All posts/ #security
ZITADEL Achieves ISO 27001 Certification
ZITADEL achieved ISO 27001 certification, demonstrating its dedication to data protection and cybersecurity. This certification provides a framework for information security management, safeguarding data against unauthorized access and cyber attacks.
• 3 minTest the ZITADEL Management API with Postman
This post walks you through the process of testing the ZITADEL Management API to create ZITADEL Projects, Apps, and Users with Postman.
• 5 minTest Token Introspection in ZITADEL with Postman
This post walks you through the process of calling a protected API that utilizes token introspection in ZITADEL. We'll guide you step by step through the setup and demonstrate how to use Postman for effective testing.
• 5 minTest User Login Flows in ZITADEL with Postman
This post explains how to integrate ZITADEL's login flow into your web application, guiding you through the setup process step by step, and also how to leverage Postman to test and ensure the login flow works flawlessly.
• 5 minThank you for Making ZITADEL More Secure
In the past few weeks, we mitigated multiple vulnerabilities reported by different security researchers that could have impacted the security of systems using ZITADEL.
• 4 minMigrate Users from Keycloak to ZITADEL
With PBKDF2 support now available, transitioning your users from Keycloak to ZITADEL has become smoother than ever. Dive into this tutorial to master the migration process.
• 15 minEvolving IoT Security: From Traditional Logins to Device Authorization Flow
Delve into the transformative power of the OAuth 2.0 Device Authorization Flow, enabling seamless logins across smart devices. Learn how standards-compliant Identity Providers are anchoring this wave of secure, user-friendly authentication.
• 5 minWhy FIDO2 Passkeys are Safer than MFA and Passwords
This article explores the reasons why FIDO2 passkeys surpass passwords and MFA in terms of security.
• 5 minNavigating Session Logouts, Timeouts, and Token Expiry
Using ZITADEL's OIDC integrations as a guide, this article offers insights into mastering the essential security measures of session timeouts, logouts, and token expriy.
• 12 minHow MFA Fatigue Attacks Compromise User Security
This article discusses MFA Fatigue Attacks targeting MFA systems with push notifications and how we can mitigate them.
• 5 minZITADEL and Fine-Grained Authorization: A Code-Focused Exploration
This articles showcases fine-grained authorization with ZITADEL and delves into managing access control, validating tokens, and separating business logic from authorization rules.
• 10-15 min5 Authentication Methods at ZITADEL - Ranked from Least to Most Secure
This article showcases ZITADEL's five implementable authentication methods ranked from worst to best regarding security and user experience (UX).
• 5 min