Dmytro Onyshchenko
← All case studies

Public API Platform

A public, tenant-aware API that lets external clients and vendors read raw telemetry data, secured with Keycloak tokens and fronted by Azure API Management.

JavaQuarkusRESTOAuth2KeycloakAzure API ManagementMulti-tenancy

Customer

An industrial machinery business that engineers energy-efficient heating and cooling products and solutions for buildings, industry, infrastructure, and the food cold chain, with about 11,300 employees worldwide and €3.1bn in net sales.

Problem

External clients and vendors want to access raw store telemetry data from their own services through an API.

The goal was to create a public API for these clients, without exposing internal services and with each client seeing only the data that belongs to their tenant.

Architecture

Every external client gets a client ID and secret. The client first requests an access token from Keycloak, then calls the public API with that token. The API is exposed through Azure API Management, where a policy validates the token against Keycloak. Only valid requests are forwarded to the backend services, several of which expose public endpoints. The approach is tenant-based: each client can only read data that belongs to their own tenant.

My contribution

  • Did the design and architecture of the public API approach end to end.
  • Chose the client credentials model: every external client gets its own client ID and secret and exchanges them for a token before calling the API.
  • Used Keycloak for authorization and token issuing.
  • Placed Azure API Management at the edge, with a policy that validates the Keycloak token before any request reaches the backend.
  • Defined which backend service endpoints are exposed publicly, so clients see a curated surface instead of internal services.
  • Designed tenant-based access, so each client sees only the data related to their tenant.

Outcomes

  • External clients and vendors can access their raw telemetry data through a secured, documented public API.
  • Access is authenticated per client and limited to the client's own tenant.