Building OAuth from First Principles
IdentityShield Summit '25
A ground-up derivation of OAuth 2.0 and OpenID Connect: starting from the naive 'just share your password' approach and iteratively fixing each flaw — tokens, scopes, redirect URLs, client secrets, authorization codes, state, refresh tokens, ID tokens, and PKCE — until we arrive at the modern authorization-code-with-PKCE flow.
Slides
Download PDF
1 / 30
Use the arrow keys or the buttons to navigate. 30 slides.