Custom VNG API integration development
Appfront builds and validates integrations in line with the VNG/GEMMA API standards and the Dutch API Design Rules (ADR). For municipalities and software vendors, we deliver REST APIs that demonstrably comply with the standard, from Customer Interactions, Requests and Open Council Information to Haal Centraal queries against the base registers. If your focus is case-based working, see our page on the ZGW API integration. You can comply or explain, and keep control over your suppliers.
What are the VNG API standards?
The VNG API standards ensure that municipal software exchanges data in a uniform, predictable way. The foundation is the NLGov REST API Design Rules (ADR): design rules for REST APIs, maintained by Logius and mandated through Forum Standaardisatie under the comply-or-explain principle. This page covers that broader family of standards, not case-based working specifically. For the ZGW APIs, see our ZGW API integration.
Alongside the API Design Rules sit domain standards from the GEMMA landscape of VNG Realisatie: Customer Interactions (with Customers, Contact Moments and Requests), Open Council Information, IMWOZ queries and Rules for Activities. There are also the Haal Centraal queries, through which municipalities retrieve data directly from the base registers: BRP, BAG, WOZ, HR and BRK. In practice, compliant integration means following the right information model, adhering to the ADR and demonstrating this through the VNG API test facility.
Appfront builds according to the official NLGov REST API Design Rules and the accompanying information model for each standard. We translate the agreements into a working, testable integration, align authorisation and error handling with your landscape, and ensure the implementation keeps pace when a standard releases a new version. Whether you are a municipality steering suppliers or a vendor wanting to connect in a GEMMA-compliant way, the standard is the starting point.
API Design Rules (ADR)
The NLGov design rules for REST APIs: predictable resources, OpenAPI 3.x documentation, correct HTTP methods and status codes, pagination and versioning. Mandatory under comply-or-explain for government organisations.
GEMMA domain standards
Customer Interactions (Customers, Contact Moments, Requests), Open Council Information, IMWOZ queries and Rules for Activities, each with its own information model within the GEMMA reference architecture of VNG Realisatie.
Demonstrably compliant
With the VNG API test facility, you demonstrate that a delivered API meets the standard. Essential in tenders and RFI processes where municipalities want suppliers to adhere to the standards.
Our process for a VNG API integration
We work to a proven methodology that removes uncertainty early and delivers a testable, standards-compliant integration. From analysing the right standard and information model to validation through the API test facility and ongoing management, every step is aimed at an integration your team can understand and demonstrably keep compliant.
We determine which VNG/GEMMA standard applies, which data you exchange, which authorisation requirements apply, and how the standard relates to your existing systems.
We design the integration against the API Design Rules and the information model, choose the right authentication (such as OAuth 2.0 NL GOV and PKIoverheid) and define an error-handling strategy.
Implementation with automated tests, structured logging and monitoring. We check continuously against the standard. You will see working builds along the way.
Validation via the API testing facility and a controlled go-live with a safety net, followed by ongoing management and further development as the standard evolves.
What a VNG API integration concretely delivers
Every integration is set up specifically for the standard you need, your information model and the adjacent systems. Below are the capabilities we most often deliver for municipalities and vendors who want to integrate according to the VNG/GEMMA API standards.
ADR-compliant REST APIs
APIs that follow the NLGov REST API Design Rules: correct resource naming, OpenAPI 3.x specification, proper HTTP methods and status codes, pagination, filtering and versioning. Predictable and developer-friendly, as the standard prescribes.
Customer Interactions & Requests
Integrations on the Customer Interactions standard, covering Customers, Contact Moments and Requests, so that customer contact and applications are recorded in a structured way and made available. A request forms the link between customer, products and services, and their handling.
Haal Centraal queries
Retrieve data directly from the base registries via the Haal Centraal APIs: BRP (persons), BAG (addresses and buildings), WOZ, HR and BRK. Query the source directly, in line with the Haal Centraal specifications declared as standards.
