{
    "version": "https://jsonfeed.org/version/1",
    "title": "Curity Identity Server",
    "home_page_url": "https://curity.io",
    "feed_url": "https://curity.io/news-feed.json",
    "description": "Manage user identities with minimal coding from your team. Curity Identity Server handles the complexities of the leading identity and security standards, making them easier to use, customize and deploy.",
    "author": {
        "name": "@curityio"
    },
    "items": [
        {
            "id": "https://curity.io/news/curity-ai-and-api-security-dinner/",
            "content_html": "<p>Curity is partnering with Nordic APIs and Akamai for an upcoming event in Stockholm focused on securing the API layer as AI-driven interactions reshape digital systems.</p>\n<p>Taking place on May 7, the event brings together industry practitioners to discuss how organizations can adapt their architecture for a growing ecosystem of AI agents and autonomous services. As these agents act on behalf of users, managing identity, access and trust becomes more complex and critical.</p>\n<p>Curity will present a talk “A[P]I Security: Intelligent Access for Intelligent Agents,” led by Daniel Lindau, Principal Engineer - Director of Technical Enablement. The session will explore how to move beyond traditional access models by distinguishing between human and non-human actors and using intelligent tokens to enable a zero standing privilege approach.</p>\n<p>The program also includes a session from Akamai on real-world API security threats.</p>\n<p>The event will take place aboard a private evening cruise through the Stockholm Archipelago. Attendance is limited, with registration subject to confirmation.</p>\n<p><a href=\"https://nordicapis.com/events/api-security-dinner/\">Learn more and register here.</a></p>",
            "url": "https://curity.io/news/curity-ai-and-api-security-dinner/",
            "title": "Curity Joins Nordic APIs and Akamai for Stockholm Event on API Security in the Age of AI",
            "date_modified": "2026-03-31T11:40:03.264Z"
        },
        {
            "id": "https://curity.io/news/curity-identity-server-11-1/",
            "content_html": "<p>We’re happy to announce the release of Curity Identity Server 11.1, a minor update focused on improving flexibility, usability and stability across the platform.</p>\n<p>This release expands support for Ephemeral Clients, which can now operate as public clients and include additional OAuth capabilities such as redirect URI policies, JWKS-based authentication and ID token encryption.</p>\n<p>It also introduces more flexible alarm configuration, allowing better control over license expiration and connection-related alerts, along with a series of Admin UI improvements that streamline day-to-day management.</p>\n<p>Additional enhancements span authentication flows, APIs and system performance, making the platform more robust and easier to operate.</p>\n<p><a href=\"https://developer.curity.io/release/11.1.0/release-notes\">Read the release notes</a> to learn more.</p>\n<p>Curious to see how the Curity Identity Server can support your architecture? <a href=\"https://developer.curity.io/\">Start a free trial</a> to get hands-on or <a href=\"https://curity.io/contact/\">contact us for a demo</a>.</p>",
            "url": "https://curity.io/news/curity-identity-server-11-1/",
            "title": "Curity Identity Server 11.1 Released",
            "date_modified": "2026-03-24T09:15:57.741Z"
        },
        {
            "id": "https://curity.io/news/monica-enand-appointed-chair-of-board-curity/",
            "content_html": "<p>Large-scale adoption of agentic AI is driving transformational change across the identity market. As organizations manage both human and non-human identities at scale, modern identity infrastructure has become mission-critical. Curity’s application-centric identity platform is uniquely positioned to capture significant opportunity in this rapidly expanding global market.</p>\n<p>To support this next phase of growth, Curity is proud to welcome Monica Enand as Chair of the Board.</p>\n<p>Monica brings extensive experience from global technology scale-ups. In the identity space, she served as Chair of Auth0 during its high-growth phase leading up to its acquisition by Okta in 2021. She also brings deep operational leadership experience as Founder and CEO of Zapproved, where she led the company for 15 years through sustained growth and expansion.