SlideShare uma empresa Scribd logo
1 de 50
Baixar para ler offline
API Management Breakfast Seminar

 Francois Lascelles   Devon Winkworth             Mike Amundsen
 Chief Architect      Solutions Architect, APAC   Principal API Architect
Agenda

   API Management
     Overview and Trends
     Reaching out to Developers – B2D
     Publishing and Consuming APIs
     Engaging & Supporting Developers and Reporting the Results
   Break
   OAuth – the next step in Access Control
   Solving Mobile Challenges
   Customers Success Stories
   Summary and Wrap up
Challenges for the Modern Enterprise

X-Departments / X-Agency Connectivity       Build a Developer Channel with Open APIs
                                                 Publish Public APIs Reliably
    Real-time Supply Chain
                                                 Build Developer Ecosystems
    X-agency information sharing
                                                 Monetize Internal Information
    Media Syndication
                                                 Socialize Applications
    Trading Platforms




Cloud Access & Integration                  Connect Enterprise to Mobile Apps
                                    Login

    SaaS Access                 Password
                                                 BYOD Employee Enablement
    IaaS Integration & Governance               Field Enablement
    Hybrid Private / Public                     API Developer Communities
    Burst to the Cloud                          Smart Grid
Why APIs? The Rebirth of Applications




                        Enterprise API




                     Customers & Partners
Traditional “Closed” APIs


      Divisions

                                                Cloud




                        Enterprise
                           API

       Mobile


                                     Partners
The New “Open” API


      Divisions

                                       Cloud




                     Open
                      API

       Mobile


                            Partners
Third Parties are Key


       Divisions

                                          Cloud




                        Open
                         API

        Mobile


                               Partners
API Management Scope

    Developer


                  Developer Portal


                                                API
      App

                  API Gateway



                                     API Management Infrastructure

                    API Lifecycle                 Access control
                    Discovery, documentation      SLA enforcement
                    Developer onboarding          Threat protection
                    Performance, scaling          Analytics
                    Integration                   Monetization
Agenda

   API Management
     Overview and Trends
     Reaching out to Developers – B2D
     Publishing and Consuming APIs
     Engaging & Supporting Developers and Reporting the Results
   Break
   OAuth – the next step in Access Control
   Solving Mobile Challenges
   Customers Success Stories
   Summary and Wrap up
Attending to the Hockey Sticks
 More Devices
 More Apps
 More APIs
API Developers
 Developers are your target audience
 They need great tools to use your API
 They know what works
 And they tell others about it
Developers are your Target Audience
 APIs
 Developers
 Apps
 Users
They need great tools to use your API
 Docs
 Getting started
 Sandbox
 Registration
 Samples
Developers know what works…
 30 min to a quick win or else
  “It was easy for me to get started with this API.”
 Make them look good to peers and superiors
  “Hey, I know just the API we can use to solve this problem.”
 Make it easy for them to use/promote your API
  “Company X has a great API, you should try it.”
 Make it hard for them to mis-use/break your API
  “This API is very intuitive.”
…And they tell others about it.
 Conferences
 100+ developers, designers, project leaders
 Code-a-thons
 100- developers, API publishers, API hosts
 Meetups
 Local developers, designers, leadership
 - User Groups (~50)
 - Pub Nights (~25)
 Online
 Wide range of highly targeted communities
 - Forums
 - Chat rooms
 - Social media
Reaching out means…
 Know your target audience
 Give them the tools they need…
 To do their jobs well…
 So they will spread the good word.
Agenda

   API Management
     Overview and Trends
     Reaching out to Developers – B2D
     Publishing and Consuming APIs
     Engaging & Supporting Developers and Reporting the Results
   Break
   OAuth – the next step in Access Control
   Solving Mobile Challenges
   Customers Success Stories
   Summary and Wrap up
Example: Australia Sports API
 Sample API: Professional sports information aggregation
  - Teams
  - News
  - Results
Layer 7 Gateway

Ensure Privacy & Security Compliance:            Optimize API Traffic:




   Authorization &      Data Leak Prevention      Rate Limiting      API Key Management
   Authentication


                                                                    SOAP              REST
                                                                    XML                JSON
  Attack Prevention   Browser Exploit Blocking
                                                  Traffic Control        Transformations




Security                                         Control
Demo: Exposing an API with the Layer 7 Gateway



                            Gateway



                                         API
                                         endpoint

        REST Client




                        Policy Manager
Layer 7 Gateway Capabilities

                                  • Authentication: for different IAM, SAML, Oauth,
                                  • Authorization including Oauth, XACML
             Access Control       • Token translation / SAML STS
                                  • Horizon call back into enterprise
                                  • Identity federation across service zones



                                  • API threat protection
                                  • XML / JSON schema validation
                Security          • Data filtering, redaction
                                  • Data privacy: message- and field-level encryption
                                  • Data integrity: digital signatures, hashing, validation



                                  • Throttling, rate limiting, x-cluster message counter
                                  • Prioritization, traffic shaping and QoS
             Metering/SLA         • Content caching to reduce latency overhead
                                  • Monitoring, reporting on API usage
                                  • Activity reporting to IT management systems



                                  • Format conversion: SOAP/REST/JSON/XML
                                  • Protocol mediation: HTTP(S), messaging, file-based, SSH
          Abstraction/Mediation   • Dynamic content- and context-based routing
                                  • Composite services: in-line callouts, message enrichment
                                  • Workflow: fan-in, fan-out, looping, synch/asynch
Layer 7 Gateway Form Factors

           Hardware Appliance                              VMWare Virtual Appliance




               Rack mountable 1-U device                   Packaged virtual image of hardware appliance
Common criteria EAL 4+ certification, FIPS 140/2 level 3             “VMWare-ready” certified
 Optional hardware accelerator modules for XML, crypto           Open Virtualization Format (OVF)



                    Software                                  AWS Virtual Appliance




                                                                 Instantiate from your AMI catalog
Software installation for Linux or Solaris based systems
                                                            Integrate with EC2, RDS, Auto Scale, ELB
Agenda

   API Management
     Overview and Trends
     Reaching out to Developers – B2D
     Publishing and Consuming APIs
     Engaging & Supporting Developers and Reporting the Results
   Break
   OAuth – the next step in Access Control
   Solving Mobile Challenges
   Customers Success Stories
   Summary and Wrap up
Layer 7 API Portal Objectives

Drive Developer Adoption:            Provide Insight for all Stakeholders:




   Developer           API Docs             Analytics          Rankings
   Enrollment



                                      45%

                                      28%

     Forums           API Explorer
                                             Quotas           Task Tracking




Onboarding                           Reporting
Demo: API Portal
  Developer portal
   - Discover an API
   - Try the API
   - Register as a developer
   - Register an application
   - Get an API key
   - Metrics
   - Community
  Demo
Layer 7 API Portal Capabilities

                            • Self-service registration and colleague enrollment
                Developer   • Plans are provided to help you stratify developers into tiers
                            • Account managers assigned to help manage specific, high‐value partners
               Management   • Manage the generation of API keys/OAuth secrets for each developer
                              application



                            • Discussion Forums, integrated messaging, FAQs, Announcements to
                              foster community among developers
                Developer   • API Documentation, sample code/applications
                            • API Explorer to allow you to submit queries and see API responses
                 Support      interactively
                            • Reports that measure API usage, application usage and API latency


                            • Out‐of‐the‐box templates for API documents, landing pages, etc.
                            • Content can be versioned and rolled back
                 Content    • Personalized default dashboard for all developer and publisher users
               Management   • Look and feel easily changed (i.e. logos, fonts, colors, etc.)
                            • Control access to documentation and forums based on API status (i.e.
                              private vs. public)


                            • Account tiers defined to allow for developer grouping and actions
                            • Define unique and/or standard plans for each API
                Business    • Define quotas, rate limits and other features for each API plan
               Management   • Applications tracked as they move from development to test to production
                            • Application usage measured providing developer understanding and info
                              for planning
Time for a Break!!
Agenda

   API Management
     Overview and Trends
     Reaching out to Developers – B2D
     Publishing and Consuming APIs
     Engaging & Supporting Developers and Reporting the Results
   Break
   OAuth – the next step in Access Control
   Solving Mobile Challenges
   Customers Success Stories
   Summary and Wrap up
API access control

    You got an API key, now what?
    - An app is sometimes identified at runtime by including its API key in
      a query parameter
    - (that doesn’t count as access control)
    - Typically, the user of the mobile app needs to be authenticated
    - Standard: OAuth 2.0
    - Multiple grant types possible
    - Opaque, bearer tokens is the most common approach
OAuth Toolkit


                                                 Better Integration
                                                  – Leverage Existing Assets
                                                 Faster Time to Market
            OAuth 1            OAuth 2           Scaling
                                                  – Interpreted vs. Stateful Tokens
                                                  – Caching


        2 & 3-legged OAuth   OpenID Connect




      API
      Protection
Anatomy of an OAuth handshake
             (one of many possible grant types illustrated)


                                                                        OAuth Authorization Server

      Subscriber
(resource owner)                                              consent
                                                    1
                                                                        Authorization endpoint



                      1

         +autz code




                                                2                       Token endpoint
   Mobile App
      (client)                         +access token




                                       This is a shared secret
Why exchange a secret with an OAuth authorization
 server in the first place?


