Generated by All in One SEO v4.9.3, this is an llms.txt file, used by LLMs to index the site. # Gluu Open Source Identity and Access Management ## Sitemaps - [XML Sitemap](https://gluu.org/sitemap.xml): Contains all public & indexable URLs for this website. ## Posts - [Janssen Project is a Digital Public Good](https://gluu.org/janssen-project-is-a-digital-public-good/) - The Janssen Project has been included in the Digital Public Goods Alliance (DPG) Registry. The goal of the DPG Registry is to promote digital public goods and contribute to creating a more equitable world. - [Gluu Flex Roadmap](https://gluu.org/gluu-flex-roadmap/) - As Flex is a commercial distribution of the Janssen Project, check the Janssen Nightly Build changelog and issues. You can also check the Nightly Build changelog for the Admin UI. Gluu 4 is considered a stable release–meaning no major features are planned. - [The Ten Buts of Govstack’s Identity Building Block](https://gluu.org/the-ten-buts-of-govstacks-identity-building-block/) - Each Govstack specification offers a blueprint of a digital service landscape. Assuming you think this is possible, among the various Govstack specs, the most important is the GovStack Identity Building Block specification– because most governments that participate in the 50-in-5initiative will start their digital public infrastructure projects with “identity”. - [Keycloak Roadmap](https://gluu.org/keycloak-roadmap/) - Janssen Project to leverage enterprise workforce features of Keycloak, like SAML and Realms for access management. Get the best of both worlds! Janssen + Keycloak - [Scaling your CIAM with Managed RDBMS for Resiliency](https://gluu.org/resilient-databases-for-gluu-server/) - An important cloud native design principle is “Resiliency”. A resilient system embraces failure instead of trying to prevent it. A resilient database service that is sharded, replicated, and multi-region is hard to build. In the long term, it is also hard to train and retain database experts to operate it.Another challenge to implement Resiliency is - [Hosted vs Self-hosted Identity and Access Management Solution](https://gluu.org/hosted-vs-self-hosted-iam/) - Which one is right for your organization? Is your organization ready to develop and operate a consumer / client identity and access management system? If so, I envy you. There are many advantages of Saas or PaaS CIAM services that can’t be ignored. Many companies and organizations aren’t ready to take on the challenge of - [Which is the right MFA solution?](https://gluu.org/the-right-mfa-solution-2022/) - We can all agree that if you want to protect your organization’s data, you will need to enforce multi-factor authentication (MFA) for your users. But the challenge to balance, implement, and train users to manage MFA effectively is a burden many organizations would rather not face.Remote employees, online users, and external partners further contribute to - [Moving Open Banking towards Open Source in Brazil](https://gluu.org/moving-open-banking-towards-open-source-in-brazil-2022/) - Gluu announces that its Open Banking Distribution, based on the Linux Foundation Janssen project, meets all certification criteria for FAPI OpenID for the Brazilian Banking specification. Gluu’s open banking distribution is in production at many leading banks in Brazil through our partner products and services. With the help of the community and our partners, Gluu - [Ideal API Security](https://gluu.org/api-security-2022/) - API’s are ubiquitous, so you’d think how to secure them is an established practice–except it’s not. The goal of this blog is to lay out how Gluu thinks about API security at a high level, in particular, how to use OAuth scopes to secure endpoints. We’ll start with API authentication. Then we’ll define a three-step - [Gluu 2022 Open Source Strategy](https://gluu.org/2022-opensource-outlook/) - Since we started Gluu in 2009, the mission has not changed: to build a business that supports the development of an open source identity and access platform. Fundamentally, we believe that a strong business model drives long term innovation. But what business model to pursue has changed over the years, and in 2022, this evolution - [Patching the log4J libraries in Gluu software​](https://gluu.org/log4j-update/) - Gluu’s products are primarily Java based software. Not surprisingly, we use log4J. Like most software vendors, we have been responding and updating our software to address the issue described on the Apache.org website.Once we publish the software update, we’ll continue researching the exploit to better understand the risk.For now, we are assisting supported customers to - [Will the 3PCD Apocalypse Break the Web?](https://gluu.org/3pcd-day-is-here/) - Browsers to Block 3rd party cookies one day in 2023. Don’t worry ico-man! But you may want to duck and cover… NOW! What is this all about? What even is a third party cookie? A cookie is “third party” when it is set by a component in a browser (like an iframe) in a domain that is - [Deploy Cloud Native Gluu 4.3](https://gluu.org/deploy-cloud-native-gluu-4-3/) - In a lot of ways, not that much is new–the goal of Gluu Server 4.x is stability. But, we did add a few new features people have been requesting:Amazon Aurora and Google Spanner support for Gluu Server Cloud Native (“Gluu CN”)Cloud Native design principles instruct us to use cloud services where possible, and nowhere does - [Managing Cache in the Gluu Server](https://gluu.org/managing-cache-in-the-gluu-server/) - If you are operating an earlier version of Gluu 3.1.x and have long-lived sessions configured for a large data set, cached data should be cleared manually. - [Securing the Perimeter: Deploying Identity and Access Management](https://gluu.org/get-the-book-by-gluu-founder-and-ceo-mike-schwartz/) - If you’re interested in identity and access management (IAM) — and I assume you are, since you’re on the Gluu blog! — you’ve surely heard about SAML, OAuth and OpenID Connect. - [The Business of Free Open Source Software](https://gluu.org/the-business-of-foss/) - Ten years ago, we created the Gluu Server, a distribution of free open source software for identity and access management (IAM). - [SSO vs SSI](https://gluu.org/sso-vs-ssi/) - SSI, SSO and authentication are complementary technologies.The current vocabulary for federated identity is limited. FIDO authentication - [Utility Tokens: A New Funding Model for Open Source Enterprise](https://gluu.org/utility-tokens-a-new-funding-model-for-open-source-enterprise/) - Open source is not a business model–it’s a way to develop software. For certain requirements (like the implementation of Internet standard services), - [Authorize like a Pro with Axiomatics and UMA](https://gluu.org/authorize-like-a-pro-with-axiomatics-and-uma/) - OverviewGluu is not really a great place to store policies. While you can express policies in Gluu Server RPT interception scripts, if you have more then a few policies, this approach does not scale. For a long time, we’ve recommended using a product that makes it easier to manage your policies. Axiomatics is one of - [Auth0 Hack: JWTs Aren’t as Great as Claimed](https://gluu.org/autho-hack/) - The recent Auth0 vulnerability found by ethical hackers lays bare the specious benefits of using JWTs as access tokens and the hypocrisy of multi-tenant authentication platforms. - [Deploy a Highly Available Redis Cache Cluster](https://gluu.org/deploy-a-highly-available-redis-cache-cluster/) - In this blog we will detail a relatively easy way to get a functioning Redis-cluster to cache session data and tokens generated by the Gluu Server. - [Two Approaches to Open-Source Single Sign-On (SSO) and Access Management](https://gluu.org/2-approaches-to-open-source-single-sign-on-and-access-management/) - Due to tightening regulations, increased usage of third-party applications, and the sheer volume of breaches caused by weak credentials, single sign-on (SSO) is increasingly becoming a ubiquitous enterprise security requirement. Many organizations also need to centralize policies to control access to valuable API’s or Web resources. SaaS services seem like a good option at first, - [WWPass Login without Usernames and Passwords](https://gluu.org/wwpass-login-without-usernames-and-passwords/) - WWPass is a global cybersecurity company that provides next-generation authentication and client-side encryption technology eliminating Usernames and Passwords. - [Gluu Client Initiated Backchannel Authentication](https://gluu.org/client-initiated-backchannel-authentication/) - The Gluu Server now supports CIBA. Improve the end-user experience during authentication and authorization.OpenID Connect Client Initiated Backchannel Authentication Flow is an authentication flow like OpenID Connect. However, unlike OpenID Connect, there is a direct Relying Party to OpenID Provider communication without redirects through the user’s browser. CIBA enables a Client to initiate the authentication - [Gluu Wins 2020 Couchbase Independent Partner of the Year](https://gluu.org/gluu-wins-2020-couchbase-independent-partner-of-the-year-award/) - Couchbase, the creator of the enterprise-class, multi-cloud NoSQL database, today announced at the Connect Conference that Gluu was acknowledged with the Couchbase Independent Software Vendor Partner of the Year Award. Guest judges for the Couchbase Community Awards included Carl Olofson, Research Vice President at IDC, and Jon Reed, Co-Founder of Diginomica.Open to Couchbase’s network of - [Two-Factor Authentication (2FA) Best Practices](https://gluu.org/two-factor-authentication-2fa-best-practices/) - Two-factor authentication (2FA) is hands-down the best way to increase online account security. It’s also true tighter security typically results in less convenience. - [Gluu vs Keycloak: Comparing Open-Source Identity and Access Management Solutions](https://gluu.org/gluu-vs-keycloak/) - Discover the differences between Gluu and Keycloak, two leading open-source Identity and Access Management (IAM) tools. - [2FA like Google with Casa](https://gluu.org/2fa-like-google-with-casa/) - To combat password-related security issues many websites and applications now support two-factor authentication (2FA). 2FA has proven to be an effective deterrent, but account recovery is “the Achilles’ heel” of multi-factor authentication. - [Plurilock and Gluu Announce Launch of New Product Collaboration](https://gluu.org/plurilock-and-gluu-announce-launch-of-new-product-collaboration/) - We now are empowered to provide integrated solutions for contexts & clients that call both for Gluu-driven identity & access management capabilities & Plurilock’s advanced authentication products. - [The Janssen Project Takes on World’s Most Demanding Digital Trust Challenges at Linux Foundation](https://gluu.org/the-janssen-project-takes-on-worlds-most-demanding-digital-trust-challenges-at-linux-foundation/) - The Janssen Project Takes on World’s Most Demanding Digital Trust Challenges at Linux Foundation - [Ten Impacts of the Janssen Project on Gluu](https://gluu.org/ten-impacts-of-the-janssen-project-on-gluu/) - Here at Gluu, we are grateful to the Linux Foundation for helping us to launch Janssen. we’ll both have a more positive impact in the world. - [CENTOS Linux is Dead: A Warning to the KeyCloak Community](https://gluu.org/centos-linux-is-dead-a-warning-to-the-keycloak-community/) - We’re going to work hard to fill in the gaps to make it a world-class, cloud-native identity platform. Heed the writing on the wall. Ditch Keycloak & join us! - [The Case for Monthly Active Users](https://gluu.org/case-for-amau/) - Over the new few months, you can count on updates to our software that will help you to calculate aMAU directly from the OxAuth / Admin interface. - [Gluu Scales to a Billion Logins-per-Day](https://gluu.org/gluu-scale-to-a-billion-logins-per-day/) - Austin TX, April 14th, 2020 — While some commercial authentication systems can perform millions of authentications per day, Gluu has shown that its open source identity platform, using Couchbase as its database, can perform over a billion authentications per day.This was made possible by advances in cloud native technology and hosted Kubernetes services like Amazon Elastic - [Deploy a Cloud-based IAM Architecture](https://gluu.org/deploy-cloud-based-iam/) - Ready to deploy cloud-based IAM architecture? Is your organization ready to deploy and operate a cloud-based identity and access management (IAM) architecture?Gluu Cloud services can help mitigate challenges and help you build the right strategy and architecture for your unique requirements, understand the various user needs, and identify which capabilities are best left on-premises or - [Gluu and Openitio announce Digital Identity Platform for Open Banking](https://gluu.org/gluu-and-openitio-announce-open-core-digital-identity-platform-for-open-banking/) - Gluu and Openitio announce Open Core Digital Identity Platform for Open Banking and Open Finance Based on the Linux Foundation’s Janssen Project, the software enables banks to jumpstart implementingbest-in-class security for open banking APIs. Austin, Texas, April 30, 2021 – Gluu, a leading commercial open source vendor of digital identity software, and London-based Open Banking - [OAuth vs. SAML vs. OpenID Connect](https://gluu.org/oauth-vs-saml-vs-openid-connect/) - Today there are three dominant open web standards for identity online: OAuth, SAML and OpenID Connect. In the following article we’ll examine how the technologies relate to each other, and under which circumstances each should be used. OAuth 2.0 vs. OpenID Connect The first thing to understand is that OAuth 2.0 is an authorization framework, not - [How to *Securely* use SMS Two-factor Authentication (2FA)](https://gluu.org/sms-2fa-authentication/) - Any form of two-factor authentication (2FA) is better than just username/password. However, sending one-time passcodes (OTP) over text message (SMS) is a notoriously weak form of 2FA. All the way back in 2016 Forbes was publishing horror stories about people getting their Bitcoin stolen due to vulnerabilities with SMS 2FA.Even though there are more secure - [Gluu and Midships Announce Partnership](https://gluu.org/gluu-midships-partnership-announcement/) - Gluu and Midships announce partnership to offer hosted digital identity on any cloud. Austin, Texas, May 20, 2021 – Gluu, a leading digital identity software vendor, and Midships, a UK-based cloud solutions company, are proud to announce a new partnership today to launch a hosted digital identity service that supports traditional or passwordless authentication. This - [How to Stop Phishing Attacks with Gluu Casa](https://gluu.org/how-to-stop-phishing-attack/) - You know passwords are terrible. And you also know that some users will always click on those phishing emails, especially if it looks like it comes from your company!Maybe if you have low value transactions, who cares. Or maybe your customers are willing to take the risk.But if you have customers who do care, there - [Netbr announces Open Banking in International Partnership with Gluu and Openitio](https://gluu.org/partner-netbr-open-banking/) - Netbr announces ready-to-deploy technology platform for Open Banking Sao Paulo based Identity specialist Netbr announces readiness to meet BCB deadlines.With Phase 2, Phase 3 and Phase 4 of the Central Bank of Brasil’s Open Banking deadlines just around the corner, Digital Banking identity specialist and Gluu partner Netbr today announced their readiness to meet regulatory - [Applying Security to Clinical Trials](https://gluu.org/applying-security-to-clinical-trials/) - Apply Security to Clinical Trials and Reduce User Verification Friction. Pharmaceutical companies have been leveraging cloud services for many years. This is especially true for clinical trials which use many secure browser applications hosted by the trial management companies. Cloud-based CTMS (Clinical Trial Management Systems) have been a preferred method to provide lower costs, lower - [Gluu 4.4.1 Updates](https://gluu.org/gluu-4-4-1/) - Updates for stability, the introduction of an allowlist and blocklist for redirect_uris (which enhances security if this optional parameter is used) and more secure email handling for MFA (and other email services) - [Quickly Build PSD2 Compliance](https://gluu.org/help-for-financial-organizations-to-quickly-build-psd2-compliance/) - Gluu Server is certified to conform with the Financial Grade OpenID Provider(FAPI) profile. Called “FAPI” for short, this profile provides detailed requirements for the security features needed to perform payments. And Gluu is the only OpenID Connect Provider to be current in all OpenID Connect certifications.Organizations can use OpenID Connect for both high and low assurance use - [Gluu and BioID: Server-Side Biometric Authentication](https://gluu.org/gluu-and-bioid-server-side-biometric-authentication/) - BioID is a server-side biometric platform that uses face, voice and eye modalities and liveness