Duende Software's Avatar

Duende Software

@duendesoftware.com

Duende Software. Makers of Duende IdentityServer and the BFF security framework. https://duendesoftware.com https://youtube.com/@duendesoftware

271
Followers
6
Following
402
Posts
03.09.2024
Joined
Posts Following

Latest posts by Duende Software @duendesoftware.com

Preview
Duende Product Insiders We invite you to join a deeply technical, standards-driven community to help shape the future of .NET security and identity.

The Duende Product Insiders program is our dedicated listening channel. We share early design documents and prototypes with the Duende Insiders to get honest and impactful feedback.

Help us build the solutions that empowers you and your peers.

Apply here: duende.link/insiders

06.03.2026 17:03 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Application Modernization Future-proof your apps with Duende's identity modernization. Get better security and control while preserving your existing identity logic.

Licensing isn't just legal paperwork; it’s a safety net for your team. Knowing that Duende engineers are maintaining the Identity SDK allows you to focus on what you love building.

We carry the weight of standards and compliance so you don't have to: duende.link/appmodb

#aspnet #dotnet

06.03.2026 09:02 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
- YouTube
- YouTube Enjoy the videos and music you love, upload original content, and share it all with friends, family, and the world on YouTube.

Content Security Policy (CSP) helps against cross-site scripting attacks! πŸ₯·

Learn how this powerful HTTP header is your next line of defense. We break down the directives and show you how to implement them.

Watch here: youtu.be/B0Rz_qiQAWo #dotnet #securitytips

05.03.2026 14:35 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Duende Product Insiders We invite you to join a deeply technical, standards-driven community to help shape the future of .NET security and identity.

Standards evolve because people participate. Insiders help shape the roadmap. When we prototype new features, we ask the community how they fit real-world architectures.

Apply: duende.link/insiders

#aspnet #dotnet

05.03.2026 07:00 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Application Modernization Future-proof your apps with Duende's identity modernization. Get better security and control while preserving your existing identity logic.

Nothing is more frustrating than a tool that fights you. We respect your expertise. Our architecture gives you the control to build exactly what you need, without the black-box limitations that make work a headache.

We empower the security architect.

Learn more πŸ‘‰οΈ duende.link/appmodb

#aspnet

04.03.2026 15:02 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

Null exceptions are costly. We are enforcing strict Nullable Reference Types across the IdentityServer API in .NET 10. The compiler catches bugs before you deploy.

The community deserves rigorous design.

Learn More: duende.link/bpicb

#aspnet #dotnet

04.03.2026 07:01 πŸ‘ 0 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Rate Limiting IdentityServer Endpoints Learn why rate limiting Duende IdentityServer endpoints is usually unnecessary, and when you do need it. Explore a layered approach using network proxies, ASP.NET Core middleware, and custom…

Should you add rate limiting to your Duende IdentityServer deployment? πŸ€”

Our new article breaks down the why (and why not), plus 3 implementation options.

Read the full article πŸ‘‰ duende.link/87wrkjh

#dotnet #ASPNETCore #OAuth #OpenIDConnect

03.03.2026 18:30 πŸ‘ 0 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Livestream: Are your access tokens really secure? Are your APIs vulnerable? Explore JWT pitfalls, learn to prevent exploits, and compare JWTs vs. opaque tokens in this expert-led session.

The livestream starts NOW! πŸ”΄ Security you can’t prove isn’t security, it’s hope.

Stop relying on manual checks. We’re showing you how to automate your security testing to ensure your API only accepts your trusted tokens.

πŸ”— Join us now: duende.link/lsjwt26b

#OAuth2 #JWT #DotNet

03.03.2026 15:03 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Livestream: Are your access tokens really secure? Are your APIs vulnerable? Explore JWT pitfalls, learn to prevent exploits, and compare JWTs vs. opaque tokens in this expert-led session.

Join our livestream in 1 HOUR! πŸ“£ JWTs are the industry standard, but are they right for your specific architecture?

We’re breaking down the strategic trade-offs between JWTs vs. Opaque Tokens.

Be there: duende.link/lsjwt26b

#OAuth2 #JWT #DotNet

03.03.2026 14:02 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

.NET 10 performance benefits everyone. By optimizing IdentityServer for the new runtime, we pass those gains down to every application that relies on us.

Reduced CPU cycles in auth mean lower cloud bills for the entire community.

