StUF-ZKN & StUF-BG SOAP / XML Digikoppeling

Custom StUF integration development

Appfront builds custom StUF integrations for the municipal application landscape. We connect case management systems, BRP services, tax applications and front-office systems via StUF-ZKN and StUF-BG: XML messages over SOAP and Digikoppeling, secured with PKIoverheid. And as StUF moves towards the ZGW APIs and Common Ground, we also connect to or migrate to that modern successor.

What is a StUF integration?

StUF, short for Standaard Uitwisseling Formaat (Standard Exchange Format), is the messaging standard that VNG Realisatie (formerly KING) maintains for data exchange within the municipal application landscape. It describes how applications exchange structured XML messages, usually via SOAP on top of Digikoppeling. StUF is a mature standard that is still widely used by municipalities and the suppliers of their core applications.

StUF has sector models for different domains. StUF-ZKN governs the case and document services between, for example, a case management system and task-specific applications (cases, statuses, decisions, documents). StUF-BG governs the basic data: querying and synchronising persons, addresses and businesses from a BRP service or data warehouse. A StUF integration can be a simple request-response query, or an asynchronous stream of notifications that subscribers listen to.

Appfront builds according to the official GEMMA/VNG StUF documentation and the OWASP ASVS security standard. To be candid: StUF is now a legacy standard, and the successor is the ZGW APIs within Common Ground. That is why we not only build new StUF integrations but also advise on the migration path, and can run StUF and ZGW side by side.

StUF-ZKN: case and document services

The sector model for case-based working: creating and updating cases, passing on statuses and decisions, and exchanging documents between the case management system and task-specific applications. The foundation for an integrated case landscape within the municipality.

StUF-BG: basic data

Querying and synchronising basic data such as persons, addresses and businesses from a BRP facility or data warehouse. With recipient indications and notifications, connected applications stay up to date automatically.

Migration to ZGW / Common Ground

StUF is legacy; the future is the ZGW APIs. We run StUF and ZGW side by side, or translate StUF-ZKN to the ZGW APIs through a case bridge, so you can migrate step by step without breaking your existing integrations.

Our development process for StUF integrations

We work to a proven method that removes uncertainty early and delivers a stable integration. From an initial analysis of your application landscape, sector models and Digikoppeling connection through to go-live and ongoing maintenance, every step is aimed at an integration that your organisation can understand and trust itself.

1
Analysis & scope

We map out which applications need to connect, which sector model (StUF-ZKN, StUF-BG or both) and which message types are required, and whether a migration path to ZGW is relevant.

2
Architecture

We design the integration architecture, choose the right Digikoppeling profile with PKIoverheid, and define the message mapping and error-handling strategy.

3
Development

Implementation with XML schema validation, automated tests against the supplier's test environment, structured logging and monitoring. You will see working builds along the way.

4
Go-live & management

Controlled go-live with message validation and a safety net, followed by ongoing management, monitoring and, where applicable, further migration to ZGW.

What a StUF integration delivers in practice

Every StUF integration is built specifically for your application landscape, sector models and adjacent systems. Below are the capabilities we most often deliver for municipalities and vendors who use StUF and want to move step by step towards ZGW.

Request/response queries (Lv01/La01)

Synchronous queries in which your application sends an Lv01 request and receives an La01 response, for example looking up a person or address in a StUF-BG facility, or retrieving case data via StUF-ZKN, with correct selection and scope parameters.

Notifications & subscriptions (Lk01)

Asynchronous mutation messages (Lk01) that automatically pass changes on to recipients. With recipient indications and subscriptions, connected applications stay up to date without repeatedly querying, including the corresponding Bv03 acknowledgements.

Document exchange (StUF-ZKN)

Exchanging documents attached to cases between the case management system and task applications, including large files via MTOM/XOP. Metadata, status and decisions travel along so the case file in the case management system remains complete and current.

Digikoppeling & PKIoverheid

StUF messages travel over Digikoppeling: the WUS profile for synchronous queries and ebMS for reliable asynchronous messaging. We set up the PKIoverheid certificates, endpoints and routing in line with the applicable agreements.