detection. Organisations can self-host or use BioID’s hosted API as a service. - [R.I.P. Cloud LDAP](https://gluu.org/rip-cloud-ldap/) - RIP “Cloud LDAP”: Moving digital identity persistence to a Cloud Native DatabaseAll digital identity platforms need some kind of database. Traditionally, that database was a Berkeley DB key/value store, front-ended by an LDAP interface. Becoming a “Directory Manager”, i.e. a competent LDAP administrator, requires specialized training and experience. In the past, most companies had a - [How to Use Location and Device for 2FA](https://gluu.org/how-to-use-location-and-device-for-2fa/) - Leverage contextual information to implement intelligent authentication workflows in the Gluu Server.Two-factor authentication (2FA) is proven to increase account security, but it also adds friction to the user experience.Frequently 2FA is best employed only when there’s a reasonable likelihood of fraud–for example, if the user’s device or IP address is unrecognized.To implement custom policies and - [Detecting "Impossible Travel" with your Gluu Server and Deduce](https://gluu.org/impossible-travel-authentication/) - How can a user login from London, and one hour later, login from Sydney? Not even Virgin Galactic can get you there that fast (when it’s available)! But if we are using an IP address to determine the user’s location, and the person is using a VPN, this type of impossible travel is actually quite - [Gluu and AArete Announce Partnership](https://gluu.org/gluu-and-aarete/) - Gluu and AArete announce a strategic partnership to offer hosted digital identity on any cloud - [Integrate Stytch's SMS OTP authentication with Casa](https://gluu.org/stytch-sms-otp-with-gluu-casa/) - Stytch is a developer-friendly authentication SaaS that makes it easy to use passwordless technologies to protect your applications. At Gluu, we test a lot of authentication APIs. Stytch stands out in its ease of use. Seconds after you sign-up, you have client credentials and can start writing code to call their API. Initially, we wrote a - [Self-Service Account Security with Gluu Casa](https://gluu.org/self-service-account-security-with-gluu-casa/) - Organizations can offer a self-service portal for people to enroll and manage multiple types of strong authentication to secure their accounts in a Gluu Server - [Components of Gluu](https://gluu.org/components-of-gluu/) - The goal of Gluu is to be the best open-source IAM platform and to have the lowest total cost of operation (TCO). This has been done by building with the strongest open-source components and by designing control mechanisms to harden them. In this post we break down the components of our Gluu 4.X distribution and - [How to use Gluu 4.X in Teleport](https://gluu.org/how-to-use-gluu-in-teleport/) - Use Gluu 4.x IAM as a single source of truth for controlling user access to infrastructure such as databases, vm’s and Kubernetes clusters in Teleport In this article we will be dealing with a use case where organizations want to use one source of truth, which is their IAM system. The objective is giving users - [Strong Protection in the Era of Rising Threats](https://gluu.org/strong-protection-in-the-era-of-rising-threats/) - Legacy perimeter entry and exit points and security measures have been replaced by Identity and Authentication Management (IAM) Systems - [Whispeak and Gluu Launch Strategic Partnership](https://gluu.org/gluu-and-whispeak-announce-partnership/) - Whispeak voice authentication integrated with Gluu 4.X server distribution to simplify the adoption of secure voice recognition biometric authentication. - [4 Learnings: DPGA Meeting 2023](https://gluu.org/4-learnings-dpga-meeting-2023/) - I attended the DPGA annual meeting in Addis Ababa, Ethiopia. It was my first time meeting in person many of the people in that community and learning about the laudable goals of the DPG Alliance initiatives. - [Multi Master Multi-Cluster LDAP (OpenDJ) replication in Kubernetes? A controversial view](https://gluu.org/opendj-is-a-lightweight-directory-access-protocol-ldap-compliant-distributed-directory-written-in-java-many-organizations-use-it-as-a-persistence-mechanism-for-their-iam-systems/) - OpenDJ is a Lightweight Directory Access Protocol (LDAP) compliant distributed directory written in Java. Many organizations use it as a persistence mechanism for their IAM systems. - ["Workload Identity": It's SPIFFY, but Central Policy Management?](https://gluu.org/workload-identity-its-spiffy-but-central-policy-management/) - SPIFFY Mutual TLS (mTLS) is a way to secure workload identity and communication in a distributed system using the SPIFFE and SPIRE standards. (see also: https://spiffe.io/) SPIFFE stands for Secure Production Identity Framework for Everyone, and SPIRE stands for SPIFFE Runtime Environment. - [Decentralized Identity: Part I -- Trust](https://gluu.org/decentralized-identity-part-1/) - This blog series on Decentralized Identity will attempt to provide a hype-free summary of where we are–both the opportunities and the challenges in front of us. - [Gluu Cloud is in Flight](https://gluu.org/gluu-solo-cloud/) - Gluu Server in the Cloud offers unlimited users and possibilities. Love the freedom of open source digital identity, but don't want the deployment hassle? Learn more. - [Decentralized Identity: Part 2 -- Walletopia](https://gluu.org/decentralized-identity-part-two/) - If you missed Part 1, you can check it out here. In Part 2, we’re going to talk about wallets–a software category that is the key to the whole decentralized identity ecosystem. In this blog we will consider the wallet as it pertains to identity infrastructure, including how a wallet does these things:Authenticate the person - [Decentralized ID Part 3: Credential and DID Methods](https://gluu.org/decentralized-id-part-3-credential-and-did-methods/) - In part one of the Decentralized ID blog series, we outlined some of the trust challenges facing the implementation of decentralized identity. In part two, we covered some of the questions about digital wallets. In Decentralized ID Part 3: Credential and DID Methods3, we will discuss two more vectors of complexity: the diversity credentials and blockchain identity resolution. - [Is SSI needed for Web3?](https://gluu.org/web3-digital-identity/) - Are digital wallets, and consequently self-sovereign identity or “SSI” to present claims, required for Web 3? - [Install RHEL 8 with the DISA STIG Security Profile](https://gluu.org/installing-gluu-server-on-rhel-8-with-the-disa-stig-security-profile/) - A Secure Technical Implementation Guide (“STIG”) is a document published by the Department of Defense Cyber Exchange (DoD), which is sponsored by the Defense Information Systems Agency (DISA). It contains guidance on how to configure systems to defend against potential threats. These threats mainly include cyberattacks, but there can also be problems caused by the use - [Integrating Gluu Server with tru.ID](https://gluu.org/truid-integration/) - tru.ID technology enables organizations to verify that a data connection associated with a SIM card is associated with the person’s phone number. - [Gluu Advisory: Okta Twilio Cyberattack](https://gluu.org/okta-twilio-cyberattack/) - Okta one-time MFA passcodes exposed in Twilio cyberattack may affect Gluu 3 and Gluu 4 with Twilio SMS - [SP initiated SAML flow for Gluu Solo](https://gluu.org/sp-initiated-saml-flow-for-gluu-solo/) - This article will guide you through the process of a Service Provider (SP) initiated SAML flow for single sign-on (SSO) using Gluu as the Identity Provider. - [Provision Users for AWS with Gluu](https://gluu.org/provision-users-with-gluu-4-2022/) - This article will guide you through how to use SCIM to provision users on a Gluu 4 instance and configure Single-Sign-On (SSO) with AWS - [Gluu 4 supports Apple platform FIDO 2 like TouchID](https://gluu.org/support-fido2-webauthn-touchid/) - Gluu 4 supports Apple platform FIDO 2 / WebAuthn authenticators like TouchID The first laptop to build in FIDO was the Google Pixelbook (RIP). It was a little geeky--you enabled a hidden ChromeOS feature to activate FIDO U2F via the laptop power button. But Apple has taken this behavior to its logical next level: using - [3 Ways Banks Secure their Open Banking APIs with Gluu](https://gluu.org/open-banking-apis-2022/) - The Gluu Open Banking platform provides AISPs with the application security infrastructure to meet these new technologies and security requirements. - [APAC Digital Identity Unconference 2023: Notes from Session 1](https://gluu.org/apac-digital-identity-unconference-2023-notes-from-session-1/) - Learn from the experts who attended the APAC Digital Identity Unconference 2023, sponsored by Gluu. - [Inter-Operable Identity Journeys with Agama](https://gluu.org/inter-operable-identity-journeys-with-agama/) - With Agama Lab, a new low-code tool from Gluu, Inc., you can whiteboard the consumer, citizen, or workforce identity journeys of your dreams. - [Gluu 4.4.2 Fixes and Enhancements](https://gluu.org/gluu-4-4-2-updates/) - Gluu open-source Identity and Access Management platform provides workforce and consumer single sign-on, strong multi-factor authentication (with or without passwords), and centralized token management to control access to APIs. - [Enhancing Secure Mobile Authentication with OAuth, Dynamic Client Registration, and DPoP](https://gluu.org/enhancing-secure-mobile-authentication-with-oauth-dynamic-client-registration-and-dpop/) - Discover the latest insights from Mike Schwartz on authentication protocols, including OAuth, Dynamic Client Registration, and DPoP, in this thought-provoking blog post. ## Pages - [new](https://gluu.org/) - Gluu has passed more OpenID self-certification tests than any other platform. Build a scalable centralized identity journey today. - [Solo](https://gluu.org/solo/) - Instant consumer identity in the cloud Gluu Solo enables you to choose millions or billions of requests per month, multiple cloud locations and the SLA to right-size your business identity requirements. Find out more Gluu Solo How does it work? Select a plan based on the number of requests per month: Planet (up to 25M), - [Docs](https://gluu.org/docs/) - Janssen Docs Core docs for all Janssen Project components and tools. Start here if you have any technical questions! Docs FIPS Flex Docs Extra docs not covered in the open source, like how to obtain a trial license, deployment specific details like helm charts, and docs for the web Admin UI. Docs Agama Docs Get - [Discovery Call](https://gluu.org/discovery-booking/) - Book a 15-minute Discovery Call with our Sales Team If you’re exploring an enteprise Gluu Subscription or other commercial partnership, please schedule a meeting using the form below! Don’t see a time that works for you? Get in touch to schedule a time that does.sales@gluu.org Community Support Technical question about the open source Janssen Project - [Schedule appointment](https://gluu.org/schedule-appointment/) - [Agama Learn](https://gluu.org/learn/) - Learn Quick Start Guide Single document that lists minimal steps required to build, publish and deploy an Agama project. Documentation This is the Complete reference of Agama Lab. Each screen and feature gets in-depth coverage. Blogs Ad-hod how-tos, feature focused blogs, announcement etc. Helpful if we want to publish some content to social media. Get - [Flex](https://gluu.org/flex/) - Flex: enterprise IAM infrastructure The cloud is great, but what if your business needs to self-host authentication and authorization services? Perhaps data sovereignty or security considerations prevent the use of Solo, Gluu’s hosted platform? Or perhaps your organization is so large, you have economies of scale to operate access management infrastructure, and the limitations of - [Booking](https://gluu.org/booking/) - Need to chat? If you’re exploring an enteprise Gluu Subscription or other commercial partnership, please schedule a meeting using the form below!  Don’t see a time that works for you? Get in touch to schedule a time that does.sales@gluu.org Community Support Technical question about the open source Janssen Project software distribution. Join the Janssen - [Gluu 4](https://gluu.org/gluu-4/) - Five+ years ofGluu 4.x If you are running a legacy Gluu Server version 4.x infrastructure, and want the latest security updates, you’ll need a Gluu Subscription. There is no rush to upgrade–Gluu 4 is supported until Dec 31, 2028, and two years of extended support is available after that. That means you can run Gluu - [Gluu Service Partners](https://gluu.org/partners/) - Gluu Service Partners The Kernel The Kernel delivers cutting-edge IT Security, authentication and Forensic solutions for businesses and individuals. Middle East Identicum Success in an Identity and Access Management project depends on three fundamental factors: customer, technology and implementer. Know why Identicum is your best business partner to help you on your IAM program. South - [Quick start using Agama Lab](https://gluu.org/quick-start-guide/) - Quick start using Agama Lab Table of Content Prerequisites Create a new Agama project Log into the Agama Lab Create a new project Defining the authentication flow Design user interface Publish the project Deploy Agama project Testing using Janssen Tarp In this quick start guide, we will build, deploy and test a simple Agama project - [Home](https://gluu.org/home/) - Gluu has passed more OpenID self-certification tests than any other platform. Build a scalable centralized identity journey today. - [Identerati Office Hours Episodes](https://gluu.org/identerati-office-hours-episodes/) - Discussion of two emerging OAuth Specs: First Party Native Authentication and Global Token Revocation - [Roadmap](https://gluu.org/roadmap/) - Gluu Roadmap Gluu Flex Monthly release cycleFlex release trails Janssen release by about a weekNo known EOL Next Release: 5.1.4 Check Github Janssen Release and Github Flex Release and for a detailed change history. 2024 Priorities Upgrade FIDO serverIntroduce Lock componentIntroduce CedarlingFix Inbound SAMLAdd Shibboleth IDP Gluu 4 Quarterly release cycleSupport through: 12/31/2027 (price increase - [Super Gluu](https://gluu.org/super-gluu/) - Super GluuAuthenticator App Authenticate a person to a browser with any iOS or Android device. Free to end users on the App Store and Play Store–companies pay only $0.01 per push notification.Great for “Kiosk” login where end user scans a QR code to login. Avoids the hassle of entering annoying one-time codes sent via SMS. Android iOS - [Agama Project of the Week](https://gluu.org/agama-project-of-the-week/) - Agama Project of the Week Generic selectors Exact matches only Search in title Search in content Post Type Selectors SecurityKey Episode 6 This video focuses on the Agama Security Key project, which involves a physical USB device, also known as a FIDO token, used for authentication. Users simply plug in or tap their security key - [Agama Lab](https://gluu.org/agama-lab/) - Agama Lab makes it easy to use low-code block programming to build custom web login flows for your business. The Agama Programming Language, developed at the Linux Foundation Janssen Project, is a vendor-neutral, domain-specific language for “identity orchestration”. Agama also defines a standard project archive format–“.gama”, enabling you to deploy your project as a single file. - [Blog](https://gluu.org/blog/) - Gluu Blog This page includes announcements, random thoughts, technical howtos, reports from the field and other stuff that doesn’t fit anywhere else on the website! Articles Janssen Project is a Digital Public Good May 1, 2024 The Janssen Project has been included in the Digital Public Goods Alliance (DPG) Registry. The goal of the DPG - [Documentation](https://gluu.org/documentation/) - Documentation Agama Flow May 31, 2024 Agama is a framework that consists of: A DSL (domain-specific language) purposedly designed for writing web flows. A set of rules that drive the behavior of such flows when they are executed Introduction To Agama Lab December 1, 2024 Sign Up Sign In December 1, 2024 Flow Designer December - [Open Source at Gluu - OpenID, FIDO, SAML, SCIM, Identity, Cloud, MFA, TouchID, FaceID, Hello, Mobile, Web, Browser, SSO](https://gluu.org/foss/) - Nothing builds trust like open Source Community-governed open source supercharges innovation-- harness the power of FOSS! Janssen Project is chartered directly under the Linux FoundationGluu is the lead maintainer of the Janssen ProjectThe Agama ecosystem includes third party connectors to authentication providers, fraud detection, and AI.Janssen distributions include external community governed open source identity components, - [About](https://gluu.org/about/) - About Gluu Mission Our mission is to build the world’s best enterprise identity and access management platform and contribute back to the open source community along the way. Gluu's Story: 15 years of consistent product innovation Before starting Gluu, founder Mike Schwartz worked for ten