Trust in Protocols, Not Institutions: Transparency Logs for API Authorization
This is the sixth post in my series on Germany’s federal API authorization blueprint. We have a verified client, a sender-constrained token, and a policy-based decision about what it may do. Now co...