Mainframe Path Start learning free
Applied8 min readLesson 5 of 5

Securing and running mainframe APIs

An API opens the mainframe to callers you have never met. Securing it means encrypting traffic, proving who the caller is, mapping that identity to a RACF user so existing access rules still apply, and watching how the API is used.

Layers of protection

Each layer has one job
EncryptionTLS on every connection, often AT-TLS on z/OS
Authenticationwho is calling — OAuth tokens, certificates
Identity mappingcaller becomes a RACF user ID
AuthorisationRACF decides what that user can run and read
Limits and logsrate limits, SMF and gateway logs

Encryption

Every API connection uses TLS. On z/OS, AT-TLS can add encryption in the network stack, so applications need no TLS code, and policies are managed centrally.

From token to RACF

Callers usually present an OAuth access token or a JWT issued by an identity provider. The gateway or z/OS Connect validates it and maps the caller to a RACF user ID. From then on, the request is checked against the same RACF profiles as a terminal user, and the audit trail shows a real identity rather than one shared technical account.

Running APIs day to day

SymptomLikely layer
401 UnauthorizedToken missing or expired
403 ForbiddenToken valid, but RACF denies the resource
Timeouts under loadCICS capacity, DB2 contention or missing rate limits
TLS handshake failureExpired or untrusted certificate

Common mistakes

Running every call under one technical ID

It removes accountability and gives every caller the same broad access. Map callers to appropriate RACF IDs.

Logging tokens or personal data

Logs are read by many people and kept for a long time. Log IDs and outcomes, not secrets or customer details.

Changing a live API without versioning

Renaming a field breaks every app that uses it. Add fields freely, but publish breaking changes as a new version.

What you will see at work

Key terms

Check your understanding.
Take this lesson's quiz and save your progress. Free.

Take the lesson quiz
← Calling external APIs from COBOLBack to APIs and REST on z/OS