Case-based working Common Ground VNG standard

Custom ZGW API integration

Appfront builds custom integrations with the ZGW APIs: the standard for case-based working within Common Ground. We connect your task application, website or case management system to the Zaken API (ZRC), Documenten API (DRC), Catalogi API (ZTC), Besluiten API (BRC) and Notificaties API (NRC). This way you work with data at the source, in line with the Dutch API strategy, with authorisations per case type and real-time notifications.

What are the ZGW APIs?

The ZGW APIs are the VNG standard for case-based working within Common Ground. They replace the older, SOAP-based StUF/ZDS interfaces with a set of coherent REST/JSON APIs. The core components are the Zaken API (ZRC) for cases, the Documenten API (DRC) for documents, the Catalogi API (ZTC) for case types, the Besluiten API (BRC) for decisions and the Notificaties API (NRC) for events. Authorisation is handled through the Autorisaties API (AC).

The principle behind Common Ground is that applications and data are separated: case data, documents and case types live in separate registers that are queried and updated directly via APIs, rather than copied between systems. In practice, a custom integration means creating and updating cases, linking documents, reading case types from the catalogue, recording decisions and responding immediately to changes through subscriptions to the Notificaties API.

Appfront builds in line with the official gemma-zaken documentation from VNG Realisatie and the OWASP ASVS security standard. We align the integration, the authorisations per case type and the error handling with your actual processes, so the integration remains ZGW-compliant and keeps pace with new versions of the standard.

Data at the source

Cases, documents and decisions live in separate registers and are queried and updated directly via the API. No copies that drift out of step, but a single up-to-date source of truth that every connected application shares.

Real-time notifications

Through the Notificaties API (NRC) you subscribe to events, such as a new case, a status change or an added document. Connected applications respond immediately, without needing to poll.

Authorisation per case type

The Autorisaties API (AC) determines which application may view and edit which case types, with scopes and a maximum confidentiality level. Data is filtered at the source in line with privacy by design.

Our development process for ZGW API integrations

We work to a proven methodology that removes uncertainty early and delivers a stable, ZGW-compliant integration. From an initial analysis of your case types, processes and existing case management system through to go-live and ongoing management, every step is designed to deliver an integration your organisation can understand and trust.

1
Analysis & scope

We map out which processes and case types you want to support, which ZGW components (ZRC, DRC, ZTC, BRC, NRC) are needed, which authorisations apply, and whether a migration from StUF is required.

2
Architecture

We design the integration architecture in line with the Dutch API strategy, set up JWT authentication and authorisations per case type, and define an error handling and notification strategy.

3
Development

Implementation against the ZGW standard, with automated tests, structured logging and monitoring. You will see working builds along the way, tested against the reference implementation.

4
Go-live & management

A controlled go-live with data validation and a safety net, followed by ongoing management and keeping pace with new versions of the standard.

What a ZGW API integration delivers in practice

Every ZGW integration is set up specifically for your processes, case types and adjacent systems. Below are the capabilities we most often deliver for public sector organisations working case-based through the ZGW APIs.

Creating & updating cases (ZRC)

With the Zaken API we create cases, link roles, statuses and results, and keep case progress up to date. Your task application or website can thus register a request directly as a case in the central case registration.

Document integration (DRC)

With the Documents API we link information objects to cases: requests, attachments, decisions and correspondence. Metadata, confidentiality and versions are recorded in line with the standard and linked to the correct case.

Case types from the catalogue (ZTC)

The Catalogi API exposes case types, status types, outcome types and properties. Your application reads these definitions, so forms and process steps automatically align with the configured case type catalogue.

Recording decisions (BRC)

With the Decisions API we record the decisions made and link them to the relevant case and documents. For permits, decisions and enforcement orders this creates a complete and traceable file.

Notifications & subscriptions (NRC)

The Notifications API forwards events to connected applications. We set up channels and subscriptions and process incoming notifications via webhooks, so that processes respond immediately to a new or changed case.

