Logius standard WUS & ebMS2 PKIoverheid & OIN

Custom DigiKoppeling integration development

Appfront builds custom DigiKoppeling integrations that let your government system exchange messages securely and reliably with other government bodies and national services. We set up the interface according to the Logius standards: WUS for synchronous request-response, and ebMS2 for reliable asynchronous transport, using PKIoverheid certificates and the OIN. DigiKoppeling handles the secure transport; you decide what the content of the message is.

What is a DigiKoppeling integration?

DigiKoppeling is the Logius standard for secure, reliable message exchange between government organisations. The standard sets out the logistical agreements for electronic messaging: how a message is wrapped, addressed, secured and delivered. Important to remember: DigiKoppeling governs the transport and the interface, not the content of the message. Which data a message contains is determined by a content standard such as StUF or a ZGW API.

The standard defines two interface profiles. WUS, based on SOAP and WS-Security, is used for synchronous request-response exchanges: you ask a question and get an answer straight away. ebMS2 (ebXML Messaging Service) is aimed at reliable asynchronous transport, where a message is guaranteed to be delivered exactly once, and is also suitable for large messages and attachments. Authentication and encryption rely on PKIoverheid certificates, and organisations are identified by their OIN (Organisation Identification Number).

Appfront builds in line with the official Logius documentation for DigiKoppeling and the OWASP ASVS security standard. Together with you, we choose the right interface for the system you want to exchange data with, and set up certificates, error handling and logging so that message traffic remains reliable and traceable, even at peak volumes.

Secure transport, not the content

DigiKoppeling is the digital envelope: it wraps, secures and delivers the message between government bodies. What is inside the envelope, such as a StUF or ZGW message, is determined by a separate content standard. This keeps transport separate from content.

Two profiles: WUS & ebMS2

WUS (SOAP/WS-Security) for synchronous request-response, where you receive an immediate answer. ebMS2 for reliable asynchronous transport with guaranteed, single delivery — including for large messages and attachments. We choose the profile that suits your service.

€

PKIoverheid & OIN

Messages are encrypted and signed with PKIoverheid certificates, and parties authenticate each other mutually. Each organisation identifies itself with its OIN. That way you know exactly who you are exchanging with, and the traffic stays confidential and traceable.

Our development process for DigiKoppeling integrations

We work to a proven methodology that removes uncertainty early and delivers a stable interface. From an initial analysis of the system you want to exchange data with and selecting the right interface profile, through to go-live and ongoing management, every step is aimed at an integration your team can understand and trust.

1
Analysis and interface selection

We map out which service or chain you want to exchange data with, which messages are involved, and whether WUS (synchronous) or ebMS2 (asynchronous) is the better fit. We also review which content standard and OIN apply.

2
Architecture & certificates

We design the interface, arrange the PKIoverheid certificates and OIN configuration, choose the two-way TLS setup and define an error handling and logging strategy.

3
Development & testing

Implementation with automated tests, structured logging and monitoring, plus conformance and chain tests against the target system. You see working integrations along the way.

4
Connection and management

Controlled connection to the production environment with validation and a safety net, followed by ongoing management, including timely certificate renewal and further development.

What a DigiKoppeling integration delivers in practice

Each DigiKoppeling integration is set up specifically for the system you exchange data with, the chosen interface profile and your neighbouring systems. Below are the capabilities we most often deliver for government organisations and suppliers who need to exchange messages securely.

WUS interface (synchronous)

A SOAP interface with WS-Security for synchronous request-response exchanges: your system asks a service for information and receives a structured answer straight back. Suitable for retrieving data from registers and national services in real time.

ebMS2 interface (asynchronous)

An ebXML Messaging Service interface for reliable asynchronous transport, with guaranteed and exactly-once delivery, even if the recipient is temporarily unavailable. Suitable for reporting events, chain data exchange, and sending large messages and attachments.

Certificate & OIN management

Setting up PKIoverheid certificates for encryption and signing, two-way TLS authentication and correct OIN registration. This includes monitoring validity periods, so expiring certificates are renewed in time and traffic does not stop.

Connection to national services

Integration with national services and chains such as the Basic Registration of Persons (BRP), Digilevering and Suwinet. We handle the connection procedure, the conformity and chain tests, and the setup in your acceptance and production environments.

