Public API Platform
A public, tenant-aware API that lets external clients and vendors read raw telemetry data, secured with Keycloak tokens and fronted by Azure API Management.
Customer
An industrial machinery business that engineers energy-efficient heating and cooling products and solutions for buildings, industry, infrastructure, and the food cold chain, with about 11,300 employees worldwide and €3.1bn in net sales.
Problem
External clients and vendors want to access raw store telemetry data from their own services through an API.
The goal was to create a public API for these clients, without exposing internal services and with each client seeing only the data that belongs to their tenant.
Architecture
Every external client gets a client ID and secret. The client first requests an access token from Keycloak, then calls the public API with that token. The API is exposed through Azure API Management, where a policy validates the token against Keycloak. Only valid requests are forwarded to the backend services, several of which expose public endpoints. The approach is tenant-based: each client can only read data that belongs to their own tenant.
My contribution
- Did the design and architecture of the public API approach end to end.
- Chose the client credentials model: every external client gets its own client ID and secret and exchanges them for a token before calling the API.
- Used Keycloak for authorization and token issuing.
- Placed Azure API Management at the edge, with a policy that validates the Keycloak token before any request reaches the backend.
- Defined which backend service endpoints are exposed publicly, so clients see a curated surface instead of internal services.
- Designed tenant-based access, so each client sees only the data related to their tenant.
Outcomes
- External clients and vendors can access their raw telemetry data through a secured, documented public API.
- Access is authenticated per client and limited to the client's own tenant.