Authorisations & StUF migration

We manage access through the Authorisations API using scopes and confidentiality levels per case type, and where necessary build a translation layer between existing StUF/ZDS interfaces and the ZGW APIs, so that old and new systems keep working together during migration.

Typical use cases in practice

A ZGW API integration looks different for every organisation. We regularly see a number of patterns recurring within the public sector, and for each of them we have a proven setup with attention to case types, authorisations and correct process handling.

CRM

Case management systems at municipalities

Municipalities that work case-based and want to connect their case management system, website or mid-office to the ZGW APIs. Requests are registered as cases, documents are linked and progress is fed back. See also our software for municipalities and municipality website.

Permits, supervision & enforcement

Environmental services and VTH departments that handle permit applications, supervision files and enforcement decisions case-based. Cases (ZRC), documents (DRC) and decisions (BRC) together form a complete file, with notifications sent to the relevant task applications. Also relevant for water boards.

Migration from StUF to Common Ground

Organisations moving from the older, SOAP-based StUF/ZDS interfaces to the modern ZGW APIs. We map the existing message traffic, build an adapter or translation layer where needed, and keep old and new systems running side by side during the transition. See our StUF integration.

Connecting task applications to case registration

Specialist task applications, for example for public space reports, subsidies or objections, that communicate with the central case registration as consumer or provider. Each application works with the same data at the source, combined with our Haal Centraal integration for source data.

Technology we use

We build ZGW integrations against the official standard from VNG Realisatie: RESTful APIs with JSON, in line with the Dutch API strategy. Authentication runs via JWT and the Authorisations API; for changes we use the Notifications API. We align the back-end stack with your landscape, so your own team or supplier can manage the integration.

Zaken API (ZRC) Documenten API (DRC) Catalogi API (ZTC) Besluiten API (BRC) Notificaties API (NRC) Autorisaties API (AC) REST / JSON JWT (Bearer) authentication OpenAPI specifications Dutch API Strategy API Design Rules Common Ground Webhooks & subscriptions StUF / ZDS adapters Python / Node.js / .NET / PHP TLS & secrets management

Why choose Appfront for your ZGW API integration?

Appfront has extensive experience building API integrations for a wide range of organisations in the Netherlands. We always start with a thorough analysis of your existing systems and processes. An integration should not only work technically, but also add practical value to the way you work.

For every integration, we write clear documentation and make sure your own team, or any future supplier, can understand and manage it. No black box, just transparent code and clear agreements on monitoring, alerting and maintenance.

You work with a dedicated point of contact who understands both the technical and the functional side. This keeps communication short, prevents misunderstandings and speeds up decisions when choices need to be made during development.

You may also be interested in our wider services around custom software, AI for municipalities and government, and our other government integrations, such as the Digikoppeling integration. Questions about your situation? Feel free to get in touch.

  • Experience with the ZGW APIs (ZRC, DRC, ZTC, BRC, NRC) and the Authorisations API
  • Building in line with the Dutch API Strategy and Common Ground
  • Familiar with JWT authentication, authorisations per case type and notification subscriptions
  • Experience migrating from StUF/ZDS to the ZGW standard
  • Structured error handling and retry mechanisms
  • Comprehensive logging and monitoring from day one
  • Clear documentation that your organisation can read and manage
  • A fixed point of contact, no account managers passed around
  • Ongoing maintenance and keeping pace with new versions of the standard
  • A way of working aligned with your existing IT landscape

Security and privacy in ZGW API integrations

Case data almost always contains personal data and commercially sensitive information. The ZGW standard is therefore designed with privacy by design: a provider filters data at the source based on the authorisations in the Authorisations API, with scopes and a maximum confidentiality level per case type. On top of this, Appfront builds according to the OWASP ASVS: short-lived JWTs, secrets kept in secure vaults, separation of rights per component and regular audits of the interfaces.

Authentication runs with a JSON Web Token based on a client ID and secret, sent in the Authorization header as a Bearer token; traffic runs over TLS. We document the data flows, case types and authorisations so that your register of processing activities is complete and you can demonstrate compliance with the GDPR. For government organisations we align, where applicable, with your frameworks, such as the BIO.