                                                   OAuth Provider
 A: In order to consume an API
                                                    OAuth Authorization Server




             Consume REST API
                                                    OAuth Resource Server
             With access token from handshake
                                                                                    API endpoint


                                                 access token -> app, user
                                                 Enforce access control policies
OAuth: Leverage existing identity, existing SSO



                      API Management
                       - Get SSO cookie, integrate with policy server
                         (web agent)

     <handshake>       - Associate SSO cookie with access token


         SSO token

                              Check SSO session



 Maintain my SSO
   experience!

                                              SSO Policy Server
Token Monitoring, Revocation
 Track usage of live tokens
 Integrate with portals, BI, provider tooling through open API
 Expose token revocation to the right parties


                                             Token Management                 Look for
                                                                              unusual
                                                                               usage
                          revoke                                              patterns
       Dev portal                                                    revoke

                         revoke
                                                    check
                                                                                 BI


                                                                              API Provider
     Subscriber portal
                                                             FAIL!

                                                   exploit
                         compromise
Agenda

   API Management
     Overview and Trends
     Reaching out to Developers – B2D
     Publishing and Consuming APIs
     Engaging & Supporting Developers and Reporting the Results
   Break
   OAuth – the next step in Access Control
   Solving Mobile Challenges
   Customers Success Stories
   Summary and Wrap up
Layer 7 Mobile Access Gateway
 A lightweight, low-latency mobile gateway for solving critical mobile challenges in the
  following areas:
Demo - Mobile Access Gateway

  Mobile Access Gateway
  - http/websocket/xmpp/push
  - Mobile notification hookup
    (APNS, Android)
  - Targeted notifications
  Demo
Layer 7 Mobile Access Gateway Capabilities

                          • Map Web SSO & SAML to mobile-friendly OAuth, OpenID Connect and JSON
                            Web Tokens
             Identity     • Create granular access policies at user, app and device levels
                          • Build composite access policies combining geolocation, message content etc.
                          • Simplify PKI-based certificate delivery and provisioning


                          • Protect REST, SOAP and OData APIs against DoS and API attacks
                          • Proxy API streaming protocols like HTML5 Web Sockets and XMPP messaging
             Security     • Enforce FIPS 140-2 grade data privacy and integrity
                          • Validate data exchanges, including all JSON, XML, header and parameter
                            content


                          • Surface any legacy application or database as RESTful APIs
                          • Quickly map between data formats such as XML and JSON
            Adoption      • Recompose & virtualize APIs to specific mobile identities, apps and devices
                          • Orchestrate API mashups with configurable workflow



                          • Cache calls to backend applications
                          • Recompose small backend calls into efficiently aggregated mobile requests
           Optimisation   • Compress traffic to minimize bandwidth costs and improve user experience
                          • Pre-fetch content for hypermedia-based API calls



                          • Proxy and manage app interactions with social networks
                          • Broker call-outs to cloud services like Salesforce.com
            Integration   • Bridge connectivity to iPhone, Windows and Android notification services
                          • Integrate with legacy applications using ESB capabilities
Agenda

   API Management
     Overview and Trends
     Reaching out to Developers – B2D
     Publishing and Consuming APIs
     Engaging & Supporting Developers and Reporting the Results
   Break
   OAuth – the next step in Access Control
   Solving Mobile Challenges
   Customers Success Stories
   Summary and Wrap up
Layer 7 API Management Implemented at 200+ Enterprise and
Government Customers
 Financial Services   Communications   Public Sector   Select Others
Case Study: Publishing Telecom APIs
 Problem: publicly exposing Telecom APIs presents some unique challenges around
  how they get packaged, secured and managed for easy consumption
 Solution: SecureSpan Networking Gateway policy-based controls allowed Orange to
  define the message, identity and interface level security for their APIs; track usage;
  monitor interface health; and update APIs without breaking client applications


                                                      “    Making Nursery [Telecom APIs]
                                                           available to local, 3rd world
                                                           partners has allowed Orange to
                                                           overcome many of the barriers
                                                           that had previously limited our   “
                                                           growth in emerging markets.
                                                           Benoît Herard, Orange Labs



 Results: Orange has created an agile IT platform on which to develop new offerings
  faster and at less cost by reusing/recomposing existing services
Case Study: APIs Expanding Market Reach
 Problem: wanted to securely expose existing services to third party developers in
  order to expand their market reach
 Solution: Layer 7 API Proxy allows Alaska to securely expose and manage their
  APIs, while caching Sabre requests




 Results: significantly grew market reach, while controlling costs associated with
  constantly pulling data from Sabre to service Developer requests
Case Study: APIs Enabling the Enterprise
 Problem: reduce cost and delay in processing Medicaid member information by
 bringing the process online
 Solution: SOA Gateway allows iPad application to securely connect to backend
 APIs; provides data routing & guards APIs against intrusion with strict authentication,
 authorization and comprehensive threat protection




 Results: improves Amerigroup’s health care coverage and member services, while
 increasing the effectiveness and efficiency of its Medicaid program
Case Study: Publishing Information Service APIs
 Problem: allow customers and partners to use Google Apps to access multiple,
  existing information services
 Solution: CloudControl authorizes users and applies rate limiting; converts REST
  queries to SOAP, and provides API aggregation & orchestration




                                               “   Layer 7 offered us the closest fit to our
                                                   business requirements in a single             “
                                                   product. No other vendor was even
                                                   close.
                                                   SOA Architect, World’s leading publisher of
                                                   science and health information




 Results: implemented business logic in policy (not code), decreasing maintenance
  costs; customers and partners can now obtain richer results to their queries from
  their platform of choice, simplifying and speeding information gathering
Case Study: SaaS & Mobile Integration
 Problem: securely integrate to SaaS services such as Salesforce.com and
  Workday, as well as secure mobile payments for Mastercard’s MoneySend service
 Solution: Layer 7 securely gates all interactions with cloud-based SaaS providers
  and mobile applications, authenticating and authorizing all inbound/outbound
  interactions




 Results: users manage only a single login/password for all systems; administrators
  manage a single LDAP, thereby enhancing security and lowering administration costs
Agenda

   API Management
     Overview and Trends
     Reaching out to Developers – B2D
     Publishing and Consuming APIs
     Engaging & Supporting Developers and Reporting the Results
   Break
   OAuth – the next step in Access Control
   Solving Mobile Challenges
   Customers Success Stories
   Summary and Wrap up
Challenges for the Modern Enterprise

X-Departments / X-Agency Connectivity       Build a Developer Channel with Open APIs
                                                 Publish Public APIs Reliably
    Real-time Supply Chain
                                                 Build Developer Ecosystems
    X-agency information sharing
                                                 Monetize Internal Information
    Media Syndication
                                                 Socialize Applications
    Trading Platforms




Cloud Access & Integration                  Connect Enterprise to Mobile Apps
                                    Login

    SaaS Access                 Password
                                                 BYOD Employee Enablement
    IaaS Integration & Governance               Field Enablement
    Hybrid Private / Public                     API Developer Communities
    Burst to the Cloud                          Smart Grid
Layer 7 – One Solution for 4 Hybrid Problem Spaces




Across Divisions & Partners                 Outside Developer Communities
      Simplify Information Sharing                    Build a developer channel
      Enable Centralized Shared Services              Monetize information assets
      Improve B2B                                     Improve customer reach
      Bridge ESB Domains                               Improve customer retention
           SOA Gateway                             
                                                           API Portal




           Cloud Access
          Help Enterprises Connect To
                                                          Across Mobile
           The Cloud
                                                     Mobile Developer Onboarding
          Help Service Providers Deliver
                                                     BYOD
           New Services
                                                     Mobile application management
          Deploy Security-as-a-cloud
           CloudConnect
           Service
                                                    Mobile Access Gateway
                                                     App security
Established Leader
                 The Forrester Wave:                                                                        Gartner Magic Quadrant
       SOA & API Application Gateways, Nov 2011                                                 For SOA & API Governance Technologies, Oct 2011
                Risky                           Strong
                Bets    Contenders            Performers                   Leaders
                                                                                                                                 challengers                         leaders
     Strong