Open Raadsinformatie
Making council and committee information available through the Open Raadsinformatie standard: meetings, agenda items, decisions and documents made public and searchable in line with the OpenAPI specification from VNG Realisatie.
Validation & testing facility
We check the integration against the standard and run it through the VNG API test facility, so you can demonstrate compliance. Essential for tenders, RFI processes and supplier agreements that require the standard.
Secure authorisation
Authentication in accordance with the NL GOV Assurance profile for OAuth 2.0, with TLS 1.3 and, where the standard requires it, PKIoverheid certificates and mutual TLS. Scoped authorisations and least privilege, with full logging of every query.
Typical use cases in practice
Working in line with the VNG API standards looks different for every organisation. We see a number of recurring contexts, and for each of them we have a working, testable setup with attention to the right information model, authorisation and demonstrable compliance.
Municipalities managing their suppliers
Municipalities that want their suppliers to comply with the API standards and want to safeguard integrations between core systems. We translate the requirement into a testable integration and validate it through the test facility. See also our software for municipalities and municipal website.
Software Vendors
Suppliers of municipal software who want to make their product GEMMA-compliant. We build or test the API against the ADR and the domain information model, deliver OpenAPI 3.x documentation and demonstrate compliance, so you fit smoothly into tenders and RFIs.
Partnerships
Joint arrangements, environmental services and regional partnerships that want to bring multiple municipalities and systems into line. A single set of standards-compliant integrations avoids custom work for each party and keeps the landscape manageable.
RFI & tender processes
Projects where API standards are a hard requirement. We help you translate the requirement into testable acceptance criteria, build or assess the integration and deliver the evidence from the API test facility, so compliance doesn't remain an open-ended question.
Technology we use
We build integrations according to the VNG API standards with REST and OpenAPI 3.x, in line with the NLGov API Design Rules, combined with the backend stack that suits you. The precise choice depends on the standard and your landscape, so your own team can manage the implementation and demonstrably keep it compliant.
Why Appfront for your VNG API integration?
Appfront has extensive experience building API integrations for a wide range of organisations in the Netherlands, including the public sector. We always begin with a thorough analysis of the right standard, the information model and your existing systems. An integration must not only work technically, but also demonstrably meet the standard.
For every integration, we write clear documentation and make sure your own team, or any future supplier, can understand and manage it. No black box, just transparent code and clear agreements on monitoring, alerting and maintenance.
You work with a dedicated point of contact who understands both the technical and the functional side. This keeps communication short, prevents misunderstandings and speeds up decisions when choices need to be made during development.
See also our related standards-based integrations: ZGW API integration (case-based working), Haal Centraal integration and Digikoppeling, plus our custom software and AI for municipalities.
- Built in line with the NLGov API Design Rules and the GEMMA information model
- Experienced with Customer Interaction, Requests, Open Council Information and Haal Centraal
- Tested and validated via the VNG API test facility
- Security with OAuth 2.0 NL GOV, PKIoverheid and mutual TLS
- Structured error handling and retry mechanisms
- Comprehensive logging and monitoring from day one
- Clear documentation your team can read and manage
- A fixed point of contact, no account managers passed around
- Ongoing maintenance and further development as standards evolve
- A way of working aligned with your existing government IT landscape
Security and privacy in VNG API integrations
Government integrations almost always involve personal data from the basic registries or sensitive process information. Appfront therefore builds in line with the NL GOV Assurance profile for OAuth 2.0: TLS 1.3 (TLS 1.2 as fallback) and, where the standard requires it, PKIoverheid certificates with mutual TLS for strong client authentication based on the OIN. We focus access on least privilege with scoped authorisations.
We document the data flows, authorisations and integration points so your record of processing activities is complete and you demonstrably comply with the GDPR, with data minimisation and purpose limitation as starting points. Full logging of every request makes use traceable, and we verify compliance through the VNG API test facility.
