
Zero-code SSO for legacy apps with an eBPF proxy
How to put single sign-on in front of an old internal app without changing it, and why the identity headers it receives must be stripped and re-stamped at the boundary.
Protecting applications and services without changing their code.

How to put single sign-on in front of an old internal app without changing it, and why the identity headers it receives must be stripped and re-stamped at the boundary.

Zero-code authentication puts sign-in and access checks in front of a service instead of inside it. How sidecars, proxies and kernel interception compare, and when to use an SDK.

How services prove who they are to each other with mTLS, workload identity and short-lived certificates, and why a shared static API key is the wrong tool for the job.