Sign in

Duende Software

@duendesoftware.com
321 followers 6 following 592 posts

Duende Software. Makers of Duende IdentityServer and the BFF security framework. duendesoftware.com youtube.com/@duendesoftware

PostsRepliesMedia
Duende Software @duendesoftware.com · 29/09/2026
A practical guide to enforcing fine-grained access control on #dotnet 10 Minimal API endpoints using scope claims in JWTs issued by Duende IdentityServer. ➡️ duende.link/29spt26
012
Duende Software @duendesoftware.com · 28/09/2026
That’s a wrap on our FAPI 2.0 livestream! 🚀 Roland, Joe, and Al demonstrated how to protect financial apps against modern attacks by closing security gaps like token replay & URL leaks using PAR, DPoP, and private_key_jwt. 📺️ www.youtube.com/watch?v=OM00...
youtube.com
How Banks Protect Their Apps with FAPI 2.0
FAPI is a security profile that protects APIs in high-value scenarios that require heightened security. To be considered FAPI 2.0 compliant, an implementation must adopt the right set of OAuth best…
010
Duende Software @duendesoftware.com · 23/09/2026
Tomorrow! Even if you don't need full FAPI 2.0 compliance, you'll leave this livestream with at least ONE architectural change to instantly harden your application security. Join Roland Guijt and Joe DeCock: duendesoftware.com/webinars/how...
000
Duende Software @duendesoftware.com · 22/09/2026
Blogged: What #dotnet 11 and C# 15 change for Duende IdentityServer developers: registration confirmation, Blazor and SignalR auth refresh, sessions, and a practical upgrade checklist. duende.link/22spt26
000
Duende Software @duendesoftware.com · 21/09/2026
Banks adopted FAPI 2.0 first, but the profile applies anywhere high-value transactions happen. Is your API landscape secure enough? Learn how to harden it here: duendesoftware.com/webinars/how...
010
Duende Software @duendesoftware.com · 18/09/2026
FAPI 2.0 enforces least privilege for access tokens so compromises are contained by design. Watch us configure tightly scoped tokens live: duendesoftware.com/webinars/how...
012
Duende Software @duendesoftware.com · 16/09/2026
We are officially here at #NDCOslo! 🇳🇴 We hit the ground running today with Maarten taking the stage to give his speech on going passwordless. Such a great start to the week! Come say hi if you're around. 👋
010
Duende Software @duendesoftware.com · 15/09/2026
RFC 10017 (BCP 212) makes the Backend for Frontend pattern official IETF best current practice for browser-based OAuth apps. Here's what the RFC recommends and why it matters. duende.link/15spt26 #bff #dotnet #identity
000
Duende Software @duendesoftware.com · 14/09/2026
Stop dealing with shared secrets that can be leaked, rotated poorly, or committed to GitHub. Learn how to implement private_key_jwt for asymmetric client authentication in our FAPI 2.0 livestream. 🔑 duendesoftware.com/webinars/how...
000
Duende Software @duendesoftware.com · 11/09/2026
We've had 3,600 monthly searches for "Duende"… spelled every way except Duende. 😅 So Al Rodriguez is here to settle how to pronounce it: it's doo-EN-deh. 🎤 You're welcome. (Bloopers in video)
010
Duende Software @duendesoftware.com · 10/09/2026
Next week, we’re heading to Norway for NDC Oslo! We can't wait to dive into the sessions and connect with the incredible dev community. Will you be there? Let us know below so we can say hi! 👋 #NDCOslo
010
Duende Software @duendesoftware.com · 10/09/2026
Learn how to implement WhatsApp OTP login with Duende IdentityServer and User Management by building a custom IOtpDispatcher that delivers one-time passwords via Meta's WhatsApp Business Cloud API. duende.link/10spt26 #dotnet #identity
000
Duende Software @duendesoftware.com · 09/09/2026
Join Anders Abel's workshop on securing asp.net 10 apps. This workshop breaks down Auth Design, Cookie-Based Sessions, SSO, and Account Linking. Learn architectural patterns that actually work: ndcoslo.com/workshops/id... #NDCOslo #NDCOslo2026
ndcoslo.com
Identity & Access Control for modern Applications and APIs using ASP.NET 10 : NDC Oslo
Duende Software's legendary training on Identity and Access Management was originally created by Dominick Baier and Brock Allen. With their world-class knowledge, they’ve created a workshop focused…
020
Duende Software @duendesoftware.com · 08/09/2026
Standard OAuth 2.0 is great, but what happens when a stolen token can move money? Learn the threat model behind financial-grade security and why you might need FAPI 2.0. Register for the livestream here: duendesoftware.com/webinars/how...