</p>\n<p>Her expertise in scaling technology businesses, driving global rollouts, and expanding in the U.S. market will be instrumental as Curity accelerates its growth.</p>\n<p>“Identity is becoming the defining control plane of the agentic world. It underpins the secure and responsible use of autonomous systems, including agentic AI. Having Monica join us to help maximize our potential in this rapidly evolving market is tremendously exciting,” said Gustaf Sahlman, CEO of Curity.</p>\n<p>Monica Enand commented:</p>\n<blockquote>\n<p>I am deeply impressed by Curity’s technology platform and its differentiated position in the market. I look forward to working closely with the board and management team to help accelerate the company’s growth.</p>\n</blockquote>",
            "url": "https://curity.io/news/monica-enand-appointed-chair-of-board-curity/",
            "title": "Monica Enand Appointed Chair of the Board at Curity",
            "date_modified": "2026-03-05T07:57:09.668Z"
        },
        {
            "id": "https://curity.io/news/curity-identity-server-11-0/",
            "content_html": "<p>We’re excited to announce the release of the Curity Identity Server 11.0. This new major version brings first-class support for dynamic, non-persisted OAuth clients - along with managed database schemas, SCIM groups and a rebuilt UI Kit.</p>\n<h2>Ephemeral Clients</h2>\n<p>The headline feature is Ephemeral Clients  with support for the Client Identity Metadata Document (CIMD) specification. The server can now handle third-party OAuth clients that are never persisted - they exist only for the duration of an interaction.</p>\n<p>Traditional OAuth requires pre-registering every client. That model breaks down when clients are short-lived or dynamically created - think AI agents and other transient workloads. Ephemeral Clients enable secure, standards-based client interactions without traditional client registration.</p>\n<h2>Managed Database Schemas</h2>\n<p>A new framework for database lifecycle management means all new schemas are now managed within a unified system (currently for JDBC data sources). This lays the foundation for simplified upgrades and consistent multi-tenant database handling going forward.</p>\n<h2>Entity Management and SCIM Groups</h2>\n<p>A new Entity Management subsystem provides a unified foundation for managing users, groups, and related entities. The User Management Service now supports the SCIM Groups endpoint and schema, and both SCIM and GraphQL APIs leverage a configured Account Manager when creating accounts.</p>\n<h2>New Curity UI Kit</h2>\n<p>The front-end customization experience has been reworked into a dedicated GitHub project. All templates and styles - including the Self-Service Portal - live in a single monorepo with a new React Component Library, pure CSS (replacing SASS), and clean separation between product and customization assets.</p>\n<p><a href=\"https://developer.curity.io/release/11.0.0/release-notes\">Read the release notes</a> to learn more.</p>\n<h2>Release Webinar</h2>\n<p><img src=\"https://images.ctfassets.net/tldhjvq55hjd/4rdb6bytfaMokOHfvzbqFh/183b1690ca543eb67ccd272f6122aacd/curity-website-news-webinar.png\" alt=\"curity-website-news-webinar\"></p>\n<p><a href=\"https://youtu.be/3y2-HUjCFoE\">Watch the release webinar</a></p>\n<p>Curious to see what Curity Identity Server 11.0 can do for your architecture? <a href=\"https://developer.curity.io/\">Start a free trial</a> to get hands-on or <a href=\"https://curity.io/contact/\">contact us for a demo</a>.</p>",
            "url": "https://curity.io/news/curity-identity-server-11-0/",
            "title": "Curity Identity Server 11.0: Ephemeral Clients, Managed Schemas and SCIM Groups",
            "date_modified": "2026-02-12T08:19:28.847Z"
        },
        {
            "id": "https://curity.io/news/curity-gartner-iam-summit-2026-london/",