                                                     Intel
                                                                     Vordel                                                                                                 Software AG
                                                Forum Systems
                                                                           IBM                                                                                     Oracle
                                                                                                                                                            IBM
                                                                                                                                                HP
                                                                                                                                                              Progress Software




                                                                                                    ability to execute
                                                                                                                                                                            Layer 7
                                                    Progress Software                                                                                    Tibco Software
                                                                                                                                                Vordel
     Current                                                 Software AG                                                                                           SOA Software
     Offering                                                                                                            Crosscheck Networks
                                                                                                                                                                             Mashery
                                   Bee Ware                                                                                            Managed Methods
                                                                                                                                                                      WS02
                                                    Tibco Software                                                                  Intel




                 Market Presence


      Weak

                Weak                              Strategy                           Strong                                     niche players                      visionaries
“Layer 7 SecureSpan is strong across the board. SecureSpan SOA Gateway                          “[Layer 7 has a] …. complete offering, with good coverage of general SOA
 scored well in all of the major functional evaluation categories…It has the                   governance (on-premises and in the cloud), B2B, ESB and API management
   broadest array of form factors and one of the strongest strategies for                     functionality…[The Company is] fast-moving, well on its way to implementing
                virtualization and cloud-based deployment.”                                        its good vision for SOA governance and the related marketplaces.”


Additional Notable Recognition
Thank You
For more information contact:
     Colman McCaffery
  cmccaffery@layer7tech.com
      + 61 413 776 428

Mais conteúdo relacionado

Mais procurados

API Strategy Introduction
API Strategy IntroductionAPI Strategy Introduction
API Strategy IntroductionDoug Gregory
 
Api-First service design
Api-First service designApi-First service design
Api-First service designStefaan Ponnet
 
API Management in Digital Transformation
API Management in Digital TransformationAPI Management in Digital Transformation
API Management in Digital TransformationAditya Thatte
 
API Management Solution Powerpoint Presentation Slides
API Management Solution Powerpoint Presentation SlidesAPI Management Solution Powerpoint Presentation Slides
API Management Solution Powerpoint Presentation SlidesSlideTeam
 
Deep dive: Monetize your API Programs
Deep dive: Monetize your API ProgramsDeep dive: Monetize your API Programs
Deep dive: Monetize your API ProgramsApigee | Google Cloud
 
Rest api standards and best practices
Rest api standards and best practicesRest api standards and best practices
Rest api standards and best practicesAnkita Mahajan
 
API Management - Why it matters!
API Management - Why it matters!API Management - Why it matters!
API Management - Why it matters!Sven Bernhardt
 
API Maturity Model (Webcast with Accenture)
API Maturity Model (Webcast with Accenture)API Maturity Model (Webcast with Accenture)
API Maturity Model (Webcast with Accenture)Apigee | Google Cloud
 
Building APIs with the OpenApi Spec
Building APIs with the OpenApi SpecBuilding APIs with the OpenApi Spec
Building APIs with the OpenApi SpecPedro J. Molina
 
API first Design and Microservices
API first Design and MicroservicesAPI first Design and Microservices
API first Design and MicroservicesSven Bernhardt
 
APIs as a Product Strategy
APIs as a Product StrategyAPIs as a Product Strategy
APIs as a Product StrategyRavi Kumar
 
APIsecure 2023 - API orchestration: to build resilient applications, Cherish ...
APIsecure 2023 - API orchestration: to build resilient applications, Cherish ...APIsecure 2023 - API orchestration: to build resilient applications, Cherish ...
APIsecure 2023 - API orchestration: to build resilient applications, Cherish ...apidays
 

Mais procurados (20)

API Design- Best Practices
API Design-   Best PracticesAPI Design-   Best Practices
API Design- Best Practices
 
API Strategy Introduction
API Strategy IntroductionAPI Strategy Introduction
API Strategy Introduction
 
API strategy with IBM API connect
API strategy with IBM API connectAPI strategy with IBM API connect
API strategy with IBM API connect
 
Guide to an API-first Strategy
Guide to an API-first StrategyGuide to an API-first Strategy
Guide to an API-first Strategy
 
Api-First service design
Api-First service designApi-First service design
Api-First service design
 
API Management in Digital Transformation
API Management in Digital TransformationAPI Management in Digital Transformation
API Management in Digital Transformation
 
API Management Solution Powerpoint Presentation Slides
API Management Solution Powerpoint Presentation SlidesAPI Management Solution Powerpoint Presentation Slides
API Management Solution Powerpoint Presentation Slides
 
Deep dive: Monetize your API Programs
Deep dive: Monetize your API ProgramsDeep dive: Monetize your API Programs
Deep dive: Monetize your API Programs
 
Rest api standards and best practices
Rest api standards and best practicesRest api standards and best practices
Rest api standards and best practices
 
API Management - Why it matters!
API Management - Why it matters!API Management - Why it matters!
API Management - Why it matters!
 
Definitive Guide to API Management
Definitive Guide to API ManagementDefinitive Guide to API Management
Definitive Guide to API Management
 
Apigee Edge Overview and Roadmap
Apigee Edge Overview and RoadmapApigee Edge Overview and Roadmap
Apigee Edge Overview and Roadmap
 
API Maturity Model (Webcast with Accenture)
API Maturity Model (Webcast with Accenture)API Maturity Model (Webcast with Accenture)
API Maturity Model (Webcast with Accenture)
 
Apigee Products Overview
Apigee Products OverviewApigee Products Overview
Apigee Products Overview
 
Building APIs with the OpenApi Spec
Building APIs with the OpenApi SpecBuilding APIs with the OpenApi Spec
Building APIs with the OpenApi Spec
 
Architecture for the API-enterprise
Architecture for the API-enterpriseArchitecture for the API-enterprise
Architecture for the API-enterprise
 
How Secure Are Your APIs?
How Secure Are Your APIs?How Secure Are Your APIs?
How Secure Are Your APIs?
 
API first Design and Microservices
API first Design and MicroservicesAPI first Design and Microservices
API first Design and Microservices
 
APIs as a Product Strategy
APIs as a Product StrategyAPIs as a Product Strategy
APIs as a Product Strategy
 
APIsecure 2023 - API orchestration: to build resilient applications, Cherish ...
APIsecure 2023 - API orchestration: to build resilient applications, Cherish ...APIsecure 2023 - API orchestration: to build resilient applications, Cherish ...
APIsecure 2023 - API orchestration: to build resilient applications, Cherish ...
 

Destaque

Cross Platform Mobile Apps with APIs from Qcon San Francisco
Cross Platform Mobile Apps with APIs from Qcon San FranciscoCross Platform Mobile Apps with APIs from Qcon San Francisco
Cross Platform Mobile Apps with APIs from Qcon San FranciscoCA API Management
 
Networks, cloud & operator innovation- Mats Alendal
Networks, cloud & operator innovation- Mats AlendalNetworks, cloud & operator innovation- Mats Alendal
Networks, cloud & operator innovation- Mats AlendalEricsson
 
Payveris_Whitepaper The Case for API in Retail Banking
Payveris_Whitepaper The Case for API in Retail BankingPayveris_Whitepaper The Case for API in Retail Banking
Payveris_Whitepaper The Case for API in Retail BankingWanda Gorges
 
Identity Management for the 21st Century IT Mission
Identity Management for the 21st Century IT MissionIdentity Management for the 21st Century IT Mission
Identity Management for the 21st Century IT MissionCA API Management
 
Kontomatik FinDEVr Presentation 2015
Kontomatik FinDEVr Presentation 2015Kontomatik FinDEVr Presentation 2015
Kontomatik FinDEVr Presentation 2015Kontomatik
 
Best Practices in Software Vendor Selection
Best Practices in Software Vendor SelectionBest Practices in Software Vendor Selection
Best Practices in Software Vendor SelectionAdvantiv Solutions, LLC
 
figo Banking API: A Banking Service Provider for FinTech Startups
figo Banking API: A Banking Service Provider for FinTech Startupsfigo Banking API: A Banking Service Provider for FinTech Startups
figo Banking API: A Banking Service Provider for FinTech StartupsLars Markull
 
API Adoption Patterns in Banking & The Promise of Microservices
API Adoption Patterns in Banking & The Promise of MicroservicesAPI Adoption Patterns in Banking & The Promise of Microservices
API Adoption Patterns in Banking & The Promise of MicroservicesAkana
 
