Technology

AuthHub is built on open standards and proven distributed systems — and you can prove it: every authorization capability below is live in your tenant dashboard at the AuthZEN playground, not just asserted.

Standards-tested — and demonstrable live

AuthHub's AuthZEN 1.0 authorization API (evaluation, batch, subject / resource / action search) is validated against the OpenID Foundation interoperability test harness — and every one of those endpoints is callable live in the playground. Its Shared Signals (SSF/CAEP) transmitter signs, delivers, and verifies real Security Event Tokens — see it live. AuthHub is authorization behind your identity provider (token exchange, ID-JAG, introspection) — it is not an interactive OIDC login provider, so it has no /authorize.

AuthZEN 1.0 — eval · batch · search SSF/CAEP transmitter OAuth token exchange · DPoP · CIMD MCP Gateway (Beta) — in OpenID interop testing

Standards & Protocols

Every protocol is implemented to specification — no proprietary extensions, no vendor lock-in.

StandardCategoryStatus
OpenID Connect Discovery 1.0 (metadata)IdentityLive
OAuth 2.0 Authorization Server Metadata (RFC 8414)IdentityLive
OAuth 2.0 Token Exchange (RFC 8693)IdentityLive
OAuth 2.0 Token Introspection (RFC 7662)IdentityLive
OAuth 2.0 DPoP (RFC 9449)IdentityLive
Rich Authorization Requests (RFC 9396)IdentityLive
XAA / Cross-App Access (ID-JAG)IdentityLive
Client ID Metadata Document (CIMD)IdentityLive
AuthZEN 1.0 Authorization API (eval, batch, search)AuthorizationLive
Google Zanzibar / ReBAC (SpiceDB)AuthorizationLive
MCP Gateway — OAuth 2.1 resource server (RFC 9728 · RFC 8707 audience binding)AuthorizationBeta
OpenID Shared Signals Framework (SSF) 1.0Security EventsLive
Continuous Access Evaluation Profile (CAEP) 1.0Security EventsLive
Security Event Tokens (RFC 8417 / 9493) — signed + delivered + verifiedSecurity EventsLive
SCIM 2.0 ProvisioningIntegrationLive
NHS CIS2 Identity Federation (OIDC)IntegrationBeta
JSON Web Token (RFC 7519)Tokens & KeysLive
JSON Web Key Set (RFC 7517) — publishedTokens & KeysLive
JWK Thumbprint (RFC 7638)Tokens & KeysLive
Protocol Buffers (gRPC/Connect)TransportLive

Client ID Metadata Document (CIMD) client authentication is demonstrable live in the CIMD policy console — AuthHub fetches a client's metadata document over HTTPS, validates it, checks it against an admission policy, and authenticates the client.

MCP Gateway (Beta): AuthHub can sit in front of Model Context Protocol servers as an OAuth 2.1 resource server — publishing RFC 9728 protected-resource metadata, validating audience-bound tokens (RFC 8707), authorizing every tool / resource / prompt call through AuthZEN with real-time governance revocation, and forwarding to the upstream MCP server without passing the client's token through. This has been verified end-to-end with a standard MCP client (MCP Inspector), and AuthHub is participating in the OpenID MCP interoperability testing programme. It is not certified, and the interactive client login flow is provided by a fronting identity provider (Keycloak/Okta/Entra) — AuthHub is the authorization gateway, not the login server.

Conformance Test Results

Validated against the OpenID Foundation conformance suite (v5.2.0) — the same test harness used for official certification worldwide.

Test SuiteTestsResult
AuthZEN 1.0 — Evaluation (Interop + PDP Server)40+Passed
AuthZEN 1.0 — Batch Evaluations10+Passed
AuthZEN 1.0 — Subject Search20+Passed
AuthZEN 1.0 — Resource Search20+Passed
AuthZEN 1.0 — Action Search20+Passed

Architecture

Distributed systems built for low-latency authorization decisions at scale.

Google Zanzibar ReBAC

Relationship-based access control via SpiceDB — consistent, cached permission checks with low, predictable latency.

Multi-Tenant Namespace Isolation

Per-tenant cryptographic namespace prefixes ensure complete data separation in a shared authorization engine.

Three-Clock Governance

Event-time detection, attestation-time signatures, execution-time admissibility — zero temporal drift.

Circuit Breakers (Redis-backed)

Distributed circuit breakers on SpiceDB, ODS API, JWKS fetching, and webhook delivery prevent cascade failures.

Kafka/Redpanda Event Streaming

Audit events, governance signals, and webhook delivery via Kafka-compatible event bus with consumer group isolation.

Prometheus + Grafana Observability

Application metrics, SpiceDB latency histograms, and infrastructure dashboards with alerting.

Security Model

Zero-trust by default. Every token is bound, every decision is audited, every key is rotated.

DPoP Sender-Constrained Tokens

Tokens cryptographically bound to client key pairs — stolen tokens are useless without the private key. Fail-closed mode for NHS clinical safety.

XAA / Cross-App Access

Enterprise IdP-mediated agent authorization. AI agents and MCP tools access resources without per-user consent prompts or static secrets.

Break-Glass Emergency Access (AARP)

Time-limited clinical override with full audit trail, dual-clinician authorisation, and automatic revocation.

HSM-Ready Key Management

AES-256-GCM encrypted key storage with automated rotation, propagation delay, and 7-day retention. Thales Luna HSM integration planned.

GDPR Right to Erasure

Complete data erasure with erasure locks preventing re-creation. NHS 7-year immutable audit trail maintained.

AI Agent Governance

Registered agents with scope bounds, rate limits, human-in-the-loop approval, and delegated authorization via SpiceDB caveats.

NHS-Specific Capabilities

Purpose-built for the UK National Health Service — ODS codes, clinical safety, and DSPT compliance out of the box.

NHS CIS2 Federation (OIDC)

Consumes NHS Care Identity Service 2 OIDC tokens — users authenticate at CIS2 (Smartcard, Windows Hello) and AuthHub verifies the token and its NHS identity + ODS claims. Implemented; wiring into the live flow in progress.

NHS DSPT Alignment

Data Security and Protection Toolkit — policies, DPIA, risk register, and annual spot-check documentation maintained.

ODS Organisation Codes

Automatic ODS hierarchy resolution with FHIR API integration for trust/ICB/PCN validation.

Clinical Data Protection

Sensitive resource tagging, VIP patient protection, psychiatric note isolation, and Caldicott guardian overrides.

Break-Glass for Clinical Safety

Emergency override mechanism for A&E, cardiac arrest, and safeguarding scenarios with mandatory justification.

Want to see it in action?

Explore the interactive demos or start integrating with AuthHub today.