Logto blog

Discover Logto and explore plenty of resources on authentication, authorization, identity management, open standards (OAuth, OpenID Connect, SAML), and more.

All posts

  • Cover
    RBAC in practice: Implementing secure authorization for your application
  • Cover
    Logto is now SOC 2 Type II compliant!
  • Cover
    Logto cloud muti-region support - Japan region coming soon
  • Cover
    2025 Amazon Cognito's latest pricing explained and the best Amazon Cognito alternatives
  • Cover
    Simplify SAML app integration for developers
  • Cover
    How to use Logto for your Encore application
  • Cover
    Logto product updates
  • Cover
    What is B2B SaaS, and what will the post-SaaS era (2025+) with AI look like?
  • Cover
    Build a multi-tenant SaaS application: A complete guide from design to implementation
  • Cover
    HTTP status code 401 or 403? How authentication and authorization errors differ
  • Cover
    Logto product updates
  • Cover
    SSO vs SAML, explained for everyone
  • Cover
    What is one-time password (OTP)?
  • Cover
    What is refresh token rotation and why is it important?
  • Cover
    JWT signing algorithms overview
  • Cover
    JWT vs Session authentication
  • Cover
    Logto plan update: Optimizing token quotas to protect Logto from abuse and ensure reliability
  • Cover
    What is OIDC: From why we need it to how it works
  • Cover
    Understanding access tokens, refresh tokens, and ID tokens in OpenID Connect (OIDC) protocol
  • Cover
    Understanding Redirect URI and Authorization Code Flow in OpenID Connect (OIDC)