Curity logo
  • Identity ServerAccess IntelligenceToken Intelligence
    Read more→

    See how the platform fits together

  • By use case iconBy Use Case
    API Access ControlB2B and Partner IdentityCIAMModernize InfrastructureOpen Banking and Financial-Grade APIsSecure AI and Machine Access
    By industry iconBy Industry
    Financial ServicesGovernmentHealthcareTech & SaaSTelecom
  • Pricing
  • Business iconBusiness
    ArticlesBlogCoursesResearch & InsightsTrainingVideosWebinars
    For developers iconFor developers
    Code ExamplesDeveloper PortalDocumentationGetting StartedGuidesHow-tosOAuth Tools
  • AboutCareersContact
    CustomersESGEvents Calendar
    NewsPartners
  • Talk to an Expert
  • Get Started
ArticlesBlogCode ExamplesCoursesDocumentationGetting StartedGuidesHow-tosResearch & InsightsTrainingVideosWebinars & EventsWhat's new

Learn by topics

  • Security Architecture
    • An Introduction to Authorization
    • An Introduction to Identity and Access Management
    • Introducing the Neo-Security Architecture
    • Curity and the Neo-Security Architecture
    • What is an Identity Management System?
    • What is an API Management System?
    • What is an Entitlement Management System?
    • OpenID Authorization Exchange (AuthZEN)
    • Authentication vs. Authorization, What's the Difference?
    • Glossary of Identity Management Terms
  • Security Architecture Best Practices
    • Identity and Access Management Primer
    • Zero Trust Architecture is a Token-Based Architecture
    • The Token Handler Pattern for SPAs
    • Elevating API Security with Token Patterns
    • Integrate Identity with Business Data
    • Open Policy Agent: Integration Overview
    • Privacy and GDPR Using OAuth
    • Federation Requirements Introduced in FIPS 201-3
  • Customer Identity and Access Management
    • What's CIAM and Why it Matters
    • CIAM vs IAM: What's the Difference?
    • How CIAM Protects Data
    • CIAM and API Security
    • What's PIAM in a B2B Context?
  • Single Sign-On
    • Single Sign-On Introduction
    • What is a Single Sign-On Session?
    • Implementing SSO for Web Apps
    • Implementing SSO for AI Agents
    • Implementing SSO for Mobile Apps
    • SSO and Authentication Methods
    • Administrative Management of SSO
    • Prompting for Login during SSO
    • SSO for Web with OpenID Connect
  • Multi-Factor Authentication
    • Introduction to Multi-Factor Authentication
    • MFA and the Curity Identity Server
    • Approaches to Multi-Factor Authentication
    • New Country vs. Changed Country, What's the Difference?
    • The Impossible Journey Authentication Action
    • Using Geo-Location Data in the Authentication Process
    • An Overview of WebAuthn
    • What are Passkeys?
    • Passkeys - Design your Solution
    • Account Linking Recipes
  • Claims & Scopes
    • Scopes vs Claims
    • Claims Explained
    • Scopes Explained
    • Designing Claims
    • Using Claims in APIs
    • Scopes, Claims and the Client
    • Centralizing Identity Data
    • What is a Claims Authority?
    • Consent and Claims
    • Selective Disclosure for JWTs (SD-JWT)
    • Default Scopes
    • Using Vectors of Trust
    • Scope Best Practices
    • Claims Best Practices
  • OpenID Connect
    • What Is OpenID Connect, and How Does It Work?
    • OpenID Connect Authorization Code Flow
    • Validating an OpenID Connect ID Token
    • Dynamic Client Registration Overview
    • Using Dynamic Client Registration
    • Dynamic Client Registration Authentication Methods
    • Dynamic Client Registration Management
    • OAuth and OIDC Request Objects
    • JWT Secured Authorization Response Mode (JARM)
    • Pairwise Pseudonymous Identifiers
    • OpenID Connect Hybrid Flow
    • OpenID Connect Standards
    • OpenID Connect Single Logout
    • Client Initiated Backchannel Authentication (CIBA)
    • Client Initiated Backchannel Authentication (CIBA) Flow
    • Device Flow vs CIBA?
    • Encrypted ID Tokens
  • OAuth 2.0
    • OAuth 2.0 Overview
    • Which OAuth Flow Should I Use?
    • OAuth Code Flow
    • Proof Key for Code Exchange Overview
    • Demonstrating Proof of Possession Overview
    • OAuth Implicit Flow
    • OAuth Token Exchange Flow
    • OAuth Client Credentials Flow
    • OAuth Resource Owner Password Credentials Flow
    • OAuth Device Flow
    • OAuth Refresh
    • OAuth Revoke Flow
    • Mutual TLS Client Authentication
    • Mutual TLS Sender Constrained Access Tokens
    • Client Assertions and the JWKS URI
    • Pushed Authorization Requests (PAR)
    • OAuth Client ID Metadata Document
    • Supported OAuth 2.0 RFCs
  • AI Agents Security
    • Design AI for Enterprises
    • API Security Best Practices for AI Agents
    • Design MCP Authorization for APIs
    • MCP Authorization Lifecycle
    • API Access Across Trust Domains
    • Dynamic Trust for AI Agents
    • Browserless OAuth
  • Client Security
    • Best Practices - OAuth for Single Page Apps
    • Best Practices - OAuth and XSS Prevention
    • Best Practices - OAuth and Same Site Cookies
    • Best Practices - OAuth for Mobile Apps
    • Token Handler Design Overview
    • Token Handler Deployment Patterns
    • The Nonce Authenticator Pattern
    • OAuth With Unsolicited SAML Responses
  • API Security
    • The API Security Maturity Model
    • API Security Best Practices
    • Identities in a Kubernetes Environment
    • JWT Security Best Practices
    • Top 10 API Security Vulnerabilities According to OWASP
    • Implementing Zero Trust APIs
    • The Phantom Token Approach
    • The Split Token Approach
    • Self-contained JWTs
    • Token Sharing Approaches
    • Impersonation Approaches
    • Harden API Access with Workload Identities
    • JWT Signatures and EdDSA
    • Zero Trust API Events
  • Hypermedia Authentication API
    • What is Hypermedia Authentication API
    • Mobile Attestation Fallback
  • Financial Grade
    • What is Financial-Grade Security?
    • What is PSD2, and How Does it Work?
    • What is Open Banking?
    • Implement Financial-Grade Security
    • App2App Mobile Architecture
    • Consentors in Financial-Grade
    • Open Banking Brazil DCR Request Validation
  • Decentralized Identities
    • Overview of Decentralized Identities
    • Decentralized Identifiers (DIDs) Explained
    • Verifiable Credentials Explained
    • Issue Verifiable Credentials using OpenID4VC
  • User Management
    • User Provisioning With SCIM
    • Managing Users With SCIM
  • Operation and Configuration
    • Using External IDPs
    • Multi-Region Deployment
    • Dynamic User Routing
    • OAuth Troubleshooting for Developers
    • OAuth Troubleshooting for DevOps
    • IAM Configuration Best Practices

