Foreword
Our team successfully coded an advanced OAuth and OpenID Connect server that supported the complex security standards covered in this book. In doing so, we gained deep insights into these standards and productive ways to use them. Despite our years of hard work, we quickly realized that it would be for naught if we were unable to help others understand where our product fit in the confluence of digital identity and API security.
As organizations digitalize their services, they inevitably need to expose data as web services. These APIs are consumed by mobile apps, single-page applications, and traditional websites. In effect, this makes those APIs platforms for new digital processes, business models, and experiences. This metamorphosis to digital natives requires organizations to authenticate users and authorize access to data APIs. These are difficult problems that the OAuth and OpenID Connect specifications were designed to help solve. It is paramount that those seeking to adopt digital business also embrace and deploy these standards.
To explain how to do so, we needed to add to our team people that had not only mastered these technologies but also had an ability to teach them to others. Those people had to be skilled communicators, engaging instructors, and fluent writers. We found these qualities in Gary, Judith, and Michał and were immediately fond of their desires to uplift the industry through knowledge sharing. All three of them have a passion to teach complex ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access