OAuth2 Token Exchange for Microservice API Security
CNCF [Cloud Native Computing Foundation] via YouTube
Overview
Explore the intricacies of OAuth2 Token Exchange for securing microservice APIs in this informative conference talk. Dive into typical OAuth2.0 flows with practical examples using Keycloak, and discover the challenges of applying OAuth2 in microservice environments. Learn about common workarounds and their potential vulnerabilities. Gain insights into the OAuth2 Token Exchange RFC8693 standard as a recommended approach for authorization and identity propagation. Through live demonstrations, understand the essentials of OAuth 2.0, its shortcomings in microservice architectures, and the importance of Token Exchange RFC8693 in addressing these issues. Enhance your knowledge of API authentication, authorization, and secure identity propagation in complex microservice ecosystems.
Syllabus
OAuth2 Token Exchange for Microservice API Security - Ahmet Soormally & Letz Yaara, Tyk
Taught by
CNCF [Cloud Native Computing Foundation]