            "content_html": "<p>On March 9–10, Curity will be at the Gartner Identity &#x26; Access Management Summit in London, joining IAM leaders, architects and security teams to explore what it means to put identity at the core of modern digital systems.</p>\n<p>If you’re attending, come talk to us at booth 210 about how identity needs to evolve as autonomous services and intelligent agents become part of everyday business. We’ll be sharing practical perspectives from working with API-first platforms and organizations that already operate at machine scale.</p>\n<h2>Don't miss the Curity session at Gartner IAM London</h2>\n<p><strong>A(P)I Security: Intelligent Access for Intelligent Agents</strong></p>\n<p>March 10, 2026 | 13:15 GMT | Theatre 1</p>\n<p>AI agents and autonomous services don't just replace human users but also act on their behalf. This expands the interaction surface between customers, partners and businesses, creating new opportunities and new risks.</p>\n<p>In this session, our CTO Jacob Ideskog will explore what it takes to build an access architecture that is ready for the agentic era. He will also show how organizations can distinguish humans from agents and move from static permissions to a zero standing privilege model using intelligent tokens.</p>\n<p>The result is stronger control over in-house agents and unknown third-party agents alike, reduced breach impact and better alignment with regulatory and audit requirements. Helpful robots should not turn into long-term access liabilities.</p>\n<p><strong>About the event</strong></p>\n<p>The Gartner Identity &#x26; Access Management Summit brings together IAM leaders, architects and security professionals to tackle challenges across IAM program management, automation, ITDR, IGA, privacy and cybersecurity. With more than 2,000 attendees expected, the 2026 theme, Identity at the Core, highlights IAM’s role in building resilience across people, machines, and organizations.</p>\n<p>If you’re heading to Gartner IAM London, we’d love to connect and compare notes on where identity is heading next.</p>",
            "url": "https://curity.io/news/curity-gartner-iam-summit-2026-london/",
            "title": "Curity at Gartner IAM London: Intelligent Access for the Agentic Era",
            "date_modified": "2026-01-30T08:50:16.060Z"
        },
        {
            "id": "https://curity.io/news/curity-at-ai-big-data-expo-2026/",
            "content_html": "<p>Curity will be at AI &#x26; Big Data Expo London 2026, taking place on February 4–5 at the Olympia Exhibition Centre. The event brings together technology leaders, innovators and practitioners to explore how AI and data-driven technologies are reshaping industries.</p>\n<p>Visit us at <strong>Booth 201</strong> to learn how Curity’s application-centric, identity-first approach secures APIs, services and AI-driven workloads at scale. Our team will be happy to discuss your unique use cases and demonstrate how Curity enables organizations to establish trust, enforce least-privilege dynamic access and protect data across modern, distributed architectures.</p>\n<p><a href=\"https://www.ai-expo.net/\">Learn more about the event here</a>. We look forward to connecting with you in London!</p>",
            "url": "https://curity.io/news/curity-at-ai-big-data-expo-2026/",
            "title": "Curity at AI & Big Data Expo London 2026",
            "date_modified": "2026-01-12T08:34:31.223Z"
        },
        {
            "id": "https://curity.io/news/curity-identity-server-10-7/",
            "content_html": "<p>We’re pleased to announce the release of the Curity Identity Server 10.7. This release delivers a broad set of enhancements focused on usability, extensibility, and enterprise readiness.</p>\n<p>Here are some highlights:</p>\n<h3>New Documentation System</h3>\n<p>The most significant addition in this release is the launch of a new Documentation system with a refreshed structure that emphasizes practical product usage. Content is now organized to better mirror how pages, modals, and workflows are structured in the Admin UI, making it easier for administrators and integrators to find relevant guidance and understand configuration options.</p>\n<h3>Enhanced HAAPI Support for Optional Fields across Authentication Flows</h3>\n<p>On the API side, Hypermedia Authentication API (HAAPI) support for optional fields has been expanded. Authentication API responses now include a <code>required</code> attribute on form fields, and this capability has been extended to the Signup action. These changes give clients greater flexibility when rendering forms and handling user input. BankID HAAPI flows have also been enhanced with additional timing information and richer hint code support.</p>\n<p><img src=\"https://images.ctfassets.net/tldhjvq55hjd/2V16ulelbSU70uSuAEVh06/cea21f6d2d74f8e246e73c6a2297a85e/curity-release_10-7_1.png\" alt=\"curity-release 10-7 1\"></p>\n<h3>Expanded SAML IdP Capabilities</h3>\n<p>The SAML IdP Service continues to evolve with major enhancements. Service providers can now be stored in the database and managed through the Admin UI, enabling improved scalability and customization. Support for map-valued attributes has been corrected and formalized as a breaking change, ensuring more predictable and standards-compliant behavior. Several more critical SAML fixes are also included in this release.