000
Duende Software @duendesoftware.com · 08/09/2026
Blogged: a strategic architecture guide for migrating from OWIN-based IdentityServer3 to modern Duende IdentityServer. duende.link/8s3pt26 #dotnet
duende.link
Planning a Successful Migration from IdentityServer3 to Duende IdentityServer
A strategic architecture guide for migrating from IdentityServer3 to Duende IdentityServer, covering compliance risks, cost drivers, code archaeology, and execution steps for a successful identity…
000
Duende Software @duendesoftware.com · 04/09/2026
Curious how DPoP and mTLS bind a token exclusively to the client that requested it? We are demonstrating it live, end-to-end. Watch the live implementation: duendesoftware.com/webinars/how...
000
Duende Software @duendesoftware.com · 04/09/2026
Blogged: Wesley compares three OAuth client authentication methods in ASP.NET Core: Client Secrets, Private Key JWT, and Mutual TLS, with code examples for Duende IdentityServer. duende.link/3s3pt26 #dotnet #oidc #identity
020
Duende Software @duendesoftware.com · 01/09/2026
.NET 11 adds automatic CSRF protection that rejects cross-origin browser requests by default. Learn how this impacts SPAs and IdentityServer deployments, and how to prepare your apps. duende.link/1s3pt26 #dotnet
010
Duende Software @duendesoftware.com · 28/08/2026
Prevent outages from expired signing keys. 🛡️ Duende IdentityServer’s Automatic Key Management handles the lifecycle natively: 🔹 Generation 🔹 Rotation 🔹 Propagation 🔹 Retirement Zero-downtime rollover. Put your security on autopilot: duendesoftware.com/products/cap...
duendesoftware.com
Automatic Key Management
Duende Software is a company that builds industry-leading security software.
000
Duende Software @duendesoftware.com · 27/08/2026
Learn what TOTP (Time-based One-Time Password) means, how the algorithm works, and how it fits into multi-factor authentication flows. duende.link/97w4iou #dotnet
duende.link
Security Lingo Explained: TOTP (Time-based One-Time Password)
An accessible explainer of TOTP (the algorithm behind those six-digit authenticator codes) covering how it works, its role in MFA, and Duende's built-in support.
010
Duende Software @duendesoftware.com · 26/08/2026
The next era of Duende is live! 🚀 We're expanding from a token server to identity infrastructure. IdentityServer v8 brings modular Add-Ons (Adopt what you need, when you need). Learn more: duendesoftware.com/products/ide...
010
Duende Software @duendesoftware.com · 25/08/2026
Blogged: Learn how to restrict passkey registration to approved hardware security keys like YubiKey using Duende User Management's IAttestationTrustPolicy interface. duende.link/p4k4tta #dotnet #webauthn
020
Duende Software @duendesoftware.com · 24/08/2026
IdentityServer v8 brings architectural refinements to modern .NET workloads. 🛠️ Enjoy unified model for OIDC & SAML connected apps, idiomatic cooperative cancellation, and TimeProvider integration. Read the release notes: docs.duendesoftware.com/identityserv...
docs.duendesoftware.com
Duende IdentityServer
Overview of Duende IdentityServer framework for OpenID Connect and OAuth 2.x protocols, covering extensibility, security scenarios, licensing, and support.
