

We’re pleased to announce that Seiko Epson Corporation (Seiko Epson) has adopted our OAuth and OpenID Connect (OIDC) backend service for the authentication and authorization infrastructure of the Epson Connect API.
Seiko Epson offers Epson Connect, a cloud service that connects smart devices and PCs with Epson printers and multifunction printers via the internet, enabling remote printing and the upload of scanned data to cloud storage. The company also provides the Epson Connect API, a free web API that enables registered developer partners to embed scanning and printing functionality into their own applications.
For Epson Connect API Ver. 2.0, the latest version of the API, Seiko Epson adopted Authlete to implement OAuth for its authentication and authorization infrastructure.
Since its launch in 2011, Epson Connect has continuously added new features, and its usage has grown to approach initial projections. Consequently, from 2024 to 2025, Seiko Epson undertook a fundamental upgrade to an architecture capable of handling high-volume printing. Along with this architectural overhaul, the company decided to release the new Epson Connect API Ver. 2.0 (API v2) with enhanced security, and to redesign the authentication and authorization capabilities for API v2.
The requirements for the authentication and authorization of the new API v2 infrastructure were as follows:
Initially, Seiko Epson considered building an OAuth authorization server from scratch in-house to meet these requirements. However, the company determined that it would require substantial development time. It also concluded that handling ongoing security updates and responding swiftly to new vulnerabilities solely with internal resources would be unrealistic.
As an alternative, they considered adopting a managed Identity as a Service (IDaaS) solution such as Auth0. Although IDaaS would solve the challenges associated with in-house development and operations, the company had concerns about whether it could support the service-specific requirement of issuing access tokens for device-level control.
Ultimately, Seiko Epson chose to build its OAuth authorization server in-house using Authlete. Within the new authorization server’s functionality, the company externalized user authentication to Epson Global ID and implemented new authorization logic for issuing access tokens based on a device information database. Meanwhile, OAuth protocol processing and token lifecycle management were delegated to Authlete via its APIs.
This enabled the required authorization flow: when a user logs in via Epson Global ID and selects a device on the printer/scanner selection screen, the partner application is granted permission only for operations related to that specific device.

By adopting Authlete, Seiko Epson achieved the following results:
"Authlete's service was an ideal fit for building an authorization server in combination with our user authentication infrastructure. Developing it from scratch was unrealistic, and it would have been extremely difficult to upgrade our authentication and authorization infrastructure on schedule without introducing Authlete. Since Authlete keeps up with standard security updates and the latest specifications, it is a huge help to be able to focus on developing business logic while maintaining security."
Read more customer success stories here.