years as an IT consultant, helping enterprises build IAM infrastructure. - [Agama Blog](https://gluu.org/agama-blog/) - Agama Blog How To Integrate Agama‐Lab Github App With Your GitHub Account December 18, 2024 Publish Agama Project And Register To The Explore Catalog March 22, 2024 You need it only when you are planning to add your project to explore catalog so that community can use your agama flow and add your security rules - [Scan](https://gluu.org/scan/) - SCAN API Marketplace A trusted marketplace in Agama Lab to buy security, identity, fraud detection, AI and cryptographic services from Gluu and third party vendors. Order On Agama Lab Gluu Scan How does it work? You’ll need to sign up for an Agama Lab account. One you’ve registered, you’ll be able to sign-up for SCAN - [Casa](https://gluu.org/casa/) - Self-Service MFA with Casa A self-service credential management portal key to a successful MFA rollout. Casa provides this portal, enabling end users to register credentials: FIDO, TOTP, Super Gluu, SMS, X.509 Certificates, external IDPs. Casa plugins support additional third party authentication providers. Casa provides out-of-the-box MFA features for organizations that don’t need the flexibility of - [About Agama Lab](https://gluu.org/about-agama-lab/) - About Agama Lab The Story of Agama As developers, we love the convenience of cloud identity, but we also want the flexibility to meet our exact business requirements for login, registration, and account recovery. Most good cloud identity platforms provide a way to customize the user experience by implementing code. But frequently this code requires us - [Components](https://gluu.org/components/) - Components of Gluu distributions Enroll and you’ll be free to try Gluu Flex for one month. The maximum number of active users during the trial period is 5,000. You can activate your subscription at any time to increase your capacity. Gluu Flex Gluu Flex is our flagship product, a commercial Identity Provider with an open - [Thank You](https://gluu.org/thank-you/) - Thank you! Your submission has been received. Please check your email for confirmation. Back to home page - [Contact Us](https://gluu.org/contact-us/) - Contact us Questions about commercial engagement? Fill out this form and we’ll follow up. Technical questions about open source? Post on Janssen Project Discussions forum! Need to meet? Book a meeting during U.S. hours (GMT -5) or contact sales@gluu.org for a different time. Name Email* Phone Number* Country —Please choose an option—United StatesCanadaMexicoUnited KingdomAfghanistanAlbaniaAlgeriaAmerican SamoaAndorraAngolaAnguillaAntigua - [Gluu Terms and Conditions](https://gluu.org/gluu-terms-and-conditions/) - Gluu Terms and Conditions Terms and Conditions Gluu offers this Web site, including all information, software, products and services available from this Web site or offered as part of or in conjunction with this Web site (the “Web site”), to you, the user, conditioned upon your acceptance of all of the terms, conditions, policies and - [Gluu Privacy Policy](https://gluu.org/gluu-privacy-policy/) - Gluu Privacy Policy Privacy Policy Gluu is committed to respecting the privacy rights of all visitors to our website. The following policy describes how we collect, use, share, transfer and disclose Personal Information (as defined below). This Privacy Policy covers information we collect online, not offline. The Services are owned and operated by Gluu, Inc., - [Howto Submit an Agama Project to the Explore Catalog](https://gluu.org/how-to-submit-agama-project-to-catalog/) - Learn Project of the Week Agama Lab Story Learn Project of the Week Agama Lab Story Login ⟶ Howto Submit an Agama Project to the Explore Catalog Step 1: Create Project Github Repo blah blah blah Step 2: Publish Project from Agama Lab blah blah blah Step 3: Gluu Code Review blah blah blah Step - [AArete](https://gluu.org/aarete/) - Humanizing Data for Purposeful Change Introduction AArete is a global management and technology consulting firm. Our people focus on delivering strategic profitability improvement, analytics, technology, and advisory solutions, driven by market intelligence and digital innovation.AArete, a global management and technology consulting firm, has been named to the inaugural list of Forbes World’s Best Management Consulting - [Fronix](https://gluu.org/fronix/) - Technology which you can Control Introduction Fronix has developed the expertise in multidomain platform under four major pillars – Infrastructure, Cloud, Security and Maintenance. Fronix designs, architect, implements and manages ICT security solutions for enterprise infrastructures. B-21-2, Zenith Corporate Park 3 Jalan SS 7/26, 47301 Petaling Jaya Selangor Darul Ehsan, Malaysia Visit Website - [Azimuth Labs](https://gluu.org/azimuth-labs/) - Sun WebSpace Server, OpenSSO, Directory Server, OpenDS and Identity Manager Introduction Based in Singapore, Azimuth Labs is a consulting company that provides professional identity services in the Asia region. It has successfully deployed numerous projects that require portal customization, single sign-on integration, directory service implementation and identity management.Azimuth Labs’ strong history with Sun WebSpace Server, - [Nixu](https://gluu.org/nixu/) - Embrace Digital Securely Introduction Nixu is a cybersecurity services company on a mission to keep the digital society running. Nixu helps organizations embrace digitalization securely. Partnering with our clients we provide practical solutions for ensuring business continuity, an easy access to digital services and data protection.Nixu has implemented Gluu’s mobile app based login. There’s also - [Technology Partners](https://gluu.org/technology-partners/) - Gluu Technology Partners The Gluu Server is a widely used server that provides strong authentication for users through partner offerings in FIDO2, biometrics, public key fingerprint cryptography, and more. Partners Gluu Technology Partners Authentrend AuthenTrend is leading the way in authentication with biometric technology. Their mission is to replace passwords with fingerprints for higher security - [Casa Documentation](https://gluu.org/casa-documentation/) - Gluu Casa Documentation Overview Gluu Casa (“Casa”) is a self-service web portal for end-users to manage authentication and authorization preferences for their account in acts. For example, as people interact with an organization’s digital services, they may need to: Gluu Casa ("Casa") is a self-service web portal for end-users to manage authentication and authorization preferences - [Super Gluu Documentation](https://gluu.org/super-gluu-documentation/) - Super Gluu Documentation Overview Super Gluu is a free and secure two-factor authentication (2FA) mobile app.Super Gluu is tightly bundled with the Gluu Server identity and access management platform, and can be used to achieve 2FA for web and mobile applications that leverage Gluu for authentication. Super Gluu documentation is organized into the following sections: ## My Templates - [govops.gds.4](https://gluu.org/?elementor_library=govops-gds-4) - GovOps: Measure Risk, Transparency and Accountability With declarative policies, formal analysis, explicit federation, and continuous compliance, organizations can finally govern in real time — matching the velocity of the systems they are securing. Request Demo Learn More About GovOps Why GovOps Real-Time Governance GovOps continuously measures and verifies system behavior, aligning compliance with actual runtime - [booking_251003](https://gluu.org/?elementor_library=booking_251003) - Need to chat? If you’re exploring an enteprise Gluu Subscription or other commercial partnership, please schedule a meeting using the form below!  Don’t see a time that works for you? Get in touch to schedule a time that does.sales@gluu.org Community Support Technical question about the open source Janssen Project software distribution. Join the Janssen - [new4_land_250929](https://gluu.org/?elementor_library=new4_land_250929) - Scalable cloud authentication and authorization infrastructure for enterprises Get started with solo SaaS identity Management Service Learn more about Flex Self-hosted Software Stack Open Standards Solutions: Scalable cloud authentication and authorization infrastructure for enterprises. Get started with solo Learn more about Flex SaaS identity Management Service Self-hosted Software Stack Built on Open Standards: Gluu flex - [Agama Lab Header](https://gluu.org/?elementor_library=agama-lab-header) - Content area - [new_home_25_04_06](https://gluu.org/?elementor_library=new_home_25_04_06) - Enterprise security signed and sealed... with JWTs. Implement Token Based Access Control (“TBAC”) with Gluu infrastructure for authorization, authentication, and federation. Developer Schedule demo Open Standards Solutions: Enterprise security signed and sealed... with JWT tokens. Implement Token Based Access Control (“TBAC”) with Gluu infrastructure for authorization, authentication, and federation. Book Meeting Built on Open Standards: - [service_partners250327_2](https://gluu.org/?elementor_library=service_partners250327_2) - Our Service Partners Deployment of an enterprise security platform like Gluu is a lot of work, and so Gluu tries to work with a local partner to deliver this complex IT project. Our network is located around the world, and offers a wide array of services. Partners Gluu Service Partners NIXU Nixu is a cybersecurity - [service_partners250327](https://gluu.org/?elementor_library=service_partners250327) - Our Service Partners Deployment of an enterprise security platform like Gluu is a lot of work, and so Gluu tries to work with a local partner to deliver this complex IT project. Our network is located around the world, and offers a wide array of services. Partners Gluu Service Partners NIXU Nixu is a cybersecurity - [New Footer](https://gluu.org/?elementor_library=new-footer) - Content area - [New header](https://gluu.org/?elementor_library=new-header) - Content area - [homenewa](https://gluu.org/?elementor_library=homenewa) - Modern Authentication On Your Way Does your business need to glue together a patchwork of identity services and technologies? Use low code and cloud native technologies. Developer Schedule demo Open Standards Solutions: Enterprise security signed and sealed... with JWTs. Implement Token Based Access Control (“TBAC”) with Gluu infrastructure for authorization, authentication, and federation. Book Meeting - [Inner Page Header](https://gluu.org/?elementor_library=elementor-header-2729) - Content area - [header_home_page](https://gluu.org/?elementor_library=header_home_page) - Products Solo Flex Gluu 4 Open Source Partners Gluu Service Partners Technology Partners Learn Documentation Blog Identerati Office Hours Livestream Gluu Academy Support Agama Lab Products Solo Flex Gluu 4 Open Source Partners Gluu Service Partners Technology Partners Learn Documentation Blog Identerati Office Hours Livestream Gluu Academy Support Agama Lab Contact - [gluu_header2](https://gluu.org/?elementor_library=gluu_header2) - Learn Project of the Week Agama Lab Story Learn Project of the Week Agama Lab Story Login - [gluu_header1](https://gluu.org/?elementor_library=gluu_header1) - with Agama Lab, Gluu’s low code identity orchestration platform, your business can build the perfect identity flows in minutes, not months. - [quick_start_guide_agama](https://gluu.org/?elementor_library=quick_start_guide_agama) - Agama Lab Quick Start Guide Table of Content Agama-Lab Online Tool Install GitHub-App and select Repository Make a Project Make a Flow File Make a Simple Basic Auth Flow Download Basic Flow Make a template file Make a gama file / Release Project Deploy a gama file on Jans Testing using Jans Tarp Overview Agama - [Agama Doc](https://gluu.org/?elementor_library=agama-doc) - Agama Doc Table of Contents Introduction To Agama Lab Sign Up/Sign In Flow Designer Project Dashboard Project Editor Node Types Test Agama Lab Projects Explore Section Policy Designer Helping Nations Build Trusted Digital Identity Citizens want to use the Internet to connect to their government for a myriad of reasons. Wouldn’t it be great if - [Introduction To Agama Lab 3](https://gluu.org/?elementor_library=introduction-to-agama-lab-3) - Agama Lab Features Agama Lab is your web-based toolbox for authoring authentication and authorization projects. It offers drag and drop interface for authoring authentication flows using the Flow Designer while policy designer helps you write policies for authorization. The Explore section hosts ready-to-use authentication projects that can be downloaded and integrated into your IAM server - [Agama Introduction To Agama Lab All Page](https://gluu.org/?elementor_library=agama-introduction-to-agama-lab-all-page) - Agama Lab Features Agama Lab is your web-based toolbox for authoring authentication and authorization projects. It offers drag and drop interface for authoring authentication flows using the Flow Designer while policy designer helps you write policies for authorization. The Explore section hosts ready-to-use authentication projects that can be downloaded and integrated into your IAM server - [introduction_content](https://gluu.org/?elementor_library=introduction_content-2) - Agama Lab Features Agama Lab is your web-based toolbox for authoring authentication and authorization projects. It offers drag and drop interface for authoring authentication flows using the Flow Designer while policy designer helps you write policies for authorization. The Explore section hosts ready-to-use authentication projects that can be downloaded and integrated into your IAM server - [introduction_content](https://gluu.org/?elementor_library=introduction_content) - Agama Lab Features Agama Lab is your web-based toolbox for authoring authentication and authorization projects. It offers drag and drop interface for authoring authentication flows using the Flow Designer while policy designer helps you write policies for authorization. The Explore section hosts ready-to-use authentication projects that can be downloaded and integrated into your IAM server - [Agama Introduction To Agama Lab 2](https://gluu.org/?elementor_library=agama-introduction-to-agama-lab-2) - Agama Introduction To Agama Lab 2 Table of Contents Introduction To Agama Lab Logging In Project Dashboard Project Editor Agama Flow Widgets Widget 1 Widget 2 Custom Branding Testing Agama Project Releasing Agama Project Contributing an Agama Project Using a Project From Explore Catalog Buying Scan Credits Subscribing To Flex License Subscribing To Solo License - [Introduction To Agama Lab](https://gluu.org/?elementor_library=introduction-to-agama-lab-2) - Agama Lab Features Agama Lab is your web-based toolbox for authoring authentication and authorization projects. It offers drag and drop interface for authoring authentication flows using the Flow Designer while policy designer helps you write policies for authorization. The Explore section hosts ready-to-use authentication projects that can be downloaded and integrated into your IAM server - [Introduction To Agama Lab](https://gluu.org/?elementor_library=introduction-to-agama-lab) - Agama Lab Features Agama Lab is your web-based toolbox for authoring authentication and authorization projects. It offers drag and drop interface for authoring authentication flows using the Flow Designer while policy designer helps you write policies for authorization. The Explore section hosts ready-to-use authentication projects that can be downloaded and integrated into your IAM server - [Default Kit](https://gluu.org/?elementor_library=default-kit) - [Identerati](https://gluu.org/?elementor_library=identerati) - Identerati Office Hours Episode Generic selectors Exact matches only Search in title Search in content Post Type Selectors Episode 100: Is TBAC the Next Big Thing? The number of JWT tokens out there is rapidly expanding. Beyond traditional federation tokens, like OAuth access tokens, and OpenID identity assertions, there is whole new category of “decentralized - [Header](https://gluu.org/?elementor_library=elementor-header-10) - Content area - [Footer](https://gluu.org/?elementor_library=footer) - Content area - [Featured Posts](https://gluu.org/?elementor_library=featured-posts) - Featured Post Help shape the future of digital transformation, identity management, payment, connectivity, and security. Coming Soon Featured Post Gluu Flex Roadmap April 29, 2024 As Flex is a commercial distribution of the Janssen Project, check the Janssen Nightly Build changelog and issues. You can also check the Nightly Build changelog for the Admin UI. - [TOC](https://gluu.org/?elementor_library=toc) - Table of Contents Introduction To Agama Lab Sign Up/Sign In Flow Designer Project Dashboard Project Editor Node Types Test Agama Lab Projects Explore Section Policy Designer Introduction to Agama Lab Logging In Project Dashboard Project Editor Flow Widgets Widget 1 Widget 2 Custom Branding Testing Agama Project Releasing Agama Project