APIdays Open Banking & Fintech: Workshop - Financial Services Use Cases for APIs
APIdays Open Banking & Fintech: Workshop - Financial Services Use Cases for APIsAPIdays Open Banking & Fintech: Workshop - Financial Services Use Cases for APIs
APIdays Open Banking & Fintech: Workshop - Financial Services Use Cases for APIsJeremy Brown
 
Digital Businesses of the Future
Digital Businesses of the Future Digital Businesses of the Future
Digital Businesses of the Future MuleSoft
 
Case Study: Open Banking, APIs and Digital Transformation—the Banco Original ...
Case Study: Open Banking, APIs and Digital Transformation—the Banco Original ...Case Study: Open Banking, APIs and Digital Transformation—the Banco Original ...
Case Study: Open Banking, APIs and Digital Transformation—the Banco Original ...CA Technologies
 
IBM DataPower Gateway - Common Use Cases
IBM DataPower Gateway - Common Use CasesIBM DataPower Gateway - Common Use Cases
IBM DataPower Gateway - Common Use CasesIBM DataPower Gateway
 
Ericsson Technology Review: Securing the cloud with compliance auditing
Ericsson Technology Review: Securing the cloud with compliance auditingEricsson Technology Review: Securing the cloud with compliance auditing
Ericsson Technology Review: Securing the cloud with compliance auditingEricsson
 
I Love APIs 2015 : Zero to Thousands TPS Private Cloud Operations Workshop
I Love APIs 2015 : Zero to Thousands TPS Private Cloud Operations WorkshopI Love APIs 2015 : Zero to Thousands TPS Private Cloud Operations Workshop
I Love APIs 2015 : Zero to Thousands TPS Private Cloud Operations WorkshopApigee | Google Cloud
 
API Management architect presentation
API Management architect presentationAPI Management architect presentation
API Management architect presentationsflynn073
 

Destaque (17)

Cross Platform Mobile Apps with APIs from Qcon San Francisco
Cross Platform Mobile Apps with APIs from Qcon San FranciscoCross Platform Mobile Apps with APIs from Qcon San Francisco
Cross Platform Mobile Apps with APIs from Qcon San Francisco
 
Networks, cloud & operator innovation- Mats Alendal
Networks, cloud & operator innovation- Mats AlendalNetworks, cloud & operator innovation- Mats Alendal
Networks, cloud & operator innovation- Mats Alendal
 
Payveris_Whitepaper The Case for API in Retail Banking
Payveris_Whitepaper The Case for API in Retail BankingPayveris_Whitepaper The Case for API in Retail Banking
Payveris_Whitepaper The Case for API in Retail Banking
 
APIs matter
APIs matterAPIs matter
APIs matter
 
Identity Management for the 21st Century IT Mission
Identity Management for the 21st Century IT MissionIdentity Management for the 21st Century IT Mission
Identity Management for the 21st Century IT Mission
 
Deep-Dive: Secure API Management
Deep-Dive: Secure API ManagementDeep-Dive: Secure API Management
Deep-Dive: Secure API Management
 
Kontomatik FinDEVr Presentation 2015
Kontomatik FinDEVr Presentation 2015Kontomatik FinDEVr Presentation 2015
Kontomatik FinDEVr Presentation 2015
 
Best Practices in Software Vendor Selection
Best Practices in Software Vendor SelectionBest Practices in Software Vendor Selection
Best Practices in Software Vendor Selection
 
figo Banking API: A Banking Service Provider for FinTech Startups
figo Banking API: A Banking Service Provider for FinTech Startupsfigo Banking API: A Banking Service Provider for FinTech Startups
figo Banking API: A Banking Service Provider for FinTech Startups
 
API Adoption Patterns in Banking & The Promise of Microservices
API Adoption Patterns in Banking & The Promise of MicroservicesAPI Adoption Patterns in Banking & The Promise of Microservices
API Adoption Patterns in Banking & The Promise of Microservices
 
APIdays Open Banking & Fintech: Workshop - Financial Services Use Cases for APIs
APIdays Open Banking & Fintech: Workshop - Financial Services Use Cases for APIsAPIdays Open Banking & Fintech: Workshop - Financial Services Use Cases for APIs
APIdays Open Banking & Fintech: Workshop - Financial Services Use Cases for APIs
 
Digital Businesses of the Future
Digital Businesses of the Future Digital Businesses of the Future
Digital Businesses of the Future
 
Case Study: Open Banking, APIs and Digital Transformation—the Banco Original ...
Case Study: Open Banking, APIs and Digital Transformation—the Banco Original ...Case Study: Open Banking, APIs and Digital Transformation—the Banco Original ...
Case Study: Open Banking, APIs and Digital Transformation—the Banco Original ...
 
IBM DataPower Gateway - Common Use Cases
IBM DataPower Gateway - Common Use CasesIBM DataPower Gateway - Common Use Cases
IBM DataPower Gateway - Common Use Cases
 
Ericsson Technology Review: Securing the cloud with compliance auditing
Ericsson Technology Review: Securing the cloud with compliance auditingEricsson Technology Review: Securing the cloud with compliance auditing
Ericsson Technology Review: Securing the cloud with compliance auditing
 
I Love APIs 2015 : Zero to Thousands TPS Private Cloud Operations Workshop
I Love APIs 2015 : Zero to Thousands TPS Private Cloud Operations WorkshopI Love APIs 2015 : Zero to Thousands TPS Private Cloud Operations Workshop
I Love APIs 2015 : Zero to Thousands TPS Private Cloud Operations Workshop
 
API Management architect presentation
API Management architect presentationAPI Management architect presentation
API Management architect presentation
 

Semelhante a Melbourne API Management Seminar

AADI Mashery/Coca-Cola Enterprises November 2012
AADI Mashery/Coca-Cola Enterprises November 2012  AADI Mashery/Coca-Cola Enterprises November 2012
AADI Mashery/Coca-Cola Enterprises November 2012 BAPISFNYLONDON
 
Triangle Node Meetup : APIs in Minutes with Node.js
Triangle Node Meetup :  APIs in Minutes with Node.jsTriangle Node Meetup :  APIs in Minutes with Node.js
Triangle Node Meetup : APIs in Minutes with Node.jsShubhra Kar
 
AWS Customer Presentation - Alcatel Lucent
AWS Customer Presentation - Alcatel LucentAWS Customer Presentation - Alcatel Lucent
AWS Customer Presentation - Alcatel LucentAmazon Web Services
 
WSO2Con EU 2015: Case Study – Digital Transformation: To Monetise Business by...
WSO2Con EU 2015: Case Study – Digital Transformation: To Monetise Business by...WSO2Con EU 2015: Case Study – Digital Transformation: To Monetise Business by...
WSO2Con EU 2015: Case Study – Digital Transformation: To Monetise Business by...WSO2
 
Digital Transformation: Connected API Ecosystems
Digital Transformation: Connected API EcosystemsDigital Transformation: Connected API Ecosystems
Digital Transformation: Connected API EcosystemsHARMAN Services
 
Enable Oauth2.0 with Sentinet API Management (Massimo Crippa @ BTUG Event)
Enable Oauth2.0 with Sentinet API Management (Massimo Crippa @ BTUG Event)Enable Oauth2.0 with Sentinet API Management (Massimo Crippa @ BTUG Event)
Enable Oauth2.0 with Sentinet API Management (Massimo Crippa @ BTUG Event)Codit
 
Microservices&amp;ap imanagement
Microservices&amp;ap imanagementMicroservices&amp;ap imanagement
Microservices&amp;ap imanagementpramodkumards
 
2013 02-apache conna-api-manager-asanka
2013 02-apache conna-api-manager-asanka2013 02-apache conna-api-manager-asanka
2013 02-apache conna-api-manager-asankaWSO2
 
APIdays Barcelona 2019 - How a Cloud native Architecture helps to drive Busin...
APIdays Barcelona 2019 - How a Cloud native Architecture helps to drive Busin...APIdays Barcelona 2019 - How a Cloud native Architecture helps to drive Busin...
APIdays Barcelona 2019 - How a Cloud native Architecture helps to drive Busin...apidays
 
Oracle API Platform Cloud Service Best Practices & Lessons Learnt
Oracle API Platform Cloud Service Best Practices & Lessons LearntOracle API Platform Cloud Service Best Practices & Lessons Learnt
Oracle API Platform Cloud Service Best Practices & Lessons Learntluisw19
 
2014 q3-platform-update-v1.06.johnmathon
2014 q3-platform-update-v1.06.johnmathon2014 q3-platform-update-v1.06.johnmathon
2014 q3-platform-update-v1.06.johnmathonaaronwso2
 
Securely expose protected resources as ap is with app42 api gateway
Securely expose protected resources as ap is with app42 api gatewaySecurely expose protected resources as ap is with app42 api gateway
Securely expose protected resources as ap is with app42 api gatewayZuaib
 
