Like many other organisations, Colruyt is exposing more and more information and business assets through APIs to reach new markets, where speed to delivery and ease of consumption are the key to success. For that reason, they started to realise that controlling the access to their APIs was highly important as the number of APIs was only going to grow in the future.
“Not only did we want to take control on API level, but also on functionality level. In addition, we wanted to facilitate row-level security based on the interaction between the end-user and the client’s application. On top of these business aspects, a technology shift took place (JSF -> Angular Mobile) which came with new security requirements. Next to this the service landscape changed from SOAP to REST, which also influenced our API Security Architecture/ Approach. All of the above led to the awareness that we needed to evaluate our API Security approach”, according to Tom, Security Architect at Colruyt Group.





