Articles tagged with oauth.
An IETF draft lets workloads authenticate to an OAuth server with SPIFFE JWT-SVIDs, not client secrets. What it specifies and…
Keycloak checks an audience client is enabled during token exchange, but not when that refresh token is used. What CVE-2026-93999…
AI shopping agents need two separate proofs: a token saying who acts for whom, and a signed mandate saying what…
Keycloak has shipped experimental CIMD support since 26.6 behind the cimd flag. Here is the client policy that lets Claude…
Okta, Ping and JumpCloud all shipped agentic IAM in the last three weeks. Here is what those launches actually add,…
JWT lifecycle guide: expiration, refresh token rotation per RFC 9700, Keycloak revocation, and Spring Boot resource server validation with zero…
Step-by-step social login with OAuth authentication: Google, GitHub, and Microsoft setup, Keycloak broker config, duplicate email account linking, and mappers.
Implement IoT identity management with Keycloak: OAuth 2.0 Device Authorization Grant, machine-to-machine authentication, and Zero Trust for connected devices.
OAuth and SSO are not the same: OAuth delegates access to APIs, SSO lets one login cover many apps. How…
Discover OAuth 2.1 changes including mandatory PKCE, deprecated implicit flow, and how Keycloak implements these security improvements since version 24.
Get tutorials, product updates, and Keycloak tips delivered to your inbox.