SlideShare une entreprise Scribd logo
1  sur  67
Télécharger pour lire hors ligne
Key points of an API
strategy
Dorian Rougier
May 2022
|
Your speaker
Dorian Rougier
Expert APIM
May 2022
Key points of an API strategy 3
|
The digital
imperative
API oriented
Architecture
New assets,
new
management
Secure APIs
Monitor API
Usage and
performance
Key takeouts
Key points of an API Strategy
May 2022
Key points of an API strategy 4
|
The digital imperative
May 2022
Key points of an API strategy 5
|
• “Any time, Anywhere, Any device”
are the key problems of
digitalization
• The opening of the information
system is a major issue
Why digital strategy
May 2022
Key points of an API strategy 6
|
API are a solution providing “Business Agility”
• APIs are the interface to offer service
• API Management is the process to manage API
• API Strategy is not only put in place an API Management
Are APIs a solution ?
May 2022
Key points of an API strategy 7
|
API Oriented Architecture
May 2022
Key points of an API strategy 8
|
• API : Application Programming Interface : normalized
interface to offer service
• API is not a technology
• API is a product
• API is about creating business value
• APIs should be designed to deliver business outcomes
API
May 2022
Key points of an API strategy 9
|
Level 1 “ Internal API ”
API used by the company
Level 2 “ Partner API ”
API used by internal developers&
partner developers
Level 3 “ Open API”
API used by internal developers,partner
developers & external developers
API Levels
May 2022
Key points of an API strategy 10
At level 1 : the success is to involveevery internalapplication touse API
At level 3 : the success depend of the registrationprocess and the quality of its documentation
|
Organizational impact
May 2022
Key points of an API strategy 11
|
Our solution packaged workshop
May 2022
Key points of an API strategy 12
|
Define your KPIs
May 2022
Key points of an API strategy 13
|
New assets, new management
May 2022
Key points of an API strategy 14
|
API Publisher
API Administrator
App Developers
Users Policy Developers
Devices
Apps
Register andmanage API lifecycle
Performpartner, policy andprocess
admin
Monitor andreport API use
Create andextendcustompolicies
Integratewithapplications and
infrastructure
APIs
Self-registertoresources
Browse andlearnAPIs
Manage applicationcredentials
Deploy
Connect
May 2022
Key points of an API strategy 15
| May 2022
Key points of an API strategy 16
|
Secure APIs
May 2022
Key points of an API strategy 17
|
Gateway
May 2022
Key points of an API strategy
• Link external apps to internal apps, with security, using SOA and APIs
Solution
Challenges
Identity Management
Authentication
Authorization
Audit
API Management
Services
Applications
Data
Backend Services
Messaging
Internal or
partner
18
|
Service Broker
May 2022
Key points of an API strategy
• An “outbound Gateway”
• Connects to services, partners, and the Cloud
Solution
Challenges
Applies
Security
Services
Applications
Data
Backend Services
Messaging
API Management
Cloud and on
premise
Partners
Com Agency
19
|
Token Mediation
May 2022
Key points of an API strategy
Identities Tokens
Repositories Authorization
Security Infrastructure
Extensive set of connectors to SecurityInfrastructure
Service Request
Service/User Credential
Validated Access
Throttled Request
External App
Identity Management
Authentication
Authorization
Audit
Transformed Response Standard Response
API Gateway
• Manage heterogeneous security infrastructure
Solution
Challenges
20
|
Token Mediation
May 2022
Key points of an API strategy 21
Azure
Access token
Get ADFS
Access token
Validate ADFS
Access token
Azure
Access token
ADFS
Access token Validate ADFS
Access token
ADFS DMZ
Access token Get ADFS
Access token
|
Monitor API usage and
performance
May 2022
Key points of an API strategy 22
|
API Portal
May 2022
Key points of an API strategy 23
|
API Analytics
May 2022
Key points of an API strategy 24
|
Key takeouts
May 2022
Key points of an API strategy 25
|
• API Management tool is not a golden hammer
• Address minor part of an API Strategy
• Implement all feature of the APIM before use it
• You must iterate on the implementation of the tool
• API Management not manage the versioning
• The version must instead be crafted and developed at the
applicative level
Common mistakes
May 2022
Key points of an API strategy 26
|
• Think about your API governance strategy
• Design API with a clear documentation
• Don’t expose all your service, only useful services
• Put in place metrics
Recommendations
May 2022
Key points of an API strategy 27
|
Questions
May 2022
Key points of an API strategy 28
|
SmartWave S.A.
Chemin de la Scie 4A – CH-1290 Versoix
Tel. +41 22 783 20 20
Fax +41 22 783 20 22
www.smartwavesa.com
May 2022
Key points of an API strategy
Your contact
DorianRougier
Mob. +41 79 375 90 91
drougier@smartwavesa.com
Senior Consultant
29
|
API Strategy
May 2022
Key points of an API strategy 30
API-First
Company
|
Use cases
May 2022
Key points of an API strategy 31
|
Governance
Typical use cases
May 2022
Key points of an API strategy 32
|
Solution
Challenges
API Governance
May 2022
Key points of an API strategy
• Exposeexisting applications as APIs, securely.
• Onboard developers who want to use your APIs
• Manage large amount of API
Retailers
33
| May 2022
Key points of an API strategy 34
Best Practices
Processes
RACI
KPI
Business
Cases
Drivers
API
Management
Concept
Stakeholder
Map
Stakeholder Map Use Cases KPI Governance
Analysis Design
Best Practices
Governance
|
RACI & Processes
May 2022
Key points of an API strategy 35
|
API exposition
Typical use cases
May 2022
Key points of an API strategy 36
|
Gateway
May 2022
Key points of an API strategy
• Link external apps to internal apps, with security, using SOA and APIs
Solution
Challenges
Identity Management
Authentication
Authorization
Audit
API Management
Services
Applications
Data
Backend Services
Messaging
Internal or
partner
37
|
Service Broker
May 2022
Key points of an API strategy
• An “outbound Gateway”
• Connects to services, partners, and the Cloud
Solution
Challenges
Applies
Security
Services
Applications
Data
Backend Services
Messaging
API Management
Cloud and on
premise
Partners
Com Agency
38
|
Multiple exposition
May 2022
Key points of an API strategy 39
|
Token Mediation
Typical use cases
May 2022
Key points of an API strategy 40
|
Token Mediation
May 2022
Key points of an API strategy
Identities Tokens
Repositories Authorization
Security Infrastructure
Extensive set of connectors to SecurityInfrastructure
Service Request