Contributing an Agama Project Using - [Wiki Content](https://gluu.org/?elementor_library=wiki-content) - Table of Contents Introduction Agama Lab makes it easy to use low code block programming to build custom web login flows for your business. The Agama Programming Language, developed at the Linux Foundation Janssen Project, is a vendor neutral, domain specific language for identity orchestration. Agama also defines a standard project archive format–.gama, enabling you - [Agama Blog Post](https://gluu.org/?elementor_library=agama-blog-post-2) - Agama Blog Post Helping Nations Build Trusted Digital Identity Citizens want to use the Internet to connect to their government for a myriad of reasons. Wouldn’t it be great if you could use the Web to pay your taxes, vote, obtain a driver’s license, or apply for a birth certificate? To a large extent, governments - [Gluu Search Results](https://gluu.org/?elementor_library=elementor-search-results-32377) - Search Result... GovOps Landing Page GovOps: Measure Risk, Transparency and Accountability With declarative policies, formal analysis, explicit federation, and continuous compliance, organizations can finally govern in real time — matching the velocity of the systems they are securing. Request Demo Learn More About GovOps Why GovOps Real-Time Governance GovOps continuously measures and verifies system behavior, - [Featured Post](https://gluu.org/?elementor_library=elementor-loop-item-29356) - Featured Post September 25, 2023 - [Agama Project of the Week](https://gluu.org/?elementor_library=elementor-single-post-32642) - Agama Project of the Week - [Office Hours](https://gluu.org/?elementor_library=elementor-single-post-32396) - Office Hours - [Office Hours Episode](https://gluu.org/?elementor_library=office-hours-episode) - Office Hours Episode - [Agama Project Episode](https://gluu.org/?elementor_library=agama-project-episode) - Agama Project Episode - [Agama Episodes](https://gluu.org/?elementor_library=agama-episodes) - Latest Episodes Lorem ipsum dolor sit amet, consectetur adipiscing elit. Curabitur aliquet nibh nisi, vitae tincidunt ante hendrerit at. Episode 04 Episode 4: OpenID Overview and Demo of Gluu’s Agama OpenID project, for connecting to external OpenID Providers. I show an out-of-the-box configuration where you just list the external providers in a JSON configuration file. - [Blog Post](https://gluu.org/?elementor_library=elementor-single-post-29597) - Blog Post September 27, 2023 Helping Nations Build Trusted Digital Identity Citizens want to use the Internet to connect to their government for a myriad of reasons. Wouldn’t it be great if you could use the Web to pay your taxes, vote, obtain a driver’s license, or apply for a birth certificate? To a large - [About](https://gluu.org/?elementor_library=about) - About Gluu Mission To curate and commercialize a distribution of the world’s best open-source digital identity infrastructure projects to foster adoption by organizations. How we got started In late 2008, Mike Schwartz, founder of Gluu, had a hunch that digital identity was too complex, too proprietary, and too expensive for many organizations. The Gluu Server - [Agama Blog](https://gluu.org/?elementor_library=elementor-loop-item-30625) - Agama Blog November 30, 2023 - [Agama - Contact Details](https://gluu.org/?elementor_library=agama-contact-details) - Create a custom login flow that integrates with your existing systems and meets your specific security requirements. Implement multi-factor authentication for your users to enhance security. Create a seamless single sign-on experience for your customers across multiple applications. - [Agama - Contact](https://gluu.org/?elementor_library=agama-contact) - Get Ready to Design It is a long established fact that a reader will be distracted by the readable content of a page when looking at its layout. Join Agama lab - [Register - Agama](https://gluu.org/?elementor_library=register-agama) - Help Build Identity Journeys and Earn Swag!! Publish in the Explore Catalog and get a FREE t-shirt! Learn more about how to submit your project for review! Register Agama - [Agama- Get Ready](https://gluu.org/?elementor_library=agama-get-ready) - Get Ready for the Journey An Agama project archive contains everything an IDP needs to execute an identity journey–e.g. web forms, images, CSS, code, and flows. Right now, you can deploy your Agama projects to a Gluu Flex or Linux Foundation Janssen Auth Server. Join Agama lab - [Agama-Steps](https://gluu.org/?elementor_library=agama-steps) - In 3 Steps 1. Design Use Agama Lab to orchestrate your identity journeys, design forms, and write code. You don’t need to learn the Agama programming language–use block programming, and Agama Lab generates the code for you! If you’re curious what the code looks like, use the “Generate Code” button. 2. Build When you select - [Hero Section Agama](https://gluu.org/?elementor_library=hero-section-agama) - DIY IdentityJourneys Agama Lab makes it easy to use low code block programming to build custom web login flows for your business.The Agama Programming Language, developed at the Linux Foundation Janssen Project, is a vendor neutral, domain specific language for “identity orchestration”. Agama also defines a standard project archive format–“.gama”, enabling you to deploy your - [Agama Blog Post](https://gluu.org/?elementor_library=agama-blog-post) - Learn Project of the Week Agama Lab Story Learn Project of the Week Agama Lab Story Login ⟶ Agama Blog Post Gluu Admin November 30, 2023 12:04 pm Intention Discovery call Sales Name* Business Email* Phone number Company Industry Product Interest* — Select — Solo Flex Gluu 4 Primary Needs* Urgency* <3 months 3–6 - [Agama Banner](https://gluu.org/?elementor_library=agama-banner) - Agama Banner - [Gluu Help](https://gluu.org/?elementor_library=gluu-help) - Learn Gluu Docs Gluu Academy Agama Lab Docs Identerati Office Hours Livestream Docs Gluu Academy Agama Lab Docs Identerati Office Hours Livestream Offering Gluu Flex Solo Gluu 4 Gluu Flex Solo Gluu 4 Company About Gluu Support Agama Lab Schedule a Demo Privacy Policy Website Terms and Conditions About Gluu Support Agama Lab Schedule a - [Jans Tent](https://gluu.org/?elementor_library=jans-tent) - Testing using Jans Tent Setup Jans-Tent. Instructions Setup config.py as per your need. Configuration to run Agama flow ACR_VALUES = "agama" ADDITIONAL_PARAMS = { 'agama_flow': 'co.basic' } Run Tent Successfully login - [File on Jans](https://gluu.org/?elementor_library=file-on-jans) - Deploy a gama file on Jans Make sure you have enabled Agama and Agama Script on your Jans server. Check Agama Docs for Details Let’s enable it using TUI, Open TUI in your Jans Server # cd /opt/jans/jans-cli # python3 jans_cli_tui.py Enable Agama Configuration, In TUI, navigate to AuthServer > Properties > agamaConfiguration > Enabled [*] > - [Release Project](https://gluu.org/?elementor_library=release-project) - Make a gama file / Release Project Right-click on anything in File Tree and select Release Project - [Template File](https://gluu.org/?elementor_library=template-file) - Make a template file The above flow is using login.ftlh template file. Let’s create it. Right-click on the web folder and select the new free maker template Select Template and add details. It is up to you to make a beautiful design using UI-Editor. Edit HTML to add existing code. You can make your own. - [Download Basic Flow](https://gluu.org/?elementor_library=download-basic-flow) - Download Basic Flow If you created the above flow successfully then skip this part. There is an import facility. If you have any existing flow’s JSON file then you can directly import and make a flow quickly. co.basic.zip Download the above zip, extract it, and import the JSON file: - [Basic Auth Flow](https://gluu.org/?elementor_library=basic-auth-flow) - Make a Simple Basic Auth Flow Final look at the flow diagram: Save it and you can click on the Code button to see the actual flow It will look like this: Flow co.basic Basepath "" authService = Call io.jans.as.server.service.AuthenticationService#class cdiUtil = Call io.jans.service.cdi.util.CdiUtil#bean authService authResult = {} Repeat 3 times max creds = RRF "login.ftlh" authResult - [Make a Flow File](https://gluu.org/?elementor_library=make-a-flow-file) - Make a Flow File Right Click on the Code folder and select New Flow file Enter Details in Form - [Make a Project](https://gluu.org/?elementor_library=make-a-project) - Make a Project The first step is to make a Project. Navigate to the Project Tree File view to make Agama Flows and .gama files. - [Agama Lab Online Tool](https://gluu.org/?elementor_library=agama-lab-online-tool) - Agama-Lab Online Tool Use https://cloud.gluu.org/agama-lab online tool to make an agama flow. Hit the above URL and you will see a page with Login with GitHub button. Click on it and give access to agama-lab. In the next step, it will ask you to enter the repository path. Right now, Agama Lab always users your personal repository. You just - [Quick Guide Anchor](https://gluu.org/?elementor_library=quick-guide-anchor) - Overview Agama Lab tool helps developers to make a flow for Jans Agama.Table of ContentAgama-Lab Online ToolMake a ProjectMake a Flow FileMake a Simple Basic Auth FlowDownload Basic FlowMake a template fileMake a gama file / Release ProjectDeploy a gama file on JansTesting using Jans Tent - [About Agama Lab](https://gluu.org/?elementor_library=about-agama-lab) - About Agama Lab The Story of Agama As developers, we love the convenience of cloud identity, but we also want the flexibility to meet our exact business requirements for login, registration, and account recovery. Most good cloud identity platforms provide a way to customize the user experience by implementing code. But frequently this code requires us - [Agama Lab Footer](https://gluu.org/?elementor_library=agama-lab-footer) - Content area - [Agama Lab Homepage](https://gluu.org/?elementor_library=agama-lab-homepage) - DIY Identity Journeys Join Agama Lab Don’t build another login form! You can use Agama Lab to white board the identity workflow of your IAM dreams. The Agama Programming Language for the first time enables vendor-neutral, inter-operable web “identity journeys”. Agama Lab, hosted by Gluu, is where you can author, share, comment, and star your favorite Agama projects. Integrated with - [Blog Posts](https://gluu.org/?elementor_library=elementor-loop-item-29478) - Blog Posts September 26, 2023 - [Blog](https://gluu.org/?elementor_library=elementor-archive-29333) - IAM Open Source If you use this site regularly and would like to help keep the site on the Internet, please consider donating a small sum to help pay for the hosting and bandwidth bill. There is no minimum donation, any sum is appreciated – click here to donate using PayPal. Thank you for your - [Fronix](https://gluu.org/?elementor_library=fronix) - Technology which you can Control Introduction Fronix has developed the expertise in multidomain platform under four major pillars – Infrastructure, Cloud, Security and Maintenance. Fronix designs, architect, implements and manages ICT security solutions for enterprise infrastructures. B-21-2, Zenith Corporate Park 3 Jalan SS 7/26, 47301 Petaling Jaya Selangor Darul Ehsan, Malaysia Visit Website - [AArete](https://gluu.org/?elementor_library=aarete) - Humanizing Data for Purposeful Change Introduction AArete is a global management and technology consulting firm. Our people focus on delivering strategic profitability improvement, analytics, technology, and advisory solutions, driven by market intelligence and digital innovation.AArete, a global management and technology consulting firm, has been named to the inaugural list of Forbes World’s Best Management Consulting - [Azimuth](https://gluu.org/?elementor_library=azimuth) - Sun WebSpace Server, OpenSSO, Directory Server, OpenDS and Identity Manager Introduction Based in Singapore, Azimuth Labs is a consulting company that provides professional identity services in the Asia region. It has successfully deployed numerous projects that require portal customization, single sign-on integration, directory service implementation and identity management.Azimuth Labs’ strong history with Sun WebSpace Server, - [Nixu](https://gluu.org/?elementor_library=nixu) - Embrace Digital Securely Introduction Nixu is a cybersecurity services company on a mission to keep the digital society running. Nixu helps organizations embrace digitalization securely. Partnering with our clients we provide practical solutions for ensuring business continuity, an easy access to digital services and data protection.Nixu has implemented Gluu’s mobile app based login. There’s also - [Services Partners](https://gluu.org/?elementor_library=services-partners) - Our Service Partners Key Service Partners are located around the world, to help implement and manage your Gluu identity and access management platform. Partners Gluu Service Partners AArete AArete is a global management and technology consulting firm delivering strategic profitability improvement, analytics, technology and advisory solutions, driven by market intelligence and digital innovation. London Fronix - [Technology Partners](https://gluu.org/?elementor_library=technology-partners) - Gluu Technology Partners The Gluu Server is a widely used server that provides strong authentication for users through partner offerings in FIDO2, biometrics, public key fingerprint cryptography, and more. Partners Gluu Technology Partners Authentrend AuthenTrend is leading the way in authentication with biometric technology. Their mission is to replace passwords with fingerprints for higher security - [Super Gluu Documentation](https://gluu.org/?elementor_library=super-gluu-documentation) - Super Gluu Documentation Overview Super Gluu is a free and secure two-factor authentication (2FA) mobile app.Super Gluu is tightly bundled with the Gluu Server identity and access management platform, and can be used to achieve 2FA for web and mobile applications that leverage Gluu for authentication. Super Gluu documentation is organized into the following sections: - [Janssen Project Documentation](https://gluu.org/?elementor_library=janssen-project-documentation) - Janssen Project Documentation Introduction Janssen enables organizations to build a scalable centralized authentication and authorization service using free open source software. The components of the project include client and server implementations of the OAuth, OpenID Connect, SCIM and FIDO standards. Administration Guide The Janssen Server is highly extensible and customizable. Resources for deployment, operation, and - [Casa Documentation](https://gluu.org/?elementor_library=casa-documentation) - Gluu Casa Documentation Overview Gluu Casa (“Casa”) is a self-service web portal for end-users to manage authentication and authorization preferences for their account in acts. For example, as people interact with an organization’s digital services, they may need to: Gluu Casa ("Casa") is a self-service web portal for end-users to manage authentication and authorization preferences - [Solo](https://gluu.org/?elementor_library=solo) - Instant consumer, workforce or partner identity in the cloud Gluu Solo enables you to choose millions or billions of requests per month, multiple cloud locations and the SLA to right-size your business identity requirements. Sign up for Agama Lab Gluu Solo How dose it work? Select plan based on your requests per month: Planet (up - [Gluu Home](https://gluu.org/?elementor_library=gluu-home) - Gluu Flex Platform Modern Authentication Your Way Does your business need to glue together a patchwork of identity services and technologies? Have it your way with Gluu Flex, a platform based on open source and open standards.Secure web, mobile, command line or API applications.Integrate identity into your existing infrastructure.Empower end users to enroll the credentials - [Casa](https://gluu.org/?elementor_library=casa) - Self-Service MFA with Casa Everyone knows passwords are bad. Try typing your password in to a game console. Usability is terrible. Password security is even worse. The attack surface area of passwords is large and getting larger every day. So why don’t all organizations use Multi-Factor Authentication (MFA)? Start Now Request Demo MFA Multi-Factor Authentication ## Agama Lab - [Node Types](https://gluu.org/agama/node-types/) - A flow in Agama flow visual editor comprises of several connected nodes. Each node represents an Agama DSL directive. Each node also allows the user to pass parameters to the underlying Agama DSL directive. Adding a New Node When the user drags the connector, the Agama Lab presents a list to choose the next node - [Authorization Policy Designer](https://gluu.org/agama/authorization-policy-designer/) - Policy Designer Policy designer tool provides you a visual editor to build, manage, and test authorization policies written in Cedar language. Policy designer helps you quickly test these policies to authorise users