Learn more: duende.link/bpicb

#aspnet #aspnetcore #dotnet

02.03.2026 18:03 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Livestream: Are your access tokens really secure? Are your APIs vulnerable? Explore JWT pitfalls, learn to prevent exploits, and compare JWTs vs. opaque tokens in this expert-led session.

Tomorrow! Join our livestream on March 3rd.

Stop relying on manual checks. We’re showing you how to automate your security testing to ensure your API only accepts your trusted tokens.

πŸ”— March 3rd. Be there: duende.link/lsjwt26b

#OAuth2 #JWT #DotNet

02.03.2026 12:00 πŸ‘ 1 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Preview
Duende IdentityServer v7.4 is now available Duende IdentityServer v7.4 is here! Full compatibility with .NET 10 LTS, plus a standards-based foundation for agentic AI systems and MCP.

Stability is a community asset. Aligning with the Microsoft LTS schedule provides a shared timeline for the industry. We can all plan, budget, and coordinate releases together.

Predictability helps the whole community function better.

Learn More: duende.link/is74b0b

#aspnet #dotnet #LTS

27.02.2026 19:01 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Livestream: Are your access tokens really secure? Are your APIs vulnerable? Explore JWT pitfalls, learn to prevent exploits, and compare JWTs vs. opaque tokens in this expert-led session.

JWTs are the industry standard, but are they right for your specific architecture?
We’re breaking down the strategic trade-offs between JWTs vs. Opaque Tokens.

πŸ”— March 3rd. Be there: duende.link/lsjwt26b

#OAuth2 #JWT #DotNet

27.02.2026 14:02 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Security Lingo Explained: JWT JWT (JSON Web Token) is an internet standard data format and an essential element of OAuth 2.0 and OpenID Connect.

Expand your security lingo with our latest article on JWT (JSON Web Token), pronounced "jot"! πŸͺ

Learn what a JWT is, and its role in OAuth 2.0/OpenID Connect: duende.link/q2nage

#dotnet #securitylingo

27.02.2026 08:01 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
The Big Picture An overview of modern application architecture patterns and how OpenID Connect and OAuth 2.0 protocols implemented by IdentityServer solve authentication and API access challenges

Stability is a community asset. Aligning with the Microsoft LTS schedule provides a shared timeline for the industry. We can all plan, budget, and coordinate releases together.

Predictability helps the whole community function better.

Learn more: duende.link/bpicb

#aspnet #dotnet #LTS

26.02.2026 18:01 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Duende IdentityServer Overview of Duende IdentityServer framework for OpenID Connect and OAuth 2.x protocols, covering extensibility, security scenarios, licensing, and support.

SaaS providers are black boxes. Duende gives you full source access.

Step-through to understand exactly how it all works. πŸ”οΈ

Explore: docs.duendesoftware.com/identityserv...

#aspnet #dotnet

26.02.2026 14:30 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Duende Product Insiders We invite you to join a deeply technical, standards-driven community to help shape the future of .NET security and identity.

Identity is hard. Building it alone is harder. 🀝

Join our private Insiders Discord to talk BFF, Passkeys, and OpenTelemetry with the Duende team and senior devs worldwide. A no-fluff zone for mission-critical systems.

Apply: duende.link/insiders

#IdentityServer #DotNet

25.02.2026 15:02 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Security Lingo Explained: DPoP DPoP (Demonstrating Proof of Possession) uses asymmetric keys to secure OpenID Connect and OAuth against token replay attacks.

DPoP is not shorthand for Danish pop music. 🎢

Instead, Demonstrating Proof of Possession (DPoP) is used to fight back against token replay attacks in OpenID Connect and OAuth.

Security Lingo Explained: duende.link/lgodpop

#SecurityLingo #dotnet

25.02.2026 06:45 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
It's Probably DNS - Can You Dig It? How to use the powerful dig utility to quickly diagnose and troubleshoot common DNS issues like incorrect A/AAAA records, CNAME problems, and TTL cache issues for your web applications.

Stop saying "It's probably DNS" when things go south. 🧭

Fix it faster, and learn why the professional networking community favors dig over nslookup for DNS troubleshooting: duende.link/y26224

#dotnet #dns

24.02.2026 17:03 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Livestream: Are your access tokens really secure? Are your APIs vulnerable? Explore JWT pitfalls, learn to prevent exploits, and compare JWTs vs. opaque tokens in this expert-led session.

