© Mapbox, © OpenStreetMap

Speaker

Mathieu Santostefano

Mathieu Santostefano

Tech Expert / Symfony Core Team member

Tech Expert / Membre de la Core Team Symfony

Niort, France

Actions

As a developer for almost 15 years, I work with Symfony on a daily basis. Having worked with almost every version since 1.4, I have followed the evolution of the entire PHP ecosystem, eventually becoming an active contributor and joining the Symfony Core Team in 2021! My favorite topics are about i18n, authentication / authorization, performance and software architecture.

Still passionate about this community and its enthusiasm, I enjoy sharing my experience on stage at conferences such as SymfonyLive, SymfonyCon, API Platform Con or Confoo!

En tant que développeur depuis près de 15 ans, je travaille quotidiennement avec Symfony. Ayant utilisé presque toutes les versions depuis la 1.4, j'ai suivi l'évolution de l'ensemble de l'écosystème PHP, pour finalement devenir un contributeur actif et rejoindre la Core Team de Symfony en 2021 ! Mes sujets de prédilections sont l'i18n, l'authentification / authorisation, la performance et l'architecture logicielle.

Toujours passionné par cette communauté et son enthousiasme, j'aime partager mon expérience sur scène lors de conférences telles que SymfonyLive, SymfonyCon, API Platform Con ou Confoo !

Area of Expertise

  • Information & Communications Technology

Topics

  • PHP
  • Symfony
  • Cybersecurity
  • Artificial Intelligence
  • Web
  • Enterprise Software Architecture
  • Authentication
  • Authorization
  • OAuth 2.0 and OIDC
  • web
  • Web Development
  • api

Sessions

Painless authentication with Access Tokens en

Via some simple but real scenarios, we will discover the power of the new AccessToken Authenticator shipped in Symfony 6.2. For example, we are developing a SaaS product, which exposes a private API. Our users can register many applications into their accounts, for each one we will generate an API Token that users must inject in their requests. Now, with a pinch of YAML and a dash of PHP, we will be able to authenticate users from their API Token. In this talk, I will show you how it also works with JWT and some other exotic tokens!

Symfony, Mercure, and an LLM raise a chat(bot). en fr

For several years now, we have known how to create chats between two human users. With the advent of LLMs, we are led to design these same chats but between a human and an LLM. Let's see together how to leverage proven software components, combined with recent AI technologies, to create a real-time chat between a human user and an LLM. On the technical agenda: Symfony AI, Mercure, and SSE client in PHP.

Mercure, SSE, API Platform et un LLM élèvent un chat(bot) en fr

Voilà plusieurs années que l'on sait bien faire des chats entre 2 utilisateurs humains. Avec l'arrivée des LLMs, nous sommes ammenés à concevoir ces mêmes chats mais entre un humain et un LLM.
Voyons ensemble comment tirer partie de briques logicielles éprouvées, aliées aux récentes technologies d'IA pour parvenir à créer un chat temps réel entre un utilisateur humain et un LLM.
Au programme technique: Symfony AI, Mercure et client SSE en PHP

APIs protected, the modern way en fr

Protecting an API hasn't always been easy, but in recent years authentication has become standardized, and modern, robust solutions have emerged.

You may have come across Oauth2, OIDC, SAML, JWT keywords in the past years. These are the technologies that will form the foundations for securing your APIs. Then, how to protect your resources from abuse? Rate limiting, IP/Geo blocking, WAF, etc.
We're going one step further, with dedicated tools and brand new features of Symfony, that will save us the trouble of implementing such protocols and techniques.

Whether you're developing your own API, or a customer of an external API, come and learn how to work securely without losing your head!

Des APIs protégées sans perdre la tête en fr

La protection d'une API n'a pas toujours été facile, mais ces dernières années, l'authentification a été standardisée. Des solutions modernes et robustes ont vu le jour.