based on tokens using Jans Cedarling.You can use policy designer to:Create and manage policy stores that store multiple Cedar policies in a GitHub - [Deploying and configuring an Agama project on the Janssen Server](https://gluu.org/agama/deploying-an-agama-project-to-jans-server/) - This page provides steps to deploy a project to your Jans Server. Ensure you have - [How To Integrate Agama‐Lab Github App With Your GitHub Account](https://gluu.org/agama/how-to-integrate-agama‐lab-github-app-with-your-github-account/) - What Is the Agama Lab GitHub App This app enables developers to specify granular repository access control for the Agama Lab code authoring tool. See here why the Agama Lab requires access to the GitHub account. Install the Agama-Lab GitHub App To integrate the Agama Lab GitHub app with your GitHub accountSign In to the - [Explore Section](https://gluu.org/agama/explore-section/) - Explore section lists all the community-contributed, ready-to-use Agama projects. It contains the most frequently used authentication journeys like passwords, passkeys, SMS-OTP, E-Mail OTP, etc. These projects can be downloaded in form of a .gama package and start using after providing a minimal required configuration. An Agama project can be added to an IDP that has - [Project Editor](https://gluu.org/agama/project-editor/) - Project editor is the development tool to write authentication flows. It has a low-code editor that can be used to drag and drop the code blocks and the actual Agama code gets generated in the background. Major components of the project editor are noted below: Project explorer: Left hand panel shows all the artifacts in - [Flow Designer](https://gluu.org/agama/flow-designer/) - Authentication Flow Designer is a complete set of tools that you need to build, manage, maintain, and test your Agama projects and authentication flows. You can use the flow designer to Create and manage Agama projects using the dashboard Create and make changes to the authentication flows using a low-code drag-drop visual editor Manage multiple - [Sign Up Sign In](https://gluu.org/agama/sign-up-sign-in/) - Sign In You can sign into the Agama Lab using your GitHub account(recommended) or using your email ID. If you haven’t registered your email ID before, then the registration form will get you started. The registration process is not required if signing in using the GitHub. Sign up Need For GitHub Account Agama Lab uses - [Introduction To Agama Lab](https://gluu.org/agama/introduction-to-agama-lab/) - Agama Lab Features Agama Lab is your web-based toolbox for authoring authentication and authorization projects. It offers drag and drop interface for authoring authentication flows using the Flow Designer while policy designer helps you write policies for authorization. The Explore section hosts ready-to-use authentication projects that can be downloaded and integrated into your IAM server - [Test Agama Lab Projects](https://gluu.org/agama/test-agama-lab-projects/) - Coming Soon - [Agama Lab Project Dashboard](https://gluu.org/agama/agama-lab-project-dashboard/) - Project Dashboard lists projects in the repository and releases attached to those projects. A project from the dashboard can be opened in the project editor for modifications. When the user has not selected the repository yet, the project dashboard shows instructions for GitHub integration and repository selection as shown below: After successful GitHub integration, the - [TOTP](https://gluu.org/agama/totp/) - In this video, I discuss Agama TOTP, to enable people to enroll and authenticate with standard OATH TOTP apps like Google Authenticator. I demonstrate how to deploy the project and show its configuration options. It serves as an informative guide to understand and explore Agama TOTP project, which is Apache 2.0 license. - [OpenID](https://gluu.org/agama/openid/) - Overview and Demo of Gluu’s Agama OpenID project, for connecting to external OpenID Providers. I show an out-of-the-box configuration where you just list the external providers in a JSON configuration file. Use this project to create an identity broker or OpenID discovery service. - [Agama PW](https://gluu.org/agama/agama-pw/) - Overview and Demo of Gluu’s Agama OpenID project, for connecting to external OpenID Providers. I show an out-of-the-box configuration where you just list the external providers in a JSON configuration file. Use this project to create an identity broker or OpenID discovery service. - [Forgot-PW / Registration](https://gluu.org/agama/agama-smtp/) - Welcome to Agama Project of the Week! In this video, I, Mike Schwartz, founder of Gluu, will be discussing Agama SMTP, a project governed by Glu and published under the Apache 2 license. I’ll provide an overview of the project, demonstrate how to open it in the Agama orchestrator, and explain the main flow and its three subflows. - [SecurityKey](https://gluu.org/agama/securitykey/) - This video focuses on the Agama Security Key project, which involves a physical USB device, also known as a FIDO token, used for authentication. Users simply plug in or tap their security key to verify their identity, enhancing security and resisting phishing attacks for online accounts. I'll guide you through integrating Security Key authentication into your apps. Let's explore the Agama Security Key project together! - [Agama Hellō](https://gluu.org/agama/agama-hello/) - In this video, I will be discussing Agama Hello, a fascinating Agama Project that allows you to integrate Hanno co-op's social integration services into your authentication journey. I will explain how Agama Hello enables the seamless integration of authentication flows from different Agama Projects, allowing you to build complex authentication journeys without starting from scratch. - [Agama Flow](https://gluu.org/agama/agama-flow/) - Agama is a framework that consists of: A DSL (domain-specific language) purposedly designed for writing web flows. A set of rules that drive the behavior of such flows when they are executed - [Agama Projects](https://gluu.org/agama/projects/) - This section provides you a set of tools to create and manage agama projects. You can add one or multiple projects in one Repository. - [Log into Agama Lab](https://gluu.org/agama/log-into-agama-lab/) - Hit the above URL and you will see a page with the Sign in with GitHub button. Click on it and give access to agama-lab. Agama-Lab uses your repository to store projects and flows. - [Project Orchestration](https://gluu.org/agama/project-orchestration/) - This section provides you a set of tools to manage projects' flows, web template pages, java code file, and other project assets. - [3 OpenID Tricks on How to Author Bespoke Identity Journeys with Low Code and Agama](https://gluu.org/agama/3-openid-tricks-on-how-to-author-bespoke-identity-journeys-with-low-code-and-agama/) - Is your login or registration flow an identity special flower? Now it’s easier then ever - [Publish Agama Project And Register To The Explore Catalog](https://gluu.org/agama/publish-agama-project-and-register-to-the-explore-catalog/) - You need it only when you are planning to add your project to explore catalog so that community can use your agama flow and add your security rules easily. ## Office Episodes - [Episode 100: Is TBAC the Next Big Thing?](https://gluu.org/office-episodes/episode-100-is-tbac-the-next-big-thing/) - The number of JWT tokens out there is rapidly expanding. Beyond traditional federation tokens, like OAuth access tokens, and OpenID identity assertions, there is whole new category of "decentralized tokens", i.e. verifiable credentials, with myriad issuers and potential ecosystem schemas. We are also seeing JWTs issued by platforms like Google to attest to the integrity of mobile software installed on a device. FIDO is defining JWT attestations about the security of authenticators (how is the key stored?). Tokens are used by federations to convey trust, for example the JWTs issued by open banking federations to fintech companies. The pace is not slowing down. The WIMSE working group at the IETF is likely to introduce several new tokens for workload identity. And another draft at the IETF called "transaction tokens" is enabling enteprises to embed business-specific details into tokens. How are access control models going to evolve to address this new important input to policies? There is one inevitable conclusion: person-centric access control models like RBAC can solve an increasingly smaller subset of the access control challenges enterprises are facing. In this 100th episode, we'll discuss if a new solution has presented itself: Token Based Access Control. Does TBAC offer enterprises a way to implement continuous authentication and just in time access control for both humans and workloads across a range of mobile, cloud, and even disconnected applications? And if so, what would be the impact on how enterprises need to think about access control in the post token-explosion world we are living in? - [Episode 98: Eclipse Decentralized Claims Protocol](https://gluu.org/office-episodes/episode-98-eclipse-decentralized-claims-protocol/) - The Eclipse Decentralized Claims specification defines "Dataspaces" which enable participants to secure data access using credentials associated with an identity. The specification defines a set of protocols for asserting participant identities, issuing verifiable credentials, and presenting verifiable credentials using a decentralized architecture for verification and trust. Is this an example of TBAC? Join the discussion to find out! - [Episode 99: OpenID Provider Commands: New JWT Tokens for RP Acct Mgt](https://gluu.org/office-episodes/episode-99-openid-provider-commands-new-jwt-tokens-for-rp-acct-mgt/) - "OpenID Provider Commands" is a new proposed protocol via Dick Hardt and Karl McGuinness which introduces a mechanism for delivering backchannel "command tokens" (a JWT) that allows an OpenID Provider (OP) to send the following messages to an OpenID Relying Party (RP): 🔑 Activate an account 🔄 Maintain an account ⏸️ Suspend an account 🔓 Reactivate an account 📦 Archive an account ♻️ Restore an account ❌ Delete an account 🚫 Unauthorize an account In this episode we'll hear from the authors why they think this new protocol is needed, and why their solution is the right design for the Internet. - [Episode 97: Patterns and Anti-patterns in Privileged Access Management (PAM)](https://gluu.org/office-episodes/episode-97-patterns-and-anti-patterns-in-privileged-access-management-pam/) - Managing privileged access is one of the most critical aspects of cybersecurity, yet organizations often struggle with implementing it effectively. In this episode of Identerati Office Hours, we’re joined by Rainer Hörbe, Senior Manager at KPMG, to explore the key patterns and anti-patterns in Privileged Access Management (PAM). We’ll discuss: 🔹 Common PAM pitfalls and how to avoid them 🔹 Best practices for securing privileged accounts 🔹 Strategies for balancing security, usability, and compliance 🔹 Real-world insights on what works—and what doesn’t—in PAM Join us for a deep dive into the do’s and don’ts of PAM with one of the industry’s leading experts. Whether you're designing a PAM strategy or optimizing an existing one, this session will provide actionable takeaways to strengthen your security posture. - [Episode 91: Powering Continuous Identity with OAuth and OpenID](https://gluu.org/office-episodes/episode-91-powering-continuous-identity-with-oauth-and-openid-2/) - Continuous identity requires new enterprise infrastructure to publish events related to a login session and token lifecycle. One solution could be Shared Signals Transmitters (SSTs) based on the OpenID Shared Signals Framework (SSF) and the Continuous Access Evaluation Protocol (CAEP). Another solution could leverage recent OAuth drafts for global token revocation and OAuth Status List JWTs. Join us as we discuss why continuous identity is the future and if it fits into a token based access control model. - [Episode 93: Is TBAC the Future? Gluu, SGNL & Strata Weigh In](https://gluu.org/office-episodes/episode-93-is-tbac-the-future-gluu-sgnl-strata-weigh-in/) - TBAC is a new access control model that leverages the rich context encoded in tokens, such as JWTs, to make dynamic, fine-grained access decisions. Unlike existing models like RBAC, ABAC, or ReBAC, which rely on roles, attributes, or relationships, TBAC evaluates access based on the information embedded in a bundle of tokens, providing unparalleled flexibility and contextual awareness. But is a new access control model needed? Is TBAC a re-hashing of other access control models, like ABAC or PBAC? Can tokens contain the context necessary to make decisions without access to other data sources? Could enterprises implement "Zero Standing Priviledge" using a TBAC approach? In this episode of Identerati Office Hours, three of the leaders in modern enterprise identity will discuss the merits of TBAC and the arguments for and against the approach. - [Episode 96: iShare: Bringing Trust to Data with JWT-Based Access](https://gluu.org/office-episodes/episode-96-ishare-bringing-trust-to-data-with-jwt-based-access/) - The iShare ecosystems have been leveraging Token-Based Access Control (TBAC) for years to address the complex challenges of secure and seamless data sharing across enterprise boundaries within the European Union. This innovative framework enables organizations to establish trust, enforce fine-grained access policies, and ensure compliance while facilitating interoperability between different entities. Join this discussion to gain insights into how iShare’s approach works, the benefits it offers for cross-organizational data exchange, and how it compares to other access control models. Whether you're a security professional, developer, or business leader, this session will provide valuable knowledge on the future of data sovereignty and access management in the EU. - [Episode 91: Powering Continuous Identity with OAuth and OpenID](https://gluu.org/office-episodes/episode-91-powering-continuous-identity-with-oauth-and-openid/) - Continuous identity requires new enterprise infrastructure to publish events related to a login session and token lifecycle. One solution could be Shared Signals Transmitters (SSTs) based on the OpenID Shared Signals Framework (SSF) and the Continuous Access Evaluation Protocol (CAEP). Another solution could leverage recent OAuth drafts for global token revocation and OAuth Status List JWTs. Join us as we discuss why continuous identity is the future and if it fits into a token based access control model. - [Episode 95: Are JWTs bad for authz?](https://gluu.org/office-episodes/episode-95-are-jwts-bad-for-authz/) - Relying on data in token claims for authorization is a slippery slope that can lead to unexpected failures and painful debugging sessions. JWT bloat—caused by excessive claims—can run into header size limitations, triggering intermittent outages due to constraints on proxies, load balancers, and firewalls. Beyond sheer size, data encoding schemes introduce additional complexity, especially when dealing with binary-encoded claim values. Dynamic claims in tokens can also risk inconsistency if not handled properly. And then there's the issue of revocation. In this episode, we’ll break down the hidden dangers of overloading JWTs, consider real-world horror stories, and discuss best practices for keeping your tokens lean or when you should consider reference tokens instead. - [Episode 94: The IPSIE Standard: A New Era of Identity Interoperability](https://gluu.org/office-episodes/episode-94-the-ipsie-standard-a-new-era-of-identity-interoperability/) - IPSIE (pronounced "ip-see") stands for Interoperability Profiling for Secure Identity in the Enterprise. Its mission is to develop interoperability and security profiles of existing specifications. The current situation is that the enterprise deployments of OpenID, OAuth, passkeys and other identity technologies are so varied, two implementations are NOT guaranteed to work together. For example, is it acr or amr that shows how the user was authenticated? Can re-usable IPSIE profiles enable much sought after IT consolidation? In this epsiode with working group contributors... we'll see! - [Episode 92: Tracking Identity Threats Before They Track You](https://gluu.org/office-episodes/episode-92-tracking-identity-threats-before-they-track-you/) - As identity-based attacks grow more sophisticated, traditional IAM solutions need a boost. In this episode of Identerati Office Hours, we dive into Identity Threat Detection & Response (ITDR)—a critical enhancement for modern IAM strategies. How can ITDR go beyond access management to detect, mitigate, and respond to identity threats in real-time? Will a ITDR become essential for security teams to stay ahead of evolving threats? Tune into this IOH episode to learn more! - [Episode 90: The Ecosystem Driving MOSIP’s Mission](https://gluu.org/office-episodes/episode-90-the-ecosystem-driving-mosips-mission/) - MOSIP requires a foundation of complementary technologies and human expertise--no one company or firm can deploy robust digital public infrastructure for a nation. In this episode, we'll explore how MOSIP is building an ecosystem of software vendors, infrastructure providers, IT integrators, custom development firms, and other domain experts who provide the business, legal and cloud technology capable of delivering their solution to diverse markets. We'll also discuss how this collaborative approach positions nations to expand MOSIP’s reach by linking identity credentials to critical public and private services. - [Episode 89: Detecting and Correcting API Drift](https://gluu.org/office-episodes/episode-89-detecting-and-correcting-api-drift/) - APIs are the lifeblood of modern digital ecosystems, driving 80% of internet traffic and enabling seamless integration between applications, services, and devices. The gap between API specifications and production behavior—known as "API drift"—is a major source of inefficiency and friction in the API ecosystem. Drawing insights from APIContext's recent white paper, this discussion will explore the state of API specifications, their critical role in ensuring interoperability, and why keeping them up-to-date and accurate is essential for robust API governance. Join us for Identerati Office Hours to uncover insights on: 🚀 The Role of APIs: Powering 80% of all internet traffic, APIs are the backbone of modern digital applications. 