010
Duende Software @duendesoftware.com · 20/08/2026
We’re continuing our web security series with a deep dive into HTTP Strict Transport Security (HSTS) in ASP.NET Core. Learn how to move beyond the defaults, configure production settings, and understand how HSTS preload works. youtu.be/9U10DySH6zg #dotnet #security
youtube.com
HTTP Strict Transport Security (HSTS) with IdentityServer
In this video, we continue our Duende web application security series with a deep dive into HTTP Strict Transport Security (HSTS). HSTS is a crucial security mechanism that enforces the use of HTTPS…
000
Duende Software @duendesoftware.com · 20/08/2026
Joe DeCock covers three key identity standards milestones from summer 2026: OAuth Identity Chaining reaching Proposed Standard, the Transaction Authorization Challenge draft for human-in-the-loop approval, and Transaction Token chaining across trust domains. duende.link/jhnr982 #identity #dotnet
010
Duende Software @duendesoftware.com · 19/08/2026
🛠️ .NET Devs: The MCP RC brings a great DCR update! SEP-837 advises declaring OIDC application_type to validate redirect URIs with precision (e.g., enforcing HTTPS for web). Grab the C# code to implement this easily in our newest post: duendesoftware.com/blog/2026073...
duendesoftware.com
Hardening OAuth in the newest 2026-07-28 MCP Release Candidate
The MCP 2026-07-28 release candidate tightens OAuth security for AI agents. Analyze the spec changes and implement them with Duende IdentityServer.
100
Duende Software @duendesoftware.com · 18/08/2026
Before writing code, every team needs to answer what identity means for their organization. Learn the core vocabulary and the critical questions that turn 'add auth' from a vague task into an architecture. duende.link/87qegkh #dotnet
duende.link
What is Identity? - The Question Every Team Should Answer Before Writing Code
Before writing code, every team needs to answer what identity means for their organization. Learn the core vocabulary—authentication, authorization, claims, tokens, federation—and the critical…
000
Duende Software @duendesoftware.com · 17/08/2026
The new Model Context Protocol (MCP) RC is stateless! 🚀 No more tracking sessions or sticky load balancers. Deploying MCP servers just got easier. Plus, 6 new SEPs are hardening OAuth security. Read the full architectural breakdown here: duendesoftware.com/blog/2026073...
duendesoftware.com
Hardening OAuth in the newest 2026-07-28 MCP Release Candidate
The MCP 2026-07-28 release candidate tightens OAuth security for AI agents. Analyze the spec changes and implement them with Duende IdentityServer.
130
Duende Software @duendesoftware.com · 13/08/2026
🛠️ .NET Devs: The MCP RC brings a great DCR update! SEP-837 advises declaring OIDC application_type to validate redirect URIs with precision (e.g., enforcing HTTPS for web). Grab the C# code to implement this easily in our newest post: duendesoftware.com/blog/2026073...
020
Duende Software @duendesoftware.com · 12/08/2026
Heading to #NDCOslo! 🇳🇴 Visit the Duende Software booth to talk identity & security! Catch our sessions: 🎤 Anders (Sustainsys): ASP.NET Core meets OWASP Top 10 2025 🎤 Maarten Balliauw: Going Passwordless - A Practical Guide to Passkeys in ASP.NET Core See you there! ✨
020
Duende Software @duendesoftware.com · 11/08/2026
A practical guide to choosing session and token lifetimes in Duende IdentityServer. Learn how to align your security configuration with your specific risk profile. duende.link/87qkhaq #dotnet
duende.link
Security Is a Spectrum: How to Choose Session Lifetimes in Duende IdentityServer
A practical guide to choosing session and token lifetimes in Duende IdentityServer. Learn how to align your security configuration with your specific risk profile instead of relying on defaults.
