To see our schedule with full functionality, like timezone conversion and personal scheduling, please enable JavaScript and go here.
09:00
09:00
30min
Registration and Coffee
Arena
09:00
30min
Registration and Coffee
Work Lab I
09:00
30min
Registration and Coffee
Work Lab II
09:00
30min
Registration and Coffee
Eatery
09:30
09:30
30min
IAM for AI: From "Eh, I?" to "I am."
Brian Campbell

A pragmatic look at "IAM for AI," showing how familiar tools like OAuth, and emerging work such as CIMD and ID-JAG, can meet AI’s needs without inciting revolution.

Arena
10:00
10:00
30min
Scaling Workload Identity Lifecycle Management with Standards
Pieter Kasselman, Dag Sneeggen

This session shares real world lessons learnt and gaps identified from using SPIFFE, OAuth 2.0, and mTLS to automate identity lifecycle management, OAuth client registration, sender-constrain tokens and eradicate secrets.

Arena
10:30
10:30
30min
Coffee break
Arena
10:30
30min
Coffee Break
Work Lab I
10:30
30min
Coffee Break
Work Lab II
10:30
30min
Coffee Break
Eatery
11:00
11:00
30min
Experience report from implementing OpenID4VC issuance and presentation specifications in Norway
Elias Botterli Sørensen

This team has been implementing and testing VC specification drafts for the last 3-4 years. Come to hear their story about lessons learned and challenges encountered, as I present results from interviewing five individuals with various backgrounds.

Arena
11:00
60min
Integrating the OIDF conformance suite into CI, what can go wrong
Mirko Mollik

Integrating the OIDF conformance suite into GitHub CI sounded easy—until it wasn’t. This talk shares real-world failures, CI-specific pitfalls, and hard-won lessons on turning flaky red tests into meaningful conformance signals.

Work Lab II
11:30
11:30
30min
Progress Report on Handling an Actionable Security Vulnerability
Michael B. Jones

University of Stuttgart security researchers discovered an actionable security vulnerability in mid-2024 in the audience values used for JWT Client Authentication. This presentation will delve into the details of what happened next and why.

Arena
12:00
12:00
60min
Lunch Break
Arena
12:00
60min
Lunch Break
Work Lab I
12:00
60min
Lunch Break
Work Lab II
12:00
60min
Lunch Break
Eatery
13:00
13:00
30min
Unconference Planning Wednesday

We assemble to plan the unconference slots in the afternoon.

Arena
13:30
13:30
90min
Unconference Sessions

Unconference Sessions

Arena
15:00
15:00
30min
Coffee Break
Arena
15:00
30min
Coffee Break
Work Lab I
15:00
30min
Coffee Break
Work Lab II
15:00
30min
Coffee Break
Eatery
15:30
15:30
90min
Unconference Sessions

Unconference Sessions

Arena
18:00
18:00
60min
Reception

Reception at Lancaster University Leipzig's Rooftop Terrace

Arena
09:00
09:00
15min
Registration and Coffee
Arena
09:00
15min
Registration and Coffee
Work Lab I
09:00
15min
Registration and Coffee
Work Lab II
09:00
15min
Registration and Coffee
Eatery
09:15
09:15
15min
Sponsor Welcome

A welcome from our main sponsor, Authlete

Arena
09:30
09:30
30min
Delegate SD-JWTs
Gareth Oliver

Discuss an extension to SD-JWTs(RFC9901) to support further delegation from the Holder to a Delegate Holder. This is done by allowing the KB-JWT to also be an SD-JWT, optionally with its own Key Binding.

Arena
09:30
30min
Expanding eIDAS2.0 Framework to include associated Agentic and Embodied Systems
Emily Genatowski

eIDAS2.0 framework expansion to include ID holders' affiliated autonomous systems could underpin transparency & accountability measures as we integrate Agentic & Embodied Systems into current sectors like banking, logistics, insurance & taxation.

Work Lab II
10:00
10:00
30min
Human and Workload Identities: Bridging the Gap with Transaction Tokens
Dmitry Telegin, Pieter Kasselman

In this talk, we will introduce the two emerging OAuth technologies related to workload identity, namely Transaction Tokens and SPIFFE Client Authentication, and demonstrate them working together.

Work Lab II
10:00
30min
SD-JWT: From Selective Disclosure to Zero Knowledge
Patrick Amrein, Christopher Meier

Extending the definition of the hash algorithm defined in SD-JWT allows zero knowledge proofs to be used on properties. Here we show how sigma protocols with Pedersen commitments could be added with almost no (structural) modifications to RFC-9901.

Arena
10:30
10:30
30min
Coffee Break
Arena
10:30
30min
Coffee Break
Work Lab I
10:30
30min
Coffee Break
Work Lab II
10:30
30min
Coffee Break
Eatery
11:00
11:00
30min
DPoP - Lessons learned and improvement proposals
Christian Bormann, Paul Bastian

DPoP adoption is accelerating, but some use-cases are challenging the specification's initial design assumptions and choices. In this session, we will discuss some of the friction points we have experienced, and propose potential solutions.