📉 The Problem of API Drift: 25% of APIs don't conform to their specifications. What is the impact to performance and reliability? 🛠️ Best Practices for API Governance: Explore actionable strategies to mitigate API drift, from publishing clear OpenAPI Specifications to proactive monitoring. 🤖 Agentic AI: Amplifying API Drift: The rise of autonomous AI agents adds a new layer of complexity to the existing challenge of API drift. Managing agent interactions and ensuring they adhere to evolving API specifications makes maintaining accuracy and preventing drift even more critical. - [Episode 88: Rethink AuthZ: Immutable, Versionable Auth* Models & Trusted Delegation](https://gluu.org/office-episodes/episode-88-rethink-authz-immutable-versionable-auth-models-trusted-delegation/) - ZTAuth* redefines authentication, authorization, and trusted delegation to address the challenges of disconnected systems in edge and IoT environments. By leveraging transferable, versionable, and resilient models, it aligns with Zero Trust principles while embracing CAP theorem constraints and eventual consistency. PermGuard is actively implementing this architecture to deliver scalable and secure policy-driven solutions for distributed systems. The Permguard Auth* Provider allows enterprises to specify who or what can access resources by the means of fine-grained permissions: Who: Identities (Users and Actors) authenticated in the application Can Access: Permissions granted by attaching policies Resources: Resources targeted by permissions Developers use implement the Permguard Policy Enforcement Point using available SDKs, and call the PermGuard Authorization API, sending the principal with its JWT token--to protect against types of attacks such as: Authorization Inference Attack Excessive Data Exposure Side-Channel Attack on Authorization Privilege Escalation Passing the token JWT in the PDP authorization request can avoid sharing information with the PEP, adding a mechanism for trusted delegation. The Permguard PDP can run as a "remote service" or a "proximity service", the latter of which achieves low network latency by operating on an eventual consistent basis for policies. In this livestream, we'll discuss PermGuard and how why systems like this are causing enterprises to re-think authorization. - [Episode 87: Why Identity Orchestration Matters](https://gluu.org/office-episodes/episode-87-why-identity-orchestration-matters/) - OpenID for Verifiable Presentations (OpenID4VP) is an implementers draft specification that defines a mechanism on top of OAuth that enables presentation of Verifiable Credentials (in any format) as Verifiable Presentations. Kristina, Torsten and others have been presenting OpenID4VP at conferences and IIWs for years. Where is it now? What can we expect in 2025? What is the feedback from early adopters? Join us for this discussion, and bring your own questions for two of the spec authors. - [Episode 86: OpenID for Verifiable Credentials Update](https://gluu.org/office-episodes/episode-86-openid-for-verifiable-credentials-update/) - OpenID for Verifiable Presentations (OpenID4VP) is an implementers draft specification that defines a mechanism on top of OAuth that enables presentation of Verifiable Credentials (in any format) as Verifiable Presentations. Kristina, Torsten and others have been presenting OpenID4VP at conferences and IIWs for years. Where is it now? What can we expect in 2025? What is the feedback from early adopters? Join us for this discussion, and bring your own questions for two of the spec authors. - [Episode 82: Achieving Standard DID Methods](https://gluu.org/office-episodes/episode-82-achieving-standard-did-methods/) - Decentralized Identifiers (DIDs) promise to reshape the digital identity landscape, empowering individuals and organizations with greater security, privacy, and control. Join us for a discussion with Daniel Buchner, a leading innovator in decentralized identity and former Microsoft executive, as he delves into the topic of "Achieving Standard DID Methods." We'll discuss the technical and organizational hurdles to interoperability, and learn how open standards and collaboration across the ecosystem are driving the adoption of decentralized identity. - [Episode 81: OAuth Status List and Attestation-Based Client Authentication](https://gluu.org/office-episodes/episode-81-oauth-status-list-and-attestation-based-client-authentication/) - In SAML, the entityID identifier is used for both IDPs and RPs. But in OpenID Connect, there is no stable identifier for the RP. This has become problematic for verifiable credential presentation. One solution is to enable the client to assert their identity, via an attestation. Oversight? Feature? Either way, it's going to be really helpful! We're going to save a few minutes at the end to talk about a new draft OAuth standard for Status Lists, which is like a more efficient "certificate revocation list" design to revoke JWT tokens. Clients should verify not only the signature, but also the status of the token--just like we check for revocation of X.509 certificates. - [Episode 80: Introducing Ayra](https://gluu.org/office-episodes/episode-80-introducing-ayra/) - The Ayra Association is a new Swiss nonprofit association that will serve as the governing body for the Ayra Trust Network, which is a "trust network of trust networks". The first trust networks are seeking to exchange and verify digital credentials. other "trust clusters" are forming in financial services, workforce credentials, supply chain, personhood credentials, and organizational ID. Join us for a discussion on this new network and how you can maybe even trust cluster your federation! - [Episode 79: Authorization for the Modern Enterprise - Reschedule](https://gluu.org/office-episodes/episode-79-authorization-for-the-modern-enterprise-reschedule/) - PlainID’s strengths lie in its ability to centralize and simplify policy management--enforcement, visibility, discovery, authoring, lifecycle management, consistency validation, and governance. This unified approach enables granular control of how identities access data and resources. Join us for a conversation with Gal Helemsky, co-founder and CTO of PlainID, as we explore the future of authorization in today’s complex enterprise environments. - [Episode 78: The 2025 NHI Cybersecurity Landscape](https://gluu.org/office-episodes/episode-78-the-2025-nhi-cybersecurity-landscape/) - Beware the threat of unmanaged Non-Human Identity! Join us for a discussion on what you need to know to survive the coming apocolyptic reckoning of unconstrained machine access! 🧑‍💻 What are Non-Human Identities ⏰ Why Now – Why Should You Be Concerned ♻️ Key Lifecycles Processes for managing NHI Risks ⚖️ Regulatory Perspective 📏 Standards e..g SPIFFE/SPIRE, WIMSE ... 📊 The NHI Market 🔮 2025 Outlook and Predictions - [Episode 77: How Cedar Simplifies Authz for Developers](https://gluu.org/office-episodes/episode-77-how-cedar-simplifies-authz-for-developers/) - "Ergonomic syntax" was a core design requirement of the Cedar language. In plain English, that means Cedar should be intutitive for developers to express complex access rules... and hopefully fun! By mapping easily to the application model, Cedar entites and resources integrate seamlessly with modern applications. Join us as we unpack Cedar’s core features and discuss how it empowers developers to deliver robust, secure authorization solutions without getting lost in complicated policy logic. - [Episode 76: The Future of IGA](https://gluu.org/office-episodes/episode-76-the-future-of-iga/) - 🚀 Join us for the first Identerati Office Hours Livestream of 2025 🎆 , as we dive into the Future of Identity Governance and Administration (IGA)! We're thrilled to host identerati Radovan Semančík , Slávek Licehammer of Evolveum and André Koot of SonicBee for discussions on the IGA trends shaping the industry, and strategies to future-proof your identity governance program. - [Episode 75: Trinsic's pivot from SSI to identity acceptance](https://gluu.org/office-episodes/episode-75-trinsics-pivot-from-ssi-to-identity-acceptance/) - SSI adoption has been slow for years. Trinsic has iterated a great deal in the space and settled on a new business model in identity acceptance. Riley will walk us through lessons learned and how it led them to disrupt the identity verification market. - [Episode 74: Cedarling Launch](https://gluu.org/office-episodes/episode-74-cedarling-launch/) - It's been a long journey, but the first commercial release of Cedarling is finally here! Join Mike and Mike for a quick tour and demonstration of the Cedarling! - [Episode 73: The Future of AuthZ, from A to Z](https://gluu.org/office-episodes/episode-73-the-future-of-authz-from-a-to-z/) - Summarizing lessons learned from a year of editing the free weekly AuthZ.substack.com newsletter, and my personal thoughts on the future of DecentIAM.com, this talk tackles • Why will we need AuthZ? • What problems will it solve? • How soon will it be adopted? - [Episode 72: Intro to MOSIP for foundational national identity](https://gluu.org/office-episodes/episode-72-intro-to-mosip-for-foundational-national-identity/) - The Gates Foundation and other donors are funding the open source MOSIP platform to provide some of the tools nations need to build a foundational identity system--a key enabler for digital public infrastructure. Making a foundational identity offering accessible in nations with significant ethnic and regional diversity is especially challenging. This discussion will introduce some of the basic features of MOSIP and how it's used as part of Ethiopia's National ID program. - [Episode 71: ConnectID – one year on](https://gluu.org/office-episodes/episode-71-connectid-one-year-on/) - Building a new ecosystem is not for a faint hearted but it is possible if you work with the industry, international standards bodies, and global identity community. The conversation will cover what worked and what didn’t; what is next for ConnectID? - [Episode 70: Removing Cloud Providers From the Zero Trust Equation](https://gluu.org/office-episodes/episode-70-removing-cloud-providers-from-the-zero-trust-equation/) - SPIFFE is a framework to generate identities for software systems in dynamic and heterogeneous environments. SPIFFE Verifiable Identity Documents (SVIDs) enable us to be explicit about the trust we place in systems. However, the degree of trust we can place in SVIDs relies heavily on the soundness of the data gathering and verification process during node attestation. By leveraging confidential computing technologies, specifically Confidential Virtual Machines (CVMs) we can track platform information directly in hardware, including firmware, boot loader, and kernel images, which are then signed with a key rooted inside the CPU itself. By incorporating hardware-protected platform information directly into the SVID generation process, we can significantly enhance the confidence placed in the resulting identity documents. Additionally, consumers of these SVIDs will be able to assert these properties before placing trust in a system. - [Episode 68: UN and OpenWallet Digital Public Infrastructure Collaboration](https://gluu.org/office-episodes/episode-68-un-and-openwallet-digital-public-infrastructure-collaboration/) - The UN sees public sector adoption of open source software as playing a key role in governments’ digital transformation. The OpenWallet Forum, building on the success of the OpenWallet Foundation, will offer a platform for multistakeholder cooperation to integrate wide-ranging requirements from governments and companies into coordinated policies and technical standards for digital wallets. The forum will also be supported by the UN International Computing Centre (UNICC) and the Government of Switzerland. - [Episode 67: Unraveling the 6Ws of Identity Security with ObserveID](https://gluu.org/office-episodes/episode-67-unraveling-the-6ws-of-identity-security-with-observeid/) - Traditionally, identity security has primarily focused on addressing three of the six Ws – Who, What, and Why. However, ObserveID takes identity security to the next level by delving into the When’s, the Where’s, and the What’s. By considering not just “Who” has access and “What” actions they perform, but also “When” these actions occur and “Where” they take place, ObserveID employs a comprehensive approach that significantly reduces the surface attack area and enhances overall security. This thorough examination of the timing, location, and specific activities associated with user identities enables a more precise and dynamic implementation of access control and monitoring, strengthening an organization’s defenses against both external and internal threats, and ensuring a more resilient and adaptive security posture. - [Episode 66: Demystifying Non-Human Identity Management](https://gluu.org/office-episodes/episode-66-demystifying-non-human-identity-management/) - In today’s digital landscape, the rise of Cloud, SaaS, Generative AI, and data-driven automation has led to the proliferation of Non-Human Identities (NHIs) within organizations. These digital entities—such as service accounts, access keys, and API tokens—play a crucial role in driving business operations, but also introduce a growing attack vector. Mismanaged NHIs have contributed to 85% of security breaches, including ransomware attacks, where weak NHIs are exploited to access critical data. Organizations need an enterprise-wide Non-Human Identity strategy, without which they risk exposing themselves to security breaches or outages originating from inefficient administration of NHIs. Join the conversation to discuss best practices for discovering, securing, and managing the Non-Human Identities in your environment. - [Episode 65: Improving bank mobile security](https://gluu.org/office-episodes/episode-65-improving-bank-mobile-security/) - Identerati are excited about the potential for EU identity wallets. But less obvious is what the proponents intend to do to enable PAYMENTS. Identity and payments have different functional requirements, making it challenging creating a "unified" standard without ending up with an unimplementable "frankenwallet". This episode will discuss an idea for a different kind of Payment Authorization Wallet, uniquely targeting payments, that it is based on Deterministically Encoded CBOR rather than JSON. - [Episode 64: Amazon's Cedar Open Source Strategy](https://gluu.org/office-episodes/episode-64-amazons-cedar-open-source-strategy/) - Amazon released Cedar as an open source project on May 10, 2023. Why? The open source strategy will shed light on what AWS is expecting to accomplish with Cedar. Are they expecting open source contributions? Does AWS believe open source will increase the rate of developer adoption? Why did AWS chose to open source both the policy syntax and the Engines (Rust, Java, Go). Why choose the Apache 2.0 license? What was the business case the Cedar team made to AWS management? What are some of the metrics that AWS will use to measure the success of Cedar adoption? What other open source projects does Cedar resemble at AWS? Join this episode for a deep dive into the Cedar open source strategy! - [Episode 63: Beyond Whack-a-Mole: Future-Proof Against Tomorrow's Threats](https://gluu.org/office-episodes/episode-63-beyond-whack-a-mole-future-proof-against-tomorrows-threats/) - Heather Vescent takes us beyond the endless game of reactive cybersecurity—whack-a-mole style—to understand how strategic foresight can future-proof against