A system for controlling access to computing resources within an
enterprise. The system can consist of a web server and a web security
agent controlling access to URLs, a security gatekeeper and an access
server controlling access to APIs, and a core security framework used by
both the web server and web security agent and the security gatekeeper
and access server to store security data and policies and make security
decisions. The access server can be a SOAP server. The core security
framework can consist of a policy store, a data store, and a policy
server, where the data store can be a relational database or a directory.
A session token can be attached to an approved request for access to an
API and can provide access to the API for the duration of a session.