More on our security approach: information security policy and CVD policy.

  • GDPR-compliant data processing and data minimisation
  • Filtering at the source via the Authorisations API (privacy by design)
  • JWT authentication with scopes and confidentiality classification per case type
  • Encryption in transit (TLS 1.2+) and at rest
  • Audit logs with traceable data flows
  • Monitoring and alerting for anomalies
  • Secrets management in line with best practice
  • Documentation for your record of processing activities

Frequently asked questions about ZGW API integrations

Answers to the questions we are asked most often about integrations with the ZGW APIs.

The ZGW APIs are the standard APIs for case-based working developed by VNG Realisatie within Common Ground. They form a set of interrelated REST/JSON APIs: the Zaken API (ZRC) for cases, the Documenten API (DRC) for documents, the Catalogi API (ZTC) for case types, the Besluiten API (BRC) for decisions and the Notificaties API (NRC) for events. Authorisation runs through the Autorisaties API (AC). Together they replace the older StUF/ZDS interfaces and make it possible to query and update data at the source rather than copying it between applications.

We integrate with all core components of the ZGW standard: the Zaken API (ZRC), Documenten API (DRC), Catalogi API (ZTC), Besluiten API (BRC) and Notificaties API (NRC), plus the Autorisaties API (AC) for managing permissions. Depending on your situation, we connect to an existing reference or vendor implementation of the standard, or build a task application that communicates with these APIs as a consumer or provider.

That depends on the number of components, the number of case types and the degree of custom work in the process logic. A focused integration with the Zaken API and Documenten API for a single process is a manageable project; a full integration across ZRC, DRC, ZTC, BRC and NRC, with notification subscriptions and authorisations per case type, takes longer. After an intake meeting, we will give you a realistic estimate.

The ZGW APIs are RESTful APIs using JSON, in line with the Dutch API strategy and the API Design Rules. Authentication uses a JSON Web Token (JWT) based on a client ID and secret, sent in the Authorization header as a Bearer token. Authorisations per case type, scope and confidentiality level are managed through the Autorisaties API. To process changes, we use the Notificaties API with subscriptions and webhooks. We build the back end in the stack that suits you, such as Python, Node.js, .NET or PHP.

The cost is determined by the number of components to integrate, the number of case types and processes, the required authorisation and notification logic, and the amount of custom work in case handling. Ongoing management, monitoring and keeping pace with new versions of the standard also play a part. We always provide a clear quote following a no-obligation analysis of your situation.

Yes. The ZGW standard is designed with privacy by design: the provider filters data at source based on the authorisations in the Autorisaties API, with scopes and a maximum confidentiality level per case type. Appfront builds on this in line with OWASP ASVS: short-lived JWTs, secrets kept in secure vaults, TLS, separation of rights between components and comprehensive logging. We document the data flows so your record of processing activities stays complete and you can demonstrate GDPR compliance.

Yes. Many organisations are moving from the older, SOAP-based StUF/ZDS interfaces to the modern ZGW APIs within Common Ground. We map your existing StUF message traffic and case types, design the target architecture on the ZGW standard and, where necessary, build a translation layer or adapter so that old and new systems can continue to run side by side during the transition.

The ZGW APIs are intended for the Dutch public sector working on a case-based basis: municipalities, environmental services, water boards and implementing organisations. Typical applications include case management systems, permit processing and VTH (permits, supervision and enforcement), connecting task-specific applications to a central case registration, and the transition from StUF to Common Ground. Software vendors who want to make their product ZGW-compliant are also welcome to contact us.

Ready to build your ZGW API integration?

Tell us which processes and case types you want to support on a case-based basis and which ZGW components you want to integrate with. We are happy to think along about the Zaken, Documenten, Catalogi, Besluiten and Notificaties APIs, authorisations and any migration from StUF. A no-obligation first conversation will quickly give you a clear picture of what is possible.

Edit content