Advisor
API security and open banking readiness
Advisory engagement with a state-owned Indonesian financial institution.
The client is a large state-owned financial institution in Indonesia opening its services to third-party developers. SNAP, Indonesia's payment interoperability standard, sets requirements for how those APIs are secured and operated, and regulated institutions have to meet it.
Brankas was engaged as the advisor. My work was to establish where the organisation stood, define where it needed to be, and write the path between the two.
What I do here
Maturity assessment
Graded API and security capability against a structured maturity model across several pillars, drawing on stakeholder interviews, questionnaires, and a review of the existing API estate.
Standards gap analysis
Mapped the current state against FAPI and SNAP requirements, establishing what compliance actually demands rather than what it is assumed to demand.
Target architecture
Produced as-is and to-be blueprints covering centralised identity, credential lifecycle and rotation, secrets management, mTLS and OAuth flows, and third-party client registration and consent.
Roadmap and enablement
Turned the assessment into a prioritised roadmap with delivery evidence criteria, and ran workshops so the client's own teams could carry it forward.
FAPI · SNAP · OAuth 2.0 · mTLS · API governance · Secrets management
Every line here describes what the engagement involved. None of it describes what was found, and the client is not named.