Vous avez peut-être rencontré les mots-clés Oauth2, OIDC, SAML, JWT au cours des dernières années. Ce sont les technologies qui sont les fondations de la sécurisation de vos API. De plus, comment protéger vos ressources des abus ? Restrictions d'usage, IP/Geo blocage, WAF, etc. Mais nous irons plus loin, avec des outils adaptés et les toutes nouvelles fonctionnalités de Symfony, qui nous éviteront d'avoir à implémenter des protocoles et techniques complexes en PHP.

Que vous développiez votre propre API ou que vous soyez client d'une API externe, venez apprendre à travailler en toute sécurité sans perdre la tête !

Translate the UIs of your Sylius applications efficiently en

Leverage Symfony’s Translation component to efficiently translate the UIs of your Sylius applications.

This talk will cover best practices, tips, and tricks for managing translations in Sylius, ensuring your application is accessible to a global audience.

From translation keys extractions to SaaS tools used to translate your static texts, this talk will cover everything you need to know to efficiently translate the UIs of your Sylius applications.

Unveil Symfony AI en

Last July 2025, the Symfony AI was launched as an initiative, just like Symfony UX, to help developers integrate AI into their apps with ready-to-use components and bundles.
In this talk, let’s discover Symfony AI’s origins, explore its components, and learn how to use them with any AI platform. We’ll also cover how to get started using it in your PHP apps and contribute to the project!

Des APIs sécurisées sans perdre la tête fr

La sécurisation d’une API n’a pas toujours été facile, mais ces dernières années, l’authentification a été standardisée. Des solutions modernes et robustes ont vu le jour.

Vous avez peut-être rencontré les mots-clés Oauth2, OIDC, JWT, Rate Limiting au cours des dernières années. Ce sont les technologies qui sont les fondations de la sécurisation de vos API. Mais nous irons plus loin, avec des outils comme Keycloak et de toutes nouvelles fonctionnalités de Symfony, qui nous éviteront d’avoir à implémenter des protocoles complexes en PHP.

En tant que développeur d’API, vous découvrirez comment améliorer la sécurité de votre API de façon moderne, en utilisant les bons outils. En tant que consommateur d’API, vous découvrirez comment interagir en toute sécurité avec des API externes.

Que vous développiez votre propre API ou que vous soyez client d’une API externe, venez apprendre à travailler en toute sécurité sans perdre la tête !

API Platform Conference 2026

Des APIs sécurisées sans perdre la tête

September 2026 Lille, France

ConFoo 2026

Unveil Symfony AI
APIs secured, the modern way

February 2026 Montréal, Canada

SymfonyCon Amsterdam 2025

Workshop - Mastering OOP & Design Patterns

November 2025 Amsterdam, The Netherlands

API Platform Conference 2025

Mercure, SSE, API Platform et un LLM élèvent un chat(bot)

September 2025 Lille, France

SymfonyOnline June 2025

Mastering OOP & Design Patterns

June 2025

SyliusDays 2025

Translate the UIs of your Sylius applications efficiently

May 2025 Asnières-sur-Seine, France

SymfonyLive Paris 2025

Lightning Talk - L'année des agents GenAI

March 2025 Paris, France

SymfonyCon Brussels 2023

Workshop - From 0 to master the translation of your app

December 2023 Brussels, Belgium

SymfonyLive Paris 2023

Lightning Talk - Au moins 4 façons de définir un DateTime avec un Time réinitialisé

March 2023 Paris, France

SymfonyCon Disneyland Paris 2022

Painless authentication with Access Tokens

November 2022 Marne La Vallée, France

SymfonyWorld 2020

Internationalize your Symfony application

December 2020

SymfonyLive Paris 2019

Des images au cordeau pour vos applications Symfony

March 2019 Paris, France

PHP Tour Montpellier 2018

Traduire efficacement une application Symfony

May 2018 Montpellier, France

SymfonyLive Paris 2018

Traduire efficacement une application Symfony

March 2018 Paris, France

Mathieu Santostefano

Tech Expert / Symfony Core Team member

Niort, France

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top