Api management customer
Api management customerApi management customer
Api management customernick_garrod
 
Federation Evolved: How Cloud, Mobile & APIs Change the Way We Broker Identity
Federation Evolved: How Cloud, Mobile & APIs Change the Way We Broker IdentityFederation Evolved: How Cloud, Mobile & APIs Change the Way We Broker Identity
Federation Evolved: How Cloud, Mobile & APIs Change the Way We Broker IdentityCA API Management
 
Azure IPaaS: #IntegrationEvolved (Glenn Colpaert @ Codit's BizTalk 2016 Launch)
Azure IPaaS: #IntegrationEvolved (Glenn Colpaert @ Codit's BizTalk 2016 Launch)Azure IPaaS: #IntegrationEvolved (Glenn Colpaert @ Codit's BizTalk 2016 Launch)
Azure IPaaS: #IntegrationEvolved (Glenn Colpaert @ Codit's BizTalk 2016 Launch)Codit
 
A great api is hard to find
A great api is hard to findA great api is hard to find
A great api is hard to findDan Diephouse
 
Manage your ap is securely and easily ibm apim 4.0
Manage your ap is securely and easily ibm apim 4.0Manage your ap is securely and easily ibm apim 4.0
Manage your ap is securely and easily ibm apim 4.0sflynn073
 
APIs and Beyond
APIs and BeyondAPIs and Beyond
APIs and BeyondWSO2
 

Semelhante a Melbourne API Management Seminar (20)

AADI Mashery/Coca-Cola Enterprises November 2012
AADI Mashery/Coca-Cola Enterprises November 2012  AADI Mashery/Coca-Cola Enterprises November 2012
AADI Mashery/Coca-Cola Enterprises November 2012
 
Triangle Node Meetup : APIs in Minutes with Node.js
Triangle Node Meetup :  APIs in Minutes with Node.jsTriangle Node Meetup :  APIs in Minutes with Node.js
Triangle Node Meetup : APIs in Minutes with Node.js
 
AWS Customer Presentation - Alcatel Lucent
AWS Customer Presentation - Alcatel LucentAWS Customer Presentation - Alcatel Lucent
AWS Customer Presentation - Alcatel Lucent
 
WSO2Con EU 2015: Case Study – Digital Transformation: To Monetise Business by...
WSO2Con EU 2015: Case Study – Digital Transformation: To Monetise Business by...WSO2Con EU 2015: Case Study – Digital Transformation: To Monetise Business by...
WSO2Con EU 2015: Case Study – Digital Transformation: To Monetise Business by...
 
Digital Transformation: Connected API Ecosystems
Digital Transformation: Connected API EcosystemsDigital Transformation: Connected API Ecosystems
Digital Transformation: Connected API Ecosystems
 
Enable Oauth2.0 with Sentinet API Management (Massimo Crippa @ BTUG Event)
Enable Oauth2.0 with Sentinet API Management (Massimo Crippa @ BTUG Event)Enable Oauth2.0 with Sentinet API Management (Massimo Crippa @ BTUG Event)
Enable Oauth2.0 with Sentinet API Management (Massimo Crippa @ BTUG Event)
 
Microservices&amp;ap imanagement
Microservices&amp;ap imanagementMicroservices&amp;ap imanagement
Microservices&amp;ap imanagement
 
2013 02-apache conna-api-manager-asanka
2013 02-apache conna-api-manager-asanka2013 02-apache conna-api-manager-asanka
2013 02-apache conna-api-manager-asanka
 
APIdays Barcelona 2019 - How a Cloud native Architecture helps to drive Busin...
APIdays Barcelona 2019 - How a Cloud native Architecture helps to drive Busin...APIdays Barcelona 2019 - How a Cloud native Architecture helps to drive Busin...
APIdays Barcelona 2019 - How a Cloud native Architecture helps to drive Busin...
 
Oracle API Platform Cloud Service Best Practices & Lessons Learnt
Oracle API Platform Cloud Service Best Practices & Lessons LearntOracle API Platform Cloud Service Best Practices & Lessons Learnt
Oracle API Platform Cloud Service Best Practices & Lessons Learnt
 
2014 q3-platform-update-v1.06.johnmathon
2014 q3-platform-update-v1.06.johnmathon2014 q3-platform-update-v1.06.johnmathon
2014 q3-platform-update-v1.06.johnmathon
 
Open api in enterprise
Open api in enterpriseOpen api in enterprise
Open api in enterprise
 
Securely expose protected resources as ap is with app42 api gateway
Securely expose protected resources as ap is with app42 api gatewaySecurely expose protected resources as ap is with app42 api gateway
Securely expose protected resources as ap is with app42 api gateway
 
Api management customer
Api management customerApi management customer
Api management customer
 
Federation Evolved: How Cloud, Mobile & APIs Change the Way We Broker Identity
Federation Evolved: How Cloud, Mobile & APIs Change the Way We Broker IdentityFederation Evolved: How Cloud, Mobile & APIs Change the Way We Broker Identity
Federation Evolved: How Cloud, Mobile & APIs Change the Way We Broker Identity
 
Azure IPaaS: #IntegrationEvolved (Glenn Colpaert @ Codit's BizTalk 2016 Launch)
Azure IPaaS: #IntegrationEvolved (Glenn Colpaert @ Codit's BizTalk 2016 Launch)Azure IPaaS: #IntegrationEvolved (Glenn Colpaert @ Codit's BizTalk 2016 Launch)
Azure IPaaS: #IntegrationEvolved (Glenn Colpaert @ Codit's BizTalk 2016 Launch)
 
A great api is hard to find
A great api is hard to findA great api is hard to find
A great api is hard to find
 
Manage your ap is securely and easily ibm apim 4.0
Manage your ap is securely and easily ibm apim 4.0Manage your ap is securely and easily ibm apim 4.0
Manage your ap is securely and easily ibm apim 4.0
 
Agility and DevOps on AWS
Agility and DevOps on AWSAgility and DevOps on AWS
Agility and DevOps on AWS
 
APIs and Beyond
APIs and BeyondAPIs and Beyond
APIs and Beyond
 

Mais de CA API Management

Api architectures for the modern enterprise
Api architectures for the modern enterpriseApi architectures for the modern enterprise
Api architectures for the modern enterpriseCA API Management
 
Mastering Digital Channels with APIs
Mastering Digital Channels with APIsMastering Digital Channels with APIs
Mastering Digital Channels with APIsCA API Management
 
Takeaways from API Security Breaches Webinar
Takeaways from API Security Breaches WebinarTakeaways from API Security Breaches Webinar
Takeaways from API Security Breaches WebinarCA API Management
 
API Design Methodology - Mike Amundsen, Director of API Architecture, API Aca...
API Design Methodology - Mike Amundsen, Director of API Architecture, API Aca...API Design Methodology - Mike Amundsen, Director of API Architecture, API Aca...
API Design Methodology - Mike Amundsen, Director of API Architecture, API Aca...CA API Management
 
Liberating the API Economy with Scale-Free Networks - Mike Amundsen, Director...
Liberating the API Economy with Scale-Free Networks - Mike Amundsen, Director...Liberating the API Economy with Scale-Free Networks - Mike Amundsen, Director...
Liberating the API Economy with Scale-Free Networks - Mike Amundsen, Director...CA API Management
 
API360 – A How-To Guide for Enterprise APIs - Learn how to position your ente...
API360 – A How-To Guide for Enterprise APIs - Learn how to position your ente...API360 – A How-To Guide for Enterprise APIs - Learn how to position your ente...
API360 – A How-To Guide for Enterprise APIs - Learn how to position your ente...CA API Management
 
API Monetization: Unlock the Value of Your Data
API Monetization: Unlock the Value of Your DataAPI Monetization: Unlock the Value of Your Data
API Monetization: Unlock the Value of Your DataCA API Management
 
Revisiting Geddes' Outlook Tower - Mike Amundsen, Director of API Architectur...
Revisiting Geddes' Outlook Tower - Mike Amundsen, Director of API Architectur...Revisiting Geddes' Outlook Tower - Mike Amundsen, Director of API Architectur...
Revisiting Geddes' Outlook Tower - Mike Amundsen, Director of API Architectur...CA API Management
 
Managing Identity by Giving Up Control - Scott Morrison, SVP & Distinguished ...
Managing Identity by Giving Up Control - Scott Morrison, SVP & Distinguished ...Managing Identity by Giving Up Control - Scott Morrison, SVP & Distinguished ...
Managing Identity by Giving Up Control - Scott Morrison, SVP & Distinguished ...CA API Management
 
