Logto blog

Discover Logto and explore plenty of resources on authentication, authorization, identity management, open standards (OAuth, OpenID Connect, SAML), and more.

All posts

  • Cover
    JWT vs Session authentication
  • Cover
    Logto plan update: Optimizing token quotas to protect Logto from abuse and ensure reliability
  • Cover
    Understanding access tokens, refresh tokens, and ID tokens in OpenID Connect (OIDC) protocol
  • Cover
    What is OIDC: From why we need it to how it works
  • Cover
    Understanding Redirect URI and Authorization Code Flow in OpenID Connect (OIDC)
  • Cover
    SAML vs OIDC
  • Cover
    2024 Auth0's latest pricing explained and the best Auth0 alternatives
  • Cover
    What is client assertion in OAuth 2.0 client authentication?
  • Cover
    How to implement two-factor authentication (2FA) in Node.js with authenticator apps
  • Cover
    OTP bots: What they are and how to prevent attacks
  • Cover
    What is an authenticator app
  • Cover
    Multi-tenancy implementation with PostgreSQL: Learn through a simple real-world example
  • Cover
    What is AuthZ (Authorization)?
  • Cover
    Understand IAM, OAuth, OpenID Connect, SAML, SSO, and JWT in one article
  • Cover
    Logto product updates
  • Cover
    How to fix cookie size exceeded error by splitting cookies
  • Cover
    OIDC session management
  • Cover
    How to set up invitation-only sign-up in Logto
  • Cover
    How does one-time-password (OTP) work?
  • Cover
    Why you might see a 404 when signing in to your Logto-integrated app