

We’re pleased to announce that Coincheck, Inc. (Coincheck) has adopted Authlete’s OAuth/OpenID Connect (OIDC) backend service to build an OAuth/OIDC-compliant identity provider (IdP).
Coincheck is a group company of Monex Group, Inc., listed on the Tokyo Stock Exchange Prime Market, and Coincheck Group N.V., listed on the Nasdaq Stock Market. The company operates Coincheck, a retail crypto asset trading service; Coincheck Prime, which helps corporate and institutional investors trade and custody crypto assets; and Coincheck Partners, which supports businesses in building crypto-related ventures.
Coincheck deployed Authlete to handle the OAuth/OIDC processing for the new IdP, which securely connects its smartphone app with its newly launched service, Coincheck Leverage. By reusing its existing authentication flow and user database, the company quickly built the IdP in-house with FAPI 2.0 compliance to ensure advanced security.
Coincheck is diversifying its revenue sources by leveraging its customer base, one of the largest in Japan. To accelerate new service launches, the company needed a highly secure, scalable IdP infrastructure. To this end, the company had to implement extensions such as PKCE*1, PAR*2, and DPoP*3 to strengthen OAuth 2.0 authorization security for smartphone apps. It also recognized that complying with FAPI 2.0, a financial-grade security standard, would be essential to growing its business by offering APIs to partner companies.
With an in-house-first policy, Coincheck initially explored developing and operating the IdP entirely on its own. However, because implementing the protocols is inherently difficult and keeping up with the latest specifications creates a heavy operational burden, the company realized that it could not rely solely on internal resources.
Coincheck also considered building on Doorkeeper, open-source software (OSS). However, since it lacked support for the latest standards like PAR, DPoP, and FAPI, Coincheck concluded that implementing and maintaining these missing features internally would be extremely difficult.
After weighing these options, Coincheck pivoted from its purely in-house development strategy and decided to adopt an external solution that could handle advanced OAuth/OIDC processing.
When Coincheck evaluated external OAuth/OIDC solutions, it prioritized the following:
After comparing Authlete, Ory Hydra, Auth0, and Amazon Cognito, Coincheck decided to build the IdP internally while delegating the highly complex OAuth/OIDC protocol processing and token management to Authlete. Beyond meeting its requirements, Coincheck valued Authlete for the following reasons:
Using Authlete, Coincheck successfully built its IdP in six months, launching operations in September 2026. Coincheck Leverage is the first service integrated with the new IdP. The company’s smartphone app connects to its backend APIs in line with the latest OAuth 2.0 Security Best Current Practice, helping Coincheck deliver a secure, trustworthy service.

“To implement our IdP and authorization server, we compared OSS like Doorkeeper and fully managed services like Auth0 and Amazon Cognito. But OSS fell short on the latest security specifications, such as DPoP and FAPI 2.0, and fully managed services made it difficult to integrate with our existing authentication infrastructure.
Because Authlete provides complex OAuth/OIDC protocol processing and token management as APIs, we highly valued the ability to build an in-house IdP that complies with the latest OIDC standards while utilizing our existing user database and authentication infrastructure.
We first deployed this in-house IdP with Coincheck Leverage, but we also plan to use it as the infrastructure for the Crypto as a Service (CaaS) initiative we’re spearheading.
We’ll need to comply with FAPI 2.0, a financial-grade security standard, as we provide APIs to multiple external partner businesses going forward. So being able to design with future scalability in mind was also a major achievement. I feel the key to the success of this project was maintaining our development flexibility while solidly implementing the core security components.”
*1 PKCE (RFC 7636: Proof Key for Code Exchange by OAuth Public Clients)
*2 PAR (RFC 9126: OAuth 2.0 Pushed Authorization Requests)
*3 DPoP (RFC 9449: OAuth 2.0 Demonstrating Proof of Possession)
Read more customer success stories here.