
Access and refresh tokens: different lifetimes
How can you separate presenting an access token from exchanging a refresh token?
JWT
Find an answer. Explore it further.
Explore the topic mapMaterial language: English
1073 materials · page 13 of 90

How can you separate presenting an access token from exchanging a refresh token?
JWT

How can you assign OAuth client, resource-owner, and server responsibilities?
OAuth, OIDC, and external identity providers

How can you trace a PKCE code exchange without sharing the password with the app?
OAuth, OIDC, and external identity providers

How can you distinguish proof of sign-in from permission to call an API?
OAuth, OIDC, and external identity providers

How can you build a permission matrix for member roles?
Permissions and Ory Keto

How can you check feature availability using an active entitlement?
Subscriptions and payments

How can you express an access rule using request and resource attributes?
Permissions and Ory Keto

How can you explain access through user-object relationships?
Permissions and Ory Keto

How can you trace permission inheritance from an organization to a project?
Permissions and Ory Keto

How can you define owner and reader relationships for folders and documents?
Permissions and Ory Keto

How can you locate the policy enforcement point at an application boundary?
Ory Oathkeeper and policy enforcement

How can you justify business authorization inside the data operation?
Ory Oathkeeper and policy enforcement