Skip to main content

7 docs tagged with "app-security"

View all tags

Advanced security options

PAR, JAR, and rate limiting for LuxID Partners with elevated security requirements. PAR and JAR are informational only - not currently implemented by LuxID.

Calling LuxID reliably

Operational guidance for integrating with LuxID: timeouts, retries and backoff, idempotency, JWKS caching, and how to behave during a LuxID outage.

Client credentials

Viewing and rotating Client Secrets, and SAML signing certificate lifecycle in the LuxID Console.

Integration security checklist

A self-test checklist for LuxID Partners: what to verify in your own OIDC/OAuth 2.0 integration, and what LuxID enforces for you.

Protect your Application

Security checklist for LuxID integrations: HTTPS, PKCE, state/nonce, ID Token validation, token storage, open redirects, and anti-patterns to avoid.

Secure

Security guidance for LuxID integrations: application protection, session lifecycle, key management, and advanced options such as PAR and JAR.