Should you blindly trust JWTs for accessing APIs? 😟

You’ve got OAuth 2.0 and #JWT's, but a single misconfiguration in your library can leave you wide open. Join Wesley to see why "standard" validation isn't always enough.

πŸ”— Be there on March 3rd: duende.link/lsjwt26b

#OAuth2 #DotNet

24.02.2026 11:01 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Application Modernization Future-proof your apps with Duende's identity modernization. Get better security and control while preserving your existing identity logic.

Nothing is more frustrating than a tool that fights you. We respect your expertise.

Our architecture gives you the control to build exactly what you need, without the black-box limitations that make work a headache.

We empower the security architect.

Learn More: duende.link/appmodb

#aspnet

23.02.2026 20:02 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Duende IdentityServer v7.4 is now available Duende IdentityServer v7.4 is here! Full compatibility with .NET 10 LTS, plus a standards-based foundation for agentic AI systems and MCP.

#dotnet 10 performance benefits everyone. By optimizing IdentityServer for the new runtime, we pass those gains down to every application that relies on us.

Reduced CPU cycles in auth mean lower cloud bills for the entire community.

Learn more: duende.link/is74b0b

23.02.2026 14:00 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Duende IdentityServer The most flexible and standards-compliant OpenID Connect and OAuth framework for ASP.NET Core.

Don't rely on status pages during an outage. Commercial licenses include priority support. 🀝

Direct assistance from the maintainers is a necessity for mission-critical infra.

#aspnet #dotnet

Learn More:

20.02.2026 19:00 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Stability is a community asset. Aligning with the Microsoft LTS schedule provides a shared timeline for the industry. We can all plan, budget, and coordinate releases together.

Predictability helps the whole community function better. πŸ’ͺ

#aspnet #aspnetcore #dotnet

20.02.2026 13:01 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
- YouTube
- YouTube Enjoy the videos and music you love, upload original content, and share it all with friends, family, and the world on YouTube.

Cross-Site Scripting (XSS) is one of the most common web attacks! πŸ’₯

Learn the 3 types (Reflected, Stored, DOM-based), the main developer mistake, and how to defend your app with #ASPNETCore and proper HTML escaping.

youtu.be/Zqvw6XR9Lug #XSS #WebSecurity #dotnet

19.02.2026 16:02 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
BenchmarkDotNet - Open Source Sponsorship Duende Software's latest Open Source Sponsorship goes to BenchmarkDotNet, a benchmarking library for .NET.

Duende Software's latest Open Source Sponsorship goes to #BenchmarkDotNet! πŸš€
It's a great project to help analyze (and maintain) performance of #dotnet code.

Check out the full post for details on the project: duende.link/o55bmd

19.02.2026 14:30 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Security you can’t prove isn’t security, it’s hope.

Stop relying on manual checks. We’re showing you how to automate your security testing to ensure your API only accepts your trusted tokens.

πŸ”— March 3rd. Be there: duende.link/lsjwt26b

#OAuth2 #JWT #DotNet

19.02.2026 07:01 πŸ‘ 3 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Duende Product Insiders We invite you to join a deeply technical, standards-driven community to help shape the future of .NET security and identity.

Your best defense is collective knowledge. The Insiders' community acts as a radar for emerging .NET security and identity trends.

Don't wait for the blog post; define best practices with us today.

Apply: duende.link/insiders

#aspnet #dotnet

18.02.2026 15:02 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Securing OpenAPI and Swagger UI with OAuth in .NET 10 See how to secure an ASP.NET Core API with JWT Bearer tokens, set up the solution to generate an OpenAPI specification, and then secure calls from a Swagger UI to authenticate against Duende’s…

Secure your #ASPNETCore APIs! πŸ›‘οΈ

Learn how to integrate OAuth/OpenID Connect with JWT Bearer tokens, generate an OpenAPI spec, and secure calls from your #SwaggerUI using Duende IdentityServer.

duende.link/4tqhgh4

#dotnet #webdev

18.02.2026 07:00 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
HttpOnly Cookies with IdentityServer
HttpOnly Cookies with IdentityServer Cookies are essential for web applications, but did you know they can be vulnerable to JavaScript attacks? In this video, we look at the HttpOnly flag and show you how to protect your cookies from…

Cookies are essential for web applications, but did you know they can be vulnerable to JavaScript attacks? In this video, we look at the HttpOnly flag and show you how to protect your cookies from malicious JavaScript access!

youtu.be/ZMDBX9T8Z7o

#SecurityTips #dotnet

17.02.2026 23:01 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0