010
Duende Software @duendesoftware.com · 10/08/2026
Adopting new AI protocols? For Duende IdentityServer users, the new MCP RC is smooth sailing. 😌 The heavy lifting for the 6 new OAuth security SEPs is largely built-in. We recommend just one quick C# tweak for DCR. See how to get MCP-ready: duendesoftware.com/blog/2026073...
duendesoftware.com
Hardening OAuth in the newest 2026-07-28 MCP Release Candidate
A breakdown of six new OAuth security enhancements in the latest MCP release candidate, covering DCR application types, issuer identification, discovery clarifications, credential binding, refresh…
010
Duende Software @duendesoftware.com · 06/08/2026
Want to ensure your web app is always served over HTTPS? 🔒 In our latest episode, we look at enforcing transport security to secure your traffic in ASP.NET Core using UseHttpsRedirection() and the more robust UseHsts(). Watch here: youtu.be/oIwdoscInWw #aspnetcore #WebSecurity #dotnet
youtu.be
Enforcing HTTPS with IdentityServer
In this episode, we explore how to enforce transport security in your web applications by ensuring HTTPS is used throughout your ASP.NET Core project. Topics covered in this video: - Using…
000
Duende Software @duendesoftware.com · 06/08/2026
Blogged: How to implement passkeys with IdentityServer, including ceremony endpoints, progressive onboarding, and deployment considerations. duende.link/8keq2ui #webauthn #dotnet #passkey
duende.link
Passkeys and WebAuthn with Duende IdentityServer and User Management
Learn how to implement passkeys and WebAuthn with Duende IdentityServer and User Management, including progressive onboarding patterns and deployment considerations.
010
Duende Software @duendesoftware.com · 05/08/2026
While OpenID Connect (OIDC) is the "cool kid" of modern web development, SAML remains the bedrock of the enterprise world. Our new SAML 2.0 Add-On lets you bridge OIDC and SAML (IdP and SP) in one identity solution Watch the deep dive: www.youtube.com/watch?v=o_tG...
youtube.com
A First Look at Duende’s first-party SAML 2.0 support
OpenID Connect may be the standard of tomorrow, but SAML is the bedrock of today’s enterprise. Mastering this legacy giant isn’t just about maintenance; it’s the essential gateway to high-value…
010
Duende Software @duendesoftware.com · 04/08/2026
The future of .NET identity is here. 🚀 Hear from the architects shaping the ecosystem. The Duende leadership team dives into ISv8, modular add-ons, and our commitment to expanding identity infrastructure. 📺 Watch the full walkthrough: www.youtube.com/watch?v=qloC...
youtube.com
Spring Launch Event: The Next Era of Duende Identity Infrastructure
This isn't a point release. This is a new chapter. On June 2, Duende ships the most significant release in the company's history: IdentityServer v8 - a .NET 10-exclusive major release, five modular…
010
Duende Software @duendesoftware.com · 04/08/2026
Putting our game face on 🎮 Learn how to authenticate players in Godot 4 game engine using OAuth 2.0 and OpenID Connect with IdentityServer. Also covering approaches for consoles and limited-input devices. duende.link/u7q4kjm #dotnet
duende.link
020
Duende Software @duendesoftware.com · 03/08/2026
Are your AI agents vulnerable to mix-up attacks? The new MCP RC introduces SEP-2468 to definitively identify Authorization Servers & stop bad actors. Good news: Duende IdentityServer users are already protected by default! 🛡️ Dive deep here: duendesoftware.com/blog/2026073...
010
Duende Software @duendesoftware.com · 31/07/2026
"P@ssw0rd1!" passes every password complexity rule, but it's in 100K+ data breaches. 🚨 Complexity ≠ Security. Learn how to integrate the Have I Been Pwned API with Duende User Management to automatically reject compromised passwords at registration. 🛡️👇 duendesoftware.com/blog/2026072...
020
Duende Software @duendesoftware.com · 30/07/2026
The new Model Context Protocol (MCP) RC is stateless! 🚀 No more tracking sessions or sticky load balancers. Deploying MCP servers just got easier. Plus, 6 new SEPs are hardening OAuth security. Read the full architectural breakdown here: duendesoftware.com/blog/2026073... #MCP #AI
020
Duende Software @duendesoftware.com · 29/07/2026
Fresh blog post: configure Duende IdentityServer to wrap auto-managed signing keys in X.509 certificates, enabling unified SAML and OIDC key rotation. Read more: duende.link/7qiusr2 #dotnet #saml #identity
duende.link
Unify Your SAML and OIDC Signing Keys with Automatic Rotation and Duende IdentityServer
How to configure Duende IdentityServer to wrap auto-managed signing keys in X.509 certificates, enabling unified SAML and OIDC key rotation with a single configuration change.
