
GovWay
Compliant with AGID guidelines for interoperability (mode profile) and prepared for access to the main Italian public services
Vitality
Quick links
Description
Derived from the experience of the Italian Dominium Porta, GovWay is an API Gateway that complies with the rules of the public administration:
— Compliance with market standards: management of standard market protocols, such as SOAP 1.1 and 1.2, RESTful API serialised in Json or XML or simple binary data on Http.
— Compliance with Italian specifications for interoperability: support for the new AGID interoperability guidelines, both for technical profiles under the new interoperability model (modes) and for managing tokens issued by PDND (signed JWT, purposeId, sessionInfo).
— Compliance with European Interoperability Specifications: supporting the AS4 protocol, by integrating the Connecting European Facilities (Connecting European Facilities) project with the Building Block eDelivery.
— Backward compatibility with the SPCoop protocol, which is still widely adopted for public administration services.
— Compliance with the specifications for electronic invoicing on the SdiCoop channel.
— Availability of ready-to-use connectors for the main intangible services of the public administration, such as PagoPA, ANPR and Electron Fatturation.
Features
- NRRP
- NRRP/Misura/1.3.1
- NRRPs/Beneficiaries/Municipalities
- NRRP/Beneficiaries/Schools
- NRRPs/Beneficiaries/Regional Entities
- NRRP/Beneficiaries/Universities
- Central NRRPs/Beneficiaries/PAs
- NRRP/Beneficiaries/Provinces
- NRRPs/Beneficiaries/Research Institutes and AFAM
- NRRP/Beneficiaries/Other entities
- Compliance with new AGID guidelines for interoperability (mode profile)
- Compliance with market standards SOAP, REST, HTTP (API Gateway profile)
- Compliance with European Interoperability Standards (eDelivery profile)
- Backward compatible with SPCoop (SPCoop profile)
- API Register: interface descriptors (OpenAPI 3, WSDL, Swagger 2 and WADL)
- Token management (JWT, OAuth2, OIDC) and AuthServer integration (UserInfo, Introspection)
- Rate Limiting: number of requests, band, average processing time
- Authentication: HTTP-Basic, TLS, Api Key, Identity Management External System Integration
- Permission: specific subscriptions, roles, scope, evaluation of XACML policy via PDD
- Validation: verification of compliance of requests/responses with API descriptors
- Tracking: issue of traces in accordance with the rules for each application request managed
- Response cache
- CORS management
- Content security: Ws-security, XMLEncryption/XMLSignature, JOSE (JWS/JWE)
- MTOM format management
- Message transformation both as a protocol (SOAP < - > REST) and for header, url or payload
- Routing: native support for forwarding to the backend via http, https, JMS or file
- Management console for the registration of APIs and the various policies governing them
- Monitoring console for diagnostics and traffic monitoring managed by GovWay