IAM API
REST and OIDC/SAML endpoints for user authentication, token issuance, SCIM provisioning, and session management.
Software Subsystem Application active
IAM API exposes Keycloak's admin REST API and OIDC discovery endpoints. Custom endpoints handle SCIM 2.0 for automated user provisioning from enterprise IdPs. All token responses comply with JWT standards with configurable expiry per tenant policy.
Relationships
Composes outgoing 3
Part of incoming 3
Owned by incoming 1
Served by incoming 1
Architecture Context
Diagrams
Not yet referenced in any diagram
Properties
Type Software Subsystem
Layer Application
Domain Security and Compliance
Status active
Owner Security Team
Additional Metadata
Catalog Id SUB-SEC-001
Environments production, staging
Owns Data Aggregates Identity Record Aggregate
Served By Cloud Services Security GKE Cluster
Archimate Type application-component
C4 Type Container
Togaf Type Application Component
Meta Model
Business
Organization
Application current
Technology