Frank,
I've been involved in a few such implementations and technically there are numerous approaches to go about implementing such an integration without the need to create any additional APIs. I suggest you look up
Siteminder's Authentication and Authorization web services as well in addition to the above suggested links.
Additionally, If there is a specific use-case that you need help with , post it here ?
Paul