</p>\n<h3>Improved Admin and DevOps UI Usability and Reliability</h3>\n<p>Administrators will notice multiple Admin UI and DevOps Dashboard improvements, including clearer cookie consent labeling, restored and corrected UI actions, improved dialogs, and new support for triggering account activation workflows directly from the DevOps Dashboard.</p>\n<p>Additional enhancements include improved handling of unverified accounts in GraphQL, better workload identity support, richer server event data with client IP addresses, and the ability to host a default document at the webroot.</p>\n<p><a href=\"https://developer.curity.io/release/10.7.0/release-notes\">Read the release notes</a> to learn more.</p>\n<p>The 11.0.0 train will leave the station on February 9, 2026</p>\n<h1>Release Webinar</h1>\n<p><img src=\"https://images.ctfassets.net/tldhjvq55hjd/4rdb6bytfaMokOHfvzbqFh/183b1690ca543eb67ccd272f6122aacd/curity-website-news-webinar.png\" alt=\"curity-website-news-webinar\"></p>\n<p>We explored what’s new in 10.7 in a release webinar. In the session, we had a conversation with product management, highlighting new features, fixes and enhancements.</p>\n<p><a href=\"https://developer.curity.io/release/10.7.0\">Watch the release webinar here</a>.</p>",
            "url": "https://curity.io/news/curity-identity-server-10-7/",
            "title": "New Release: Curity Identity Server 10.7",
            "date_modified": "2025-12-15T13:58:35.283Z"
        },
        {
            "id": "https://curity.io/news/curity-gartner-iam-summit-2025-usa/",
            "content_html": "<p>Curity is pleased to announce participation in the Gartner Identity &#x26; Access Management Summit 2025 in Grapevine, TX on December 8-10. We look forward to engaging with innovative leaders across industries and discuss emerging trends and key challenges in IAM.</p>\n<p><strong>Are you attending the event?</strong> Visit us in our booth #219, or why not <a href=\"https://curity.io/gartner-iam-us/\">schedule a meeting with our team</a> ahead of time? We’d love to hear from you.</p>\n<p>Also, make sure to attend Curity's session - <strong>Curity: Securing the Non-Human Internet - OAuth in the Age of AI</strong> - presented by our CTO Jacob Ideskog on December 8th at 1:15 PM on the Theater 2 stage. In this talk, Jacob will examine how the rise of AI is reshaping identity consumption. As autonomous agents connect to APIs, permissions may extend beyond their intended use, and short-lived workloads appear and disappear rapidly creating new security challenges. The session explores how OAuth can evolve to protect privacy, reduce risk and maintain control in an environment where many actors are no longer human.</p>\n<p>About the Gartner Identity &#x26; Access Management Summit:</p>\n<p>Gartner Identity &#x26; Access Management Summit 2025 is the premier conference for IAM leaders and architects to tackle priorities like IAM program management, automation, identity threat detection and response (ITDR), cybersecurity and privacy, and identity governance and administration (IGA) in an increasingly complex environment.</p>",
            "url": "https://curity.io/news/curity-gartner-iam-summit-2025-usa/",
            "title": "Curity at the 2025 Gartner Identity & Access Management Summit in Texas",
            "date_modified": "2025-11-20T13:53:57.812Z"
        },
        {
            "id": "https://curity.io/news/digital-finance-summit-2025/",
            "content_html": "<p>Curity is proud to take part in <a href=\"https://www.digitalfinancesummit.com/\">Digital Finance Summit 2025</a> on December 2, where industry leaders will gather to explore how technology is shaping the future of financial services.</p>\n<p>Under the theme “Europe’s Digital Leap – Powering the Future of FinTech,” the summit will highlight how Europe’s talent, infrastructure and innovation are driving a new era of digital finance. From AI-driven banking to next-generation payment systems and quantum-safe security, experts and innovators will discuss how to strengthen Europe’s global leadership in finance and technology.</p>\n<p>Our team will be on site at Booth 6 - come and talk to us on digital identity, API security and what’s next for FinTech. Also, don't miss our CRO Sutton Maxwell's talk - <em>Are You Human? Or Robot? Winning Customer Trust in an AI-Driven World with Identity</em> - at 14:45 on Stage 2. Sutton will share how modern identity frameworks help organizations understand who or what is accessing their services as AI-driven traffic grows. He will also join the <a href=\"https://www.digitalfinancesummit.com/agenda/session/1763687\">roundtable on AI and fraud detection</a> to discuss how to strengthen trust in systems that are becoming more automated.</p>",
