← ALL SESSIONS
Tue Dec 8 · 8:30 AM ARCHITECTURE SESSION #53247

Identity, Tokens, and Access Control

Daniel Hinojosa
Daniel Hinojosa
INDEPENDENT CONSULTANT
01 / ABOUT THIS SESSION

Authentication and authorization are foundational concerns in modern systems, yet they’re often treated as afterthoughts or re-implemented inconsistently across services.

In this talk, we’ll explore Keycloak, an open-source identity and access management system, and how it fits into modern application architectures. We’ll break down what Keycloak actually does (and what it doesn’t), explain the role of JWTs and OAuth2/OpenID Connect, and examine how identity, trust, and access control are handled across distributed systems.

We’ll also compare Keycloak to secret management systems like Vault, clarify common misconceptions, and walk through integrations you will need with Spring, Quarkus, and other frameworks

By the end, you’ll understand when Keycloak is the right tool, how to integrate it cleanly, and how to avoid the most common architectural mistakes.

In this session, we will define what Keycloak is, its value, and how it integrates with your existing architecture. Here is the layout of the talk:

  • “Who are you?” vs “What are you allowed to do?”
  • Authentication vs Authorization vs Identity
  • Avoiding Rolling your Own Auth(n|z)
  • What is Keycloak
  • What isn't Keycloak
  • Core Concepts
  • Review of OAuth2, OpenID, JWT, and Tokens
  • Identity Federation
  • Difference between Keycloak and Vault
  • Where do we put it in architecture
  • Integration with Spring, Quarkus, and other Frameworks
  • Integration with other Architecture and Components
  • What to do on Monday Morning
02 / SESSION DETAILS
FORMAT
90-minute session
TRACK
ARCHITECTURE
All signal.
Zero fluff.
DECEMBER 7 - 10, 2026 · OPAL SANDS RESORT · CLEARWATER, FL