tomorrow’s threats. Discover how to shift from a defensive stance to an anticipatory strategy that stays ahead of emerging dangers. Learn how to outsmart future threats before they hit your systems. - [Episode 62: Reflecting on FIDO's evolution to passkeys](https://gluu.org/office-episodes/episode-62-reflecting-on-fidos-evolution-to-passkeys/) - What were passkeys before 2022? What are the passkeys today? What is missing? - [Episode 59: Product Manager Strategies for Trust and Safety](https://gluu.org/office-episodes/episode-59-product-manager-strategies-for-trust-and-safety/) - When it comes to preventing bad actions on online platforms, the goals are different. Priorities are set... and then change. And measuring success is often "inverted". What are tactics that accomodate these differences to enable trust and safety issues on a platform? How can product owners or similar leadership roles support these differences? - [Episode 58: Corporate Wallets](https://gluu.org/office-episodes/episode-58-corporate-wallets/) - Will your future business leverage decentralized identities to issue credentials to authorize its workforce to transact? Is federated identity enough, or is this a use case for decentralized identity? How does a business even assert a legal identity? What new tools and rules are needed to minimize the transaction costs of inter-domain trust? In this episode, we'll discuss if a "Corporate Wallet" is a key enabler for digital transformation for both an organization's workforce and its end-users. - [Episode 57: Latest developments in DIDs](https://gluu.org/office-episodes/episode-57-latest-developments-in-dids/) - Decentralied Identifiers (DIDs) are being used in numerous digital identity projects around the world and serve as the basis for Verifiable Credentials (VC) and many other technical specifications and protocols. At W3C, a new DID Working Group has been launched to update and expand on the existing DID standard. Let's take a look at the current state and recent developments around DIDs! - [Episode 56: How modern AuthZ will change banking](https://gluu.org/office-episodes/episode-56-how-modern-authz-will-change-banking/) - Banking has many security challenges: privacy, regulatory compliance, MFA, third-party vendor threats, insider threats, api security, cloud security, incident response and breach management. What can we learn from how banks are adapting to this new security landscape by supporting central policy management? What are the concerns and unique challenges that are driving the momentum to externalize application security policies? And how has their current strategy worked out so far? - [Episode 55: X.509 Certificate Rotation: Why TLS is still a pain point](https://gluu.org/office-episodes/episode-55-x-509-certificate-rotation-why-tls-is-still-a-pain-point/) - Anchor is a developer-friendly platform that provides private CAs for internal TLS encryption. Anchor strives to make HTTPS certificates easy to get on your servers and offers a seamless ACME flow, which allows developers to focus on building rather than managing security. In this livestream we'll discuss: How Anchor is changing the game for developers with its innovative approach to internal CA provisioning. The evolution of certificate management and why internal TLS is still a pain point. Insights from his days at GitHub, Cloudflare, and Heroku — from certificate rotations to back-end encryption. How to integrate strong encryption and certificate management into your development workflow. - [Episode 54: Jumping the Decentralized Identity S Curve](https://gluu.org/office-episodes/episode-54-jumping-the-decentralized-identity-s-curve/) - There are a lot of promises in the market around decentralized identities with enterprises beginning to embrace digital wallets, DIDs and VCs. But the challenge still exists for users moving to new or shared devices that they have not previously registered. How do we account for those scenarios – without bootstrapping trust based on another trusted device, token or password? This is the core challenge Dr. Tina Srivastava, Cofounder of privacy tech company Badge has been working on solving with a team of MIT cryptography PhDs at a privacy company called Badge. Dr. Srivastava is a serial cybersecurity entrepreneur and the former Chief Engineer at Raytheon. Dr. Srivastava is excited to discuss the blueprint for how identity vendors and enterprises can effectively jump the identity S curve. - [Episode 53: ID Transformer: Okta to Ping in 45 Days](https://gluu.org/office-episodes/episode-53-id-transformer-okta-to-ping-in-45-days/) - Migrating from one enterprise IDP to another is always a big challenge. Normally, its a project that takes months of planning. So when a renown boutique identity intergrator like Hub City says they've gotten such a migration down to 45 days... it's worth it to hear how they accomplish this! - [Episode 52: Canada's 103-1 Digital Trust and Identity Certification](https://gluu.org/office-episodes/episode-52-canadas-103-1-digital-trust-and-identity-certification/) - While identity and risk can be largely mitigated by default in the physical world through closed and fragmented systems, established standards, and regulatory safeguards, the same cannot be said in an online world. In the absence of a national standard, public and private sector organizations are continuing to rely on organization-specific, vendor-driven and ad-hoc document-based identity management processes, impacting integrity, security, privacy, trust, and service delivery Canada's 103-1 Digital Trust and Identity Standard specifies minimum requirements and a set of controls for developing, implementing, operating, monitoring, and governing trust in systems and services that consume and assert digital identity within and between organizations. The requirements in the standard ensure that digital systems and services are safe, secure, reliable, and protected. It has a super-detailed assessment process, and several juristications have been certified. What is it? And how can those outside of Canada benefit from the work? - [Episode 51: Digital Insanity: Flexibility of NIST Digital Identity Assurance Levels](https://gluu.org/office-episodes/episode-51-digital-insanity-flexibility-of-nist-digital-identity-assurance-levels/) - NIST Special Publication 800-63-3 base volume is all about digital identity risk management including conducting a risk assessment. How do you conduct a digital identity risk assessment? Tune into this episode of the identerati office hours to learn everything you need to know. - [Episode 50: Universal Online Identification](https://gluu.org/office-episodes/episode-50-universal-online-identification/) - There is no safe haven of anonymity for internet users. Users are being universally identified for marketing purposes as a matter of practice. Identity resolution and customer data platforms are the evil twin of identity and access management. These are mature industries that are highly interconnected with hundreds of publishers (i.e. brands) AND amongst themselves. Moreover, nearly 40% of companies that perform identity resolution are registered data brokers. There's insufficient awareness and regulatory oversight of these industries, and privacy policies are inadequate to explain the worldwide networks of marketing entities sharing and selling user data. Why is privacy important, why is it so hard to be private in the digital world, what can you do to maintain a little privacy and how is AI making it even harder! - [Episode 49: Latest News on EU Wallet Initiatives](https://gluu.org/office-episodes/episode-49-latest-news-on-eu-wallet-initiatives/) - Currently, the EU Digital Wallet Consortium (EWC) is testing digital wallets across four critical scenarios: 🔹 Payment Use Cases 🔹 Completing a Flight Online Check-In 🔹 Buying a Ticket for a Tourist Tour 🔹 Purchasing a Domestic Ferry Ticket The idea is that citizens will present verifiable credentail presentation from their wallet, presumably online. Where does this effort fit into the other EU initiatives, pilots and organizations. What are the currently anticipated gaps in the technology, business and legal landscape that would present challenges to scale the EU wallet identity ecosystem? And where should identerati go to stay current on progress? - [Episode 48: Apache Fortress: ANSI RBAC with OpenLDAP](https://gluu.org/office-episodes/episode-48-apache-fortress-ansi-rbac-with-openldap/) - RBAC is battle tested. Its properties and limitations are well understood. It aligns perfectly with existing enterprise security governance tools. Join us for a deep dive into Apache Fortress, a Java framework which implements ANSI RBAC and leverages OpenLDAP for persistence. In this livestream, we'll explore the architecture of Apache Fortress and discuss how enterprises can use it develop applications that align with centralized access management controls. And we'll consider RBAC's history: what have we learned? - [Episode 47: Is IAM asleep at the wheel?](https://gluu.org/office-episodes/episode-47-is-iam-asleep-at-the-wheel/) - In the past year AI has hit center stage - the tech world is talking about the future potential and organizations are implementing first projects. But the identity world…crickets! In this chat we will discuss the biggest opportunity no one is talking about - the importance of trustworthy and secure data for the AI revolution. Join us as we challenge the industry to think beyond their typical silos and become active participants in the future of enterprise. - [Episode 46: Multi-layer authz? Yes please!](https://gluu.org/office-episodes/episode-46-multi-layer-authz-yes-please/) - Q: Where should you enforce your authorization policy? A: Everywhere you can! There are four common scenarios and enforcement points for a defense-in-depth strategy: ⚡ during the authentication ceremony ⚡ in the resource server ⚡ at the API gateway ⚡ in service-to-service communication - [Episode 45: Intro to the Cedarling](https://gluu.org/office-episodes/episode-45-intro-to-the-cedarling/) - Cedar is a policy syntax invented by Amazon. It's used by the AWS Verified Permissions, Authz-as-a-Service offering. Gluu is working on a new product at the Janssen Project called the "Cedarling"--which leverages the Cedar policy syntax and Amazon's open source Cedar Rust engine. The Cedarling can run anywhere--as a local agent in the browser, embedded in a mobile application, or as a cloud service. It needs no data, because it trusts the JWT tokens that are input to the request by the application. Beyond policy evaluation, the Cedarlng agent has two other capabilities: JWT validation and audit logging. In this episode, Mike will present Gluu's current progress on the Cedarling and show a demo of the Cedarling in action! - [Episode 44: Securing identity and context in microservices](https://gluu.org/office-episodes/episode-44-securing-identity-and-context-in-microservices/) - Defending against privileged user compromise and software supply chain attacks requires newer standards that can reduce the trust in non-human (or machine) identities used by services to communicate with each other. Transaction tokens is a new proposed standard in the IETF which can effectively defend against these attacks. Learn all about it in this episode with Atul Tulshibagwale, CTO of SGNL, the inventor of CAEP and an Okta Identity 25 Listee. - [Episode 43: Intersection of IAM with cloud](https://gluu.org/office-episodes/episode-43-intersection-of-iam-with-cloud/) - Managing IAM for your own users and employees is hard enough, and with the adoption of cloud (including SaaS) it’s only getting harder. Especially when you consider the addition of 3rd parties into the mix, such as contractors, BPOs, MSPs and other kinds of vendors. In this podcast we’ll discuss the intersection of IAM with cloud (with a particular discussion of AWS cross-account access and the Snowflake incident) and with Third Party Cyber Risk Management in general. - [Episode 41: National ID Challenges](https://gluu.org/office-episodes/episode-41-national-id-challenges/) - What are the priorities and tradeoffs of certain approaches to building a national identity infrastructure? How can you build a system that enables people to assert their identity and claims, and also protects their privacy ? What are the most pressing use cases? Voting? Healthcare? Opening bank account ? Other private sector RPs? How to balance the tradeoffs of privacy, fraud reduction, and poverty reduction presented by a system like Aadhaar. Do Verifiable Credentials offer a "leapfrog opportunity"? What to put on the blockchain (if anything) ? What did Singpass get right in Singapore ? Whether to engage with the 50-in-5 initiative, DPGA, or Govstack Sovereignty vs availability ? Accessibility v. progress ? - [Episode 40: You got the JWT... now what?](https://gluu.org/office-episodes/episode-40-you-got-the-jwt-now-what/) - Once you have obtained a JSON Web Token (JWT), the next steps involve understanding, securely storing, and effectively using it for authentication and communication within your web application. A JWT comprises three parts: the Header, Payload, and Signature. It is crucial to store the JWT securely on the client-side, often in local storage or an HTTP-only cookie, to prevent cross-site scripting (XSS) attacks. For API requests, the JWT should be included in the Authorization header using the Bearer schema. On the server-side, you must verify the token’s signature, check its expiration, and validate its claims to ensure its authenticity and relevance. Handling token expiration through refresh tokens, decoding the JWT to access user information, and protecting your endpoints with role-based access control (RBAC) are essential steps to maintain security. Additionally, monitoring and logging JWT usage are vital for auditing and troubleshooting. Proper handling of JWTs ensures the security and efficiency of your authentication processes, safeguarding your application against potential vulnerabilities. - [Episode 39: Blockchain vs. The Right To Be Forgotten - one Solution](https://gluu.org/office-episodes/episode-39-blockchain-vs-the-right-to-be-forgotten-one-solution/) - 1. Can a blockchain be made to support the many new regulations that require the “Right of Erasure”? 2. If so, how can it then remain an immutable source of truth? 3. Does a solution require a specialized blockchain or can it be applied to existing blockchains? 4. What are the issues that arise from incorporating the solution? - [Episode 37: The Rise of Browser Identity APIs](https://gluu.org/office-episodes/episode-37-the-rise-of-browser-identity-apis/) - In the last few years, there have been a number of new browser APIs proposed and implemented that assist developers to authenticate people or establish identity. This talk will discuss a few of these, like WebAuthn, WebOTP, FedCM, DBSC and the Digital Credentials API. - [Episode 38: Immortal passwords versus vulnerable humans](https://gluu.org/office-episodes/episode-38-immortal-passwords-versus-vulnerable-humans/) - Immortal Passwords refers to the concept of password practices and protocols that are designed to be incredibly secure and resistant to various forms of cyber-attacks, essentially making them 'immortal' in the face of evolving threats. These passwords typically adhere to stringent security standards, including long character lengths, a mix of symbols, numbers, and letters, and regular updates. Additionally, they are often managed through sophisticated password management systems or algorithms that can generate and store complex passwords securely. Vulnerable Humans, on the other hand, highlight the inherent weaknesses in human behaviors and practices when it comes to password security. Despite the availability of strong password guidelines, many individuals still use weak passwords, reuse passwords across multiple sites, or fail to update them regularly. This makes them susceptible to common cyber threats such as phishing, brute force attacks, and credential stuffing. - [Episode 36: Deepfakes II: BioID's Combat Strategy](https://gluu.org/office-episodes/episode-36-deepfakes-ii-bioids-combat-strategy/) - The applications for Deepfake Detection are numerous, especially as generative AI has advanced significantly. The question arises: can online media and identity verification processes still be deemed reliable? Discover methods to protect your identity and systems against impersonation and learn how to identify deepfakes on your own – or is that even possible? - [Episode 35: Next Gen Open Banking and Bank ID is beginning](https://gluu.org/office-episodes/episode-35-next-gen-open-banking-and-bank-id-is-beginning/) - The increased mobility of users and their demand for personalized, unified omnichannel access experiences has stretched federated IAM beyond its limits. Meanwhile, the need for organizations to collaborate more to compete, and build communities of trust and value for those same users affordably and securely, cannot be met by existing