Securing Web Apps with Okta: Moving from Implicit to Authorization Code Flow
Stop leaking tokens in your URLs. Learn how to implement the OIDC Authorization Code Flow with Okta to secure user identity and verify JWTs using discovery endpoints.
ReadMeFeed / Community knowledge
Real questions. Useful conversations. Find the people who know your stack.
Stop leaking tokens in your URLs. Learn how to implement the OIDC Authorization Code Flow with Okta to secure user identity and verify JWTs using discovery endpoints.
Learn how to add OAuth login with Google or GitHub, embed role claims in the JWT via Supabase Admin API, and read those claims in Edge Functions for fine‑grained access control.
Secure a backend API with Okta by validating JWTs against the Authorization Server’s JWKS, enforcing issuer, audience, and custom scopes. Follow a minimal design that uses a single AS and RS, implement caching, monitor JWKS rotation, and be ready to switch to FGA or mTLS when needed.
When implementing secure service-to-service communication in Ballerina, managing the lifecycle of access tokens is critical for maintaining least-privilege access without causing service downtime. The Constraint The ballerina/auth/oauth2 module provides mechanisms for token management, but a design trade-off exists when handling expired credentials for user-
I have an SPA application derived from the Identity Platform sample that originally calls a Graph API. I've changed the endpoint to call a local API. The SPA uses Azure AD for authentication. The API sample is derived from the VS 2019 project template for API. ,NET 4.7.2 - no .NET Core. I can authenticate OK and both ID and access tokens are present when I d
I am developing an application that is spread across multiple Function App running on .net5 . I need to authenticate HTTP calls between functions. To do so, I am using Azure Active Directory . I have created a registered application in my tenant and generated a new secret. Whenever Function1 needs to contact Function2 , I retrieve an access token from AAD, l
I am using System.IdentityModel.Tokens.Jwt package and the below code decoding the jwt token, but it won't give exp value? var handler = new JwtSecurityTokenHandler(); var decodedValue = handler.ReadJwtToken("token"); How to get exp and compare it with the current DateTime to calculate token is expired or not? Update: I am using Azure.Core.AccessToken where
Problem When I receive a JWK from Azure AD in Python, I would like to validate and decode it. I, however, keep getting the error "Signature verification failed". My Setup I have the following setup: Azure Setup In Azure I have created an app registration with the setting "Personal Microsoft accounts only". Python Setup In Python I use the MSAL package for re
It has been a nightmare. I'm facing problems to verify Azure Access Token Signature using jwt.io. Doesn't matter what I do, the answer is always an invalid signature. Could someone try to help with this, please? My Steps: I generated a Token Id and Access Token from the MSAL Java App Example (msal-java-webapp-sample). I get from my Azure Access Token the "ki