Secure APIs & Identities: JWT, mTLS, OAuth & Zero Trust

Protect the connections and identities that hold modern systems together. This track goes deep into API security and authentication, including the JWT vs mTLS question, OAuth/OIDC, and identity & access management (IAM). You'll secure cloud-native and Kubernetes workloads, manage secrets with short-lived, secretless credentials, enforce Zero Trust, and prepare for post-quantum cryptography. With digital sovereignty now a board-level topic, the track also covers encryption, key management, and keeping data under your control.

Cloud, API Security & Identity

What you can learn:

  • API security: secure REST & cloud-native APIs with the OWASP API Security Top 10
  • JWT vs mTLS: choose and combine the right authentication for your APIs
  • OAuth, OIDC & IAM: implement modern authentication, authorization & identity management
  • Zero Trust & secrets: enforce least privilege with secretless, short-lived credentials
  • Cloud-native & Kubernetes security: harden multi-cloud and container workloads
  • Digital & data sovereignty: encryption, key management and jurisdiction control
  • Post-quantum cryptography: prepare your crypto for the quantum era

Track Speakers Munich 2026

Track Speakers Berlin 2026

Track Program Munich 2026

Track Program Berlin 2026

Track Sessions Berlin 2026

Track Sessions Berlin 2026

View all sessions

Track Sessions Munich 2026

Track Sessions Munich 2026

View all sessions

FAQ

JWT vs mTLS: which should you use for API security?

JWTs carry identity and claims at the application layer; mTLS authenticates both endpoints at the transport layer. Many architectures combine them: mTLS for service-to-service trust and JWT for user/authorization context.

What is API security?

API security is the practice of protecting your APIs from abuse and data exposure through authentication, authorization, rate limiting, and input validation guided by the OWASP (Open Worldwide Application Security Project) API Security Top 10.

What's the difference between OAuth and OIDC?

OAuth 2.0 handles authorization (granting access); OpenID Connect (OIDC) adds an identity layer on top for authentication (verifying who the user is).

What is Zero Trust?

Zero Trust is a model that never trusts by default. Every request is authenticated, authorized, and given least-privilege, regardless of network location.

What is digital sovereignty?

Digital (or data) sovereignty is a principle about maintaining control over where data is stored, processed, and governed, and which jurisdiction's laws apply. This topic is increasingly critical for European organizations.

Enjoying the content?

Get the most out of IT Security Summit by becoming a free community member — curated resources, weekly newsletter, and member-only perks.

Weekly
Articles + tutorials

The reads you'd find if you had time

2× / mo
Live webinars

Experts you can actually ask

Monthly
Magazine + whitepapers

Deep dives worth your weekend

On-demand
Recordings + courses

Past conferences, ready when you are

AI-Powered Security
Harness AI for security automation, threat detection, and integrating AI-driven solutions into DevSecOps.

Cloud, API Security & Identity
Safeguard your cloud environments, APIs, and identities with advanced strategies.

DevSecOps
Integrate security into your DevOps processes with precision.

Pentesting, Vulnerability Management & Forensics
Advance your offensive security skills with cutting-edge penetration testing techniques.

Secure Coding & Software Development Lifecycle
Create secure software from the ground up by mastering secure coding practices and embedding security throughout the Software Development Lifecycle (SDLC).