10 parts · 18 chapters

Identity, Authentication and Authorisation

Authentication answers who you are; authorisation answers what you may do. Most breaches exploit the gaps between them: a token accepted where it should not be, a permission checked in the UI but not the API, a recovery flow weaker than the login it bypasses. This course builds both from the protocol level up.

Ten parts: sessions versus tokens; OAuth 2.1 and OpenID Connect flows; JWTs and their pitfalls; passkeys, WebAuthn and MFA; RBAC, ABAC and ReBAC; Zanzibar-style authorisation with OpenFGA and SpiceDB; service-to-service authentication with mTLS and workload identity; multi-tenant isolation; account recovery and fraud; and a capstone auth service.

sessions vs tokens · OAuth 2.1 and OIDC · JWTs · passkeys and MFA · RBAC, ABAC, ReBAC · Zanzibar · service-to-service auth · multi-tenant isolation · recovery and fraud · capstonesenior → staff · backend and platform engineers who own identity or permissions
sessions and tokensServer sessions, cookies, bearer tokens, refresh tokens, and where each belongs.
OAuth and OIDCAuthorisation code with PKCE, client credentials, device flow, ID tokens.
JWTsSigning, validation, algorithms, key rotation, revocation.
strong authPasskeys, WebAuthn, TOTP, step-up authentication.
authorisationRBAC, ABAC, ReBAC, Zanzibar tuples, policy engines.
machinesmTLS, SPIFFE, workload identity, token exchange.
Built on Trust and CryptoMoney, Identity and Trust part 1 covered the client side; Cryptography (course 34) covers the primitives. Service Mesh covers mTLS operationally.