Today on the blog, we welcome Gary Archer from @curityio to explore how to bring a #zerotrust approach to event-based #microservices architecture. https://t.co/Fm67IsQDME
Are you at @Identiverse? Come meet us at booth 1114 and make sure to catch two sessions by @iggbom - Scalable API Security Using OAuth on June 23 and Financial- Grade Security: Not Just For Banks on June 24.
Meet us at Identiverse in a week!
Be sure to swing by our booth (1114) to discuss identity and API security. Also, catch our @iggbom's talks on June 23 and June 24.
Schedule a meeting ahead: https://t.co/f4x4r0jMR7
In our whitepaper on financial-grade APIs using #OAuth and #OIDC, we cover many topics, including:
- Proof Key
- #StrongAuthentication
- Dynamic Client Registration for PSD2 Conformance
- Interactive User Consent
Get your free copy: https://t.co/nVDa5SiGuv
It's simple to start using JWTs, but it's important to use them securely to ensure the safety of your APIs.
Read @mz_trojan's blog to learn what aspects to consider when protecting your APIs with JWTs: https://t.co/3Zk6cNzk1n
We are excited to announce the release of Curity Identity Server 7.1.
What's new:
- Configure look and feel in the admin UI
- The OAuth client page has a graphical overview
- Use of HAAPI with devices that have out of sync clocks
Learn more here: https://t.co/OcW3Qc3Dqu
Join Curity and @Yubico on March 9 to learn why WebAuthn is the most robust and secure approach for achieving phishing-resistant authentication. They will also show how to use YubiKey authentication options in OAuth and OIDC flows.
Register: https://t.co/PPHTza7pPE
We are excited to announce our next webinar - Phishing Resistant Passwordless Authentication with Curity and
@Yubico - that will take place on March 9.
Learn more and register: https://t.co/vteNmAuKrA
What is your go-to approach to Zero Trust Architecture?
One of our tips is to look for highly flexible and configurable solutions to handle any and all types of scenarios that offer extensibility with minimal effort.
Read our blog post to learn more: https://t.co/d7VLrVftQ2
Utilizing a token-based architecture to protect APIs is a robust, secure and scalable approach.
Read a blog post by @iggbom to learn how to implement the Phantom Token Approach with Curity, @kong Gateway, and @OpenPolicyAgent: https://t.co/eOEv9tGS5o
FIPS 201-3 went "final" an hour ago. Federation using OpenID Connect (or SAML) is now required for all US federal employees and contractors https://t.co/AnHvE9Qupt
Show me your access token, and I will tell you who you are 🕵️
Our identity expert @mz_trojan explains what data your access token can reveal and how to make sure it is protected.
Read it here: https://t.co/OhIgh51vUH
OAuth Tools has been developed as a place to experiment, learn and explore the inner workings of OpenID Connect and OAuth.
Have you tried it yet?
If not, give it a go: https://t.co/AJcjnZLF9H