Deutsche Bank Secures Agility with API-Based Ecosystem
Key point
Deutsche Bank integrated API governance, security, and scalability using Apigee.
Details
Deutsche Bank determined that it needed a central platform to manage APIs after transitioning its application environment from monolithic systems to a modular, reusable API structure. It selected Google Cloud Apigee as its API Management Platform (APIM) because it allows for built-in documentation, security policies, and governance from the start.
Currently, Apigee manages Deutsche Bank's API ecosystem, ranging from open banking APIs connecting with fintech partners to internal microservices and customer-facing applications like online banking.
Key features include:
- Integrated Governance: Catalogs API endpoints, versions, and dependencies to enable developers to search for and reuse existing APIs. OpenAPI specifications, schema validation, and error handling policies are consistently applied across the platform.
- API Security: Configures service-specific access permissions based on the principle of least privilege using OAuth2 scopes and API key management. It logs API calls and applies rate limiting and quotas to restrict the impact of malfunctions in automated systems.
- Handling Large-Scale Traffic: Distributes traffic through load balancing and autoscaling, and bypasses failed services using health checks and circuit breakers. Frequently accessed data is cached to provide fast responses without backend access.
- Observability: Provides an integrated dashboard to monitor API performance, consolidating operational information scattered across multiple systems into one place.
This API-ready foundation supports faster development speeds while simultaneously ensuring the security, stability, and auditability required for financial services.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.