October 7, 2026

Coincheck Adopts Authlete to Implement OAuth/OIDC for Authentication and Authorization Infrastructure

By integrating Authlete into its existing systems, Coincheck rapidly built a FAPI 2.0-compliant IdP in-house, enabling secure API access for a new service

We’re pleased to announce that Coincheck, Inc. (Coincheck) has adopted Authlete’s OAuth/OpenID Connect (OIDC) backend service to build an OAuth/OIDC-compliant identity provider (IdP).

Coincheck is a group company of Monex Group, Inc., listed on the Tokyo Stock Exchange Prime Market, and Coincheck Group N.V., listed on the Nasdaq Stock Market. The company operates Coincheck, a retail crypto asset trading service; Coincheck Prime, which helps corporate and institutional investors trade and custody crypto assets; and Coincheck Partners, which supports businesses in building crypto-related ventures.

Coincheck deployed Authlete to handle the OAuth/OIDC processing for the new IdP, which securely connects its smartphone app with its newly launched service, Coincheck Leverage. By reusing its existing authentication flow and user database, the company quickly built the IdP in-house with FAPI 2.0 compliance to ensure advanced security.

The Challenges of Implementing OAuth/OIDC Extensions In-House

Coincheck is diversifying its revenue sources by leveraging its customer base, one of the largest in Japan. To accelerate new service launches, the company needed a highly secure, scalable IdP infrastructure. To this end, the company had to implement extensions such as PKCE*1, PAR*2, and DPoP*3 to strengthen OAuth 2.0 authorization security for smartphone apps. It also recognized that complying with FAPI 2.0, a financial-grade security standard, would be essential to growing its business by offering APIs to partner companies.

With an in-house-first policy, Coincheck initially explored developing and operating the IdP entirely on its own. However, because implementing the protocols is inherently difficult and keeping up with the latest specifications creates a heavy operational burden, the company realized that it could not rely solely on internal resources.

Coincheck also considered building on Doorkeeper, open-source software (OSS). However, since it lacked support for the latest standards like PAR, DPoP, and FAPI, Coincheck concluded that implementing and maintaining these missing features internally would be extremely difficult.

After weighing these options, Coincheck pivoted from its purely in-house development strategy and decided to adopt an external solution that could handle advanced OAuth/OIDC processing.

Requirements for an OAuth/OIDC Solution: Flexible Integration Into the Existing Environment and Support for Advanced Security Standards

When Coincheck evaluated external OAuth/OIDC solutions, it prioritized the following:

  • ‍Use the existing user database and authentication infrastructure: The solution had to work with the user database and authentication infrastructure, including passkeys, already built into Coincheck’s current service.‍
  • Deploy and operate in a self-managed environment: As a financial services provider facing strict audit requirements, Coincheck needed to manage the solution in-house rather than adopt a SaaS offering.‍
  • Integrate seamlessly with the Ruby ecosystem: Since Coincheck planned to build its IdP in Ruby, it needed an SDK and API that would integrate easily with Ruby applications.‍
  • Comply with FAPI: The solution had to comply with FAPI 1.0 and FAPI 2.0 and enable Coincheck to enforce FAPI at the service or client level.‍
  • Support PAR, DPoP, and PKCE: The solution had to already support these extensions to strengthen authorization security for smartphone apps.‍
  • Integrate quickly and easily: Coincheck needed to deploy the solution on a short timeline.

Why Coincheck Chose Authlete: Cost-Effectiveness, OpenID Certification for FAPI 2.0, and Robust Management APIs

After comparing Authlete, Ory Hydra, Auth0, and Amazon Cognito, Coincheck decided to build the IdP internally while delegating the highly complex OAuth/OIDC protocol processing and token management to Authlete. Beyond meeting its requirements, Coincheck valued Authlete for the following reasons:

  • ‍Cost-effectiveness: Authlete specializes in OAuth/OIDC protocol processing and token management. By outsourcing only the most difficult part to Authlete, Coincheck was able to build the rest of the IdP in-house, keeping external costs down.‍
  • OpenID Certification for FAPI 2.0: Authlete has earned FAPI-related OpenID certifications, including FAPI 2.0, ensuring compliance with advanced security specifications. Authlete also supports a wide range of OAuth/OIDC extensions and keeps up with the latest security updates.‍
  • Robust Management APIs: Because Authlete exposes all of its functionality through APIs, Coincheck can execute bulk token revocations—a critical security measure—from its internal management systems.

Building a FAPI 2.0-Compliant IdP in Six Months

Using Authlete, Coincheck successfully built its IdP in six months, launching operations in September 2026. Coincheck Leverage is the first service integrated with the new IdP. The company’s smartphone app connects to its backend APIs in line with the latest OAuth 2.0 Security Best Current Practice, helping Coincheck deliver a secure, trustworthy service.

Coincheck’s IdP built with Authlete

Comment from Yuki Osone, Application Platform Department, Development & AI Division, Coincheck, Inc.

“To implement our IdP and authorization server, we compared OSS like Doorkeeper and fully managed services like Auth0 and Amazon Cognito. But OSS fell short on the latest security specifications, such as DPoP and FAPI 2.0, and fully managed services made it difficult to integrate with our existing authentication infrastructure.

Because Authlete provides complex OAuth/OIDC protocol processing and token management as APIs, we highly valued the ability to build an in-house IdP that complies with the latest OIDC standards while utilizing our existing user database and authentication infrastructure.

We first deployed this in-house IdP with Coincheck Leverage, but we also plan to use it as the infrastructure for the Crypto as a Service (CaaS) initiative we’re spearheading.

We’ll need to comply with FAPI 2.0, a financial-grade security standard, as we provide APIs to multiple external partner businesses going forward. So being able to design with future scalability in mind was also a major achievement. I feel the key to the success of this project was maintaining our development flexibility while solidly implementing the core security components.”

‍

*1 PKCE (RFC 7636: Proof Key for Code Exchange by OAuth Public Clients)

*2 PAR (RFC 9126: OAuth 2.0 Pushed Authorization Requests)

*3 DPoP (RFC 9449: OAuth 2.0 Demonstrating Proof of Possession)

‍

Read more customer success stories here.

‍

‍

‍

‍