federated IAM solutions. Learn how banks are embracing the new paradigm of decentralized identity (DCI) to improve existing experiences and create the opportunity for new, valuable user experiences and increased levels of engagement and collaboration with business partners across multiple jurisdictions, without the need to replace their infrastructure. Simultaneously, understand why starting their journey now, enables banks to future-proof their ecosystem to rapidly support the EUDI and official digital credentials that will become available. Get a glimpse into the solution architecture being deployed at banks and an understanding of the benefits and how they can be communicated to executive leadership and business partners. Learn how DCI can also solve today’s problems in a practical way, including fighting fraud from adversarial and generative AI, and work in harmony with existing IAM systems enhancing existing federation platforms, and still set the banks up for the art of the possible tomorrow. - [Episode 34: Fear not the rise of the machines, for we have standards](https://gluu.org/office-episodes/episode-34-fear-not-the-rise-of-the-machines-for-we-have-standards-3/) - Machine identities have been proliferating, outnumbering human identities by a considerable margin. Despite often having far more privilege than humans, they remain under governed relative to user identities. In this episode we will discuss the drivers behind this rise in machine identities and the work happening in standards working groups like the Workload Identity in Multi-System Environments (WIMSE) and OAuth working groups that will help make these environments safer and more secure. - [Episode 32: No things in IGA: Considering non-human account management](https://gluu.org/office-episodes/episode-32-no-things-in-iga-considering-non-human-account-management/) - Often vendors suggest our customers to manage things--robotic process automation (RPA), service accounts, etc--in an IGA system. Naaahh, that's not how you manage those type of accounts! - [Episode 33: Consent Is Dead: How Bad Is It Really?](https://gluu.org/office-episodes/episode-33-consent-is-dead-how-bad-is-it-really/) - At EIC24, Eve laid out a case that digital consent is a fiction. How bad is the situation? How does it impact identity, security, and privacy? And do identitarians need to start getting their heads around the identity resolution industry? - [Episode 26: Shared Signals / CAEP](https://gluu.org/office-episodes/episode-26-shared-signals-caep/) - Shared Signals wants to limit the damage of compromised accounts used from one website to gain access to accounts on another website. CAEP uses the Shared Signals event framework to defines some typical events: Session Revoked, Credential Change, Assurance Level Change, Device Compliance Change, Session Established. - [Episode 24: Enhancing User Experience in First Party Native Applications](https://gluu.org/office-episodes/episode-24-enhancing-user-experience-in-first-party-native-applications/) - In native mobile applications, authentication often involves redirecting users to an external browser to complete the login process. This approach disrupts the seamless user experience that mobile app users expect. - [Episode 23: EIC 2024 Debrief](https://gluu.org/office-episodes/episode-23-eic-2024-debrief/) - Couldn't make it to "EIC" (the European Identity Conference)? Luckily Sebastian and Henk took notes for you, and we scheduled this debrief session to discuss. - [Episode 22: Debunking Misconceptions About Passkeys](https://gluu.org/office-episodes/episode-22-debunking-misconceptions-about-passkeys/) - There have been a few blog posts (and resulting social media and forum discussions) going around the past few weeks about #passkeys, mostly painting them (or organizations who have been working hard to bring passkeys to users all over the world) in a negative light. - [Episode 21: Go Beyond With AI & Identity](https://gluu.org/office-episodes/episode-21-go-beyond-with-ai-identity/) - AI represents a huge opportunity for digital identity advancement potential: proactive security for organizations, efficient workflow automation for the workforce, faster development, and a better UX for customers. - [Episode 20: Identity Governance for the Whole Enterprise](https://gluu.org/office-episodes/episode-20-identity-governance-for-the-whole-enterprise/) - Software to assist with Identity Governance, and reviewing user's access has been around for a decade. Many implementors struggle with integrating quickly and onboarding applications. - [Episode 18: Best ROI for National ID](https://gluu.org/office-episodes/episode-18-best-roi-for-national-id/) - This episode Kalyan will discuss and even demo how Bhutan rolled out foundational identity with the CREDEBL Platform. We'll also discuss the Singapore SingPass model, which enables sign-in to over 2,700+ services government and private sector websites. - [Episode 19: Continuous Authorization](https://gluu.org/office-episodes/episode-19-continuous-authorization/) - Mike has been working on a new design for distributed authorization in the Janssen Project which could enable near real-time JWT token revocation. Revoking JWTs more quickly can limit the blast area of account takeover. - [Episode 17: Agama Low Code Identity Orchestration](https://gluu.org/office-episodes/episode-17-agama-low-code-identity-orchestration/) - Agama is a domain specific language ("DSL") for identity orchestration. It's governed at the Linux Foundation Janssen Project. There is also an Agama project archive format, which is a standard way to package all the assets required by an IDP to run an Agama Project. - [Episode 16: Post Deep-Fake: Can We Stop Identity Fraud?](https://gluu.org/office-episodes/episode-16-post-deep-fake-can-we-stop-identity-fraud/) - Identity fraud is becoming big business. New web sites like OnlyFake.org (now residing under a new name) are enabling fraudsters to purchase realistic AI-generated fake IDs, and deepfake tech has advanced to the point that one facial swap tool can even manipulate selfie/ID comparisons - [Episode 15: OAuth First Party Native Authn / Global Token Revocation](https://gluu.org/office-episodes/episode-15-oauth-first-party-native-authn-global-token-revocation/) - Discussion of two emerging OAuth Specs: First Party Native Authentication and Global Token Revocation. - [Episode 13: Big Tech Can't Solve Identity Crisis](https://gluu.org/office-episodes/episode-13-big-tech-cant-solve-identity-crisis/) - How digital identity can empower consumers to build trust online, and why we can't rely on Big Tech to solve the identity crisis. - [Episode 14: What's unique about NFTs](https://gluu.org/office-episodes/episode-14-whats-unique-about-nfts/) - Do proposed decentralized identity solutions share some common patterns with Bitcoin and NFTs? - [Episode 12: SSI Beyond Identities](https://gluu.org/office-episodes/episode-12-ssi-beyond-identities/) - Did you know Self-Sovereign Identity is not only about identities? In this episode, we're going to uncover another side of SSI universe - [Episode 11: Rethinking the Rush to Policy as Code](https://gluu.org/office-episodes/episode-11-rethinking-the-rush-to-policy-as-code/) - Policy as Code (PoC) is current in vogue. This method extends the principles of Infrastructure as Code to security policies. - [Episode 10: Cerbos Deep Dive](https://gluu.org/office-episodes/episode-10-cerbos-deep-dive/) - Cerbos is a new startup in the authorization space, positioned as an authz technology for developers, product and security teams who prefer YAML over Rego. - [Episode 09: Zero Standing Priviledge](https://gluu.org/office-episodes/episode-09-zero-standing-priviledge/) - "Least privilege" is the total entitlements required to perform a job over time. - [Episode 08: "Digital Double" Discussion WS02, Gluu and Phil Windley](https://gluu.org/office-episodes/episode-08-digital-double-discussion-ws02-gluu-and-phil-windley/) - India Listeners: Our first Tuesday episode at 9:30AM IST. We're going to try to do this at least once a month! - [Episode 06: IIW 38 Live: OpenID VC Presentation](https://gluu.org/office-episodes/episode-06-iiw-38-live-openid-vc-presentation/) - IIW 38 is upon us. Mike is attending and bringing his microphones! Happening Tue during IIW Session 5. - [Episode 05: Best Practices for Client Authentication](https://gluu.org/office-episodes/episode-05-best-practices-for-client-authentication/) - In this episode, we'll dive into best practices for client authentication. Is private_key_jwt really so hard? - [Episode 04: Authz Renaissance: Why now?](https://gluu.org/office-episodes/episode-04-authz-renaissance-why-now/) - Identerati Office Hours, Episode 004: Authz: Authz Renaissance: Why now? - [Episode 03: Token Exchange Discussion with Tyk, Gluu, and Curity](https://gluu.org/office-episodes/identerati-office-hours-kubecon-token-exchange-discussion/) - Token exchange seems to be a dependable source of confusion for API developers and security architects. - [Episode 02: Is privacy possible in America without a US trust framework](https://gluu.org/office-episodes/episode-02-is-privacy-possible-in-america-without-a-us-trust-framework/) - David posits that privacy isn't safe in any digital identity architecture, and without a trust framework operating in the US, we will not implement privacy. - [Episode 01: Compare-Contrast: India Aadhaar v. United States SSN](https://gluu.org/office-episodes/episode-01-compare-contrast-india-aadhaar-v-united-states-ssn/) - IdentityWoman Kaliya Young on the topic of "Compare--Contrast: India Aadhaar v. United States SSN" - [Episode 27: Holy Grail A Physical and Logical Access Card](https://gluu.org/office-episodes/holy-grail-a-physical-and-logical-access-card/) - There are a bunch of FIDO keys in the card form factor, but most of them don't have an HID antenna to open door locks. Combining biometric and phsyical access is a game changer for physical access control--no more card sharing. - [Episode 31: The Three Wallet Problem](https://gluu.org/office-episodes/episode-31-the-three-wallet-problem/) - Decentralized identity wallets are the keys to unlocking vast potential business value. But when misaligned with user expectations, wallets become a closed valve to hold back the rising tide. The implications of the "Three Wallet Problem are profound. If you are interested in decentralized identity adoption, you won't want to miss this pivotal Identerati Office Hours episode! - [Episode 30: OpenFGA Deep Dive](https://gluu.org/office-episodes/episode-30-openfga-deep-dive/) - OpenFGA (Open Fine-Grained Authorization) is a CNCF sandbox project designed to provide scalable, fine-grained access control for applications. It is based on the Zanzibar model, originally developed by Google, which offers flexible and expressive policy management. Developers might prefer OpenFGA over other authorization solutions due to its ability to handle complex relationships and permissions with high performance and low latency, making it suitable for large-scale, real-time systems. In this episode, we'll do a deep dive on OpenFGA to help identerati understand the current state and future promise. - [Episode 29: Deploying passkeys for high-security use cases](https://gluu.org/office-episodes/episode-29-deploying-passkeys-for-high-security-use-cases/) - "Synced passkeys" offer a convenient way to authenticate across devices – similar to how consumers have learned to authenticate with passwords. For organizations with high security needs, however, the duplication of keys and lack of control when introducing new devices poses a compliance challenge. Additionally, the lack of granularity when suspending or revoking multi-device credentials adds complexity to practical implementations. The good news is that there are strategies for overcoming these challenges, making it possible for banks, fintechs, mobile network operators, and other industries with high security needs to leverage the benefits of passkeys as part of their passwordless journey." - [Episode 07: BlastRADIUS: It's time to upgrade the world.](https://gluu.org/office-episodes/episode-07-blastradius-its-time-to-upgrade-the-world/) - The recent BlastRADIUS vulnerability has hit the world by storm. The impact is that every switch, router, VPN concentrator, access point controller, etc. world-wide has to be udpated. In this podcast, we interview Alan DeKok, the founder of FreeRADIUS and InkBridge Networks. Alan is acknowledged as the world expert in the RADIUS protocol, and was the first person that contacted when the researchers found the issue. We will discuss the history of the RADIUS protocol, this issue, and what vendors and system administrators have to do in order to address the vulnerability. In short, don't panic! Listen to the podcast, and you will find out what to do. - [Episode 28: Transparency Performance Schema for Regulators](https://gluu.org/office-episodes/episode-28-transparency-performance-schema-for-regulators/) - Enterprises commonly use terms and conditions and data sharing agreements that do not legally manage consent. The "Transparency Performance Schema for Regulators" (TPS4R), developed at Kantara, is a framework designed to provide a standardized approach for enterprises to report and demonstrate their compliance with regulatory requirements related to data transparency and privacy. The schema focuses on performance metrics and transparency reporting, aiming to facilitate clear communication between enterprises and regulatory bodies. - [Episode 25: Empowering Authorization Through Data](https://gluu.org/office-episodes/episode-25-empowering-authorization-through-data/) - Authorization decisions are only as good as the data used to make them. An identity data fabric, identity data lake, or master user record pulls data from many sources, which it prioritizes by authoritative ranking by data element. - [Episode 017: Agama Low Code Identity Orchestration](https://gluu.org/office-episodes/episode-017-agama-low-code-identity-orchestration-2/) - Agama is a domain specific language ("DSL") for identity orchestration. It's governed at the Linux Foundation Janssen Project. There is also an Agama project archive format, which is a standard way to package all the assets required by an IDP to run an Agama Project. - [IIW 38](https://gluu.org/office-episodes/iiw-38/) - Restream helps you multistream & reach your audience, wherever they are. ## Categories - [News](https://gluu.org/category/news/) - [Coming Soon](https://gluu.org/category/coming-soon/) - [Opinions](https://gluu.org/category/opinions/) - [Press Releases](https://gluu.org/category/press-releases/) - [Articles](https://gluu.org/category/gluu-articles/) - [Tutorials](https://gluu.org/category/gluu-server-tutorials/) - [Featured Post](https://gluu.org/category/featured-post/) ## Tags - [2fa](https://gluu.org/tag/2fa/) - [foss](https://gluu.org/tag/foss/) - [keycloak](https://gluu.org/tag/keycloak/) - [ldap](https://gluu.org/tag/ldap/) - [linux](https://gluu.org/tag/linux/) - [open source](https://gluu.org/tag/open-source/) - [openid](https://gluu.org/tag/openid/) - [opensource](https://gluu.org/tag/opensource/) - [oss](https://gluu.org/tag/oss/) - [redhat](https://gluu.org/tag/redhat/) - [saml](https://gluu.org/tag/saml/) - [sso](https://gluu.org/tag/sso/) - [SPIFFY](https://gluu.org/tag/spiffy/) - [Mutual TLS](https://gluu.org/tag/mutual-tls/) - [mTLS](https://gluu.org/tag/mtls/) - [SPIFFE](https://gluu.org/tag/spiffe/) - [SPIRE](https://gluu.org/tag/spire/) - [Secure Production Identity Framework for Everyone](https://gluu.org/tag/secure-production-identity-framework-for-everyone/) - [SPIFFE Runtime Environment](https://gluu.org/tag/spiffe-runtime-environment/) - [X.509 client certificates](https://gluu.org/tag/x-509-client-certificates/) - [East-West service mesh](https://gluu.org/tag/east-west-service-mesh/) - [Istio](https://gluu.org/tag/istio/) - [Cilium](https://gluu.org/tag/cilium/) - [Policy enforcement](https://gluu.org/tag/policy-enforcement/) - [Cilium YAML](https://gluu.org/tag/cilium-yaml/) - [CEL policy language](https://gluu.org/tag/cel-policy-language/) - [OPA (Open Policy Agent)](https://gluu.org/tag/opa-open-policy-agent/) - [Policy Decision Points (PDP)](https://gluu.org/tag/policy-decision-points-pdp/) - [Enterprise policies](https://gluu.org/tag/enterprise-policies/) - [OAuth clients](https://gluu.org/tag/oauth-clients/) - [RFC 8705](https://gluu.org/tag/rfc-8705/) - [RFC 9449](https://gluu.org/tag/rfc-9449/) - [authentication](https://gluu.org/tag/authentication/) - [openidconnect](https://gluu.org/tag/openidconnect/) - [oauth](https://gluu.org/tag/oauth/) - [dpo](https://gluu.org/tag/dpo/) - [gluu](https://gluu.org/tag/gluu/) ## Post Categories - [Project of the Week](https://gluu.org/post-categories/project-of-the-week/) - [Blog](https://gluu.org/post-categories/blog/) - [Docs](https://gluu.org/post-categories/docs/) ## Categories - [Identerati Office Hours Episode](https://gluu.org/categories/identerati-office-hours-episode/)