Large messages & attachments

For messages too large for standard transport, we set up the Large Messages profile: the message refers to a separate, securely retrieved file. This lets you send sizeable attachments reliably without burdening the message flow.

Logging & monitoring

Complete logging of message traffic with traceable data flows, status monitoring and alerting for deviations or failed deliveries. Your management team can see immediately whether messages have been processed correctly, and every exchange remains traceable for audits.

Typical use cases in practice

A DigiKoppeling integration works out differently for each organisation and each service. We see a number of patterns recurring, and for each of them we have a working setup, with attention to the right interface profile, the certificates and the content standard in the message.

CRM

Interface between government systems

Municipalities, provinces and implementing organisations that want to communicate securely with other government systems from their case management system, BRP service or specialist application. DigiKoppeling provides the secure interface; the content runs through standards such as StUF or a ZGW API. Relevant for custom software for municipalities.

Connection to national services

Organisations that want to connect to national services such as the Personal Records Database (BRP), Digilevering or Suwinet. We take care of the interface, the PKIoverheid certificates, the OIN and the conformity tests, so you can request or receive data reliably.

Data exchange within chains

Collaborative partnerships and supply chain partners, for example in the social domain or in licensing, that exchange messages in a structured way. ebMS2 ensures reliable, guaranteed delivery between parties, including for larger messages and attachments.

Government software suppliers

Software vendors who need to make their product DigiKoppeling-compliant in order to sell it to government bodies. We build a reusable WUS and ebMS2 interface into your application, so your customers can connect per organisation without custom work. See also our ZGW API integration and StUF integration.

Technology we use

We build DigiKoppeling integrations according to the official Logius interface standards, combined with the backend stack that suits you. The exact implementation depends on the chosen profile and the service you exchange data with, so that your own team can manage or further develop the interface.

For message exchange in education there is a separate variant of this standard; see our page on Edukoppeling.

DigiKoppeling WUS DigiKoppeling ebMS2 Large Messages Profile SOAP / WSDL WS-Security & WS-Addressing ebXML Messaging Service PKIoverheid certificates Two-way TLS OIN / COR XML & XSD validation StUF & ZGW message content Java / .NET / Node.js / Python DigiKoppeling adapters Logging & monitoring Conformity & chain tests Acceptance & production connection

Why choose Appfront for your DigiKoppeling integration?

Appfront has extensive experience building integrations for public sector organisations in the Netherlands. We always start with a thorough analysis of your existing systems, the service you want to exchange data with and the chosen interface profile. An integration must not only be technically correct according to the standard, but also work in practice within your organisation.

For every integration, we write clear documentation and make sure your own team, or any future supplier, can understand and manage it. No black box, just transparent code and clear agreements on monitoring, alerting and maintenance.

You work with a dedicated point of contact who understands both the technical and the functional side. This keeps communication short, prevents misunderstandings and speeds up decisions when choices need to be made during development.

Take a look at our wider services around software for municipalities, municipality websites and custom software. Would you like to talk through your situation? Get in touch for a no-obligation conversation.

  • Experience with the DigiKoppeling WUS and ebMS2 interface standards
  • Familiar with PKIoverheid certificates, OIN and two-way TLS
  • Knowledge of content standards such as StUF and the ZGW APIs
  • Secure by default: certificates in vaults, strict permissions per integration
  • Structured error handling and reliable delivery
  • Comprehensive logging and monitoring from day one
  • Clear documentation your team can read and manage
  • A fixed point of contact, no account managers passed around
  • Ongoing management, including timely certificate renewal
  • A way of working aligned with your existing government IT landscape

Security and privacy in DigiKoppeling integrations

Messages between government bodies almost always contain personal data or confidential information. DigiKoppeling is specifically designed for this: messages are encrypted and signed with PKIoverheid certificates, and parties authenticate each other two-way via their OIN. On top of that, Appfront builds to the OWASP ASVS: certificates in secure vaults, strict permissions per integration and full logging of message traffic.

Because DigiKoppeling handles the transport rather than the content, we align data processing with the content standard and with the purpose of the exchange. We document the data flows, certificates and OIN configuration so that your record of processing activities is complete and you can demonstrably comply with the GDPR. The logs serve as traceable evidence of every exchange.

