Category Archives: IdentityServer

Thinktecture IdentityServer v2.2

Every now and then I take a snapshot of the current main branch and package it into a published build. It’s that time again. Have a look here for v2.2: http://thinktecture.github.io/Thinktecture.IdentityServer.v2/downloads/ The big thing for this release is certainly the … Continue reading

Posted in IdentityModel, IdentityServer, OAuth, WebAPI | Leave a comment

Authentication in AuthorizationServer

AS does not do its own authentication – that’s by design. When you download from the repo, AS is set up to be a WS-Federation relying party. In the configuration folder of the WebHost project you’ll find two config files: … Continue reading

Posted in AuthorizationServer, IdentityModel, IdentityServer, OAuth, WebAPI | 3 Comments

Relationship between IdentityServer and AuthorizationServer

We released a preview version of AuthorizationServer this week. AuthorizationServer is an implementation of the OAuth2 design pattern and helps making API authorization easier. IdentityServer also has OAuth2 endpoints – so you might ask yourself why we started from scratch … Continue reading

Posted in IdentityModel, IdentityServer, OAuth, WebAPI | 7 Comments

NDC Oslo 2013 Slides

As usual this was my favourite conference of the year! I already uploaded the slides – I will keep you posted once the videos are online as well. Securing ASP.NET Web API OAuth2 – The good, the bad & the … Continue reading

Posted in IdentityModel, IdentityServer, OAuth, WebAPI | Leave a comment

Announcing Thinktecture AuthorizationServer

Today at NDC I announced Brock’s and my new open source project – Thinktecture.AuthorizationServer. AuthorizationServer (AS from now on) is an implementation of the OAuth2 patterns I described here.It has an implementation of the four OAuth2 flows and a nice … Continue reading

Posted in Conferences & Training, IdentityModel, IdentityServer, OAuth, WebAPI | 5 Comments

OAuth2 done right

I think I mentioned once or twice that OAuth2 is not for authentication. It is rather a set of patterns for doing delegated authorization for HTTP/Web APIs using access tokens. But most people don’t use it like that. OAuth2 is … Continue reading

Posted in IdentityModel, IdentityServer, OAuth, WebAPI | 6 Comments

Update on IdentityModel and IdentityServer

Big news: the Microsoft JWT support is now generally available!. That means that I will update IdentityServer and IdentityModel ASAP (by the end of next week, or rather – after I am done with all my talks at NDC). Speaking … Continue reading

Posted in .NET Security, ASP.NET, IdentityModel, IdentityServer, OAuth, WebAPI | Leave a comment

Two Weeks to go: NDC Identity & Access Control Workshop

…really looking forward to it! http://www.ndcoslo.com/Article/Workshops/claims Also announcing a special guest: Pedro Felix will do a introduction lecture on OpenID Connect! See you there!

Posted in .NET Security, Azure, Conferences & Training, IdentityModel, IdentityServer, OAuth, WCF, WebAPI | Leave a comment

Customizing IdentityServer

IdentityServer was designed with extensibility in mind. And since the question how to do that comes up quite frequently, here’s a overview to get you started. Certain parts of IdSrv that we thought might need to be extended or customized … Continue reading

Posted in IdentityServer | 16 Comments

Web API Security: JSON Web Token/OAuth2 with Thinktecture.IdentityModel AuthenticationHandler

(OK – I only included OAuth2 in the title to get your attention – this applies to whatever framework or technology you use to work with JSON web tokens aka JWTs) Following the pattern from my two previous posts, you … Continue reading

Posted in .NET Security, IdentityModel, IdentityServer, OAuth, WebAPI | 5 Comments