Arena
11:30
11:30
30min
Unconference Planning Thursday

We assemble to plan the unconference slots in the afternoon.

Arena
12:00
12:00
60min
Lunch Break
Arena
12:00
60min
Lunch Break
Work Lab I
12:00
60min
Lunch Break
Work Lab II
12:00
60min
Lunch Break
Eatery
13:00
13:00
90min
Unconference Sessions

Unconference Sessions

Arena
14:30
14:30
30min
Coffee Break
Arena
14:30
30min
Coffee Break
Work Lab I
14:30
30min
Coffee Break
Work Lab II
14:30
30min
Coffee Break
Eatery
15:00
15:00
60min
Unconference Sessions

Unconference Sessions

Arena
17:00
17:00
120min
City Tour

City Tour

Arena
19:00
19:00
180min
Conference Dinner

Dinner at Ratskeller

Arena
09:00
09:00
30min
Registration and Coffee
Arena
09:00
30min
Registration and Coffee
Work Lab I
09:00
30min
Registration and Coffee
Work Lab II
09:00
30min
Registration and Coffee
Eatery
09:30
09:30
30min
Attacks and Security Proofs for Authentication and Authorization Protocols
Pedram Hosseyni

We give an overview of formal methods, including mechanized approaches, and present our prior and ongoing work on finding attacks and carrying out proofs for authentication and authorization protocols.

Work Lab II
09:30
30min
Introducing Elicitation Concept of MCP for Secure Cross-domain Multi-hop API Calls in OAuth World
Takashi Norimatsu

This session explores the possibility of applying the concept of "Elicitation in URL mode", introduced in MCP, to the OAuth world to make cross-domain multi-hop API calls secure and compares it with the existing token-exchange based method.

Arena
10:00
10:00
30min
Browser Swapping – How to Hack & How to Fix?
Jonas Primbs

The rediscovered Browser Swapping attack threatens modern OAuth 2 and OpenID Connect deployments. This talk demonstrates how attackers exploit the vulnerability and how you can protect your systems in the short and long term.

Work Lab II
10:00
30min
From Draft to Deployment: Building a Production Ecosystem on Moving Standards
Mirko Mollik

Building the EUDI Wallet ecosystem means deploying production systems on evolving drafts. This talk shares lessons from OID4VC, interoperability gaps, and the security challenges that arise when standards change faster than deployments.

Arena
10:30
10:30
30min
Coffee Break
Arena
10:30
30min
Coffee Break
Work Lab I
10:30
30min
Coffee Break
Work Lab II
10:30
30min
Coffee Break
Eatery
11:00
11:00
30min
AI Agent Authentication and Authorization
Pieter Kasselman, Yaroslav Rosomakho, Brian Campbell

This talk explains why AI agents should be treated as workloads, not magical new identity subjects. It shows how existing standards such as SPIFFE, WIMSE, OAuth 2.0, and SSF applies to agent systems, while also identifying gaps.

Arena
11:00
30min
Understanding OAuth Session Fixation in Connector Ecosystems
Kaixuan Luo

Session fixation attacks affect certain OAuth-related standards but remain unexamined in mainstream OAuth 2.0 deployments. We identify 40+ vulnerable vendors in "connector ecosystems" for app integration and agentic AI, and propose mitigations.

Work Lab II
11:30
11:30
30min
Inmor: a new openid-federation trust anchor
Kushal Das

Inmor is an open-source Trust Anchor implementation for OpenID Federation 1.0, it is being developed with keeping performance and easy maintenance in mind, with Rust and Python, splitting the performance and ease of use for operators.

Arena
11:30
30min
Outcomes from the Quant-ID Project - PQC and QRNG in the Scope of OAuth and OIDC
Xenia Bogomolec

Quant-ID is a project funded by the BMFTR for researching quantum entropy and post-quantum cryptography in OAuth and OIDC, including analyses and implementations by four partner organizations. We would like to share some results with the community.

Work Lab II
12:00
12:00
60min
Lunch Break
Arena
12:00
60min
Lunch Break
Work Lab I
12:00
60min
Lunch Break
Work Lab II
12:00
60min
Lunch Break
Eatery
13:00
13:00
30min
Unconference Planning Friday

We assemble to plan the unconference slots in the afternoon.

Arena
13:30
13:30
90min
Unconference Sessions

Unconference Sessions

Arena
15:00
15:00
30min
Coffee Break
Arena
15:00
30min
Coffee Break
Work Lab I
15:00
30min
Coffee Break
Work Lab II
15:00
30min
Coffee Break
Eatery
15:30
15:30
60min
Unconference Sessions

Unconference Sessions

Arena
16:30
16:30
30min
Closing Ceremony

(not an actual ceremony)

Arena