
Zero-code SSO for legacy apps with an eBPF proxy
How to put single sign-on in front of an old internal app without changing it, and why the identity headers it receives must be stripped and re-stamped at the boundary.
5 posts

How to put single sign-on in front of an old internal app without changing it, and why the identity headers it receives must be stripped and re-stamped at the boundary.

Zero-code authentication puts sign-in and access checks in front of a service instead of inside it. How sidecars, proxies and kernel interception compare, and when to use an SDK.

SAML 2.0 and OpenID Connect both deliver single sign-on, in different shapes. How each one works, when to pick which, and what it takes to run both side by side.

Employees and customers both sign in, but the users, scale, lifecycle and sign-in methods differ. Here is how the two compare and when one platform fits both.

A vendor-neutral checklist for choosing an identity provider: protocols, sign-in methods, lifecycle, audit, data residency, key custody, AI agents and your exit plan.