What you'll learn:
- Secure ASP.NET Core apps with OAuth2, OpenID Connect and JWT.
- Implement Client Credentials, PKCE and On Behalf Of flows.
- Manage secrets safely using Managed Identity and Workload Identity.
- Validate and use access, ID and refresh tokens in real apps.
- Design secure API, microservice and AI agent architectures.
Mastering modern application security is now essential for anyone building APIs, cloud services or AI driven applications. This course gives you a practical, hands on path to understanding authentication, authorisation and identity in ASP.NET Core.
You will learn how real world identity flows work, how to secure your APIs, how to handle users safely, and how to protect services talking to each other in distributed systems.
This course is designed for developers who want a strong, practical understanding of OAuth2, OpenID Connect, JWTs, PKCE, secrets management, delegated access and externalised policy-based authorisation.
What you will learn:
• The fundamentals of modern authentication and authorisation
• How identity actually flows through an application
• How JSON Web Tokens are structured, decoded and validated
• How to issue and inspect tokens using tools like Postman
• How to secure service to service communication with the Client Credentials Flow
• How to call protected APIs using C sharp and bearer tokens
• How to validate JWTs manually when you are not using ASP.NET Core middleware
• Why OpenID Connect is required for user authentication
• How ID tokens work and where they fit in the login process
• When to use OAuth and when to use OpenID Connect
• How the Authorisation Code Flow with PKCE protects mobile and browser based apps
• How to implement PKCE inside ASP.NET Core
• How to use refresh tokens safely
• How to call APIs on behalf of the signed in user
• Modern secrets management in the cloud
• How Managed Identity and Workload Identity remove the need for stored secrets
• How delegated authorisation works using the On Behalf Of Flow
• How to design upstream and downstream API security
• How to build policy based authorisation using PDP and PEP patterns
Throughout the corse you will work with Auth0 and Microsoft Entra ID to implement various authentication scenarios. We will also see how a modern Policy Decision Point pattern is implemented so easily using Amazon Verified Permissions.
Please bear in mind that in this third edition of the course, ASP.NET Identity Framework is not thaught, as the modern applications do not implement their own identity systems.
By the end of this course, you will understand modern identity flows with absolute clarity and have the confidence to design and secure applications using current industry standards.