Service/User Credential
Validated Access
Throttled Request
External App
Identity Management
Authentication
Authorization
Audit
Transformed Response Standard Response
API Gateway
• Manage heterogeneous security infrastructure
Solution
Challenges
41
|
Oauth Implicit / Auth code
App Interne
User
Gateway
API
(+ Access Token)
Response
Valid Access Token
Back-end
Ask Internal token
ADFS
API + Backend Token
AzureAD
Authentication
Get Access Token
Azure Acess token
Backend token
Response
Valid Backend Token
Valid Access Token
Token Mediation
May 2022
Key points of an API strategy 42
|
Token Mediation
May 2022
Key points of an API strategy 43
Azure
Access token
Get ADFS
Access token
Validate ADFS
Access token
Azure
Access token
ADFS
Access token Validate ADFS
Access token
ADFS DMZ
Access token Get ADFS
Access token
|
Omni Chanel and modernization
May 2022
Key points of an API strategy 44
|
Services
Applications
Data
Backend Services
Messaging
Services
Applications
Data
Backend Services
Messaging
API Modernization / Integration
May 2022
Key points of an API strategy
Solution
Challenge
• Protocol and message mediation
• Service Modernization
HTTP
REST/SOAP
JSON/XML
FTP
JMS JMS
HTTP
REST/SOAP
JSON/XML
FTP
API Gateway
For Backend Service
45
|
Mobile & Single Page App Solution
May 2022
Key points of an API strategy
• Mobile apps require access to data which is behind the firewall
• Technologies such as OAuth must be used to authenticate clients
Solution
Challenge
UX Multi-canal REST
Secure
API Gateway
Services
Applications
Data
Backend Services
Messaging
46
|
Hybrid integration
May 2022
Key points of an API strategy 47
|
Project implementation
May 2022
Key points of an API strategy 48
| May 2022
Key points of an API strategy 49
|
API Publisher
API Administrator
App Developers
Users Policy Developers
Devices
Apps
Register andmanage API lifecycle
Performpartner, policy andprocess
admin
Monitor andreport API use
Create andextendcustompolicies
Integratewithapplications and
infrastructure
APIs
Self-registertoresources
Browse andlearnAPIs
Manage applicationcredentials
Deploy
Connect
May 2022
Key points of an API strategy 50
|
Architecture definition
May 2022
Key points of an API strategy
App Interne
App Externe
API
Management
DMZ
API
Management
Interne
Interne
DMZ
Internet / Partner
BAckend App
Access
point
protection
(WAF)
API Portal
DMZ
API Portal
Interne
App Interne
App Externe
API
Management
DMZ
API
Management
Interne
Interne
DMZ
Internet / Partner
BAckend App
Access
point
protection
(WAF)
API Portal
DMZ
API Portal
Interne
51
|
• #1 Front security definition
• User / Application / IDP
• #2 Backend Security
• #3 Security enforcement by zone
• #4 Consolidation
Security Definition
May 2022
Key points of an API strategy 52
|
Governance
May 2022
Key points of an API strategy 53
|
• Which product most suitable
• Architecture
• Security : Front (multiple, simple, IDP) / backend (standard, legacy, SaaS)
• Governance : organization / role / user
• Traffic monitoring
• Customization
• Integration in CI / CD
Solution definition
May 2022
Key points of an API strategy 54
|
Operation
Foundation Pilot
Change
Management
Project Phase
May 2022
Key points of an API strategy 55
• Installation
• Configuration
• Policies developement
• Analyitcs
• CI/CD
• Adapt governance
• API best practice
• Implement governance
• Support new backend
• Security update
• API linter
• API Community
|
Typical New Customer APIM Project
May 2022
Key points of an API strategy 56
STUDY POC BUILD RUN
• Architecture
• Security
• Governance
• Validateaspects
of study
• Platform
• Security policy
• Governance
|
Integrate at the
begin of the project
governance aspect
Promote platform
to other projects
since day 1 for
better ROI
Force every new
external API to use
the gateway for
normalized security
API roadmap
definition in the
project
Usage case of the
pilot
Put in place IDP
solution before
APIM
Lesson learn from our clients
May 2022
Key points of an API strategy 57
|
How do we deliver value
May 2022
Key points of an API strategy 58
BUILD
CARE
To build your digital transformation projects
To support and maintain your applications
EMPOWER
To strengthen your technical team
|
Backup
May 2022
Key points of an API strategy 59
|
• Convention center managing
100+ shows per year
• Information system composed
of on premises and cloud
applications
• Limited IT budget and team (7)
• Share volatile information with
partners: price list, exhibitor
list
Context
• Automate information sharing:
remove manual actions
• Complex information access:
located in an ERP not designed
to expose data
• Many integration cases: cash
register, web site, mobile
• Sensitive information: Need to
limit access
Challenges
Case study 1: digitalize partners’ relationship
May 2022
Key points of an API strategy 60
|
On premise
Apps
Web Site
App A
Case study 1: solution architecture
May 2022
Key points of an API strategy
API Gateway
ERP
Database
Enterprise
Service Bus
Cloud
Apps
Cash Register
DMZ INTERNAL
On premise
Apps
Internet
Data access
services
API Manager IDP
Firewall
INTERNET
ERP
Mobile
61
|
• Simplified and acceleratedpartner data exchange: 7 API to
automate information sharing
• Improveddata quality:no risk of human error by full
automation
• Low investment: less than 20 days
• Easy integration:no change in the existing applications
• Foundationfor the future:Easy to add new services in the
platform and support current and future integrations
• Fresh data and internalsystemsprotected: cache and
throttling functions to secure application exposition
Results
Case study 1: API Management for everyone
May 2022
Key points of an API strategy 62
|
• Define a v1 of the future roles, responsibilities and processes for your new
API Management Solution.
Roles, responsibilities & processes
Description
May 2022
Key points of an API strategy 64
Align
Stakeholders
• Drivers
• Concepts & Terms
• Goals/Expectations
3
Workshops
• Roles &
Responsibilities
• Processes
• Stakeholder
dynamics
Restitution
• RACI Matrix
• Processes
|
Roles, responsibilities & processes
Workshop preview
May 2022
Key points of an API strategy 65
|
Define your KPIs
May 2022
Key points of an API strategy 66
|
• REST Concepts
• API Contract
• Data model and naming conventions
• Responses and monitoring
• API life cycle, versioning
Best Practice Agenda
May 2022
Key points of an API strategy 67
|
• Work with the business to
• Define function
• Create data model
• Validate sequence between API
• Create API contract following Best Practice
Design API
May 2022
Key points of an API strategy 68