Message validation & mapping

Incoming and outgoing messages are validated against the StUF schemas (version 03.01) and the sector models. We build clear mappings between your internal data model and the StUF elements, with clean error handling via Fo0x error messages.

StUF to ZGW case bridge

A translation layer that converts StUF-ZKN messages into ZGW APIs and back again. This keeps existing StUF applications working while you connect new components to modern REST/JSON APIs: the practical route to Common Ground.

Typical use cases in practice

A StUF integration looks quite different from one organisation to the next. We see a number of patterns recur across the public sector, and for each we have a working setup that takes the right sector models, Digikoppeling and the migration path to ZGW into account.

ZAAK

Case management and task applications

Municipalities linking their case management system via StUF-ZKN to task-specific applications for permits, notifications or the social domain. Cases, statuses, decisions and documents flow back and forth so the case file stays central and complete. See also our software for municipalities.

Basic data from the BRP

Applications that query or synchronise persons, addresses and businesses via StUF-BG, with a BRP facility or data warehouse. Supply subscriptions and notifications keep data current without duplicate registration, a core principle of single data collection. Related: our BRP integration.

Middle office, broker and taxation

A middle-office layer or broker acting as a central hub that routes StUF messages between core applications, and integrations with the tax application for assessments and objections. We set up reliable message traffic with clear routing, logging and monitoring across the whole landscape.

Migration to Common Ground

Organisations that want to move from StUF to the ZGW APIs without a big bang. With a case bridge, we let StUF and ZGW run side by side and migrate applications in phases, so service delivery keeps working during the transition.

Technology we use

We build StUF integrations with the official StUF standard (version 03.01) and the sector models, combined with the backend stack that suits you. The exact choice depends on your application landscape, your Digikoppeling connection and the desired migration path to ZGW, so that your organisation can manage or further develop the integration.

StUF 03.01 StUF-ZKN (Case and Document Services) StUF-BG (Basic Data) SOAP / XML XML Schema validation (XSD) Digikoppeling WUS & ebMS PKIoverheid certificates Lv01 / La01 / Lk01 / Bv03 / Di01 / Du01 MTOM/XOP for documents Supply subscriptions & subscriptions ZGW APIs (REST/JSON) StUF-ZGW case bridge Java / .NET / Node.js / Python BIO / government control frameworks Logging & monitoring GitHub Actions

Why choose Appfront for your StUF integration?

Appfront has extensive experience building integrations for a wide range of organisations in the Netherlands, including in the public sector. We always begin with a thorough analysis of the existing systems and processes. A StUF integration must not only work technically, but also add practical value within your application landscape.

For every integration, we write clear documentation and make sure your own team, or any future supplier, can understand and manage it. No black box, just transparent code and clear agreements on monitoring, alerting and maintenance.

You work with a dedicated point of contact who understands both the technical and the functional side. This keeps communication short, prevents misunderstandings and speeds up decisions when choices need to be made during development.

You may also be interested in our broader services around software for municipalities, municipal websites, custom software and Digikoppeling integrations.

  • Experience with StUF-ZKN, StUF-BG and the StUF message types
  • Experienced with Digikoppeling (WUS/ebMS) and PKIoverheid
  • Builds both StUF and ZGW integrations, and migrates between them
  • Secure by default: separation of rights, authorisation at message level
  • Structured error handling, validation and retry mechanisms
  • Comprehensive logging and monitoring from day one
  • Clear documentation your team can read and manage
  • A fixed point of contact, no account managers passed around
  • Ongoing maintenance and proactive further development
  • A way of working tailored to your existing application landscape

Security and privacy in StUF integrations

StUF messages containing case and basic data almost always include personal data. Transport therefore runs over Digikoppeling with PKIoverheid certificates and encryption, with authorisation at message level so that a recipient only receives the data it is entitled to. Appfront builds in line with the OWASP ASVS and the government control frameworks (BIO), with separation of rights and full logging.

We work from data minimisation: only the data a recipient needs is exchanged. We document the data flows, mappings and message definitions so that your record of processing activities is complete and you can demonstrate compliance with the GDPR. Logging at message level makes the traffic traceable and auditable.

