
The Risks of User Impersonation
What is user impersonation? User impersonation is anything that allows your systems to...

Organization profile
Delivering plug-in security API for any software application. Authress is the Lock in the identity lock and key model. Security doesn't end with Authentication.
Browse the latest writing surfaced through DevArt.

What is user impersonation? User impersonation is anything that allows your systems to...

This article is a rebuttal to Truffle Security's post on Millions of Accounts Vulnerable due to...

Machine to machine auth is how you ensure secure communication between individual services, and each...

(Note, this article continues from Part 1: AWS Metrics: Advanced) We can't use...

Normally I'm the last proponent of collecting metrics. The reason is: metrics don't tell you...

This article is part of the Authress Academy and discusses the different ways to invalidate a user's...

Having built many Product APIs in my experience for multiple companies, there are a number of Myths...

Before we get into how to handle a breaking change, we should first identify what is even a breaking...

An obvious story you might decide to tell yourself is Logging is easy. And writing to the console or...

Step up authorization is the process of converting a user’s auth from a base level to an elevated or...

It’s pretty common in monolith architectures to have to handle migrations. But this isn’t the only...

You're building out a SaaS solution and realize for one reason or another supporting custom domains...

AWS Cognito is AWS auth solution, it’s much better than Azure’s and many others that think Auth is...

Making changes to your DNS and it still doesn't work, here's a troubleshooting guide

How to solve those nasty CORS errors that pop up all the time

A common pattern often found in software engineering is magic identifiers. These identifiers are used...

Never. That’s the end of the story… Okay not really, there is one great use case for using AWS...

Identity providers solve the issue of identity verification, but never include solutions for CIAM...

AWS + Gitlab — Leveling up security of your CICD platform. For eons there have only been...

The most common lifecycle of a resource flows from Creation , to Updates , to Deletion. When a...

Breach — Enabling emergency data protection US Capitol building (Washington D.C.) The...

Applications that provide first class APIs require more than simple authentication, they require...

Authentication more frequently works as identity aggregation. This means that it provides a central...

A Multitenant application Multitenancy is the concept that your application serves...

Perhaps it happened to you. You’re working on a project, developing some fancy software where users...

Every aspect of your technology can be vulnerable to some sort of exploit. Each of these is a...