More about our approach: Digikoppeling integration for standardised message exchange, or get in touch directly for a security review of your integration.
- GDPR-compliant data processing, purpose limitation and data minimisation
- TLS 1.3 in transit and encryption at rest
- PKIoverheid certificates and mutual TLS where required
- OAuth 2.0 NL GOV with scoped, least-privilege authorisations
- Full logging with traceable requests
- Monitoring and alerting for anomalies
- Secrets management in line with best practice
- Documentation for your record of processing activities
Frequently asked questions about VNG API integrations
Answers to the questions we are asked most often about integrating according to the VNG API standards.
The VNG API standards are the agreements that allow municipal software to exchange data in a uniform, predictable way. The foundation is the NLGov REST API Design Rules (ADR), maintained by Logius and mandated through Forum Standaardisatie under the apply-or-explain principle. On top of that are domain standards from the GEMMA landscape of VNG Realisatie, such as Customer Interactions (Customers, Contact Moments, Requests), Open Council Information, IMWOZ inquiries and the Haal Centraal queries on the basic registries. Case-based working (the ZGW APIs) is a standard of its own within this landscape, and we have a separate page for it.
The ZGW APIs (Zaken, Documenten, Catalogi, Besluiten) are the specific standard for case-based working. This page covers the broader family of VNG/GEMMA API standards and the Dutch API Design Rules: the overarching design rules plus standards such as Customer Interaction, Requests, Open Council Information and Haal Centraal. If you specifically need to build a case-based working integration, we refer you to our page on ZGW API integration; the two complement each other.
A compliant integration means your API or integration demonstrably meets the applicable standard. For REST APIs, the ADR requires, among other things, correct resource naming, OpenAPI 3.x documentation, correct HTTP methods and status codes, pagination and versioning. For the domain standards, the corresponding information model applies. VNG provides an API testing facility that lets you demonstrate that an implemented API meets the standard, which is useful in tenders and supplier agreements.
The core is the NLGov REST API Design Rules (ADR). Around it sit standards including Customer Interaction (Customers, Contact Moments, Requests), Open Council Information, IMWOZ inquiries, Rules for Activities and the Haal Centraal inquiries on the base registers (BRP, BAG, WOZ, HR, BRK). For case-based working there is the separate ZGW standard. We help you determine which standard fits your use case and how it relates to your existing systems.
The cost depends on which standard(s) you are integrating, the complexity of the data flows, the number of systems to be connected and the degree of custom business logic. Demonstrating compliance via the API testing facility, the authentication requirements (such as PKIoverheid and mTLS) and ongoing management also play a part. We always provide a clear quote after a no-obligation analysis of your situation.
Yes. Government data demands strict security. We work in line with the NL GOV Assurance profile for OAuth 2.0, using TLS 1.3 (TLS 1.2 as fallback) and, where the standard requires it, PKIoverheid certificates and mutual TLS for strong client authentication. We implement access on a least-privilege basis with scoped authorisations and comprehensive logging. We document the data flows so your processing register stays complete and you can demonstrably comply with the GDPR.
Yes. Appfront regularly takes over existing integrations, including those set up by another party. We test the API against the API Design Rules and the relevant information model, run the API testing facility, document the current setup and propose improvements. From that point on, we can handle adjustments, extensions and monitoring, so you stay compliant as the standards evolve.
For municipalities that want to hold their suppliers to the API standards, for software suppliers who want to integrate in a GEMMA-compliant way, for partnerships and joint arrangements, and for RFI and tender processes that require API standards. We translate the standards into a working, testable integration that your own team can understand and manage.
Ready to integrate according to the VNG API standards?
Tell us which standard you need and which systems need to connect, whether you are a municipality looking to steer suppliers or a supplier wanting to connect in a GEMMA-compliant way. We are happy to help with the information model, authorisation and demonstrating compliance via the testing facility. Book a no-obligation advisory call and you will quickly get a clear picture of the possibilities.