Identity Propagation in an API Gateway Architecture
The power of end-to-end user security context with APIs
Read article: Identity Propagation in an API Gateway ArchitectureNotes on application security, API security, identity, and API management from the field. Articles are also published on Medium. Browse the archive by topic instead — 124 subjects.
The power of end-to-end user security context with APIs
Read article: Identity Propagation in an API Gateway ArchitectureUpdate(07/01/2019): This is by far my most popular post. I’ve continued to update this article based on feedback and things that I have noticed. I’m trying to keep it relevant.Please leave feedback in the comments section.
Read article: When To Use Which (OAuth2) Grants and (OIDC) FlowsExtending OAuth2 and OpenID Connect as the enterprise standard for API security
Read article: An Alternative to Delegated Access in the EnterpriseThe following blog posts make up my series on OpenID Connect. This is part of the SAML2 vs JWT series.
Read article: Understanding OpenID Connect SeriesIn part 1 and part 2 of Understanding OpenID Connect, core concepts and the first Authentication Flow (Authorization Code Grant Flow) were introduced. In part 3, we look at the remaining Authentication Flows (Implicit Flow and Hybrid Flow) and some other features of the OIDC specification.
Read article: SAML2 vs JWT: Understanding OpenID Connect Part 3This post continues our discussion of OpenID Connect (OIDC). We look at one of the three Authentication Flows defined by the OIDC spec — the Authorization Code Grant Flow.
Read article: SAML2 vs JWT: Understanding OpenID Connect Part 2This post builds upon what we learned about OAuth2 and JWT in previous posts. OpenID Connect will give us the final building block for the JWT-related use cases that this series will explore. The goal of this blog post is to provide a deep understanding of the OpenID Connect spec without having to…
Read article: SAML2 vs JWT: Understanding OpenID Connect Part 1This post was originally published as “Design Principles for Seamless User Authentication” on the Apigee Blog.
Read article: Design Principles for Seamless User AuthenticationThis post was originally published as “Keeping Your APIs Secure for Multiple User Types” on the Apigee Blog.
Read article: Keeping Your APIs Secure for Multiple User TypesIn the first three API Management posts I wrote, we discussed “What are APIs?(The Technical Perspective)”, “What is API Management?”, and “The Anatomy of an API Management Solution”. Continuing with this theme, we will explore the API Management Stack. So, what do I mean by API Management Stack?
Read article: The Tools of API Management — The Full StackLooking for something specific? Browse all 124 topics.