Session

Tailor Made: Dynamic Fine-Frained Authorization for API Traffic

Modern API access control requires authorization models that can adapt to real-time conditions and complex relationships. Learn how to move beyond static authorization methods that are complex to revoke, like API keys and tokens, and improve your security posture with dynamic access decisions.

We'll demonstrate how to implement fine-grained authorization at the gateway level by integrating OpenFGA with Envoy Gateway in Kubernetes, enabling context-aware access decisions at the edge of your system. 

With live demonstrations, we'll showcase how OpenFGA's Relationship-based Access Control (ReBAC) model can solve complex authorization challenges. For example, has your boss approved you to access confidential information about Project X?

We'll present three entertaining yet practical examples that showcase common multi-tenant SaaS challenges, B2B API access, and data-dependent authorization rules.

Erica Hughberg

Community Advocate at Tetrate

Atlanta, Georgia, United States

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top