Thinking about a secure integration? Get in touch. We're happy to think along with you about your specific situation.

  • Encryption and signing with PKIoverheid certificates
  • Mutual authentication via OIN and two-way TLS
  • GDPR-compliant data processing and data minimisation
  • Role-based access and least-privilege principles
  • Full logging with traceable data flows
  • Reliable delivery with monitoring and alerting
  • Certificate and secrets management following best practices
  • Documentation for your record of processing activities

Frequently Asked Questions About DigiKoppeling Integrations

Answers to the questions we are asked most often about DigiKoppeling integrations.

A DigiKoppeling integration is the technical interface through which your system exchanges messages securely and reliably with other government systems. DigiKoppeling is the Logius standard that sets the logistical rules: how a message is packaged, addressed, secured and delivered. It governs transport, not the content of the message. There are two interface standards: WUS for synchronous request-response exchanges, and ebMS2 for reliable asynchronous transport of, among other things, large messages and attachments. Authentication and encryption are handled using PKIoverheid certificates, and organisations are identified by their OIN.

WUS and ebMS2 are the two interface profiles of DigiKoppeling. WUS is based on SOAP and WS-Security and is used for synchronous request-response exchanges: you send a request and receive an immediate reply, for example when retrieving data. ebMS2 (ebXML Messaging Service) is designed for reliable asynchronous transport, where a message is guaranteed to be delivered exactly once, even if the recipient is unavailable at the time. ebMS2 is often used for reporting events, sending large messages and attachments, and chain data exchange. Which profile is suitable depends on the service you are connecting to.

Since 2009, DigiKoppeling has been on the 'apply or explain' list of Forum Standaardisatie. This means government organisations must apply the standard to digital data exchange that forms part of the Generic Digital Infrastructure, including base registries, or that spans multiple sectors, where two-way authentication between systems is required. If you deviate, the 'explain' principle applies and the choice must be justified. We can help you choose the right interface for the service you want to exchange data with.

We build to the official Logius interface standards: WUS based on SOAP, WSDL and WS-Security for synchronous traffic, and ebMS2 (ebXML Messaging Service) for reliable asynchronous transport. For large messages and attachments we use the Large Messages profile. Authentication and encryption run through PKIoverheid certificates and two-way TLS; we identify organisations using the OIN from the COR. We implement the integration in the backend stack that suits you, whether Java, .NET, Node.js or Python, optionally via an existing DigiKoppeling adapter.

The cost depends on the number and type of interfaces (WUS, ebMS2 or both), the services you are connecting to, the complexity of message processing on your side, and the setup of certificates and monitoring. Ongoing management, timely renewal of PKIoverheid certificates and support also affect the total investment. We always provide a clear quote following a no-obligation analysis of your situation.

Yes. DigiKoppeling was designed precisely for secure exchange between government bodies: messages are encrypted and signed with PKIoverheid certificates, and parties authenticate each other in both directions via their OIN. On top of this, Appfront builds to OWASP ASVS and the applicable government standards: certificates held in secure vaults, strict permissions per integration, and full logging of message traffic. We document the data flows so that your record of processing activities remains complete and you can demonstrate GDPR compliance.

Yes. Appfront regularly takes over existing integrations, even when another party originally set them up. We review the WUS and ebMS2 interfaces, the certificate and OIN configuration, the error handling and the logging, document the current setup and propose improvements. From that point on, we can handle changes, extensions and monitoring, including timely renewal of expiring PKIoverheid certificates.

DigiKoppeling is the transport mechanism behind many national services and chains. You can connect to the Basic Registry of Persons (BRP) and Digilevering, among others, and it is used for data exchange in chains such as Suwinet. The message content you send, such as StUF or ZGW messages, is separate from DigiKoppeling: DigiKoppeling handles secure transport, while the content standard defines what is in the message. We help you set up both the correct interface and the associated content standard.

Ready to build your DigiKoppeling integration?

Tell us which service or chain you want to exchange data with and which messages are involved. We're happy to help you think through the right interface (WUS or ebMS2), the certificates and the connection procedure. A no-obligation first conversation will give you a clear picture of the options within half an hour. Also see our DigiD integration and Suwinet integration.

Edit content