Training Information
Duende Software's legendary training on Identity and Access Management was originally created by Dominick Baier and Brock Allen.
We're offering the training online/remotely as 6 half-day blocks in EU afternoons/US mornings, starting March 10.
Read more and sign up at sustainsys.com/training
05.03.2026 12:42
π 0
π 2
π¬ 0
π 0
Livestream: Are your access tokens really secure?
Are your APIs vulnerable? Explore JWT pitfalls, learn to prevent exploits, and compare JWTs vs. opaque tokens in this expert-led session.
The livestream starts NOW! π΄ Security you canβt prove isnβt security, itβs hope.
Stop relying on manual checks. Weβre showing you how to automate your security testing to ensure your API only accepts your trusted tokens.
π Join us now: duende.link/lsjwt26b
#OAuth2 #JWT #DotNet
03.03.2026 15:03
π 1
π 1
π¬ 0
π 0
Rate Limiting IdentityServer Endpoints
Learn why rate limiting Duende IdentityServer endpoints is usually unnecessary, and when you do need it. Explore a layered approach using network proxies, ASP.NET Core middleware, and customβ¦
Should you add rate limiting to your Duende IdentityServer deployment? π€
Our new article breaks down the why (and why not), plus 3 implementation options.
Read the full article π duende.link/87wrkjh
#dotnet #ASPNETCore #OAuth #OpenIDConnect
03.03.2026 18:30
π 0
π 1
π¬ 0
π 0
Null exceptions are costly. We are enforcing strict Nullable Reference Types across the IdentityServer API in .NET 10. The compiler catches bugs before you deploy.
The community deserves rigorous design.
Learn More: duende.link/bpicb
#aspnet #dotnet
04.03.2026 07:01
π 0
π 1
π¬ 0
π 0
The Big Picture
An overview of modern application architecture patterns and how OpenID Connect and OAuth 2.0 protocols implemented by IdentityServer solve authentication and API access challenges
Stability is a community asset. Aligning with the Microsoft LTS schedule provides a shared timeline for the industry. We can all plan, budget, and coordinate releases together.
Predictability helps the whole community function better.
Learn more: duende.link/bpicb
#aspnet #dotnet #LTS
26.02.2026 18:01
π 1
π 1
π¬ 0
π 0
MORE Essential HTTP Headers
In this video, we look deeper into critical security-related HTTP headers that can significantly strengthen your website's defenses.
What you'll learn in this video:
* X-Content-Type-Options:β¦
In this video, we look deeper into critical security-related HTTP headers that can significantly strengthen your website's defenses. Expect X-Content-Type-Options, Referrer-Policy:, X-FRAME-OPTIONS, Content Security Policy (CSP), ...
youtu.be/OztgrdMQG94 #dotnet #aspnetcore #SecurityTips
10.02.2026 21:30
π 0
π 1
π¬ 0
π 0
Jennifer Lawrence "What Do You Mean" #shorts
YouTube video by Quotes For Eternity
www.youtube.com/shorts/LRt3x...
06.02.2026 10:37
π 0
π 0
π¬ 0
π 0
Duende IdentityServer
The most flexible and standards-compliant OpenID Connect and OAuth framework for ASP.NET Core.
SaaS providers are black boxes. Duende gives you full source access. Step-through to understand exactly how it all works.
Learn More: duende.link/2swrhhw
#aspnet #aspnetcore #dotnet
05.02.2026 17:01
π 1
π 1
π¬ 0
π 0
Supply chain something something... not an issue - all focus back on AI!
30.01.2026 07:21
π 0
π 0
π¬ 0
π 1
BenchmarkDotNet - Open Source Sponsorship
Duende Software's latest Open Source Sponsorship goes to BenchmarkDotNet, a benchmarking library for .NET.
We're proud to announce that Duende Software's latest Open Source Sponsorship goes to #BenchmarkDotNet! π
Check out the full post for details on the project: duende.link/o55bmd
#dotnet
27.01.2026 13:01
π 1
π 1
π¬ 0
π 1
Going Passwordless - A Practical Guide to Passkeys in ASP.NET Core - Maarten Balliauw
YouTube video by NDC Conferences
Recording of my talk on passkeys in #aspnetcore at NDC Copenhagen is up! #dotnet
Also includes a pointer on how to add passkeys to Razor Pages for folks who aren't on the #Blazor train.
www.youtube.com/watch?v=P7eb... #dotnet
20.01.2026 20:15
π 10
π 5
π¬ 0
π 0
Duende Resolution: Don't Store Tokens in the Browser. π
Browser tokens are an XSS risk. Secure your SPAs and Blazor WASM apps with the Duende BFF framework, the best way to handle protocol interactions and token management safely.
β‘οΈ duende.link/bff4b1b
06.01.2026 20:02
π 1
π 1
π¬ 0
π 0
Join the Duende Insiders Discord Server!
Check out the Duende Insiders community on Discord β hang out with 42 other members and enjoy free voice and text chat.
