Om sesjonen
A greenfield dream of one API front door to access all services crashed through four major iterations. Every conversation waded through the IAM alphabet-soup of acronyms. It should be just who, what and where. Easy, right?
Signicat grew through acquisitions and dreamed of product-led growth with self-service APIs. But real-world scalability, security, compliance, and technical debt threatened delivery of that vision.
This technical retrospective will cover the battles won and lost with cache drift, latency spikes, risk profiles, organizational competency gaps and naive OIDC implementations, token leakage exposure and secret sprawl while serving millions of users per day. The team pieced together known standards and patterns, eliminating tokens from browsers (BFF), client secrets from microservices (SPIFFE) and extended OIDC with mTLS support (RFC 8705).
This session delivers a blueprint for platform engineers and identity architects who need to deliver invisible, "secure-by-default" authorization for developer friendly APIs across on-prem and public clouds to serve people today and AI agents tomorrow