Nordic APIs Summit 2026 - October 12-14 Early Bird Registration Open!
Supported by Curity Logotype

Session

Your JWT Is Valid. Should Your API Still Trust It?

Thomas Darimont Identity Tailor GmbH

Modern API security largely revolves around OAuth access tokens: authenticate a client or user, issue a token, and let APIs trust that token until it expires. But what happens when the security context changes while the token is still valid?

An account may be disabled, a device compromised, credentials stolen, or a session classified as high risk. In a zero trust architecture, APIs should be able to react to these changes immediately rather than waiting for tokens to expire.

This session explores how the OpenID Shared Signals Framework (SSF) and Continuous Access Evaluation Profile (CAEP) can provide an event-driven security layer for APIs. We will look at how identity providers, security systems, API gateways, and resource servers can exchange security signals and continuously re-evaluate access.

Using OAuth, Keycloak, and practical API scenarios, we’ll explore how shared signals can bridge the gap between traditional token-based API authorization and continuous zero trust enforcement.

Smarter Tech Decisions Using APIs

Smarter Tech Decisions Using APIs

API blog

High impact blog posts and eBooks on API business models, and tech advice

API conferences

Connect with market leading platform creators at our events

API community

Join a helpful community of API practitioners

API Insights Straight to Your Inbox!

Can't make it to the event? Signup to the Nordic APIs newsletter for quality content. High impact blog posts on API business models and tech advice.

By clicking below, you agree that we process your information per the terms in our Privacy Policy.

Join Our Thriving Community

Become a part of our global community of API practitioners and enthusiasts. Share your insights on the blog, speak at an event or exhibit at our conferences and create new business relationships with decision makers and top influencers responsible for API solutions.