← ALL SESSIONS
Tue Dec 8 · 10:30 AM BACKEND SESSION #53620

Full Stack Engineering : Identity, Access, and Zero Trust

Brian Sletten
Brian Sletten
FORWARD LEANING SOFTWARE ENGINEER @ BOSATSU CONSULTING
01 / ABOUT THIS SESSION

A standalone workshop on the identity layer of modern systems — the
cryptographic substrate that secures every API call, every
service-to-service connection, and every user session. We'll cover
OAuth 2.0 and OpenID Connect in depth, JWT pitfalls that have caused
real production breaches, modern session security with DPoP and
sender-constrained tokens, passkeys and WebAuthn, service-to-service
authentication patterns, and authorization beyond simple
role-checking. Two short hands-on exercises, several real breach case
studies, and a focus on the misconfigurations that actually cause
incidents.

Backend and full-stack developers who write code that handles tokens,
architects designing how services authenticate each other, and
security engineers who review the above. You should be comfortable
with HTTP and basic cryptographic vocabulary (public/private key,
signature, hash). You don't need prior OAuth experience — the
workshop explains everything before using it. Anyone whose response
to “explain OAuth flows” is “I always have to look it up” will get a
lot out of this.

02 / SESSION DETAILS
FORMAT
90-minute session
TRACK
BACKEND
All signal.
Zero fluff.
DECEMBER 7 - 10, 2026 · OPAL SANDS RESORT · CLEARWATER, FL