Enabling the Multi-Device Universe
Enabling the Multi-Device UniverseEnabling the Multi-Device Universe
Enabling the Multi-Device UniverseCA API Management
 
Building APIs That Last for Decades - Irakli Nadareishvili, Director of API S...
Building APIs That Last for Decades - Irakli Nadareishvili, Director of API S...Building APIs That Last for Decades - Irakli Nadareishvili, Director of API S...
Building APIs That Last for Decades - Irakli Nadareishvili, Director of API S...CA API Management
 
The Art of API Design - Ronnie Mitra, Director of API Design, API Academy at ...
The Art of API Design - Ronnie Mitra, Director of API Design, API Academy at ...The Art of API Design - Ronnie Mitra, Director of API Design, API Academy at ...
The Art of API Design - Ronnie Mitra, Director of API Design, API Academy at ...CA API Management
 
APIs Fueling the Connected Car Opportunity - Scott Morrison, SVP & Distinguis...
APIs Fueling the Connected Car Opportunity - Scott Morrison, SVP & Distinguis...APIs Fueling the Connected Car Opportunity - Scott Morrison, SVP & Distinguis...
APIs Fueling the Connected Car Opportunity - Scott Morrison, SVP & Distinguis...CA API Management
 
Adapting to Digital Change: Use APIs to Delight Customers & Win
Adapting to Digital Change: Use APIs to Delight Customers & WinAdapting to Digital Change: Use APIs to Delight Customers & Win
Adapting to Digital Change: Use APIs to Delight Customers & WinCA API Management
 
Balancing Security & Developer Enablement in Enterprise Mobility - Jaime Ryan...
Balancing Security & Developer Enablement in Enterprise Mobility - Jaime Ryan...Balancing Security & Developer Enablement in Enterprise Mobility - Jaime Ryan...
Balancing Security & Developer Enablement in Enterprise Mobility - Jaime Ryan...CA API Management
 
5 steps end to end security consumer apps
5 steps end to end security consumer apps5 steps end to end security consumer apps
5 steps end to end security consumer appsCA API Management
 
Best Practices You Must Apply to Secure Your APIs - Scott Morrison, SVP & Dis...
Best Practices You Must Apply to Secure Your APIs - Scott Morrison, SVP & Dis...Best Practices You Must Apply to Secure Your APIs - Scott Morrison, SVP & Dis...
Best Practices You Must Apply to Secure Your APIs - Scott Morrison, SVP & Dis...CA API Management
 
Drones, Phones & Pwns the Promise & Dangers of IoT APIs: Use APIs to Securely...
Drones, Phones & Pwns the Promise & Dangers of IoT APIs: Use APIs to Securely...Drones, Phones & Pwns the Promise & Dangers of IoT APIs: Use APIs to Securely...
Drones, Phones & Pwns the Promise & Dangers of IoT APIs: Use APIs to Securely...CA API Management
 
Gartner AADI Summit Sydney 2014 Implementing the Layer 7 API Management Pla...
Gartner AADI Summit Sydney 2014   Implementing the Layer 7 API Management Pla...Gartner AADI Summit Sydney 2014   Implementing the Layer 7 API Management Pla...
Gartner AADI Summit Sydney 2014 Implementing the Layer 7 API Management Pla...CA API Management
 
Using APIs to Create an Omni-Channel Retail Experience
Using APIs to Create an Omni-Channel Retail ExperienceUsing APIs to Create an Omni-Channel Retail Experience
Using APIs to Create an Omni-Channel Retail ExperienceCA API Management
 

Mais de CA API Management (20)

Api architectures for the modern enterprise
Api architectures for the modern enterpriseApi architectures for the modern enterprise
Api architectures for the modern enterprise
 
Mastering Digital Channels with APIs
Mastering Digital Channels with APIsMastering Digital Channels with APIs
Mastering Digital Channels with APIs
 
Takeaways from API Security Breaches Webinar
Takeaways from API Security Breaches WebinarTakeaways from API Security Breaches Webinar
Takeaways from API Security Breaches Webinar
 
API Design Methodology - Mike Amundsen, Director of API Architecture, API Aca...
API Design Methodology - Mike Amundsen, Director of API Architecture, API Aca...API Design Methodology - Mike Amundsen, Director of API Architecture, API Aca...
API Design Methodology - Mike Amundsen, Director of API Architecture, API Aca...
 
Liberating the API Economy with Scale-Free Networks - Mike Amundsen, Director...
Liberating the API Economy with Scale-Free Networks - Mike Amundsen, Director...Liberating the API Economy with Scale-Free Networks - Mike Amundsen, Director...
Liberating the API Economy with Scale-Free Networks - Mike Amundsen, Director...
 
API360 – A How-To Guide for Enterprise APIs - Learn how to position your ente...
API360 – A How-To Guide for Enterprise APIs - Learn how to position your ente...API360 – A How-To Guide for Enterprise APIs - Learn how to position your ente...
API360 – A How-To Guide for Enterprise APIs - Learn how to position your ente...
 
API Monetization: Unlock the Value of Your Data
API Monetization: Unlock the Value of Your DataAPI Monetization: Unlock the Value of Your Data
API Monetization: Unlock the Value of Your Data
 
Revisiting Geddes' Outlook Tower - Mike Amundsen, Director of API Architectur...
Revisiting Geddes' Outlook Tower - Mike Amundsen, Director of API Architectur...Revisiting Geddes' Outlook Tower - Mike Amundsen, Director of API Architectur...
Revisiting Geddes' Outlook Tower - Mike Amundsen, Director of API Architectur...
 
Managing Identity by Giving Up Control - Scott Morrison, SVP & Distinguished ...
Managing Identity by Giving Up Control - Scott Morrison, SVP & Distinguished ...Managing Identity by Giving Up Control - Scott Morrison, SVP & Distinguished ...
Managing Identity by Giving Up Control - Scott Morrison, SVP & Distinguished ...
 
Enabling the Multi-Device Universe
Enabling the Multi-Device UniverseEnabling the Multi-Device Universe
Enabling the Multi-Device Universe
 
Building APIs That Last for Decades - Irakli Nadareishvili, Director of API S...
Building APIs That Last for Decades - Irakli Nadareishvili, Director of API S...Building APIs That Last for Decades - Irakli Nadareishvili, Director of API S...
Building APIs That Last for Decades - Irakli Nadareishvili, Director of API S...
 
The Art of API Design - Ronnie Mitra, Director of API Design, API Academy at ...
The Art of API Design - Ronnie Mitra, Director of API Design, API Academy at ...The Art of API Design - Ronnie Mitra, Director of API Design, API Academy at ...
The Art of API Design - Ronnie Mitra, Director of API Design, API Academy at ...
 
APIs Fueling the Connected Car Opportunity - Scott Morrison, SVP & Distinguis...
APIs Fueling the Connected Car Opportunity - Scott Morrison, SVP & Distinguis...APIs Fueling the Connected Car Opportunity - Scott Morrison, SVP & Distinguis...
APIs Fueling the Connected Car Opportunity - Scott Morrison, SVP & Distinguis...
 
Adapting to Digital Change: Use APIs to Delight Customers & Win
Adapting to Digital Change: Use APIs to Delight Customers & WinAdapting to Digital Change: Use APIs to Delight Customers & Win
Adapting to Digital Change: Use APIs to Delight Customers & Win
 
Balancing Security & Developer Enablement in Enterprise Mobility - Jaime Ryan...
Balancing Security & Developer Enablement in Enterprise Mobility - Jaime Ryan...Balancing Security & Developer Enablement in Enterprise Mobility - Jaime Ryan...
Balancing Security & Developer Enablement in Enterprise Mobility - Jaime Ryan...
 
5 steps end to end security consumer apps
5 steps end to end security consumer apps5 steps end to end security consumer apps
5 steps end to end security consumer apps
 
Best Practices You Must Apply to Secure Your APIs - Scott Morrison, SVP & Dis...
Best Practices You Must Apply to Secure Your APIs - Scott Morrison, SVP & Dis...Best Practices You Must Apply to Secure Your APIs - Scott Morrison, SVP & Dis...
Best Practices You Must Apply to Secure Your APIs - Scott Morrison, SVP & Dis...
 
Drones, Phones & Pwns the Promise & Dangers of IoT APIs: Use APIs to Securely...
Drones, Phones & Pwns the Promise & Dangers of IoT APIs: Use APIs to Securely...Drones, Phones & Pwns the Promise & Dangers of IoT APIs: Use APIs to Securely...
Drones, Phones & Pwns the Promise & Dangers of IoT APIs: Use APIs to Securely...
 
