Skip to main content
Next-Gen Token Security for APIs

The Token Security Your APIs Deserve

Integrate Eclipse Biscuit tokens into your API gateway for cryptographic, fine-grained access control. Forge, verify, attenuate, and delegate permissions — powered by Otoroshi.

Otoroshi Biscuit Studio
6Entity Types
7Route Plugins
RBACPolicy Engine
OAuth2Client Credentials

Everything You Need for Token-Based Security

From key management to token forging, from verification to attenuation — a complete toolkit for production-grade Biscuit token infrastructure.

🔐
KeyPair Management

Create and manage cryptographic keypairs for signing, attenuating and verifying Biscuit tokens. The foundation of your token security infrastructure.

🔒
Token Verification

Validate incoming Biscuit tokens against defined rules and policies. Ensure only properly authorized requests reach your services.

🏛️
Token Forging

Generate tokens from configurable templates with facts, rules and checks. Define once, forge consistently across your entire infrastructure.

🎛️
Token Attenuation

Reduce token capabilities to grant only minimal required permissions. Fine-grained scope control for every API route.

👥
RBAC Policies

Implement Role-Based Access Control using Biscuit tokens. Structured, flexible access mechanisms for secure role-based user management.

🌐
Remote Facts Loader

Integrate external data sources to enhance authorization decisions. Dynamic, context-aware access control powered by real-time data.

🔑
Client Credentials Flow

OAuth2 client_credentials flow with Biscuit tokens as access tokens. Standards-compliant authentication for machine-to-machine communication.

👤
User Extraction

Extract user identity from Biscuit tokens and forward it to backend services. Seamless user identification without additional auth mechanisms.

📡
Public Key Exposition

Expose your public keys through .well-known/biscuit-web-keys endpoints. Enable third-party token verification with standard discovery.

Why Otoroshi Biscuit Studio?

Not just another auth layer. A complete Biscuit token management platform built for teams that take API security seriously.

🏗️
Built on Otoroshi

Leverage a battle-tested, cloud-native API gateway. Get mTLS, service mesh, plugins, and admin UI out of the box. Your token security inherits enterprise-grade infrastructure.

🛡️
Biscuit Cryptographic Security

Powered by Eclipse Biscuit tokens — cutting-edge cryptographic authorization combining public-key signatures with a logic-based policy language. Offline verification, no central authority needed.

🔗
Hierarchical Delegation

Delegate permissions across organizational boundaries while maintaining strict policy control. Each delegation layer can only restrict, never expand — security by design.

🌍
Sovereign & Open Source

Run on your infrastructure, keep your data where it belongs. Fully open source under Apache 2.0. Funded by the French Government under the France 2030 plan.

7 Otoroshi Plugins, Ready to Deploy

Drop-in plugins for your Otoroshi routes. Add Biscuit token security to any API endpoint in minutes, no code changes required.

Biscuit VerifierBiscuit AttenuatorClient CredentialsUser ExtractorUser to BiscuitApiKey BridgePublic Keys ExpositionExplore all

Built for Real-World Security Scenarios

From startups to enterprises, secure your APIs with confidence.

🏢
API Security Gateway

Centralize token-based access control across all your API routes with cryptographic proof.

🔀
Fine-Grained Authorization

Go beyond simple API keys with policy-based, attenuated permissions for every endpoint.

🛡️
Zero Trust Architecture

Verify every request with offline cryptographic proof and auditable, embedded policies.

Microservices Security

Delegate and attenuate permissions across service boundaries with compact, efficient tokens.

Ready to Secure Your APIs with Biscuit Tokens?

Get started in minutes. Open source, free forever.

Funding

This project was funded by the French Government under the France 2030 plan, operated by Cap Digital and Bpifrance, and is supported by the European Union – NextGenerationEU.

French GovernmentBpifranceNextGenerationEU