World Congress 2026 Europe • Jul 9, 2026 • Session details

Keeping applications secure by evolving OAuth 2.0 and OpenID Connect

Alexander Schwartz

Are your underlying OAuth implementations hiding critical vulnerabilities? Discover how the upcoming OAuth 2.1 standard eliminates wildcard redirects. Learn to enforce strict identity policies seamlessly using Keycloak.

Pause
Mute Enter Fullscreen
#1 about 4 min

Understanding attacker personas in FAPI 2.0 specifications

Define assumed threat models and attacker capabilities in security protocols.

#2 about 2 min

Securing the transport layer with TLS and DNSSEC

Establish baseline trust by implementing foundational encryption and network safeguards.

#3 about 2 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Discover how standard authorization redirects expose access codes and refresh tokens.

#4 about 3 min

Adopting OAuth best practices and removing outdated grants

Migrate away from implicit grants and wildcard redirects for enhanced safety.

#5 about 2 min

Enhancing flow privacy using pushed authorization requests

Send authorization parameters directly to the identity provider to prevent manipulation.

#6 about 2 min

Implementing PKCE for secure code-to-token exchanges

Defend against spoofing by verifying clients through cryptographic code challenges.

#7 about 4 min

Securing refresh tokens using demonstration proof of possession

Bind tokens to client ephemeral key pairs generated by the web crypto API.

#8 about 2 min

Authenticating API requests using DPoP headers and nonces

Exchange standard bearer tokens for structurally validated cryptographic proofs.

#9 about 4 min

Enforcing FAPI 2.0 security profiles using Keycloak client policies

Centrally mandate compliant authenticators and strict HTTPS standards during client interactions.

#10 about 2 min

Planning a gradual rollout for updated OAuth standards

Enforce modern specifications methodically without paralyzing your existing application infrastructure.

#11 about 3 min

Accelerating security compliance through deliberate API brownouts

Trigger scheduled temporary outages to identify and fix non-compliant clients.

Matching moments

2:52 min

Implementing IAM with Keycloak and OpenID Connect

Thomas Südbröcker · LIVE

9:45 min

Audience Q&A on fine-grained access and JWT encryption

Philippe De Ryck · LIVE

1:45 min

Reviewing identity endpoints alongside specific Keycloak preview features

Alexander Schwartz Alexander Schwartz · World Congress 2025

9:56 min

Final code walk-through and audience Q&A session

Germán Álvarez · LIVE

2:01 min

Implementing a layered authentication and authorization stack

Jose Manuel Ortega Jose Manuel Ortega · Europe 2026 Virtual

3:26 min

Designing APIs for security from day one

Philippe De Ryck · LIVE