Contenu connexe

Similaire à How to build an API strategy - Dorian Rougierx.

apidays London 2023 - API Metrics matters in APIOps, Ludovic Pourrat, Lombar...
apidays London 2023 - API Metrics matters in APIOps, Ludovic Pourrat,  Lombar...apidays London 2023 - API Metrics matters in APIOps, Ludovic Pourrat,  Lombar...
apidays London 2023 - API Metrics matters in APIOps, Ludovic Pourrat, Lombar...apidays
 
apidays LIVE Paris - Succeeding with API Programs by Kiran Nadgir
apidays LIVE Paris - Succeeding with API Programs by Kiran Nadgirapidays LIVE Paris - Succeeding with API Programs by Kiran Nadgir
apidays LIVE Paris - Succeeding with API Programs by Kiran Nadgirapidays
 
Enforcing Your Organization's API Design Standards with SwaggerHub
Enforcing Your Organization's API Design Standards with SwaggerHubEnforcing Your Organization's API Design Standards with SwaggerHub
Enforcing Your Organization's API Design Standards with SwaggerHubSmartBear
 
Manage your ap is securely and easily ibm apim 4.0
Manage your ap is securely and easily ibm apim 4.0Manage your ap is securely and easily ibm apim 4.0
Manage your ap is securely and easily ibm apim 4.0sflynn073
 
[WSO2 Summit Sydney 2019] Building a Successful API Strategy from Scratch and...
[WSO2 Summit Sydney 2019] Building a Successful API Strategy from Scratch and...[WSO2 Summit Sydney 2019] Building a Successful API Strategy from Scratch and...
[WSO2 Summit Sydney 2019] Building a Successful API Strategy from Scratch and...WSO2
 
APIs In Action -Harnessing the Power of Azure API Management: Building Robust...
APIs In Action -Harnessing the Power of Azure API Management: Building Robust...APIs In Action -Harnessing the Power of Azure API Management: Building Robust...
APIs In Action -Harnessing the Power of Azure API Management: Building Robust...Hamida Rebai Trabelsi
 
Crafting an API Strategy with an API Marketplace
Crafting an API Strategy with an API MarketplaceCrafting an API Strategy with an API Marketplace
Crafting an API Strategy with an API MarketplaceWSO2
 
API Management
API ManagementAPI Management
API ManagementProlifics
 
How to Navigate your Product Career and API Product Management by PayPal Sr PMs
How to Navigate your Product Career and API Product Management by PayPal Sr PMsHow to Navigate your Product Career and API Product Management by PayPal Sr PMs
How to Navigate your Product Career and API Product Management by PayPal Sr PMsProduct School
 
Azure Spring Clean 2024 event - Azure API Management: Architecting for Perfor...
Azure Spring Clean 2024 event - Azure API Management: Architecting for Perfor...Azure Spring Clean 2024 event - Azure API Management: Architecting for Perfor...
Azure Spring Clean 2024 event - Azure API Management: Architecting for Perfor...Hamida Rebai Trabelsi
 
apidays LIVE Paris - Practical API strategy with APIOps Cycles by Marjukka Ni...
apidays LIVE Paris - Practical API strategy with APIOps Cycles by Marjukka Ni...apidays LIVE Paris - Practical API strategy with APIOps Cycles by Marjukka Ni...
apidays LIVE Paris - Practical API strategy with APIOps Cycles by Marjukka Ni...apidays
 
Deep-Dive: API Analytics and Business KPIs - Measure what matters
Deep-Dive: API Analytics and Business KPIs - Measure what mattersDeep-Dive: API Analytics and Business KPIs - Measure what matters
Deep-Dive: API Analytics and Business KPIs - Measure what mattersApigee | Google Cloud
 
What's New in API Connect & DataPower Gateway in 1H 2018
What's New in API Connect & DataPower Gateway in 1H 2018What's New in API Connect & DataPower Gateway in 1H 2018
What's New in API Connect & DataPower Gateway in 1H 2018IBM API Connect
 
Χάρης Λιναρδάκης, IBM Cloud Leader Greece and Cyprus at IBM
Χάρης Λιναρδάκης, IBM Cloud Leader Greece and Cyprus at IBMΧάρης Λιναρδάκης, IBM Cloud Leader Greece and Cyprus at IBM
Χάρης Λιναρδάκης, IBM Cloud Leader Greece and Cyprus at IBMStarttech Ventures
 
Lessons in Transforming the Enterprise to an API Platform
Lessons in Transforming the Enterprise to an API PlatformLessons in Transforming the Enterprise to an API Platform
Lessons in Transforming the Enterprise to an API PlatformLaunchAny
 
La Digital Transformation ha un nuovo alleato: Value Stream Management
La Digital Transformation ha un nuovo alleato: Value Stream ManagementLa Digital Transformation ha un nuovo alleato: Value Stream Management
La Digital Transformation ha un nuovo alleato: Value Stream ManagementEmerasoft, solutions to collaborate
 

Similaire à How to build an API strategy - Dorian Rougierx. (20)

Apigee Edge Product Demo
Apigee Edge Product DemoApigee Edge Product Demo
Apigee Edge Product Demo
 
apidays London 2023 - API Metrics matters in APIOps, Ludovic Pourrat, Lombar...
apidays London 2023 - API Metrics matters in APIOps, Ludovic Pourrat,  Lombar...apidays London 2023 - API Metrics matters in APIOps, Ludovic Pourrat,  Lombar...
apidays London 2023 - API Metrics matters in APIOps, Ludovic Pourrat, Lombar...
 
apidays LIVE Paris - Succeeding with API Programs by Kiran Nadgir
apidays LIVE Paris - Succeeding with API Programs by Kiran Nadgirapidays LIVE Paris - Succeeding with API Programs by Kiran Nadgir
apidays LIVE Paris - Succeeding with API Programs by Kiran Nadgir
 
Enforcing Your Organization's API Design Standards with SwaggerHub
Enforcing Your Organization's API Design Standards with SwaggerHubEnforcing Your Organization's API Design Standards with SwaggerHub
Enforcing Your Organization's API Design Standards with SwaggerHub
 
Manage your ap is securely and easily ibm apim 4.0
Manage your ap is securely and easily ibm apim 4.0Manage your ap is securely and easily ibm apim 4.0
Manage your ap is securely and easily ibm apim 4.0
 
Webcast: Apigee Edge Product Demo
Webcast: Apigee Edge Product DemoWebcast: Apigee Edge Product Demo
Webcast: Apigee Edge Product Demo
 
[WSO2 Summit Sydney 2019] Building a Successful API Strategy from Scratch and...
[WSO2 Summit Sydney 2019] Building a Successful API Strategy from Scratch and...[WSO2 Summit Sydney 2019] Building a Successful API Strategy from Scratch and...
[WSO2 Summit Sydney 2019] Building a Successful API Strategy from Scratch and...
 
APIs In Action -Harnessing the Power of Azure API Management: Building Robust...
APIs In Action -Harnessing the Power of Azure API Management: Building Robust...APIs In Action -Harnessing the Power of Azure API Management: Building Robust...
APIs In Action -Harnessing the Power of Azure API Management: Building Robust...
 
