• Products
    • IdentityServer
    • IdentityServer for Redistribution
    • Backend for Frontend (BFF) Security Framework
    • Open Source
  • Documentation
  • Training
  • Resources
    • Company Blog
    • IdentityServer4 Upgrade Assessment
    • Customer Stories
    • Unifying Identity and Access Management in Norwegian Healthcare with HelseID
    • Customer Story: USC Shoah Foundation
    • Featured Articles
    • Access Control: A Comprehensive Guide
    • Enhancing Web Security with Identity Frameworks
    • Securing User Identities with Multi-Factor Authentication
    • Get a Free Assessment and Upgrade IdentityServer4
  • About
    • Company
      Partners
    • Careers
    • Contact
Duende
  • Products
    • IdentityServer
    • IdentityServer for Redistribution
    • Backend for Frontend (BFF) security framework
    • Open Source
  • Documentation
  • Training
  • Resources
    • Company Blog

      Stay up-to-date with the latest developments in identity and access management.

      IdentityServer 4

      Get a FREE upgrade assessment for better security, performance, and support.

    • Customer Stories
      • Unifying Identity and Access Management in Norwegian Healthcare with HelseID

      • Customer Story: USC Shoah Foundation

    • Featured Articles
      • Access Control: A Comprehensive Guide

      • Enhancing Web Security with Identity Frameworks

      • Securing User Identities with Multi-Factor Authentication

      • Get a Free Assessment and Upgrade IdentityServer4

  • About
    • Company
    • Partners
    • Careers
    • Contact
  • Start for free
    Contact sales

Duende Blog

Stay up-to-date with the latest developments in identity and access management.
Expert .NET Security Solutions, Best Practices, and Development Advice.

Join the discussion
Contact sales
  • Reusing Refresh Tokens By Default

    Joe DeCock | April 08, 2024

    Historically, IdentityServer could either issue reusable refresh tokens or enforce refresh token rotation. The default value was "rotate" which can often lead to problems. In IdentityServer 7.0, we made the decision to change the default behavior of refresh tokens so that they would be reusable by default. In this blog post, we'll describe refresh tokens and their security in detail and explain why we made this choice.

    Read more...
  • Duende IdentityServer v7 released

    Joe DeCock | January 25, 2024

    Pretty much exactly one year after the release of IdentityServer v6, we are happy to announce our next major version: IdentityServer v7.

    Read more...
  • Open Telemetry support in IdentityServer v7

    Dominick Baier, Brock Allen | January 23, 2024

    OpenTelemetry is a collection of tools, APIs, and SDKs for generating and collecting telemetry data (metrics, logs, and traces). This is very useful for analyzing software performance and behavior, especially in highly distributed systems.

    We started our journey with Traces in Duende IdentityServer v6.1. .NET 8 has full support for Open Telemetry and so does Duende IdentityServer v7. IdentityServer emits traces, metrics and logs.

    Read more...
  • Announcing Support for Pushed Authorization Requests (PAR) in IdentityServer v7

    Dominick Baier, Brock Allen | November 16, 2023

    Read more...
  • Duende IdentityServer v7 for .NET 8

    Dominick Baier, Brock Allen | November 14, 2023

    Read more...
  • DPoP support For Native and Mobile Applications

    Dominick Baier, Brock Allen | October 12, 2023

    Implementing Proof of Possession tokens in native mobile applications with IdentityModel.OidcClient

    Read more...
  • IdentityServer 6.3 and Dynamic Client Registration

    Dominick Baier, Brock Allen | May 10, 2023

    Read more...
  • IdentityServer 6.3 and DPoP Support

    Dominick Baier, Brock Allen | May 04, 2023

    Read more...
  • OAuth and Proof of Possession Access Tokens

    Dominick Baier, Brock Allen | March 28, 2023

    Read more...
  • Best Current Practices for Cross-Device Flows

    Dominick Baier, Brock Allen | November 30, 2022

    Read more...
  • <
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • >
Duende logo

Products

  • IdentityServer
  • IdentityServer for Redistribution
  • Backend for Frontend (BFF)
  • IdentityModel
  • Access Token Management
  • IdentityModel OIDC Client

Community

  • Documentation
  • Company Blog
  • GitHub Discussions

Company

  • Company
  • Partners
  • Training
  • Quickstarts
  • Careers
  • Contact

Subscribe to our newsletter

Stay up-to-date with the latest developments in identity and access management.

Copyright © 2021-2025 Duende Software. All rights reserved.

Privacy Policy | Terms of Service