
Headless CIAM architecture for a leading CEE retail bank
Replacing an over-customised, brittle legacy customer identity and access management platform with a lean, standards-based CIAM built on FAPI 2.0.
Project Impact & Velocity
Key outcomes delivered.
The challenge
Two decades of customisation had pushed the bank's customer identity platform far beyond its supportable limits. Availability — not features — had become the board-level problem: every change carried outage risk, and the incoming regulatory horizon (PSD3/PSR, eIDAS 2.0) guaranteed more change, not less.
To keep the 99.95% uptime promise to their customers, we supported the bank in removing complexity, rather than insuring against it.
What we did
From a brittle, over-customised platform to a lean, standards-based CIAM.

The Outcome
A platform smaller than the one it replaced — and defensible to any regulator.
11 RFCs
published standards the flows are built to, not bespoke protocols
2 apps → 1
the separate authenticator app retired; customers approve payments in the banking app itself
Why it worked
Key drivers behind our success.
Technologies & standards
FAPI 2.0
Financial-grade API security profile — the baseline the entire identity platform is built to.
Passkey-pattern auth
Phishing-resistant, passwordless sign-in built on the passkey / WebAuthn pattern.
3-D Secure 2.x
Strong customer authentication for card payments, aligned to SCA / PSD2.
CIBA
Client-Initiated Backchannel Authentication for decoupled, out-of-band approval across devices.
Fine-grained authorization (FGA)
Policy-based, relationship-aware access decisions that go beyond coarse role checks.
Cedar
Open-source policy language that expresses fine-grained access rules as verifiable policies, decoupled from application code.