Crafting an API Strategy with an API Marketplace
Crafting an API Strategy with an API MarketplaceCrafting an API Strategy with an API Marketplace
Crafting an API Strategy with an API Marketplace
 
API Management
API ManagementAPI Management
API Management
 
How to Navigate your Product Career and API Product Management by PayPal Sr PMs
How to Navigate your Product Career and API Product Management by PayPal Sr PMsHow to Navigate your Product Career and API Product Management by PayPal Sr PMs
How to Navigate your Product Career and API Product Management by PayPal Sr PMs
 
Azure Spring Clean 2024 event - Azure API Management: Architecting for Perfor...
Azure Spring Clean 2024 event - Azure API Management: Architecting for Perfor...Azure Spring Clean 2024 event - Azure API Management: Architecting for Perfor...
Azure Spring Clean 2024 event - Azure API Management: Architecting for Perfor...
 
apidays LIVE Paris - Practical API strategy with APIOps Cycles by Marjukka Ni...
apidays LIVE Paris - Practical API strategy with APIOps Cycles by Marjukka Ni...apidays LIVE Paris - Practical API strategy with APIOps Cycles by Marjukka Ni...
apidays LIVE Paris - Practical API strategy with APIOps Cycles by Marjukka Ni...
 
Deep-Dive: API Analytics and Business KPIs - Measure what matters
Deep-Dive: API Analytics and Business KPIs - Measure what mattersDeep-Dive: API Analytics and Business KPIs - Measure what matters
Deep-Dive: API Analytics and Business KPIs - Measure what matters
 
What's New in API Connect & DataPower Gateway in 1H 2018
What's New in API Connect & DataPower Gateway in 1H 2018What's New in API Connect & DataPower Gateway in 1H 2018
What's New in API Connect & DataPower Gateway in 1H 2018
 
Χάρης Λιναρδάκης, IBM Cloud Leader Greece and Cyprus at IBM
Χάρης Λιναρδάκης, IBM Cloud Leader Greece and Cyprus at IBMΧάρης Λιναρδάκης, IBM Cloud Leader Greece and Cyprus at IBM
Χάρης Λιναρδάκης, IBM Cloud Leader Greece and Cyprus at IBM
 
API strategy with IBM API connect
API strategy with IBM API connectAPI strategy with IBM API connect
API strategy with IBM API connect
 
Web API Management
Web API ManagementWeb API Management
Web API Management
 
Lessons in Transforming the Enterprise to an API Platform
Lessons in Transforming the Enterprise to an API PlatformLessons in Transforming the Enterprise to an API Platform
Lessons in Transforming the Enterprise to an API Platform
 
La Digital Transformation ha un nuovo alleato: Value Stream Management
La Digital Transformation ha un nuovo alleato: Value Stream ManagementLa Digital Transformation ha un nuovo alleato: Value Stream Management
La Digital Transformation ha un nuovo alleato: Value Stream Management
 

Plus de SmartWave

Répondre aux défis de la gestion des factures fournisseurs
Répondre aux défis de la gestion des factures fournisseursRépondre aux défis de la gestion des factures fournisseurs
Répondre aux défis de la gestion des factures fournisseursSmartWave
 
SmartTechTalk : Asynchronous messaging
SmartTechTalk : Asynchronous messagingSmartTechTalk : Asynchronous messaging
SmartTechTalk : Asynchronous messagingSmartWave
 
Data Virtualisation and API Management United
Data Virtualisation and API Management UnitedData Virtualisation and API Management United
Data Virtualisation and API Management UnitedSmartWave
 
Data Agility and Security with Data Virtualisation
Data Agility and Security with Data VirtualisationData Agility and Security with Data Virtualisation
Data Agility and Security with Data VirtualisationSmartWave
 
API Program Lessons learned
API Program Lessons learnedAPI Program Lessons learned
API Program Lessons learnedSmartWave
 
Customer testimonal API Program Lessons learned
Customer testimonalAPI ProgramLessons learnedCustomer testimonalAPI ProgramLessons learned
Customer testimonal API Program Lessons learnedSmartWave
 
API Management Microservices beyond HIP
API Management Microservices beyond HIPAPI Management Microservices beyond HIP
API Management Microservices beyond HIPSmartWave
 
Monitoring docker, k8s and your applications with the elastic stack
Monitoring docker, k8s and your applications with the elastic stackMonitoring docker, k8s and your applications with the elastic stack
Monitoring docker, k8s and your applications with the elastic stackSmartWave
 
The elastic stack on docker
The elastic stack on dockerThe elastic stack on docker
The elastic stack on dockerSmartWave
 
Gestion des logs de vos containers avec elastic !
Gestion des logs de vos containers avec elastic !Gestion des logs de vos containers avec elastic !
Gestion des logs de vos containers avec elastic !SmartWave
 
How api management supports the digital transformation process
How api management supports the digital transformation processHow api management supports the digital transformation process
How api management supports the digital transformation processSmartWave
 
Docker Geneva Meetup - Jelastic
Docker Geneva Meetup - JelasticDocker Geneva Meetup - Jelastic
Docker Geneva Meetup - JelasticSmartWave
 
Docker Geneva Meetup - Swarm
Docker Geneva Meetup - SwarmDocker Geneva Meetup - Swarm
Docker Geneva Meetup - SwarmSmartWave
 
Docker Geneva Meetup - Kubernetes
Docker Geneva Meetup - KubernetesDocker Geneva Meetup - Kubernetes
Docker Geneva Meetup - KubernetesSmartWave
 
Dématérialisation du traitement des factures
Dématérialisation du traitement des facturesDématérialisation du traitement des factures
Dématérialisation du traitement des facturesSmartWave
 
Axway amplify api management platform
Axway amplify api management platformAxway amplify api management platform
Axway amplify api management platformSmartWave
 
Api gateway @ vaudoise assurances
Api gateway @ vaudoise assurancesApi gateway @ vaudoise assurances
Api gateway @ vaudoise assurancesSmartWave
 
MSC Digital transformation with Axway API Management products and SmartWave S...
MSC Digital transformation with Axway API Management products and SmartWave S...MSC Digital transformation with Axway API Management products and SmartWave S...
MSC Digital transformation with Axway API Management products and SmartWave S...SmartWave
 
Docker Geneva Meetup - Introduction to Docker
Docker Geneva Meetup - Introduction to DockerDocker Geneva Meetup - Introduction to Docker
Docker Geneva Meetup - Introduction to DockerSmartWave
 
Docker Geneva Meetup - Use Case
Docker Geneva Meetup - Use CaseDocker Geneva Meetup - Use Case
Docker Geneva Meetup - Use CaseSmartWave
 

Plus de SmartWave (20)

Répondre aux défis de la gestion des factures fournisseurs
Répondre aux défis de la gestion des factures fournisseursRépondre aux défis de la gestion des factures fournisseurs
Répondre aux défis de la gestion des factures fournisseurs
 
SmartTechTalk : Asynchronous messaging
SmartTechTalk : Asynchronous messagingSmartTechTalk : Asynchronous messaging
SmartTechTalk : Asynchronous messaging
 
