World Congress 2026 Europe Jul 9, 2026 Session details

Keeping applications secure by evolving OAuth 2.0 and OpenID Connect

Alexander Schwartz

Are your underlying OAuth implementations hiding critical vulnerabilities? Discover how the upcoming OAuth 2.1 standard eliminates wildcard redirects. Learn to enforce strict identity policies seamlessly using Keycloak.

Pause
Mute Enter Fullscreen
#1 about 4 min

Understanding attacker personas in FAPI 2.0 specifications

Define assumed threat models and attacker capabilities in security protocols.

#2 about 2 min

Securing the transport layer with TLS and DNSSEC

Establish baseline trust by implementing foundational encryption and network safeguards.

#3 about 2 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Discover how standard authorization redirects expose access codes and refresh tokens.

#4 about 3 min

Adopting OAuth best practices and removing outdated grants

Migrate away from implicit grants and wildcard redirects for enhanced safety.

#5 about 2 min

Enhancing flow privacy using pushed authorization requests

Send authorization parameters directly to the identity provider to prevent manipulation.

#6 about 2 min

Implementing PKCE for secure code-to-token exchanges

Defend against spoofing by verifying clients through cryptographic code challenges.

#7 about 4 min

Securing refresh tokens using demonstration proof of possession

Bind tokens to client ephemeral key pairs generated by the web crypto API.

#8 about 2 min

Authenticating API requests using DPoP headers and nonces

Exchange standard bearer tokens for structurally validated cryptographic proofs.

#9 about 4 min

Enforcing FAPI 2.0 security profiles using Keycloak client policies

Centrally mandate compliant authenticators and strict HTTPS standards during client interactions.

#10 about 2 min

Planning a gradual rollout for updated OAuth standards

Enforce modern specifications methodically without paralyzing your existing application infrastructure.

#11 about 3 min

Accelerating security compliance through deliberate API brownouts

Trigger scheduled temporary outages to identify and fix non-compliant clients.

Matching moments

2:52 min

Implementing IAM with Keycloak and OpenID Connect

Thomas Südbröcker · LIVE

9:45 min

Audience Q&A on fine-grained access and JWT encryption

Philippe De Ryck · LIVE

1:45 min

Reviewing identity endpoints alongside specific Keycloak preview features

Alexander Schwartz Alexander Schwartz · WWC 2025

9:56 min

Final code walk-through and audience Q&A session

Germán Álvarez · LIVE

3:26 min

Designing APIs for security from day one

Philippe De Ryck · LIVE

3:15 min

The current state of enterprise APIs and security trends

Pratim Bhosale Pratim Bhosale · WWC 2025

Upcoming sessions on this topic

Open session

World Congress 2026 North America

Securing AI Agent Infrastructure: Identity, Attestation, and Trust at Scale

Abdel Fane

Founder of OpenA2A

Abdel Fane
Open session

World Congress 2026 North America

It passed auth, then production caught fire

Alex Olivier

Co-founder & CPO @ Cerbos | OpenID AuthZEN Co-chair

Alex Olivier
Open session

World Congress 2026 North America

Secure-by-Inclusion: Preventing Accessibility Barriers from Becoming Security Vulnerabilities

Radostina (Ina) Tsvetkova

Norwegian Directorate of Labour and Welfare (NAV), Senior Advisor in Digital Accessibility and Inclusive Design

Radostina (Ina) Tsvetkova
Open session

World Congress 2026 North America

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

Designing APIs That Survive AI Agents at Scale

Phani Pendurthi

Mastercard, Principal Software Engineer

Phani Pendurthi
Open session

World Congress 2026 North America

SecurePrompt: Building a Pre-Flight Security Layer for Agentic AI

Ravi Sastry Kadali

AI/ML Engineer at General Motors

Ravi Sastry Kadali