000
Duende Software @duendesoftware.com · 28/07/2026
Inherited #IdentityServer in your team? This 10-step checklist covers licensing, data protection, signing keys, data stores, client inventory, and topology. duende.link/u87w4ga #dotnet
duende.link
Duende Software
A prioritized 10-step checklist for developers who have inherited a running Duende IdentityServer, covering license verification, Data Protection, signing keys, stores, client inventory, and…
010
Duende Software @duendesoftware.com · 27/07/2026
The future of .NET identity is here. 🚀 Hear from the architects shaping the ecosystem. The Duende leadership team dives into ISv8, modular add-ons, and our commitment to expanding identity infrastructure. Watch the full walkthrough: www.youtube.com/watch?v=qloC... #dotnet #aspnet
youtube.com
Spring Launch Event: The Next Era of Duende Identity Infrastructure
This isn't a point release. This is a new chapter. On June 2, Duende ships the most significant release in the company's history: IdentityServer v8 - a .NET 10-exclusive major release, five modular…
021
Duende Software @duendesoftware.com · 23/07/2026
Stop hand-rolling bespoke user systems. 🏗️ Our new User Management add-on brings fully supported user storage, auth, and lifecycle management directly to your deployment. Passwords, MFA, and passkeys are built-in, not bolted on. Read more here: duendesoftware.com/products/cap...
duendesoftware.com
User Management
Duende Software is a company that builds industry-leading security software.
010
Duende Software @duendesoftware.com · 22/07/2026
Customize Duende User Management with HaveIBeenP0wned k-anonymity to securely block compromised passwords instead of just verifying format. Deep-dive! duende.link/8735jkh #dotnet #IdentityServer
duende.link
Duende Software
How to integrate the HaveIBeenPwned API with Duende User Management's IPasswordValidator pipeline to reject known-compromised passwords during registration, using k-anonymity to preserve user privacy.
000
Duende Software @duendesoftware.com · 21/07/2026
IdentityServer v8 brings architectural refinements to modern .NET workloads. 🛠️ Enjoy unified model for OIDC & SAML connected apps, idiomatic cooperative cancellation, and TimeProvider integration. Read the release notes: docs.duendesoftware.com/identityserv...
000
Duende Software @duendesoftware.com · 20/07/2026
Hardened security on autopilot. 🛡️ Our new v8 add-ons take the pain out of infrastructure: 🔑 Auto Key Management: Zero-downtime key rotation ✅ FGSC: Generate audit-ready FAPI 2.0 conformance reports locally. Dive into the latest capabilities: duendesoftware.com/products/cap...
duendesoftware.com
Automatic Key Management
Duende Software is a company that builds industry-leading security software.
000
Duende Software @duendesoftware.com · 20/07/2026
Enterprise identity shouldn't mean forced bundles. 🛑 Extend your infrastructure only when needed with our new Modular Add-Ons: User Management, SAML 2.0, FGSC, Key Management, and Multi-Issuer. Pay only for what you use. Explore the modules: duendesoftware.com/blog/2026060...
duendesoftware.com
Duende Spring Launch '26: Identity Infrastructure That Expands With You
Duende Software is a company that builds industry-leading security software.
010
Duende Software @duendesoftware.com · 17/07/2026
Miss our June 2 Livestream? We’ve got you covered. 📺 Watch the Duende team unpack: ISv8 architectural updates, walkthrough of of our new add-ons, including SAML & User Management, a great discussion with our founders Brock Allen and Dominick Catch the replay here: www.youtube.com/live/qloCmdG...
010
Duende Software @duendesoftware.com · 16/07/2026
Enterprise identity shouldn't mean forced bundles. 🛑 Extend your infrastructure only when needed with our new Modular Add-Ons: User Management, SAML 2.0, FGSC, Key Management, and Multi-Issuer. Pay only for what you use. Explore the modules: duendesoftware.com/blog/2026060...
010