Data Virtualisation and API Management United
Data Virtualisation and API Management UnitedData Virtualisation and API Management United
Data Virtualisation and API Management United
 
Data Agility and Security with Data Virtualisation
Data Agility and Security with Data VirtualisationData Agility and Security with Data Virtualisation
Data Agility and Security with Data Virtualisation
 
API Program Lessons learned
API Program Lessons learnedAPI Program Lessons learned
API Program Lessons learned
 
Customer testimonal API Program Lessons learned
Customer testimonalAPI ProgramLessons learnedCustomer testimonalAPI ProgramLessons learned
Customer testimonal API Program Lessons learned
 
API Management Microservices beyond HIP
API Management Microservices beyond HIPAPI Management Microservices beyond HIP
API Management Microservices beyond HIP
 
Monitoring docker, k8s and your applications with the elastic stack
Monitoring docker, k8s and your applications with the elastic stackMonitoring docker, k8s and your applications with the elastic stack
Monitoring docker, k8s and your applications with the elastic stack
 
The elastic stack on docker
The elastic stack on dockerThe elastic stack on docker
The elastic stack on docker
 
Gestion des logs de vos containers avec elastic !
Gestion des logs de vos containers avec elastic !Gestion des logs de vos containers avec elastic !
Gestion des logs de vos containers avec elastic !
 
How api management supports the digital transformation process
How api management supports the digital transformation processHow api management supports the digital transformation process
How api management supports the digital transformation process
 
Docker Geneva Meetup - Jelastic
Docker Geneva Meetup - JelasticDocker Geneva Meetup - Jelastic
Docker Geneva Meetup - Jelastic
 
Docker Geneva Meetup - Swarm
Docker Geneva Meetup - SwarmDocker Geneva Meetup - Swarm
Docker Geneva Meetup - Swarm
 
Docker Geneva Meetup - Kubernetes
Docker Geneva Meetup - KubernetesDocker Geneva Meetup - Kubernetes
Docker Geneva Meetup - Kubernetes
 
Dématérialisation du traitement des factures
Dématérialisation du traitement des facturesDématérialisation du traitement des factures
Dématérialisation du traitement des factures
 
Axway amplify api management platform
Axway amplify api management platformAxway amplify api management platform
Axway amplify api management platform
 
Api gateway @ vaudoise assurances
Api gateway @ vaudoise assurancesApi gateway @ vaudoise assurances
Api gateway @ vaudoise assurances
 
MSC Digital transformation with Axway API Management products and SmartWave S...
MSC Digital transformation with Axway API Management products and SmartWave S...MSC Digital transformation with Axway API Management products and SmartWave S...
MSC Digital transformation with Axway API Management products and SmartWave S...
 
Docker Geneva Meetup - Introduction to Docker
Docker Geneva Meetup - Introduction to DockerDocker Geneva Meetup - Introduction to Docker
Docker Geneva Meetup - Introduction to Docker
 
Docker Geneva Meetup - Use Case
Docker Geneva Meetup - Use CaseDocker Geneva Meetup - Use Case
Docker Geneva Meetup - Use Case
 

Dernier

Cyber security and its impact on E commerce
Cyber security and its impact on E commerceCyber security and its impact on E commerce
Cyber security and its impact on E commercemanigoyal112
 
Ahmed Motair CV April 2024 (Senior SW Developer)
Ahmed Motair CV April 2024 (Senior SW Developer)Ahmed Motair CV April 2024 (Senior SW Developer)
Ahmed Motair CV April 2024 (Senior SW Developer)Ahmed Mater
 
20240415 [Container Plumbing Days] Usernetes Gen2 - Kubernetes in Rootless Do...
20240415 [Container Plumbing Days] Usernetes Gen2 - Kubernetes in Rootless Do...20240415 [Container Plumbing Days] Usernetes Gen2 - Kubernetes in Rootless Do...
20240415 [Container Plumbing Days] Usernetes Gen2 - Kubernetes in Rootless Do...Akihiro Suda
 
Alfresco TTL#157 - Troubleshooting Made Easy: Deciphering Alfresco mTLS Confi...
Alfresco TTL#157 - Troubleshooting Made Easy: Deciphering Alfresco mTLS Confi...Alfresco TTL#157 - Troubleshooting Made Easy: Deciphering Alfresco mTLS Confi...
Alfresco TTL#157 - Troubleshooting Made Easy: Deciphering Alfresco mTLS Confi...Angel Borroy López
 
Xen Safety Embedded OSS Summit April 2024 v4.pdf
Xen Safety Embedded OSS Summit April 2024 v4.pdfXen Safety Embedded OSS Summit April 2024 v4.pdf
Xen Safety Embedded OSS Summit April 2024 v4.pdfStefano Stabellini
 
Unveiling Design Patterns: A Visual Guide with UML Diagrams
Unveiling Design Patterns: A Visual Guide with UML DiagramsUnveiling Design Patterns: A Visual Guide with UML Diagrams
Unveiling Design Patterns: A Visual Guide with UML DiagramsAhmed Mohamed
 
GOING AOT WITH GRAALVM – DEVOXX GREECE.pdf
GOING AOT WITH GRAALVM – DEVOXX GREECE.pdfGOING AOT WITH GRAALVM – DEVOXX GREECE.pdf
GOING AOT WITH GRAALVM – DEVOXX GREECE.pdfAlina Yurenko
 
Real-time Tracking and Monitoring with Cargo Cloud Solutions.pptx
Real-time Tracking and Monitoring with Cargo Cloud Solutions.pptxReal-time Tracking and Monitoring with Cargo Cloud Solutions.pptx
Real-time Tracking and Monitoring with Cargo Cloud Solutions.pptxRTS corp
 
Cloud Data Center Network Construction - IEEE
Cloud Data Center Network Construction - IEEECloud Data Center Network Construction - IEEE
Cloud Data Center Network Construction - IEEEVICTOR MAESTRE RAMIREZ
 
Simplifying Microservices & Apps - The art of effortless development - Meetup...
Simplifying Microservices & Apps - The art of effortless development - Meetup...Simplifying Microservices & Apps - The art of effortless development - Meetup...
Simplifying Microservices & Apps - The art of effortless development - Meetup...Rob Geurden
 
Global Identity Enrolment and Verification Pro Solution - Cizo Technology Ser...
Global Identity Enrolment and Verification Pro Solution - Cizo Technology Ser...Global Identity Enrolment and Verification Pro Solution - Cizo Technology Ser...
Global Identity Enrolment and Verification Pro Solution - Cizo Technology Ser...Cizo Technology Services
 
Maximizing Efficiency and Profitability with OnePlan’s Professional Service A...
Maximizing Efficiency and Profitability with OnePlan’s Professional Service A...Maximizing Efficiency and Profitability with OnePlan’s Professional Service A...
Maximizing Efficiency and Profitability with OnePlan’s Professional Service A...OnePlan Solutions
 
