• Products
    • IdentityServer
    • IdentityServer for Redistribution
    • Backend for Frontend (BFF) Security Framework
    • Open Source
  • Documentation
  • Pricing
    • Duende IdentityServer
    • Duende IdentityServer for Redistribution
    • Backend for Frontend (BFF) Security Framework
  • Use Cases
    • Federation Broker & Identity Orchestration
    • Control-Centric Identity Infrastructure
    • Compliance & Security-Ready Identity
    • Application Modernization
    • Secure MCP Implementation
  • Resources
    • Duende Product Insiders
    • Training
    • Company Blog
    • IdentityServer4 Upgrade Assessment
    • Customer Stories
    • Customer Story: Synthesis Software Technologies
    • Unifying Identity and Access Management in Norwegian Healthcare with HelseID
    • Customer Story: USC Shoah Foundation
    • Featured Articles
    • Implementing Token Authentication in Controller-Based ASP.NET Core Web APIs: Step-by-Step Tutorial
    • API Client Authentication and Authorization with Duende IdentityServer
    • How Access and ID Tokens Flow in OAuth & OIDC
    • Token Expiration & Refresh Best Practices for APIs
  • About
    • Company
      Partners
      Tools & Components
    • Careers
    • Contact
  • Start for free
    Talk to an expert

Livestream: Spring Launch Event - The Next Era of Duende Identity Infrastructure. Register Now!

Duende
  • Products
    • IdentityServer
    • IdentityServer for Redistribution
    • Backend for Frontend (BFF) security framework
    • Open Source
  • Documentation
  • Pricing
    • Duende IdentityServer
    • Duende IdentityServer for Redistribution
    • Backend for Frontend (BFF) Security Framework
  • Use Cases
    • Federation Broker & Identity Orchestration
    • Control-Centric Identity Infrastructure
    • Compliance & Security-Ready Identity
    • Application Modernization
    • Secure MCP Implementation
  • Resources
    • IdentityServer 4

      Get a FREE upgrade assessment for better security, performance, and support.

      Company Blog

      Stay up-to-date with the latest developments in identity and access management.

      Duende Product Insiders

      Early Access. Deep Collaboration. Better Security and Identity.

      Training

      Comprehensive training programs for identity and access management.

    • Customer Stories
      • Synthesis Software Technologies
      • Norwegian Health Network (NHN)
      • USC Shoah Foundation
    • Featured Articles
      • Implementing Token Authentication in Controller-Based ASP.NET Core Web APIs: Step-by-Step Tutorial
      • API Client Authentication and Authorization with Duende IdentityServer
      • How Access and ID Tokens Flow in OAuth & OIDC
      • Token Expiration & Refresh Best Practices for APIs
  • About
    • Company
    • Partners
    • Tools & Components
    • Careers
    • Contact
  • Start for free
    Talk to an expert

Duende Blog

Stay up-to-date with the latest developments in identity and access management.
Expert .NET Security Solutions, Best Practices, and Development Advice.

Join the discussion
Contact sales
  • Duende.AccessTokenManagement 3.0

    Joe DeCock | August 13, 2024

    Duende.AccessTokenManagement 3.0 is out now! Highlights of this release include:

    • Improved support for Blazor Server
    • Updates to dependencies
    • Bug fixes and improvements

    See the release notes for the full details, or read on for a quick summary.

    Read more...
  • Security Patch for IdentityServer (CVE-2024-39694)

    Joe DeCock | July 31, 2024

    Today we are publishing a hotfix for all supported versions of Duende.IdentityServer that addresses CVE-2024-39694, a moderate severity open redirect security vulnerability. We encourage everyone to update to the latest patch version. Note that by itself, this vulnerability does not allow an attacker to steal tokens or user credentials. An attacker would most likely exploit this vulnerability to make phishing attacks more likely to succeed.

    We have also published a security advisory with technical details about the severity, affected versions, specific APIs involved, and work-arounds for those who can't upgrade to a patched version.

    In this blog post we'll discuss open redirect vulnerabilities more generally, the process we followed to manage disclosure of the issue and patch, and lessons learned from that process.

    Read more...
  • Reusing Refresh Tokens By Default

    Joe DeCock | April 08, 2024

    Historically, IdentityServer could either issue reusable refresh tokens or enforce refresh token rotation. The default value was "rotate" which can often lead to problems. In IdentityServer 7.0, we made the decision to change the default behavior of refresh tokens so that they would be reusable by default. In this blog post, we'll describe refresh tokens and their security in detail and explain why we made this choice.

    Read more...
  • Duende IdentityServer v7 released

    Joe DeCock | January 25, 2024

    Pretty much exactly one year after the release of IdentityServer v6, we are happy to announce our next major version: IdentityServer v7.

    Read more...
  • Open Telemetry support in IdentityServer v7

    Dominick Baier, Brock Allen | January 23, 2024

    OpenTelemetry is a collection of tools, APIs, and SDKs for generating and collecting telemetry data (metrics, logs, and traces). This is very useful for analyzing software performance and behavior, especially in highly distributed systems.

    We started our journey with Traces in Duende IdentityServer v6.1. .NET 8 has full support for Open Telemetry and so does Duende IdentityServer v7. IdentityServer emits traces, metrics and logs.

    Read more...
  • Announcing Support for Pushed Authorization Requests (PAR) in IdentityServer v7

    Dominick Baier, Brock Allen | November 16, 2023

    Read more...
  • Duende IdentityServer v7 for .NET 8

    Dominick Baier, Brock Allen | November 14, 2023

    Read more...
  • DPoP support For Native and Mobile Applications

    Dominick Baier, Brock Allen | October 12, 2023

    Implementing Proof of Possession tokens in native mobile applications with IdentityModel.OidcClient

    Read more...
  • IdentityServer 6.3 and Dynamic Client Registration

    Dominick Baier, Brock Allen | May 10, 2023

    Read more...
  • IdentityServer 6.3 and DPoP Support

    Dominick Baier, Brock Allen | May 04, 2023

    Read more...
  • <<
  • <
  • …
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • >
Duende logo

Products

  • IdentityServer
  • IdentityServer for Redistribution
  • Backend for Frontend (BFF)
  • IdentityModel
  • Access Token Management
  • IdentityModel OIDC Client

Community

  • Documentation
  • Company Blog
  • GitHub Discussions

Company

  • Company
  • Partners
  • Training
  • Quickstarts
  • FAQ
  • Careers
  • Contact

Subscribe to our newsletter

Stay up-to-date with the latest developments in identity and access management.

Copyright © 2021-2026 Duende Software. All rights reserved.

Privacy Policy | Terms of Service