OAuth flows, mTLS, token design, zero-trust patterns, and securing APIs in regulated financial environments — the layered defence that satisfies regulators without sacrificing latency.
OAuth 2.1 flows, OpenID Connect, mutual TLS, JWT validation, the FAPI 2.0 profile, sender-constrained tokens, and the layered defence that secures regulated financial APIs.
CIBA, dynamic client registration, consent revocation, and the operational mechanics of TPP onboarding — the patterns that survive the SAMA audit and the peak transaction window.
Istio & Linkerd patterns for east-west mTLS, SPIFFE workload identity, certificate rotation, AuthorizationPolicy enforcement, and the zero-trust model that satisfies a SAMA audit without breaking payment latency SLAs.
FAPI 2.0 Baseline and Message Signing profiles, Pushed Authorisation Requests, DPoP proof verification, mTLS-bound access tokens, Keycloak 24 realm config, Kong and APIC enforcement, and the SAMA Open Banking security requirements that make each mandatory.
OWASP API Top 10 mitigation table, Kong OAS Validation and bot-detection plugin YAML, ModSecurity CRS 4.0 tuning for ISO 20022 payloads, and the SAMA cybersecurity framework controls that map to each vulnerability class.
Eliminating manual certificate spreadsheets from a regulated bank’s API estate: Vault PKI engine, cert-manager ClusterIssuers, zero-restart TLS rotation, RFC 8705 cert-bound OAuth tokens, and SAMA CSF alignment.