Lab
Every lesson has a lab. Each one is a step-by-step walkthrough in your own tenant: you send real protocol requests, change real settings, and read the real events your tenant records.
88 labs run completely today and 100 run with some steps still waiting on platform features. Planned labs show exactly how they will run and what you can already try. Labs with automatic checks compare your tenant's own Audit records with the steps after you press Start, so progress needs a Beyond the Login account and a tenant you manage. The lab toolkit is the small command-line helper the labs use.
Sign in to track your progress. Log in or create an account.
Identity fundamentals
LessonEstablishing an identity
LessonDeciding what someone can do
- Least privilege for Ben, enforced on the serverPartly ready
LessonStaying signed in
- Watch a session start, change identifier and endPartly ready
LessonTrust across systems
LessonHistory of SSO
Identity and trust
LessonWhat proofing establishes
- Resolve a patient to one record and record what proofing establishedPartly readyIncludes a simulation
LessonProofing methods
- Compare what each proofing method really provesPlannedIncludes a simulation
LessonSecrets and key pairs
Authentication methods
LessonPasswords and PINs
- See what the tenant does with a passwordPartly ready
LessonCodes, links, and approval prompts
- Sign in by email link, email code and authenticator codePartly readyIncludes a simulation
OAuth 2.0
LessonTrust boundaries
LessonCorrelating requests and responses
- Keep a pending transaction per session and check who answeredPartly readyIncludes a simulation
LessonErrors and denied access
- Handle denial, rejection and a lost response, then run the complete exchangeReadyIncludes a simulation
LessonClient authentication methods
- Hold a client to one authentication methodPartly ready
LessonToken introspection
LessonToken revocation
LessonBrowser applications
LessonBackends for frontends
LessonToken theft and replay
- Measure what limits a copied access tokenPartly ready
LessonRefresh token theft
LessonChecking the response issuer
- Build the collage app's callback issuer checkPartly readyIncludes a simulation
LessonProcessing and validating a request
- Validate, approve and enforce authorization details end to endPlannedIncludes a simulation
LessonTrust and validation
LessonErrors and failure cases
LessonWorking through an example
- Follow Ava's request through a two-hop token exchange chainPlannedIncludes a simulation
LessonDiscovering a protected resource
- Find an API's metadata starting from nothing but its addressPlannedIncludes a simulation
LessonLocating its authorization servers
- Go from an API's address to an access token for that APIPlannedIncludes a simulation
LessonTrust and metadata validation
- Make your discovery client refuse a document that describes a different APIPlannedIncludes a simulation
LessonThe purpose of a security profile
- Narrow your tenant to a written security profilePartly ready
LessonImplementing a client
LessonOperating and monitoring an integration
- Write a retry policy, test its rows, and read the signalsPartly readyIncludes a simulation
LessonFrom OAuth 1.0 to OAuth 2.0
- Compare a signed OAuth 1.0 request with a real bearer requestReadyIncludes a simulation
LessonThe password grant
LessonMigrating older integrations
- Inventory and migrate a legacy clientPartly ready
OpenID Connect
LessonState and nonce
LessonAuthentication errors
LessonExpiration and nonce checks
- Watch an ID token expire, separate iat from auth_time, and match nonces exactlyReadyIncludes a simulation
LessonWhen validation fails
- Produce the four kinds of validation failure and read them from your logsPartly readyIncludes a simulation
LessonProvider discovery
LessonSupporting several providers
- Run one relying party against two providers and stop a mix-up at the callbackPartly readyIncludes a simulation
LessonThe UserInfo endpoint
LessonLinking accounts
LessonLogin hints
LessonRP-initiated logout
LessonKey selection and validation failures
- Rotate a signing key against a cached key setPartly ready
LessonProcessing a login initiation request
- Build a safe login initiation endpointPartly readyIncludes a simulation
LessonPoll, ping, and push modes
- Compare CIBA delivery modesPlannedIncludes a simulation
LessonOpenID Provider responsibilities
- Audit your tenant as an OpenID ProviderPartly ready
LessonConformance testing
Identity governance
Identity security
LessonThreat modeling an identity system
- Threat-model your tenant's password resetPartly ready
LessonGetting around MFA
LessonHow attackers stay in
LessonLayered defenses and secure defaults
- Map each Cedar step to a layer in your tenantPartly ready