← Explore learning paths

For developers

Authentication & Identity Fundamentals (2026)

Understand authentication, federation, sessions, and authorization through modern identity systems.

5 lessons ready to readFree to readLearn at your own pace
Read the first lesson → My progress in this path →
01 / READ

Start with a lesson that meets you where you are.

02 / PRACTICE

Try questions to check what you understand.

03 / RETURN

Sign in to keep your practice progress together.

Your learning path

5 of 60 topics have lessons available today. Choose any available lesson.

  1. 01

    Identity in 2026

    Read the lesson, then try the practice.

  2. 02

    Passkeys & WebAuthn

    Read the lesson, then try the practice.

  3. 03

    OAuth 2.1 & OIDC

    Read the lesson, then try the practice.

  4. 04

    Token Mechanics & JWT Security

    Read the lesson, then try the practice.

  5. 05

    Workload & Agent Identity

    Read the lesson, then try the practice.

Topics without lessons yet

These are part of the outline. Lessons are not available for them yet.

  • Core Identity Concepts
  • Auth vs Authz vs Accounting
  • Subjects, Principals & Claims
  • Sessions vs Tokens vs Cookies
  • Trust & Threat Modeling
  • Trust Boundaries & Threat Model
  • Phishing-Resistant vs Phishable Factors
  • WebAuthn Ceremonies
  • WebAuthn Registration Ceremony
  • WebAuthn Authentication Ceremony
  • Attestation & Sync Models
  • Passkey Deployment
  • Conditional UI & Autofill
  • Account Recovery Without Passwords
  • Migration: Password+MFA → Passkey-First
  • OAuth 2.1 Flows
  • Authorization Code + PKCE
  • Client Credentials & Device Code
  • Refresh Token Rotation & What 2.1 Removed
  • OIDC & Sender Constraints
  • ID Token vs Access Token
  • DPoP & mTLS Sender Constraint
  • Discovery, JWKS & IdP Mappings
  • JWT Structure & Algorithms
  • JWS Signing Algorithms
  • Standard Claims & JWE Encryption
  • JWT Validation Pitfalls
  • Key Rotation & Validation Strategy
  • Local Validation vs Introspection
  • Key Rotation & JWKS Caching
  • Workload Identity
  • SPIFFE / SPIRE & WIF
  • Cloud IAM & OIDC Federation from CI
  • Short-Lived Credentials & mTLS Mesh
  • AI Agent Identity
  • Delegated Authority & MCP Auth Model
  • Confused Deputy & Audit Trails
  • Human-in-the-Loop & Revocation at Speed
  • Attacks, Defenses & Authorization Models
  • Auth Attack Patterns
  • OAuth Redirect & Mix-Up Attacks
  • XSS, CSRF & MFA Bypass
  • AI-Driven Phishing & Agent Attacks
  • Authorization Models
  • RBAC, ABAC & ReBAC / Zanzibar
  • OPA Policy-as-Code & AWS Cedar
  • Scopes vs Permissions vs Roles
  • Sessions, Federation & Post-Quantum
  • Session Lifecycle & Continuous Access
  • Cookie Attributes & Logout
  • CAEP, Shared Signals & Step-Up Auth
  • Federation, FedCM & Browser Identity
  • SAML 2.0, OIDC Federation & SCIM
  • FedCM & Browser as Auth Mediator
  • Post-Quantum Readiness