Gartner AADI Summit Sydney 2014 Implementing the Layer 7 API Management Pla...
Gartner AADI Summit Sydney 2014   Implementing the Layer 7 API Management Pla...Gartner AADI Summit Sydney 2014   Implementing the Layer 7 API Management Pla...
Gartner AADI Summit Sydney 2014 Implementing the Layer 7 API Management Pla...
 
Using APIs to Create an Omni-Channel Retail Experience
Using APIs to Create an Omni-Channel Retail ExperienceUsing APIs to Create an Omni-Channel Retail Experience
Using APIs to Create an Omni-Channel Retail Experience
 

Último

Unblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesUnblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesSinan KOZAK
 
A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024Results
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024The Digital Insurer
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountPuma Security, LLC
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking MenDelhi Call girls
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonetsnaman860154
 
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure serviceWhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure servicePooja Nehwal
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEarley Information Science
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc
 
Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101Paola De la Torre
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Servicegiselly40
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slidevu2urc
 
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsTop 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsRoshan Dwivedi
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024The Digital Insurer
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024Rafal Los
 
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...gurkirankumar98700
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityPrincipled Technologies
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsEnterprise Knowledge
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationRadu Cotescu
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 

Último (20)

Unblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesUnblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen Frames
 
A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path Mount
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure serviceWhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
 
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsTop 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 

