Intermediate · 10 articles
Identity Protocols
SAML, OAuth 2.0, OpenID Connect, JWT, SCIM and WebAuthn, in the order they build on each other, with the security details that integration guides leave out.
Developers and engineers who integrate applications, debug federation, or secure APIs.
You can read a SAML assertion or an ID token, choose the right OAuth flow, validate tokens correctly, provision users with SCIM, and explain what a passkey actually proves.
Reading order
- 1
SAML 2.0 Explained
The enterprise federation protocol you will still meet everywhere.
- 2
OAuth 2.0 Deep Dive: Mastering Modern IAM Security
Delegated authorization: the flows, the tokens, the mistakes.
- 3
OpenID Connect (OIDC) Deep Dive: The Ultimate Guide to Identity and Access Management
The identity layer on top of OAuth.
- 4
SAML vs OIDC: Mastering Identity Federation for IAM
When to use which, now that you know both.
- 5
JWT Security Deep Dive: Validate, Avoid Pitfalls, Block Attacks
The token format under OIDC, and how it is attacked.
- 6
OAuth 2.1 and DPoP Token Security Updates
What changed: PKCE everywhere, sender-constrained tokens.
- 7
Session Management Deep Dive: Lifetimes, Revocation, and Hijacking Defense
What happens after the token: sessions, refresh and logout.
- 8
SCIM Provisioning Explained
The protocol that creates and removes the accounts the other protocols sign in.
- 9
FIDO2 WebAuthn Internals
Passkeys from the inside: challenges, attestation, assertions.
- 10
Secure APIs with OAuth: Developer's IAM Playbook
Put it together on the resource server side.
Each article shows its place in this path with links to the previous and next step, so you can read straight through.