Authentication on a different device from the one you're using? π§
Learn how to implement Client-Initiated Backchannel Authentication (CIBA) in #ASPNETCore and #dotnet: duende.link/3ysz4u
Especially helpful in high-trust scenarios.
Authentication on a different device from the one you're using? π§
Learn how to implement Client-Initiated Backchannel Authentication (CIBA) in #ASPNETCore and #dotnet: duende.link/3ysz4u
Especially helpful in high-trust scenarios.
.NET 10 performance benefits everyone. By optimizing IdentityServer for the new runtime, we pass those gains down to every application that relies on us. Reduced CPU cycles in auth mean lower cloud bills for the entire community.
Learn More ποΈ duende.link/is74b0b
#aspnet #aspnetcore #dotnet
The best optimization is the one you don't write. Upgrading to .NET 10 delivers throughput gains purely through runtime improvements. Get a "free" boost by updating the package.
Learn More: duende.link/bpicb
#aspnet #dotnet
Identity is hard. Building it alone is harder. π€
Join our private Insiders Discord to talk BFF, Passkeys, and OpenTelemetry with the Duende team and senior devs worldwide. A no-fluff zone for mission-critical systems.
Apply: duende.link/insiders
The Duende Product Insiders program is our dedicated listening channel. We share early design documents and prototypes with the Duende Insiders to get honest and impactful feedback.
Help us build the solutions that empowers you and your peers.
Apply here: duende.link/insiders
Licensing isn't just legal paperwork; itβs a safety net for your team. Knowing that Duende engineers are maintaining the Identity SDK allows you to focus on what you love building.
We carry the weight of standards and compliance so you don't have to: duende.link/appmodb
#aspnet #dotnet
Content Security Policy (CSP) helps against cross-site scripting attacks! π₯·
Learn how this powerful HTTP header is your next line of defense. We break down the directives and show you how to implement them.
Watch here: youtu.be/B0Rz_qiQAWo #dotnet #securitytips
Standards evolve because people participate. Insiders help shape the roadmap. When we prototype new features, we ask the community how they fit real-world architectures.
Apply: duende.link/insiders
#aspnet #dotnet
Nothing is more frustrating than a tool that fights you. We respect your expertise. Our architecture gives you the control to build exactly what you need, without the black-box limitations that make work a headache.
We empower the security architect.
Learn more ποΈ duende.link/appmodb
#aspnet
Null exceptions are costly. We are enforcing strict Nullable Reference Types across the IdentityServer API in .NET 10. The compiler catches bugs before you deploy.
The community deserves rigorous design.
Learn More: duende.link/bpicb
#aspnet #dotnet
Should you add rate limiting to your Duende IdentityServer deployment? π€
Our new article breaks down the why (and why not), plus 3 implementation options.
Read the full article π duende.link/87wrkjh
#dotnet #ASPNETCore #OAuth #OpenIDConnect
The livestream starts NOW! π΄ Security you canβt prove isnβt security, itβs hope.
Stop relying on manual checks. Weβre showing you how to automate your security testing to ensure your API only accepts your trusted tokens.
π Join us now: duende.link/lsjwt26b
#OAuth2 #JWT #DotNet
Join our livestream in 1 HOUR! π£ JWTs are the industry standard, but are they right for your specific architecture?
Weβre breaking down the strategic trade-offs between JWTs vs. Opaque Tokens.
Be there: duende.link/lsjwt26b
#OAuth2 #JWT #DotNet
.NET 10 performance benefits everyone. By optimizing IdentityServer for the new runtime, we pass those gains down to every application that relies on us.
Reduced CPU cycles in auth mean lower cloud bills for the entire community.
Learn more: duende.link/bpicb
#aspnet #aspnetcore #dotnet
Tomorrow! Join our livestream on March 3rd.
Stop relying on manual checks. Weβre showing you how to automate your security testing to ensure your API only accepts your trusted tokens.
π March 3rd. Be there: duende.link/lsjwt26b
#OAuth2 #JWT #DotNet
Stability is a community asset. Aligning with the Microsoft LTS schedule provides a shared timeline for the industry. We can all plan, budget, and coordinate releases together.
Predictability helps the whole community function better.
Learn More: duende.link/is74b0b
#aspnet #dotnet #LTS
JWTs are the industry standard, but are they right for your specific architecture?
Weβre breaking down the strategic trade-offs between JWTs vs. Opaque Tokens.
π March 3rd. Be there: duende.link/lsjwt26b
#OAuth2 #JWT #DotNet
Expand your security lingo with our latest article on JWT (JSON Web Token), pronounced "jot"! πͺ
Learn what a JWT is, and its role in OAuth 2.0/OpenID Connect: duende.link/q2nage
#dotnet #securitylingo
Stability is a community asset. Aligning with the Microsoft LTS schedule provides a shared timeline for the industry. We can all plan, budget, and coordinate releases together.
Predictability helps the whole community function better.
Learn more: duende.link/bpicb
#aspnet #dotnet #LTS
SaaS providers are black boxes. Duende gives you full source access.
Step-through to understand exactly how it all works. ποΈ
Explore: docs.duendesoftware.com/identityserv...
#aspnet #dotnet
Identity is hard. Building it alone is harder. π€
Join our private Insiders Discord to talk BFF, Passkeys, and OpenTelemetry with the Duende team and senior devs worldwide. A no-fluff zone for mission-critical systems.
Apply: duende.link/insiders
#IdentityServer #DotNet
DPoP is not shorthand for Danish pop music. πΆ
Instead, Demonstrating Proof of Possession (DPoP) is used to fight back against token replay attacks in OpenID Connect and OAuth.
Security Lingo Explained: duende.link/lgodpop
#SecurityLingo #dotnet
Stop saying "It's probably DNS" when things go south. π§
Fix it faster, and learn why the professional networking community favors dig over nslookup for DNS troubleshooting: duende.link/y26224
#dotnet #dns
Should you blindly trust JWTs for accessing APIs? π
Youβve got OAuth 2.0 and #JWT's, but a single misconfiguration in your library can leave you wide open. Join Wesley to see why "standard" validation isn't always enough.
π Be there on March 3rd: duende.link/lsjwt26b
#OAuth2 #DotNet
Nothing is more frustrating than a tool that fights you. We respect your expertise.
Our architecture gives you the control to build exactly what you need, without the black-box limitations that make work a headache.
We empower the security architect.
Learn More: duende.link/appmodb
#aspnet
#dotnet 10 performance benefits everyone. By optimizing IdentityServer for the new runtime, we pass those gains down to every application that relies on us.
Reduced CPU cycles in auth mean lower cloud bills for the entire community.
Learn more: duende.link/is74b0b
Don't rely on status pages during an outage. Commercial licenses include priority support. π€
Direct assistance from the maintainers is a necessity for mission-critical infra.
#aspnet #dotnet
Learn More:
Stability is a community asset. Aligning with the Microsoft LTS schedule provides a shared timeline for the industry. We can all plan, budget, and coordinate releases together.
Predictability helps the whole community function better. πͺ
#aspnet #aspnetcore #dotnet
Cross-Site Scripting (XSS) is one of the most common web attacks! π₯
Learn the 3 types (Reflected, Stored, DOM-based), the main developer mistake, and how to defend your app with #ASPNETCore and proper HTML escaping.
youtu.be/Zqvw6XR9Lug #XSS #WebSecurity #dotnet
Duende Software's latest Open Source Sponsorship goes to #BenchmarkDotNet! π
It's a great project to help analyze (and maintain) performance of #dotnet code.
Check out the full post for details on the project: duende.link/o55bmd