Comparing Linux OS Image Update Models - EOSS 2024.pdf
Comparing Linux OS Image Update Models - EOSS 2024.pdfComparing Linux OS Image Update Models - EOSS 2024.pdf
Comparing Linux OS Image Update Models - EOSS 2024.pdfDrew Moseley
 
Catch the Wave: SAP Event-Driven and Data Streaming for the Intelligence Ente...
Catch the Wave: SAP Event-Driven and Data Streaming for the Intelligence Ente...Catch the Wave: SAP Event-Driven and Data Streaming for the Intelligence Ente...
Catch the Wave: SAP Event-Driven and Data Streaming for the Intelligence Ente...confluent
 
Dealing with Cultural Dispersion — Stefano Lambiase — ICSE-SEIS 2024
Dealing with Cultural Dispersion — Stefano Lambiase — ICSE-SEIS 2024Dealing with Cultural Dispersion — Stefano Lambiase — ICSE-SEIS 2024
Dealing with Cultural Dispersion — Stefano Lambiase — ICSE-SEIS 2024StefanoLambiase
 
Unveiling the Future: Sylius 2.0 New Features
Unveiling the Future: Sylius 2.0 New FeaturesUnveiling the Future: Sylius 2.0 New Features
Unveiling the Future: Sylius 2.0 New FeaturesŁukasz Chruściel
 
Large Language Models for Test Case Evolution and Repair
Large Language Models for Test Case Evolution and RepairLarge Language Models for Test Case Evolution and Repair
Large Language Models for Test Case Evolution and RepairLionel Briand
 
Open Source Summit NA 2024: Open Source Cloud Costs - OpenCost's Impact on En...
Open Source Summit NA 2024: Open Source Cloud Costs - OpenCost's Impact on En...Open Source Summit NA 2024: Open Source Cloud Costs - OpenCost's Impact on En...
Open Source Summit NA 2024: Open Source Cloud Costs - OpenCost's Impact on En...Matt Ray
 

Dernier (20)

2.pdf Ejercicios de programación competitiva
2.pdf Ejercicios de programación competitiva2.pdf Ejercicios de programación competitiva
2.pdf Ejercicios de programación competitiva
 
Cyber security and its impact on E commerce
Cyber security and its impact on E commerceCyber security and its impact on E commerce
Cyber security and its impact on E commerce
 
Ahmed Motair CV April 2024 (Senior SW Developer)
Ahmed Motair CV April 2024 (Senior SW Developer)Ahmed Motair CV April 2024 (Senior SW Developer)
Ahmed Motair CV April 2024 (Senior SW Developer)
 
20240415 [Container Plumbing Days] Usernetes Gen2 - Kubernetes in Rootless Do...
20240415 [Container Plumbing Days] Usernetes Gen2 - Kubernetes in Rootless Do...20240415 [Container Plumbing Days] Usernetes Gen2 - Kubernetes in Rootless Do...
20240415 [Container Plumbing Days] Usernetes Gen2 - Kubernetes in Rootless Do...
 
Alfresco TTL#157 - Troubleshooting Made Easy: Deciphering Alfresco mTLS Confi...
Alfresco TTL#157 - Troubleshooting Made Easy: Deciphering Alfresco mTLS Confi...Alfresco TTL#157 - Troubleshooting Made Easy: Deciphering Alfresco mTLS Confi...
Alfresco TTL#157 - Troubleshooting Made Easy: Deciphering Alfresco mTLS Confi...
 
Xen Safety Embedded OSS Summit April 2024 v4.pdf
Xen Safety Embedded OSS Summit April 2024 v4.pdfXen Safety Embedded OSS Summit April 2024 v4.pdf
Xen Safety Embedded OSS Summit April 2024 v4.pdf
 
Unveiling Design Patterns: A Visual Guide with UML Diagrams
Unveiling Design Patterns: A Visual Guide with UML DiagramsUnveiling Design Patterns: A Visual Guide with UML Diagrams
Unveiling Design Patterns: A Visual Guide with UML Diagrams
 
GOING AOT WITH GRAALVM – DEVOXX GREECE.pdf
GOING AOT WITH GRAALVM – DEVOXX GREECE.pdfGOING AOT WITH GRAALVM – DEVOXX GREECE.pdf
GOING AOT WITH GRAALVM – DEVOXX GREECE.pdf
 
Real-time Tracking and Monitoring with Cargo Cloud Solutions.pptx
Real-time Tracking and Monitoring with Cargo Cloud Solutions.pptxReal-time Tracking and Monitoring with Cargo Cloud Solutions.pptx
Real-time Tracking and Monitoring with Cargo Cloud Solutions.pptx
 
Cloud Data Center Network Construction - IEEE
Cloud Data Center Network Construction - IEEECloud Data Center Network Construction - IEEE
Cloud Data Center Network Construction - IEEE
 
Simplifying Microservices & Apps - The art of effortless development - Meetup...
Simplifying Microservices & Apps - The art of effortless development - Meetup...Simplifying Microservices & Apps - The art of effortless development - Meetup...
Simplifying Microservices & Apps - The art of effortless development - Meetup...
 
Global Identity Enrolment and Verification Pro Solution - Cizo Technology Ser...
Global Identity Enrolment and Verification Pro Solution - Cizo Technology Ser...Global Identity Enrolment and Verification Pro Solution - Cizo Technology Ser...
Global Identity Enrolment and Verification Pro Solution - Cizo Technology Ser...
 
Maximizing Efficiency and Profitability with OnePlan’s Professional Service A...
Maximizing Efficiency and Profitability with OnePlan’s Professional Service A...Maximizing Efficiency and Profitability with OnePlan’s Professional Service A...
Maximizing Efficiency and Profitability with OnePlan’s Professional Service A...
 
Comparing Linux OS Image Update Models - EOSS 2024.pdf
Comparing Linux OS Image Update Models - EOSS 2024.pdfComparing Linux OS Image Update Models - EOSS 2024.pdf
Comparing Linux OS Image Update Models - EOSS 2024.pdf
 
Catch the Wave: SAP Event-Driven and Data Streaming for the Intelligence Ente...
Catch the Wave: SAP Event-Driven and Data Streaming for the Intelligence Ente...Catch the Wave: SAP Event-Driven and Data Streaming for the Intelligence Ente...
Catch the Wave: SAP Event-Driven and Data Streaming for the Intelligence Ente...
 
