Integration architecture

From a single call to the whole ecosystem

Designed to support diverse integration patterns, from real-time APIs to event-driven architectures.

proConsul API gateway architecture: external requests flow through authentication, routing and orchestration layers to backend services.

Gateway to services — how external requests reach the platform

proConsul service layer integrating with data stores: orchestration services coordinating with credential repositories, policy engines and audit logs.

Services to data stores — how the platform coordinates state

Integration types

Connect what you already run

proConsul supports multiple integration patterns to accommodate diverse system requirements.

Identity provider integration

Connect to national identity systems, population registries, enterprise directories and external authentication providers. Support for OpenID Connect, SAML 2.0, OAuth 2.0 and LDAP, designed for OpenID Federation scenarios that establish trust across organizational boundaries.

  • National eID systems and population registries
  • Enterprise Active Directory and LDAP
  • Social identity providers
  • Multi-factor authentication systems
  • Biometric authentication platforms

Credential issuer & verifier integration

Integrate with systems that issue and verify digital credentials — government agencies, educational institutions, professional bodies and enterprises. Engineered to align with W3C Verifiable Credentials, ISO/IEC 18013-5 mobile driving licences and X.509 certificate-based credentials.

  • Government credential issuers (passports, IDs, licences)
  • Educational credential systems
  • Professional certification bodies
  • Healthcare credentialing systems
  • Relying-party verification services

TrustVault & PKI integration

Deep integration with TrustVault for all cryptographic operations and PKI services — HSM-backed key generation, certificate issuance, digital signing and validation. Support for hierarchical PKI structures, certificate policies and revocation mechanisms.

  • TrustVault PKI services
  • Hardware Security Modules (HSMs)
  • Certificate Authority operations
  • Key management systems
  • Cryptographic service providers

Wallet integration

Integration with idGuard consumer wallets and EUDI wallet applications — credential delivery, update notifications and revocation signalling. Designed to support the EUDI Wallet ecosystem, engineered to align with ARF specifications.

  • idGuard consumer wallet platform
  • EUDI Wallet implementations
  • Enterprise mobile wallet applications
  • Credential presentation protocols
  • Wallet attestation services

Monitoring & SIEM integration

Export logs, metrics and security events to enterprise monitoring systems, SIEM platforms and security operations centres. Real-time alerting, anomaly detection and incident-response coordination.

  • SIEM platforms (Splunk, ELK, QRadar)
  • Monitoring systems (Prometheus, Grafana)
  • Security operations centre tools
  • Log aggregation services
  • Alerting and notification systems

External data sources

Integration with external data sources for attribute verification, fraud detection and threat intelligence. Support for real-time API queries and batch data synchronisation.

  • Document verification services
  • Fraud intelligence networks
  • Sanctions and watchlist screening
  • Credit bureau and KYC data providers
  • Threat intelligence feeds

OpenID Federation support

Trust that crosses boundaries

Designed to support OpenID Federation for establishing trust across organizational and national boundaries.

Federated trust

One trust fabric, many parties

OpenID Federation enables trust relationships between identity providers, credential issuers and relying parties across organizational boundaries. proConsul orchestrates federation metadata, entity statements and trust-chain validation — critical for cross-border EUDI Wallet scenarios and international identity federation.

Universal credential issuance flow: an RP-initiated QR is scanned to a wallet and the credential is presented back to the relying party.

Issuance flow — RP-ID QR to wallet to relying party

EUDI Wallet ecosystem

Engineered to align with the EUDI ARF

Designed to support the European Digital Identity Wallet ecosystem, engineered to align with the Architecture Reference Framework (ARF) specifications.

EUDI Wallet trust and lifecycle flows showing credential issuance, attestation and verification patterns.

EUDI Wallet — trust and lifecycle flow

EUDI Wallet payment authentication flow demonstrating credential presentation and strong customer authentication.

EUDI Wallet — payments use-case flow

Wallet attestation

Support for Wallet Secure Cryptographic Device (WSCD) attestation. Integration with trusted execution environments, secure elements and hardware security modules provides cryptographic assurance of wallet authenticity.

Credential formats

Support for multiple credential formats required by the EUDI ARF, including ISO/IEC 18013-5 mDL (mobile driving licence), W3C Verifiable Credentials and SD-JWT (Selective Disclosure JWT).

Cross-border recognition

Orchestrate cross-border credential recognition scenarios. Manage attribute mapping, trust-framework alignment and mutual-recognition agreements between member states.

Trust framework integration

Connect with national and European trust frameworks. Integrate with qualified trust service providers (QTSPs), national identity schemes and attribute providers across the EUDI ecosystem.

Engineered to align with these standards; interoperability depends on deployment and the participating parties.

API capabilities

REST, GraphQL and events

Comprehensive REST and GraphQL APIs for programmatic platform access.

RESTful APIs

Standards-based REST APIs for credential lifecycle operations, policy management, workflow orchestration and reporting. OpenAPI 3.0 specifications are available for all endpoints, with OAuth 2.0 and JWT-based authentication, comprehensive error handling and validation.

GraphQL APIs

Flexible GraphQL endpoints for complex queries and data aggregation — a single request can retrieve related data across multiple resources. Strongly typed schema with introspection, plus subscription support for real-time updates on credential status and workflow completions.

Webhooks & events

Event-driven integration via webhooks. Subscribe to events including credential issuance, revocation, policy changes and approval completions. Configurable retry logic and delivery guarantees, webhook signature verification, and support for the CloudEvents standard format.

Developer portal

Comprehensive developer documentation, API reference, an interactive API explorer and code samples. SDKs are available for major programming languages, alongside a sandbox environment for testing integrations, with clearly documented API versioning and deprecation policies.

Integration patterns

Four ways to connect

Common patterns for connecting proConsul to your ecosystem.

Synchronous request-response

Direct API calls for real-time operations. The client makes a request, proConsul processes it immediately and returns a response — suited to low-latency needs like authentication, credential verification and policy evaluation.

Asynchronous processing

Long-running operations use asynchronous patterns. The client submits a request, receives a job identifier, then polls for completion or subscribes to a webhook — suited to credential issuance requiring approvals, batch operations and report generation.

Event-driven integration

Subscribe to platform events via webhooks or message queues. Receive notifications for credential lifecycle events, policy changes, threat alerts and compliance incidents — enabling reactive architectures and real-time monitoring.

Batch synchronisation

Scheduled batch operations for bulk data exchange. Export audit logs, import user populations, synchronise policy updates and exchange credential status — with support for JSON, XML and CSV formats.

API security & rate limiting

Secured at the edge

Authentication

OAuth 2.0 client-credentials flow for service-to-service authentication. JWT bearer tokens with configurable expiry, API-key authentication for simpler integrations, and mutual TLS support for the highest-security scenarios.

Authorization

Fine-grained authorization based on OAuth 2.0 scopes and custom claims. Role-based access control for administrative operations, and attribute-based policies for complex authorization scenarios.

Rate limiting

Configurable rate limits prevent abuse and ensure fair resource allocation. Per-client limiting with burst allowances, rate-limit headers that inform clients of current quota, and graceful degradation under load.

Encryption & transport

TLS 1.3 for all API communications with perfect forward secrecy. Certificate pinning support for mobile applications, plus request and response signing for end-to-end integrity verification.

Ready to integrate proConsul?

Contact our integration team to discuss your requirements and access developer resources.