Melbourne API Management Seminar

  • 1. API Management Breakfast Seminar Francois Lascelles Devon Winkworth Mike Amundsen Chief Architect Solutions Architect, APAC Principal API Architect
  • 2. Agenda API Management Overview and Trends Reaching out to Developers – B2D Publishing and Consuming APIs Engaging & Supporting Developers and Reporting the Results Break OAuth – the next step in Access Control Solving Mobile Challenges Customers Success Stories Summary and Wrap up
  • 3. Challenges for the Modern Enterprise X-Departments / X-Agency Connectivity Build a Developer Channel with Open APIs  Publish Public APIs Reliably  Real-time Supply Chain  Build Developer Ecosystems  X-agency information sharing  Monetize Internal Information  Media Syndication  Socialize Applications  Trading Platforms Cloud Access & Integration Connect Enterprise to Mobile Apps Login  SaaS Access Password  BYOD Employee Enablement  IaaS Integration & Governance  Field Enablement  Hybrid Private / Public  API Developer Communities  Burst to the Cloud  Smart Grid
  • 4. Why APIs? The Rebirth of Applications Enterprise API Customers & Partners
  • 5. Traditional “Closed” APIs Divisions Cloud Enterprise API Mobile Partners
  • 6. The New “Open” API Divisions Cloud Open API Mobile Partners
  • 7. Third Parties are Key Divisions Cloud Open API Mobile Partners
  • 8. API Management Scope Developer Developer Portal API App API Gateway API Management Infrastructure  API Lifecycle  Access control  Discovery, documentation  SLA enforcement  Developer onboarding  Threat protection  Performance, scaling  Analytics  Integration  Monetization
  • 9. Agenda API Management Overview and Trends Reaching out to Developers – B2D Publishing and Consuming APIs Engaging & Supporting Developers and Reporting the Results Break OAuth – the next step in Access Control Solving Mobile Challenges Customers Success Stories Summary and Wrap up
  • 10. Attending to the Hockey Sticks  More Devices  More Apps  More APIs
  • 11. API Developers  Developers are your target audience  They need great tools to use your API  They know what works  And they tell others about it
  • 12. Developers are your Target Audience  APIs  Developers  Apps  Users
  • 13. They need great tools to use your API  Docs  Getting started  Sandbox  Registration  Samples
  • 14. Developers know what works…  30 min to a quick win or else “It was easy for me to get started with this API.”  Make them look good to peers and superiors “Hey, I know just the API we can use to solve this problem.”  Make it easy for them to use/promote your API “Company X has a great API, you should try it.”  Make it hard for them to mis-use/break your API “This API is very intuitive.”
  • 15. …And they tell others about it.  Conferences 100+ developers, designers, project leaders  Code-a-thons 100- developers, API publishers, API hosts  Meetups Local developers, designers, leadership - User Groups (~50) - Pub Nights (~25)  Online Wide range of highly targeted communities - Forums - Chat rooms - Social media
  • 16. Reaching out means…  Know your target audience  Give them the tools they need…  To do their jobs well…  So they will spread the good word.
  • 17. Agenda API Management Overview and Trends Reaching out to Developers – B2D Publishing and Consuming APIs Engaging & Supporting Developers and Reporting the Results Break OAuth – the next step in Access Control Solving Mobile Challenges Customers Success Stories Summary and Wrap up
  • 18. Example: Australia Sports API  Sample API: Professional sports information aggregation - Teams - News - Results
  • 19. Layer 7 Gateway Ensure Privacy & Security Compliance: Optimize API Traffic: Authorization & Data Leak Prevention Rate Limiting API Key Management Authentication SOAP REST XML JSON Attack Prevention Browser Exploit Blocking Traffic Control Transformations Security Control
  • 20. Demo: Exposing an API with the Layer 7 Gateway Gateway API endpoint REST Client Policy Manager
  • 21. Layer 7 Gateway Capabilities • Authentication: for different IAM, SAML, Oauth, • Authorization including Oauth, XACML Access Control • Token translation / SAML STS • Horizon call back into enterprise • Identity federation across service zones • API threat protection • XML / JSON schema validation Security • Data filtering, redaction • Data privacy: message- and field-level encryption • Data integrity: digital signatures, hashing, validation • Throttling, rate limiting, x-cluster message counter • Prioritization, traffic shaping and QoS Metering/SLA • Content caching to reduce latency overhead • Monitoring, reporting on API usage • Activity reporting to IT management systems • Format conversion: SOAP/REST/JSON/XML • Protocol mediation: HTTP(S), messaging, file-based, SSH Abstraction/Mediation • Dynamic content- and context-based routing • Composite services: in-line callouts, message enrichment • Workflow: fan-in, fan-out, looping, synch/asynch
  • 22. Layer 7 Gateway Form Factors Hardware Appliance VMWare Virtual Appliance Rack mountable 1-U device Packaged virtual image of hardware appliance Common criteria EAL 4+ certification, FIPS 140/2 level 3 “VMWare-ready” certified Optional hardware accelerator modules for XML, crypto Open Virtualization Format (OVF) Software AWS Virtual Appliance Instantiate from your AMI catalog Software installation for Linux or Solaris based systems Integrate with EC2, RDS, Auto Scale, ELB
  • 23. Agenda API Management Overview and Trends Reaching out to Developers – B2D Publishing and Consuming APIs Engaging & Supporting Developers and Reporting the Results Break OAuth – the next step in Access Control Solving Mobile Challenges Customers Success Stories Summary and Wrap up
  • 24. Layer 7 API Portal Objectives Drive Developer Adoption: Provide Insight for all Stakeholders: Developer API Docs Analytics Rankings Enrollment 45% 28% Forums API Explorer Quotas Task Tracking Onboarding Reporting
  • 25. Demo: API Portal  Developer portal - Discover an API - Try the API - Register as a developer - Register an application - Get an API key - Metrics - Community  Demo
  • 26. Layer 7 API Portal Capabilities • Self-service registration and colleague enrollment Developer • Plans are provided to help you stratify developers into tiers • Account managers assigned to help manage specific, high‐value partners Management • Manage the generation of API keys/OAuth secrets for each developer application • Discussion Forums, integrated messaging, FAQs, Announcements to foster community among developers Developer • API Documentation, sample code/applications • API Explorer to allow you to submit queries and see API responses Support interactively • Reports that measure API usage, application usage and API latency • Out‐of‐the‐box templates for API documents, landing pages, etc. • Content can be versioned and rolled back Content • Personalized default dashboard for all developer and publisher users Management • Look and feel easily changed (i.e. logos, fonts, colors, etc.) • Control access to documentation and forums based on API status (i.e. private vs. public) • Account tiers defined to allow for developer grouping and actions • Define unique and/or standard plans for each API Business • Define quotas, rate limits and other features for each API plan Management • Applications tracked as they move from development to test to production • Application usage measured providing developer understanding and info for planning
  • 27. Time for a Break!!
  • 28. Agenda API Management Overview and Trends Reaching out to Developers – B2D Publishing and Consuming APIs Engaging & Supporting Developers and Reporting the Results Break OAuth – the next step in Access Control Solving Mobile Challenges Customers Success Stories Summary and Wrap up
  • 29. API access control  You got an API key, now what? - An app is sometimes identified at runtime by including its API key in a query parameter - (that doesn’t count as access control) - Typically, the user of the mobile app needs to be authenticated - Standard: OAuth 2.0 - Multiple grant types possible - Opaque, bearer tokens is the most common approach
  • 30. OAuth Toolkit  Better Integration – Leverage Existing Assets  Faster Time to Market OAuth 1 OAuth 2  Scaling – Interpreted vs. Stateful Tokens – Caching 2 & 3-legged OAuth OpenID Connect API Protection
  • 31. Anatomy of an OAuth handshake (one of many possible grant types illustrated) OAuth Authorization Server Subscriber (resource owner) consent 1 Authorization endpoint 1 +autz code 2 Token endpoint Mobile App (client) +access token This is a shared secret
  • 32. Why exchange a secret with an OAuth authorization server in the first place? OAuth Provider  A: In order to consume an API OAuth Authorization Server Consume REST API OAuth Resource Server With access token from handshake API endpoint  access token -> app, user  Enforce access control policies
  • 33. OAuth: Leverage existing identity, existing SSO  API Management - Get SSO cookie, integrate with policy server (web agent) <handshake> - Associate SSO cookie with access token SSO token Check SSO session Maintain my SSO experience!  SSO Policy Server
  • 34. Token Monitoring, Revocation  Track usage of live tokens  Integrate with portals, BI, provider tooling through open API  Expose token revocation to the right parties Token Management Look for unusual usage revoke patterns Dev portal revoke revoke check BI API Provider Subscriber portal FAIL! exploit compromise
  • 35. Agenda API Management Overview and Trends Reaching out to Developers – B2D Publishing and Consuming APIs Engaging & Supporting Developers and Reporting the Results Break OAuth – the next step in Access Control Solving Mobile Challenges Customers Success Stories Summary and Wrap up
  • 36. Layer 7 Mobile Access Gateway  A lightweight, low-latency mobile gateway for solving critical mobile challenges in the following areas:
  • 37. Demo - Mobile Access Gateway  Mobile Access Gateway - http/websocket/xmpp/push - Mobile notification hookup (APNS, Android) - Targeted notifications  Demo
  • 38. Layer 7 Mobile Access Gateway Capabilities • Map Web SSO & SAML to mobile-friendly OAuth, OpenID Connect and JSON Web Tokens Identity • Create granular access policies at user, app and device levels • Build composite access policies combining geolocation, message content etc. • Simplify PKI-based certificate delivery and provisioning • Protect REST, SOAP and OData APIs against DoS and API attacks • Proxy API streaming protocols like HTML5 Web Sockets and XMPP messaging Security • Enforce FIPS 140-2 grade data privacy and integrity • Validate data exchanges, including all JSON, XML, header and parameter content • Surface any legacy application or database as RESTful APIs • Quickly map between data formats such as XML and JSON Adoption • Recompose & virtualize APIs to specific mobile identities, apps and devices • Orchestrate API mashups with configurable workflow • Cache calls to backend applications • Recompose small backend calls into efficiently aggregated mobile requests Optimisation • Compress traffic to minimize bandwidth costs and improve user experience • Pre-fetch content for hypermedia-based API calls • Proxy and manage app interactions with social networks • Broker call-outs to cloud services like Salesforce.com Integration • Bridge connectivity to iPhone, Windows and Android notification services • Integrate with legacy applications using ESB capabilities
  • 39. Agenda API Management Overview and Trends Reaching out to Developers – B2D Publishing and Consuming APIs Engaging & Supporting Developers and Reporting the Results Break OAuth – the next step in Access Control Solving Mobile Challenges Customers Success Stories Summary and Wrap up
  • 40. Layer 7 API Management Implemented at 200+ Enterprise and Government Customers Financial Services Communications Public Sector Select Others
  • 41. Case Study: Publishing Telecom APIs  Problem: publicly exposing Telecom APIs presents some unique challenges around how they get packaged, secured and managed for easy consumption  Solution: SecureSpan Networking Gateway policy-based controls allowed Orange to define the message, identity and interface level security for their APIs; track usage; monitor interface health; and update APIs without breaking client applications “ Making Nursery [Telecom APIs] available to local, 3rd world partners has allowed Orange to overcome many of the barriers that had previously limited our “ growth in emerging markets. Benoît Herard, Orange Labs  Results: Orange has created an agile IT platform on which to develop new offerings faster and at less cost by reusing/recomposing existing services
  • 42. Case Study: APIs Expanding Market Reach  Problem: wanted to securely expose existing services to third party developers in order to expand their market reach  Solution: Layer 7 API Proxy allows Alaska to securely expose and manage their APIs, while caching Sabre requests  Results: significantly grew market reach, while controlling costs associated with constantly pulling data from Sabre to service Developer requests
  • 43. Case Study: APIs Enabling the Enterprise  Problem: reduce cost and delay in processing Medicaid member information by bringing the process online  Solution: SOA Gateway allows iPad application to securely connect to backend APIs; provides data routing & guards APIs against intrusion with strict authentication, authorization and comprehensive threat protection  Results: improves Amerigroup’s health care coverage and member services, while increasing the effectiveness and efficiency of its Medicaid program
  • 44. Case Study: Publishing Information Service APIs  Problem: allow customers and partners to use Google Apps to access multiple, existing information services  Solution: CloudControl authorizes users and applies rate limiting; converts REST queries to SOAP, and provides API aggregation & orchestration “ Layer 7 offered us the closest fit to our business requirements in a single “ product. No other vendor was even close. SOA Architect, World’s leading publisher of science and health information  Results: implemented business logic in policy (not code), decreasing maintenance costs; customers and partners can now obtain richer results to their queries from their platform of choice, simplifying and speeding information gathering
  • 45. Case Study: SaaS & Mobile Integration  Problem: securely integrate to SaaS services such as Salesforce.com and Workday, as well as secure mobile payments for Mastercard’s MoneySend service  Solution: Layer 7 securely gates all interactions with cloud-based SaaS providers and mobile applications, authenticating and authorizing all inbound/outbound interactions  Results: users manage only a single login/password for all systems; administrators manage a single LDAP, thereby enhancing security and lowering administration costs
  • 46. Agenda API Management Overview and Trends Reaching out to Developers – B2D Publishing and Consuming APIs Engaging & Supporting Developers and Reporting the Results Break OAuth – the next step in Access Control Solving Mobile Challenges Customers Success Stories Summary and Wrap up
  • 47. Challenges for the Modern Enterprise X-Departments / X-Agency Connectivity Build a Developer Channel with Open APIs  Publish Public APIs Reliably  Real-time Supply Chain  Build Developer Ecosystems  X-agency information sharing  Monetize Internal Information  Media Syndication  Socialize Applications  Trading Platforms Cloud Access & Integration Connect Enterprise to Mobile Apps Login  SaaS Access Password  BYOD Employee Enablement  IaaS Integration & Governance  Field Enablement  Hybrid Private / Public  API Developer Communities  Burst to the Cloud  Smart Grid
  • 48. Layer 7 – One Solution for 4 Hybrid Problem Spaces Across Divisions & Partners Outside Developer Communities  Simplify Information Sharing  Build a developer channel  Enable Centralized Shared Services  Monetize information assets  Improve B2B  Improve customer reach  Bridge ESB Domains Improve customer retention SOA Gateway  API Portal Cloud Access  Help Enterprises Connect To Across Mobile The Cloud  Mobile Developer Onboarding  Help Service Providers Deliver  BYOD New Services  Mobile application management  Deploy Security-as-a-cloud CloudConnect Service Mobile Access Gateway  App security
  • 49. Established Leader The Forrester Wave: Gartner Magic Quadrant SOA & API Application Gateways, Nov 2011 For SOA & API Governance Technologies, Oct 2011 Risky Strong Bets Contenders Performers Leaders challengers leaders Strong Intel Vordel Software AG Forum Systems IBM Oracle IBM HP Progress Software ability to execute Layer 7 Progress Software Tibco Software Vordel Current Software AG SOA Software Offering Crosscheck Networks Mashery Bee Ware Managed Methods WS02 Tibco Software Intel Market Presence Weak Weak Strategy Strong niche players visionaries “Layer 7 SecureSpan is strong across the board. SecureSpan SOA Gateway “[Layer 7 has a] …. complete offering, with good coverage of general SOA scored well in all of the major functional evaluation categories…It has the governance (on-premises and in the cloud), B2B, ESB and API management broadest array of form factors and one of the strongest strategies for functionality…[The Company is] fast-moving, well on its way to implementing virtualization and cloud-based deployment.” its good vision for SOA governance and the related marketplaces.” Additional Notable Recognition
  • 50. Thank You For more information contact: Colman McCaffery cmccaffery@layer7tech.com + 61 413 776 428