This document describes OAuth client authentication and certificate-bound access and refresh tokens using mutual Transport Layer Security (TLS) authentication with X.509 certificates. OAuth clients are provided a mechanism for authentication to the authorization server using mutual TLS, based on either self-signed certificates or public key infrastructure (PKI). OAuth authorization servers are provided a mechanism for binding access tokens to a client's mutual-TLS certificate, and OAuth prote...| www.rfc-editor.org
How to implement client certificate based security in a B2B API| curity.io
What is Open Banking, and what are the security requirements to implement Open Banking solutions?| curity.io
What is Mutual TLS, and how does Client Authentication with Mutual TLS work?| curity.io
Articles, whitepapers and other resources offering insights on identity management, authentication, API security and much more.| curity.io
Adopt the Phantom Token Approach:a privacy-preserving token usage pattern for securing APIs and microservices.| curity.io
This chapter describes how to use F5 NGINX Plus and NGINX Open Source to proxy and load balance TCP and UDP traffic.| docs.nginx.com