AuthHub is built on open standards and proven distributed systems — and you can prove it: every authorization capability below is live in your tenant dashboard at the AuthZEN playground, not just asserted.
AuthHub's AuthZEN 1.0 authorization API (evaluation, batch, subject / resource / action search) is validated against the OpenID Foundation interoperability test harness — and every one of those endpoints is callable live in the playground. Its Shared Signals (SSF/CAEP) transmitter signs, delivers, and verifies real Security Event Tokens — see it live. AuthHub is authorization behind your identity provider (token exchange, ID-JAG, introspection) — it is not an interactive OIDC login provider, so it has no /authorize.
Every protocol is implemented to specification — no proprietary extensions, no vendor lock-in.
| Standard | Category | Status |
|---|---|---|
| OpenID Connect Discovery 1.0 (metadata) | Identity | Live |
| OAuth 2.0 Authorization Server Metadata (RFC 8414) | Identity | Live |
| OAuth 2.0 Token Exchange (RFC 8693) | Identity | Live |
| OAuth 2.0 Token Introspection (RFC 7662) | Identity | Live |
| OAuth 2.0 DPoP (RFC 9449) | Identity | Live |
| Rich Authorization Requests (RFC 9396) | Identity | Live |
| XAA / Cross-App Access (ID-JAG) | Identity | Live |
| Client ID Metadata Document (CIMD) | Identity | Live |
| AuthZEN 1.0 Authorization API (eval, batch, search) | Authorization | Live |
| Google Zanzibar / ReBAC (SpiceDB) | Authorization | Live |
| MCP Gateway — OAuth 2.1 resource server (RFC 9728 · RFC 8707 audience binding) | Authorization | Beta |
| OpenID Shared Signals Framework (SSF) 1.0 | Security Events | Live |
| Continuous Access Evaluation Profile (CAEP) 1.0 | Security Events | Live |
| Security Event Tokens (RFC 8417 / 9493) — signed + delivered + verified | Security Events | Live |
| SCIM 2.0 Provisioning | Integration | Live |
| NHS CIS2 Identity Federation (OIDC) | Integration | Beta |
| JSON Web Token (RFC 7519) | Tokens & Keys | Live |
| JSON Web Key Set (RFC 7517) — published | Tokens & Keys | Live |
| JWK Thumbprint (RFC 7638) | Tokens & Keys | Live |
| Protocol Buffers (gRPC/Connect) | Transport | Live |
Client ID Metadata Document (CIMD) client authentication is demonstrable live in the CIMD policy console — AuthHub fetches a client's metadata document over HTTPS, validates it, checks it against an admission policy, and authenticates the client.
MCP Gateway (Beta): AuthHub can sit in front of Model Context Protocol servers as an OAuth 2.1 resource server — publishing RFC 9728 protected-resource metadata, validating audience-bound tokens (RFC 8707), authorizing every tool / resource / prompt call through AuthZEN with real-time governance revocation, and forwarding to the upstream MCP server without passing the client's token through. This has been verified end-to-end with a standard MCP client (MCP Inspector), and AuthHub is participating in the OpenID MCP interoperability testing programme. It is not certified, and the interactive client login flow is provided by a fronting identity provider (Keycloak/Okta/Entra) — AuthHub is the authorization gateway, not the login server.
Validated against the OpenID Foundation conformance suite (v5.2.0) — the same test harness used for official certification worldwide.
| Test Suite | Tests | Result |
|---|---|---|
| AuthZEN 1.0 — Evaluation (Interop + PDP Server) | 40+ | Passed |
| AuthZEN 1.0 — Batch Evaluations | 10+ | Passed |
| AuthZEN 1.0 — Subject Search | 20+ | Passed |
| AuthZEN 1.0 — Resource Search | 20+ | Passed |
| AuthZEN 1.0 — Action Search | 20+ | Passed |
Distributed systems built for low-latency authorization decisions at scale.
Relationship-based access control via SpiceDB — consistent, cached permission checks with low, predictable latency.
Per-tenant cryptographic namespace prefixes ensure complete data separation in a shared authorization engine.
Event-time detection, attestation-time signatures, execution-time admissibility — zero temporal drift.
Distributed circuit breakers on SpiceDB, ODS API, JWKS fetching, and webhook delivery prevent cascade failures.
Audit events, governance signals, and webhook delivery via Kafka-compatible event bus with consumer group isolation.
Application metrics, SpiceDB latency histograms, and infrastructure dashboards with alerting.
Zero-trust by default. Every token is bound, every decision is audited, every key is rotated.
Tokens cryptographically bound to client key pairs — stolen tokens are useless without the private key. Fail-closed mode for NHS clinical safety.
Enterprise IdP-mediated agent authorization. AI agents and MCP tools access resources without per-user consent prompts or static secrets.
Time-limited clinical override with full audit trail, dual-clinician authorisation, and automatic revocation.
AES-256-GCM encrypted key storage with automated rotation, propagation delay, and 7-day retention. Thales Luna HSM integration planned.
Complete data erasure with erasure locks preventing re-creation. NHS 7-year immutable audit trail maintained.
Registered agents with scope bounds, rate limits, human-in-the-loop approval, and delegated authorization via SpiceDB caveats.
Purpose-built for the UK National Health Service — ODS codes, clinical safety, and DSPT compliance out of the box.
Consumes NHS Care Identity Service 2 OIDC tokens — users authenticate at CIS2 (Smartcard, Windows Hello) and AuthHub verifies the token and its NHS identity + ODS claims. Implemented; wiring into the live flow in progress.
Data Security and Protection Toolkit — policies, DPIA, risk register, and annual spot-check documentation maintained.
Automatic ODS hierarchy resolution with FHIR API integration for trust/ICB/PCN validation.
Sensitive resource tagging, VIP patient protection, psychiatric note isolation, and Caldicott guardian overrides.
Emergency override mechanism for A&E, cardiac arrest, and safeguarding scenarios with mandatory justification.
Explore the interactive demos or start integrating with AuthHub today.