For developers
Authentication & Identity Fundamentals (2026)
Understand authentication, federation, sessions, and authorization through modern identity systems.
5 lessons ready to readFree to readLearn at your own pace
Read the first lesson →
Practice for five minutes →
My progress in this path →
01 / READ
Start with a lesson that meets you where you are.
02 / PRACTICE
Try questions to check what you understand.
03 / RETURN
Sign in to keep your practice progress together.
Your learning path
5 of 60 topics have lessons available today. Choose any available lesson.
- 01
Identity in 2026
Read the lesson, then try the practice.
- 02
Passkeys & WebAuthn
Read the lesson, then try the practice.
- 03
OAuth 2.1 & OIDC
Read the lesson, then try the practice.
- 04
Token Mechanics & JWT Security
Read the lesson, then try the practice.
- 05
Workload & Agent Identity
Read the lesson, then try the practice.
Topics without lessons yet
These are part of the outline. Lessons are not available for them yet.
- Core Identity Concepts
- Auth vs Authz vs Accounting
- Subjects, Principals & Claims
- Sessions vs Tokens vs Cookies
- Trust & Threat Modeling
- Trust Boundaries & Threat Model
- Phishing-Resistant vs Phishable Factors
- WebAuthn Ceremonies
- WebAuthn Registration Ceremony
- WebAuthn Authentication Ceremony
- Attestation & Sync Models
- Passkey Deployment
- Conditional UI & Autofill
- Account Recovery Without Passwords
- Migration: Password+MFA → Passkey-First
- OAuth 2.1 Flows
- Authorization Code + PKCE
- Client Credentials & Device Code
- Refresh Token Rotation & What 2.1 Removed
- OIDC & Sender Constraints
- ID Token vs Access Token
- DPoP & mTLS Sender Constraint
- Discovery, JWKS & IdP Mappings
- JWT Structure & Algorithms
- JWS Signing Algorithms
- Standard Claims & JWE Encryption
- JWT Validation Pitfalls
- Key Rotation & Validation Strategy
- Local Validation vs Introspection
- Key Rotation & JWKS Caching
- Workload Identity
- SPIFFE / SPIRE & WIF
- Cloud IAM & OIDC Federation from CI
- Short-Lived Credentials & mTLS Mesh
- AI Agent Identity
- Delegated Authority & MCP Auth Model
- Confused Deputy & Audit Trails
- Human-in-the-Loop & Revocation at Speed
- Attacks, Defenses & Authorization Models
- Auth Attack Patterns
- OAuth Redirect & Mix-Up Attacks
- XSS, CSRF & MFA Bypass
- AI-Driven Phishing & Agent Attacks
- Authorization Models
- RBAC, ABAC & ReBAC / Zanzibar
- OPA Policy-as-Code & AWS Cedar
- Scopes vs Permissions vs Roles
- Sessions, Federation & Post-Quantum
- Session Lifecycle & Continuous Access
- Cookie Attributes & Logout
- CAEP, Shared Signals & Step-Up Auth
- Federation, FedCM & Browser Identity
- SAML 2.0, OIDC Federation & SCIM
- FedCM & Browser as Auth Mediator
- Post-Quantum Readiness