11 • HTTP REST API HTTPS, HTTP over Unix socket • JSON optionally JOSE for key encapsulation • Storage layer abstraction FreeIPA Vault, sqlite, etcd, encrypted overlay • Pluggable authentication and authorization GSSAPI, TLS client certs, SO_PEERSEC/CRED • Transparent routing and forwarding based on URL Load balancing, separation of tenants