 20+ | Passed |
| AuthZEN 1.0 — Action Search (Interop + PDP Server) | 20+ | Passed |
| AuthZEN 1.0 — Resource Search (Interop) | 20+ | Passed |
| AuthZEN 1.0 — Batch Evaluations (Interop) | 10+ | Passed |
| Shared Signals Framework (SSF/CAEP) Transmitter | All | Passed |
| OpenID Connect Core (Authorization Code Flow) | Most | Passed |
Distributed systems built for sub-10ms authorization decisions at scale.
Relationship-based access control via SpiceDB — consistent, scalable permission checks at sub-10ms latency.
Per-tenant cryptographic namespace prefixes ensure complete data separation in a shared authorization engine.
Event-time detection, attestation-time signatures, execution-time admissibility — zero temporal drift.
Distributed circuit breakers on SpiceDB, ODS API, JWKS fetching, and webhook delivery prevent cascade failures.
Audit events, governance signals, and webhook delivery via Kafka-compatible event bus with consumer group isolation.
Application metrics, SpiceDB latency histograms, and infrastructure dashboards with alerting.
Zero-trust by default. Every token is bound, every decision is audited, every key is rotated.
Tokens cryptographically bound to client key pairs — stolen tokens are useless without the private key. Fail-closed mode for NHS clinical safety.
Enterprise IdP-mediated agent authorization. AI agents and MCP tools access resources without per-user consent prompts or static secrets.
Time-limited clinical override with full audit trail, dual-clinician authorisation, and automatic revocation.
AES-256-GCM encrypted key storage with automated rotation, propagation delay, and 7-day retention. Thales Luna HSM integration planned.
Complete data erasure with erasure locks preventing re-creation. NHS 7-year immutable audit trail maintained.
Registered agents with scope bounds, rate limits, human-in-the-loop approval, and delegated authorization via SpiceDB caveats.
Purpose-built for the UK National Health Service — ODS codes, clinical safety, and DSPT compliance out of the box.
Native integration with Care Identity Service 2 for Smartcard and Windows Hello authentication.
Data Security and Protection Toolkit — policies, DPIA, risk register, and annual spot-check documentation maintained.
Automatic ODS hierarchy resolution with FHIR API integration for trust/ICB/PCN validation.
Sensitive resource tagging, VIP patient protection, psychiatric note isolation, and Caldicott guardian overrides.
Emergency override mechanism for A&E, cardiac arrest, and safeguarding scenarios with mandatory justification.
Explore the interactive demos or start integrating with AuthHub today.