Dealing with Cultural Dispersion — Stefano Lambiase — ICSE-SEIS 2024
Dealing with Cultural Dispersion — Stefano Lambiase — ICSE-SEIS 2024Dealing with Cultural Dispersion — Stefano Lambiase — ICSE-SEIS 2024
Dealing with Cultural Dispersion — Stefano Lambiase — ICSE-SEIS 2024
 
Unveiling the Future: Sylius 2.0 New Features
Unveiling the Future: Sylius 2.0 New FeaturesUnveiling the Future: Sylius 2.0 New Features
Unveiling the Future: Sylius 2.0 New Features
 
Hot Sexy call girls in Patel Nagar🔝 9953056974 🔝 escort Service
Hot Sexy call girls in Patel Nagar🔝 9953056974 🔝 escort ServiceHot Sexy call girls in Patel Nagar🔝 9953056974 🔝 escort Service
Hot Sexy call girls in Patel Nagar🔝 9953056974 🔝 escort Service
 
Large Language Models for Test Case Evolution and Repair
Large Language Models for Test Case Evolution and RepairLarge Language Models for Test Case Evolution and Repair
Large Language Models for Test Case Evolution and Repair
 
Open Source Summit NA 2024: Open Source Cloud Costs - OpenCost's Impact on En...
Open Source Summit NA 2024: Open Source Cloud Costs - OpenCost's Impact on En...Open Source Summit NA 2024: Open Source Cloud Costs - OpenCost's Impact on En...
Open Source Summit NA 2024: Open Source Cloud Costs - OpenCost's Impact on En...
 

How to build an API strategy - Dorian Rougierx.

