Standard — AuthZ
Driving Interoperability: PlainID’s Native Integration with AuthZEN
Authorization logic written directly into application code is fragmented, hard to audit, and expensive to change. Externalizing that logic into Policy Enforcement Points (PEPs) and Policy Decision Points (PDPs) solves the hardcoding problem but introduces a new one: a lack of interoperability.
OpenID AuthZEN standardizes how authorization components communicate. PlainID supports the standard natively and is an active member of the working group behind it.
Subject
The entity requesting access — a user, service, or AI agent.
Resource
The asset or data object being accessed.
Action
The operation being performed — read, write, delete.
Context
Runtime signals — time, location, risk score, device posture.
PlainID & AuthZEN
Standardizing Authorization:
How PlainID is involved
PlainID is an active member of the OpenID Foundation’s AuthZEN Working Group and supported the standard on its path to Final Specification status. Support is native to the PlainID PDP, with no custom integration work required.
As a market leader in runtime authorization, PlainID is committed to removing roadblocks to adoption and promoting advanced authorization design patterns across the industry. We are proud to be an active member of the OpenID Foundation’s AuthZEN Working Group, helping to drive the standard forward while ensuring native support within our platform.
Active Working Group Member
PlainID participates in the OpenID Foundation’s AuthZEN Working Group, helping to shape the standard as it evolves.
Native Platform Support
The PlainID PDP natively supports the AuthZEN Authorization API 1.0. External enforcement points connect directly to the decision engine.
Broad Ecosystem Compatibility
Compatible with a broad spectrum of authorization engines and PDPs — from core IDPs to distributed microservices and data lakes.
Scale Without Rewriting
Scale an advanced authorization strategy that is fully compatible with your existing technology stack — no code rewrites required.
Standardization
A universal API connecting policy enforcement to decision engines
The AuthZEN Authorization API 1.0 specification standardizes the communication pattern between the PEP and the PDP. The PEP intercepts a request and asks a centralized PDP for an authorization decision. Requests use a standard JSON format built on four entities. The PDP evaluates them against its active policies and returns a boolean decision, optionally with response context such as step-up authentication requirements or policy advice. The specification also defines batch evaluations and search.
JSON — AuthZEN API 1.0
Authorization Request
{
"subject": {
"type": "user",
"id": "alice@acme.com"
},
"resource": {
"type": "report",
"id": "q4-financials"
},
"action": {
"name": "read"
},
"context": {
"ip": "192.168.1.10",
"time": "2026-04-29T09:30:00Z"
}
}
// PDP Response
{
"decision": true
}
Interoperability
Seamless interoperability with your existing tech stack
PlainID's native support for the Authorization API enables your PEPs to integrate seamlessly with any PDP that supports the standard, regardless of the underlying authorization model or policy language
This provides a universal interface that fundamentally decouples policy enforcement from the decision-making engine. With this standard in place, organizations can take full control of their authorization strategy by integrating their preferred PDPs—avoiding the need to ever rewrite application code, even if they switch authorization vendors down the line.
Flexible Architecture
The standard interface stays constant, eliminating the need to rewrite application code.
Integration agility
Use any compatible decision engine with complete flexibility.
Universal Enforcement
Any PEP can communicate with any AuthZEN-compatible PDP across your entire technology stack.
Resources
Go deeper
openid.net/wg/authzen
AuthZEN Authorization API 1.0 Specification
openid.net/wg/authzen/specifications
Talk to a PlainID authorization engineer
Get a technical walkthrough of AuthZEN support in the PlainID platform.


