Tag

oauth

Articles tagged with oauth.

auth-patterns

Workload Identity Federation to Keycloak: SPIFFE JWT-SVID as Client Auth

An IETF draft lets workloads authenticate to an OAuth server with SPIFFE JWT-SVIDs, not client secrets. What it specifies and…

Guilliano Molaire Guilliano Molaire 8 min read
security

CVE-2026-93999: Keycloak Refresh Restores a Disabled Audience

Keycloak checks an audience client is enabled during token exchange, but not when that refresh token is used. What CVE-2026-93999…

Guilliano Molaire Guilliano Molaire 9 min read
auth-patterns

Agentic Commerce Authentication: Tokens vs Payment Mandates

AI shopping agents need two separate proofs: a token saying who acts for whom, and a signed mandate saying what…

Guilliano Molaire Guilliano Molaire 9 min read
Tutorials

Keycloak CIMD for MCP: Client ID Metadata Documents for Claude Code and VS Code

Keycloak has shipped experimental CIMD support since 26.6 behind the cimd flag. Here is the client policy that lets Claude…

Guilliano Molaire Guilliano Molaire 11 min read
comparisons

Agentic IAM in September 2026: What Okta Agent SSO, Ping, and JumpCloud Mean If You Run Keycloak

Okta, Ping and JumpCloud all shipped agentic IAM in the last three weeks. Here is what those launches actually add,…

Guilliano Molaire Guilliano Molaire 11 min read
security-best-practices

JWT Token Lifecycle: Expiration, Refresh, and Revocation

JWT lifecycle guide: expiration, refresh token rotation per RFC 9700, Keycloak revocation, and Spring Boot resource server validation with zero…

Guilliano Molaire Guilliano Molaire 11 min read
Social Login Implementation: Step-by-Step Guide
Tutorials

Social Login Implementation: Step-by-Step Guide (2026)

Step-by-step social login with OAuth authentication: Google, GitHub, and Microsoft setup, Keycloak broker config, duplicate email account linking, and mappers.

Guilliano Molaire Guilliano Molaire 9 min read
Definition and Basics

IoT Identity Management: Securing Connected Devices with Keycloak

Implement IoT identity management with Keycloak: OAuth 2.0 Device Authorization Grant, machine-to-machine authentication, and Zero Trust for connected devices.

Guilliano Molaire Guilliano Molaire 9 min read
Definition and Basics

SSO vs OAuth: Is OAuth the Same as SSO?

OAuth and SSO are not the same: OAuth delegates access to APIs, SSO lets one login cover many apps. How…

Guilliano Molaire Guilliano Molaire 13 min read
oauth 2.1
security

OAuth 2.1: What Changed and How Keycloak Implements It

Discover OAuth 2.1 changes including mandatory PKCE, deprecated implicit flow, and how Keycloak implements these security improvements since version 24.

Guilliano Molaire Guilliano Molaire 4 min read

Stay ahead on identity & security

Get tutorials, product updates, and Keycloak tips delivered to your inbox.

© 2026 Skycloak. All Rights Reserved. Design by Yasser Soliman