Learn more

  • Webinars
  • Documents
  • Videos
  • Training

Operation and Configuration

Designs for deploying and operating an identity server

Designs for deploying and operating the Curity Identity Server

Articles

  • August 10, 2022

    IAM Configuration Best Practices

    Managing configuration in your Identity and Access Management (IAM) System for multiple environments

  • April 29, 2022

    OAuth Troubleshooting for Developers

    Managing the Identity Server and dealing with errors during application development

  • April 29, 2022

    OAuth Troubleshooting for DevOps

    Managing the Identity Server and dealing with issues in production environments

  • January 17, 2022

    Using External IDPs

    Why and when external IDPs may be useful

  • June 7, 2021

    Dynamic User Routing

    A design pattern for dynamically routing users to their home region in a global IAM system.

  • March 11, 2021

    Multi-Region Deployment

    How to deploy the Curity Identity Server across multiple datacenters and regions.

Architecture

See how Curity fits into modern identity and API architectures.

Explore architecture

Customer Stories

Learn how organizations run identity and API security at scale.

Read customer stories
Curity logo

To connect with a product expert today,

email us or call +46 8-410 737 70

Get started with Curity

Curity Identity ServerCurity Access Intelligence for AIFree TrialPricingContact us
Curity AB © All Rights Reserved · Terms of Service
Sign up for API Security Insights→
Follow us
  • X icon
  • Bluesky icon
  • LinkedIn icon
  • Medium icon
  • GitHub icon
  • YouTube icon
  • RSS icon
  • Nordic APIs icon