  • 1.
  • 2. Key points of an API strategy Dorian Rougier May 2022
  • 3. | Your speaker Dorian Rougier Expert APIM May 2022 Key points of an API strategy 3
  • 4. | The digital imperative API oriented Architecture New assets, new management Secure APIs Monitor API Usage and performance Key takeouts Key points of an API Strategy May 2022 Key points of an API strategy 4
  • 5. | The digital imperative May 2022 Key points of an API strategy 5
  • 6. | • “Any time, Anywhere, Any device” are the key problems of digitalization • The opening of the information system is a major issue Why digital strategy May 2022 Key points of an API strategy 6
  • 7. | API are a solution providing “Business Agility” • APIs are the interface to offer service • API Management is the process to manage API • API Strategy is not only put in place an API Management Are APIs a solution ? May 2022 Key points of an API strategy 7
  • 8. | API Oriented Architecture May 2022 Key points of an API strategy 8
  • 9. | • API : Application Programming Interface : normalized interface to offer service • API is not a technology • API is a product • API is about creating business value • APIs should be designed to deliver business outcomes API May 2022 Key points of an API strategy 9
  • 10. | Level 1 “ Internal API ” API used by the company Level 2 “ Partner API ” API used by internal developers& partner developers Level 3 “ Open API” API used by internal developers,partner developers & external developers API Levels May 2022 Key points of an API strategy 10 At level 1 : the success is to involveevery internalapplication touse API At level 3 : the success depend of the registrationprocess and the quality of its documentation
  • 11. | Organizational impact May 2022 Key points of an API strategy 11
  • 12. | Our solution packaged workshop May 2022 Key points of an API strategy 12
  • 13. | Define your KPIs May 2022 Key points of an API strategy 13
  • 14. | New assets, new management May 2022 Key points of an API strategy 14
  • 15. | API Publisher API Administrator App Developers Users Policy Developers Devices Apps Register andmanage API lifecycle Performpartner, policy andprocess admin Monitor andreport API use Create andextendcustompolicies Integratewithapplications and infrastructure APIs Self-registertoresources Browse andlearnAPIs Manage applicationcredentials Deploy Connect May 2022 Key points of an API strategy 15
  • 16. | May 2022 Key points of an API strategy 16
  • 17. | Secure APIs May 2022 Key points of an API strategy 17
  • 18. | Gateway May 2022 Key points of an API strategy • Link external apps to internal apps, with security, using SOA and APIs Solution Challenges Identity Management Authentication Authorization Audit API Management Services Applications Data Backend Services Messaging Internal or partner 18
  • 19. | Service Broker May 2022 Key points of an API strategy • An “outbound Gateway” • Connects to services, partners, and the Cloud Solution Challenges Applies Security Services Applications Data Backend Services Messaging API Management Cloud and on premise Partners Com Agency 19
  • 20. | Token Mediation May 2022 Key points of an API strategy Identities Tokens Repositories Authorization Security Infrastructure Extensive set of connectors to SecurityInfrastructure Service Request Service/User Credential Validated Access Throttled Request External App Identity Management Authentication Authorization Audit Transformed Response Standard Response API Gateway • Manage heterogeneous security infrastructure Solution Challenges 20
  • 21. | Token Mediation May 2022 Key points of an API strategy 21 Azure Access token Get ADFS Access token Validate ADFS Access token Azure Access token ADFS Access token Validate ADFS Access token ADFS DMZ Access token Get ADFS Access token
  • 22. | Monitor API usage and performance May 2022 Key points of an API strategy 22
  • 23. | API Portal May 2022 Key points of an API strategy 23
  • 24. | API Analytics May 2022 Key points of an API strategy 24
  • 25. | Key takeouts May 2022 Key points of an API strategy 25
  • 26. | • API Management tool is not a golden hammer • Address minor part of an API Strategy • Implement all feature of the APIM before use it • You must iterate on the implementation of the tool • API Management not manage the versioning • The version must instead be crafted and developed at the applicative level Common mistakes May 2022 Key points of an API strategy 26
  • 27. | • Think about your API governance strategy • Design API with a clear documentation • Don’t expose all your service, only useful services • Put in place metrics Recommendations May 2022 Key points of an API strategy 27
  • 28. | Questions May 2022 Key points of an API strategy 28
  • 29. | SmartWave S.A. Chemin de la Scie 4A – CH-1290 Versoix Tel. +41 22 783 20 20 Fax +41 22 783 20 22 www.smartwavesa.com May 2022 Key points of an API strategy Your contact DorianRougier Mob. +41 79 375 90 91 drougier@smartwavesa.com Senior Consultant 29
  • 30. | API Strategy May 2022 Key points of an API strategy 30 API-First Company
  • 31. | Use cases May 2022 Key points of an API strategy 31
  • 32. | Governance Typical use cases May 2022 Key points of an API strategy 32
  • 33. | Solution Challenges API Governance May 2022 Key points of an API strategy • Exposeexisting applications as APIs, securely. • Onboard developers who want to use your APIs • Manage large amount of API Retailers 33
  • 34. | May 2022 Key points of an API strategy 34 Best Practices Processes RACI KPI Business Cases Drivers API Management Concept Stakeholder Map Stakeholder Map Use Cases KPI Governance Analysis Design Best Practices Governance
  • 35. | RACI & Processes May 2022 Key points of an API strategy 35
  • 36. | API exposition Typical use cases May 2022 Key points of an API strategy 36
  • 37. | Gateway May 2022 Key points of an API strategy • Link external apps to internal apps, with security, using SOA and APIs Solution Challenges Identity Management Authentication Authorization Audit API Management Services Applications Data Backend Services Messaging Internal or partner 37
  • 38. | Service Broker May 2022 Key points of an API strategy • An “outbound Gateway” • Connects to services, partners, and the Cloud Solution Challenges Applies Security Services Applications Data Backend Services Messaging API Management Cloud and on premise Partners Com Agency 38
  • 39. | Multiple exposition May 2022 Key points of an API strategy 39
  • 40. | Token Mediation Typical use cases May 2022 Key points of an API strategy 40
  • 41. | Token Mediation May 2022 Key points of an API strategy Identities Tokens Repositories Authorization Security Infrastructure Extensive set of connectors to SecurityInfrastructure Service Request Service/User Credential Validated Access Throttled Request External App Identity Management Authentication Authorization Audit Transformed Response Standard Response API Gateway • Manage heterogeneous security infrastructure Solution Challenges 41
  • 42. | Oauth Implicit / Auth code App Interne User Gateway API (+ Access Token) Response Valid Access Token Back-end Ask Internal token ADFS API + Backend Token AzureAD Authentication Get Access Token Azure Acess token Backend token Response Valid Backend Token Valid Access Token Token Mediation May 2022 Key points of an API strategy 42
  • 43. | Token Mediation May 2022 Key points of an API strategy 43 Azure Access token Get ADFS Access token Validate ADFS Access token Azure Access token ADFS Access token Validate ADFS Access token ADFS DMZ Access token Get ADFS Access token
  • 44. | Omni Chanel and modernization May 2022 Key points of an API strategy 44
  • 45. | Services Applications Data Backend Services Messaging Services Applications Data Backend Services Messaging API Modernization / Integration May 2022 Key points of an API strategy Solution Challenge • Protocol and message mediation • Service Modernization HTTP REST/SOAP JSON/XML FTP JMS JMS HTTP REST/SOAP JSON/XML FTP API Gateway For Backend Service 45
  • 46. | Mobile & Single Page App Solution May 2022 Key points of an API strategy • Mobile apps require access to data which is behind the firewall • Technologies such as OAuth must be used to authenticate clients Solution Challenge UX Multi-canal REST Secure API Gateway Services Applications Data Backend Services Messaging 46
  • 47. | Hybrid integration May 2022 Key points of an API strategy 47
  • 48. | Project implementation May 2022 Key points of an API strategy 48
  • 49. | May 2022 Key points of an API strategy 49
  • 50. | API Publisher API Administrator App Developers Users Policy Developers Devices Apps Register andmanage API lifecycle Performpartner, policy andprocess admin Monitor andreport API use Create andextendcustompolicies Integratewithapplications and infrastructure APIs Self-registertoresources Browse andlearnAPIs Manage applicationcredentials Deploy Connect May 2022 Key points of an API strategy 50
  • 51. | Architecture definition May 2022 Key points of an API strategy App Interne App Externe API Management DMZ API Management Interne Interne DMZ Internet / Partner BAckend App Access point protection (WAF) API Portal DMZ API Portal Interne App Interne App Externe API Management DMZ API Management Interne Interne DMZ Internet / Partner BAckend App Access point protection (WAF) API Portal DMZ API Portal Interne 51
  • 52. | • #1 Front security definition • User / Application / IDP • #2 Backend Security • #3 Security enforcement by zone • #4 Consolidation Security Definition May 2022 Key points of an API strategy 52
  • 53. | Governance May 2022 Key points of an API strategy 53
  • 54. | • Which product most suitable • Architecture • Security : Front (multiple, simple, IDP) / backend (standard, legacy, SaaS) • Governance : organization / role / user • Traffic monitoring • Customization • Integration in CI / CD Solution definition May 2022 Key points of an API strategy 54
  • 55. | Operation Foundation Pilot Change Management Project Phase May 2022 Key points of an API strategy 55 • Installation • Configuration • Policies developement • Analyitcs • CI/CD • Adapt governance • API best practice • Implement governance • Support new backend • Security update • API linter • API Community
  • 56. | Typical New Customer APIM Project May 2022 Key points of an API strategy 56 STUDY POC BUILD RUN • Architecture • Security • Governance • Validateaspects of study • Platform • Security policy • Governance
  • 57. | Integrate at the begin of the project governance aspect Promote platform to other projects since day 1 for better ROI Force every new external API to use the gateway for normalized security API roadmap definition in the project Usage case of the pilot Put in place IDP solution before APIM Lesson learn from our clients May 2022 Key points of an API strategy 57
  • 58. | How do we deliver value May 2022 Key points of an API strategy 58 BUILD CARE To build your digital transformation projects To support and maintain your applications EMPOWER To strengthen your technical team
  • 59. | Backup May 2022 Key points of an API strategy 59
  • 60. | • Convention center managing 100+ shows per year • Information system composed of on premises and cloud applications • Limited IT budget and team (7) • Share volatile information with partners: price list, exhibitor list Context • Automate information sharing: remove manual actions • Complex information access: located in an ERP not designed to expose data • Many integration cases: cash register, web site, mobile • Sensitive information: Need to limit access Challenges Case study 1: digitalize partners’ relationship May 2022 Key points of an API strategy 60
  • 61. | On premise Apps Web Site App A Case study 1: solution architecture May 2022 Key points of an API strategy API Gateway ERP Database Enterprise Service Bus Cloud Apps Cash Register DMZ INTERNAL On premise Apps Internet Data access services API Manager IDP Firewall INTERNET ERP Mobile 61
  • 62. | • Simplified and acceleratedpartner data exchange: 7 API to automate information sharing • Improveddata quality:no risk of human error by full automation • Low investment: less than 20 days • Easy integration:no change in the existing applications • Foundationfor the future:Easy to add new services in the platform and support current and future integrations • Fresh data and internalsystemsprotected: cache and throttling functions to secure application exposition Results Case study 1: API Management for everyone May 2022 Key points of an API strategy 62
  • 63. | • Define a v1 of the future roles, responsibilities and processes for your new API Management Solution. Roles, responsibilities & processes Description May 2022 Key points of an API strategy 64 Align Stakeholders • Drivers • Concepts & Terms • Goals/Expectations 3 Workshops • Roles & Responsibilities • Processes • Stakeholder dynamics Restitution • RACI Matrix • Processes
  • 64. | Roles, responsibilities & processes Workshop preview May 2022 Key points of an API strategy 65
  • 65. | Define your KPIs May 2022 Key points of an API strategy 66
  • 66. | • REST Concepts • API Contract • Data model and naming conventions • Responses and monitoring • API life cycle, versioning Best Practice Agenda May 2022 Key points of an API strategy 67
  • 67. | • Work with the business to • Define function • Create data model • Validate sequence between API • Create API contract following Best Practice Design API May 2022 Key points of an API strategy 68