Lunnoa GmbH (internal / GTM) · Public API v1 / Headless Platform: Release Report
DEV to UAT: machine-authenticated backend access, per-key auth, and what it unlocks for corporate and financial services clients
Section 05

Recommended next steps

RecommendationDo nowEffort: SOwner: Engineering

Run the full UAT test plan before referencing this in client conversations

The deploy notes already define the smoke test: create a key, call a tagged public endpoint, revoke it, and confirm 401. Until that has been run end to end on UAT, the safest external framing is "in UAT testing" rather than "available".

RecommendationDo nextEffort: MOwner: Sasa

Build a headless integration narrative into financial services pitches

Institutions such as Al-Tijari, Partners Group, and Albin Kistler are evaluating Lunnoa partly on integration risk. A short technical appendix showing scoped API keys, per-key rate limiting, and the curated Public API v1 contract gives their architecture and security reviewers something concrete to assess, rather than asking them to take governance on faith.

RecommendationDo nextEffort: SOwner: Sasa

Write a one page API key governance note for CISO level conversations

Cover key issuance, one-time secret reveal, hashing at rest, expiry, and revocation in plain business language. This is the kind of artefact a bank's security team will ask for early in a proof of concept, and having it ready shortens the review cycle.

RecommendationLaterEffort: LOwner: Sasa

Evaluate an OEM / white-label pricing motion once the Public API v1 surface stabilises

A documented, versioned public contract is the technical precondition for a partner to embed Lunnoa inside their own product. Whether that becomes a second commercial motion alongside direct sales is a separate decision, but this release is what makes it feasible.