Skip to content
All work

Advisor

API security and open banking readiness

Advisory engagement with a state-owned Indonesian financial institution.

As-is, to-be, and the path between

The client is a large state-owned financial institution in Indonesia opening its services to third-party developers. SNAP, Indonesia's payment interoperability standard, sets requirements for how those APIs are secured and operated, and regulated institutions have to meet it.

Brankas was engaged as the advisor. My work was to establish where the organisation stood, define where it needed to be, and write the path between the two.

What I do here

Maturity assessment

Graded API and security capability against a structured maturity model across several pillars, drawing on stakeholder interviews, questionnaires, and a review of the existing API estate.

Standards gap analysis

Mapped the current state against FAPI and SNAP requirements, establishing what compliance actually demands rather than what it is assumed to demand.

Target architecture

Produced as-is and to-be blueprints covering centralised identity, credential lifecycle and rotation, secrets management, mTLS and OAuth flows, and third-party client registration and consent.

Roadmap and enablement

Turned the assessment into a prioritised roadmap with delivery evidence criteria, and ran workshops so the client's own teams could carry it forward.

FAPI · SNAP · OAuth 2.0 · mTLS · API governance · Secrets management

Every line here describes what the engagement involved. None of it describes what was found, and the client is not named.