More on our security approach: information security policy and CVD policy.

  • GDPR-compliant data processing and data minimisation
  • Encryption in transit (TLS 1.2+) and at rest
  • Role-based access and least-privilege principles
  • Audit logs with traceable data flows
  • Automatic retries and dead-letter queues
  • Monitoring and alerting for anomalies
  • Secrets management in line with best practice
  • Documentation for your record of processing activities

Frequently asked questions about StUF integrations

Answers to the questions we are asked most often about StUF integrations.

StUF (Standaard Uitwisselings Formaat) is the messaging standard maintained by VNG Realisatie (formerly KING) for exchanging data within the municipal application landscape. A StUF integration exchanges XML messages via SOAP, usually on top of Digikoppeling. The standard has sector models: StUF-ZKN for case and document services, and StUF-BG for core registry data such as persons and addresses. An integration can be simple (a request/response query) or complex (asynchronous notifications with subscriptions between multiple core applications).

StUF is a mature, widely used but now legacy standard. Its successor is the ZGW APIs (REST/JSON) within VNG's Common Ground movement. In practice both often run side by side: many core applications and national facilities still speak StUF, while new components use ZGW. Appfront builds both StUF and ZGW integrations and can migrate a StUF landscape to ZGW/Common Ground step by step, for example via a case bridge that translates StUF-ZKN into the ZGW APIs.

StUF-ZKN (Case and Document Services) handles the exchange of cases, statuses, decisions and documents between, for example, a case management system and task-specific applications. StUF-BG (Basic Data) handles querying and synchronising core data such as persons, addresses and businesses, often from a BRP facility or a data warehouse. Both build on the same StUF message structure (version 03.01) and transport layer, but cover different functional domains. Which one you need depends on the applications and processes you want to connect.

StUF messages are XML and are exchanged via SOAP, typically over the Digikoppeling WUS profile (and ebMS for certain notification traffic), with PKIoverheid certificates for authentication and security. We work with StUF message types such as Lv01/La01 (request/response), Lk01 (notification/mutation), Bv03 (acknowledgement) and the free-form messages Di01/Du01. On our side, we build the adapter in the stack that suits you, whether Java/.NET, Node.js or Python, including XML validation against the schemas, logging and monitoring.

The cost is determined by which sector model (StUF-ZKN, StUF-BG or both) and which message types you need, the number of applications to connect, whether it involves queries only or also mutations and subscriptions, and the requirements around Digikoppeling, PKIoverheid and the supplier's test environment. A possible migration path to ZGW also factors in. We always provide a clear quote following a no-obligation analysis of your application landscape.

Yes. StUF traffic involving core and case data contains personal data and falls under the GDPR. Transport runs over Digikoppeling with PKIoverheid certificates and encryption, with authorisation at message level so that a recipient only receives the data they are entitled to. Appfront builds according to OWASP ASVS and the government security frameworks (BIO), with separation of duties, full logging and a data minimisation approach. We document the data flows so that your record of processing activities stays complete and you can demonstrably comply with the GDPR.

Yes. Appfront regularly takes over existing StUF integrations, even when they were originally set up by another supplier. We review the message definitions, mappings, error handling and Digikoppeling configuration, document the current setup and propose improvements. From that point on, we handle adjustments, extensions and monitoring, and where desired we can migrate the integration to the ZGW APIs in phases.

StUF is the standard within the Dutch municipal domain. A StUF integration is therefore suited to municipalities, municipal collaborative partnerships, environmental services and implementing organisations that need to connect core applications such as a case management system, a BRP facility, a tax application or a middle office/broker, or to connect to national facilities. We also help software vendors who want to make their application StUF-compliant or expose it via ZGW.

Ready to build your StUF integration?

Tell us which applications you want to integrate via StUF, which sector models are involved and whether a migration to the ZGW APIs is on the cards. We're happy to advise on StUF-ZKN, StUF-BG, Digikoppeling and the path towards Common Ground. A no-obligation first conversation will quickly give you a clear picture of the possibilities. Feel free to get in touch.

Edit content