While I was in Munich for APIDays recently I got to MC a talk from a group working on improving the standardization, adoption, and sharing of OAuth scopes across German government APIs. They had a whole stack of standards and approaches for driving consistency across many disparate teams, but it was their approach to federating OAuth scopes—technically, but also driving the discussion and the politics around it—that has really left me thinking. Not just about security, authentication, and authorization, but about the wider world of API governance.
A Federated API Governance Rule Registry
calendar_today
July 20, 2026
domain
programmableweb