The Duende Product Insiders program is a private technical channel for partnership. Discuss Identity Strategy, Architecture, and Deployment Nuances directly with Duende experts. Stop guessing, start collaborating. π
β‘οΈ duende.link/discord
05.01.2026 20:02
π 0
π 1
π¬ 0
π 0
Duende Product Insiders
We invite you to join a deeply technical, standards-driven community to help shape the future of .NET security and identity.
For devs who care about identity π¨, Product Insiders get:
- Early access to features.
- Deep collaboration with Duende leaders.
- Direct influence on .NET identity & security.
Where standards meet code. Apply: duende.link/insiders
#DuendeInsiders #SecurityExperts
30.12.2025 19:02
π 0
π 1
π¬ 0
π 0
Secure frontend apps with the BFF Pattern
Secure frontend apps with the Backend for Frontend (BFF) pattern. Simplify token management and boost security using Duende BFF v4, with multi-frontend support.
BFF v4: You can't secure what you can't see.
OpenTelemetry is baked right in for end-to-end observability of your auth journey (redirect, token exchange, API calls).
duende.link/bff4b1b
#OpenTelemetry #Observability #DuendeBFF #Diagnostics #Tracing
29.12.2025 19:01
π 1
π 2
π¬ 0
π 0
Join the Duende Insiders Discord Server!
Check out the Duende Insiders community on Discord β hang out with 42 other members and enjoy free voice and text chat.
Your opinion on that tricky DPoP implementation? We want it. Duende Product Insiders is the high-signal, zero-noise channel for advanced .NET identity and security discussions. Join Duende's Product Insiders.
β‘οΈ duende.link/discord
#dotnet #ZeroNoise #Identity
22.12.2025 08:01
π 0
π 1
π¬ 0
π 0
Join the Duende Insiders Discord Server!
Check out the Duende Insiders community on Discord β hang out with 42 other members and enjoy free voice and text chat.
Identity developers, lead the way! Join Duende Product Insiders: Directly influence the roadmap, get early feature access, and collaborate with senior experts. Your expertise is needed.
Apply today: duende.link/discord
#DuendeInsiders #SecurityExperts
18.12.2025 08:01
π 1
π 2
π¬ 0
π 0
Duende BFFv4 is now available
Duende BFFv4 is now available! Learn about multi-frontend, simplified security, and unlock end-to-end visibility with OpenTelemetry.
π‘οΈ BFF v4: Frontend Security Simplified
Frontend devs shouldn't handle tokens or refresh cycles. BFF keeps security on the server, eliminating XSS risks.
v4 adds multi-frontend support for operational sanity. Ditch the token burden entirely.
β‘οΈ duende.link/bff4b0b
19.12.2025 08:00
π 1
π 3
π¬ 0
π 0
Happy Holidays from the Duende Team! π
As the year winds down, we want to thank our amazing community for trusting Duende Software to secure your applications. We wish you and yours a wonderful holiday season filled with joy, rest, and peace.
Wishing you safe deployments and happy days!
17.12.2025 17:02
π 3
π 1
π¬ 0
π 0
Join the Duende Insiders Discord Server!
Check out the Duende Insiders community on Discord β hang out with 42 other members and enjoy free voice and text chat.
Stop wishing for a feature. Start building it with us. The Duende Product Insiders program is your channel for direct influence on the IdentityServer and BFF roadmap.
Join the Insiders: duende.link/discord
#DuendeSoftware #IdentityServer
16.12.2025 20:00
π 0
π 1
π¬ 0
π 0
Duende BFFv4 is now available
Duende BFFv4 is now available! Learn about multi-frontend, simplified security, and unlock end-to-end visibility with OpenTelemetry.
Duende BFF v4 is available! Architecturally, this is huge: you can now support multiple frontends from a single, robust backend. Plus, we've integrated OpenTelemetry for seamless end-to-end observability in your identity flow.
Simplify your stack: duendesoftware.com/blog/2025120...
11.12.2025 20:02
π 3
π 3
π¬ 0
π 0
6 Used Cars That Are Way Too Cheap
YouTube video by Doug DeMuro
youtube.com/shorts/fseUv...
10.12.2025 11:21
π 0
π 0
π¬ 0
π 0
Understanding the X-Content-Type-Options Header
Ever wondered how browsers determine what kind of content they're displaying? It's usually through the Content-Type header. But what happens when that's missing or incorrect? That's where MIME typeβ¦
Ever wondered how browsers determine what kind of content they're displaying? It's usually through the Content-Type header. But what happens when that's missing or incorrect? It can be a serious security risk!
Let's see how to fix this in #aspnetcore youtu.be/kSaSb2hBbyk #dotnet
08.12.2025 16:15
π 0
π 2
π¬ 0
π 0
GitHub - dotnet/try: Try .NET provides developers and content authors with tools to create interactive experiences.
Try .NET provides developers and content authors with tools to create interactive experiences. - dotnet/try
Farewell to try .NET a way to run code right in docs that allowed me to introduce a new set of developers and PMs to various security challenges and problems over 10 years.
It evolved from running lots of containers in weird isolation setups, all the way through to WASM.
03.12.2025 02:32
π 22
π 6
π¬ 2
π 0