            "url": "https://curity.io/news/digital-finance-summit-2025/",
            "title": "Meet Curity at Digital Finance Summit 2025 in Brussels",
            "date_modified": "2025-11-27T10:58:35.982Z"
        },
        {
            "id": "https://curity.io/news/curity-identity-server-10-6/",
            "content_html": "<p>We’re pleased to announce the release of the Curity Identity Server 10.6. This release continues the focus on usability, compliance, and developer flexibility with a collection of impactful improvements across the Admin UI, Authentication Services, and platform tooling.</p>\n<p>Here are some highlights:</p>\n<h3>Cookie Consent Configuration with Opt-In for Non-Essential Cookies</h3>\n<p>A significant privacy-related enhancement introduces a non-essential-cookies-are-opt-in toggle in the Admin UI. Administrators can now configure environments to require explicit user consent before setting non-essential cookies, aligning deployments with modern privacy regulations.</p>\n<p><img src=\"https://images.ctfassets.net/tldhjvq55hjd/5eJByD92b7ib5EJqbIsdCb/f46dda54056288891757fd3b2d76044c/curity-release_10-6.png\" alt=\"curity-release 10-6\"></p>\n<h3>Request Validation UI in Authentication Actions</h3>\n<p>Authentication developers benefit from a new Request Validation UI available inside the Advanced section of Authentication Actions. This addition mirrors similar functionality found in Authenticators and streamlines how request validation is configured within complex workflows.</p>\n<h3>Swift Strict Concurrency Support in the HAAPI iOS SDK</h3>\n<p>The HAAPI SDKs have received major updates. The iOS library now supports Swift 6.2, and we've updated the Android library to handle the TokenResponse better.</p>\n<h3>Support for AmazonLinux Docker Images</h3>\n<p>Infrastructure teams gain new deployment options with AmazonLinux Docker image support, adding another officially supported platform for production environments.</p>\n<h3>Enhanced SAML IDP Compliance and Reliability</h3>\n<p>On the standards compliance front, the SAML IDP Service has been refined to produce assertions that more closely align with SAML specifications, including proper <code>NameFormat</code> URIs and consistent use of <code>SubjectConfirmation</code> elements.</p>\n<p>Additional updates improve the Self-Service Portal’s locale awareness and enhanced SCIM event reporting.</p>\n<p><a href=\"https://developer.curity.io/release/10.6.0/release-notes\">Read the release notes</a> to learn more.</p>\n<p>The 10.7 train will leave the station on December 15, 2025</p>",
            "url": "https://curity.io/news/curity-identity-server-10-6/",
            "title": "New Release: Curity Identity Server 10.6",
            "date_modified": "2025-11-03T11:35:07.214Z"
        },
        {
            "id": "https://curity.io/news/securing-mcp-and-ai-agents-webinar/",
            "content_html": "<p>On December 4, Curity identity specialists will host a webinar on how organizations can secure API access as AI technologies and the Model Context Protocol (MCP) reshape digital ecosystems.</p>\n<p>AI brings new opportunities but also new security challenges. As organizations begin connecting AI agents to APIs through MCP, strong identity and access controls are essential to protect data, infrastructure and user trust.</p>\n<p>In the upcoming live session, we will share practical design patterns for securing AI agent connections to APIs, showing how to enable interoperability without compromising security.</p>\n<p><a href=\"https://curity.io/resources/webinars/mcp-and-ai-agents-identity-strategies-for-safe-api-access-webinar/\">Learn more and register here.</a></p>",
            "url": "https://curity.io/news/securing-mcp-and-ai-agents-webinar/",
            "title": "Curity to Explore Identity Strategies for Securing MCP and AI Agent API Access",
            "date_modified": "2025-10-28T13:16:24.155Z"
        },
        {
            "id": "https://curity.io/news/curity-future-identity-festival/",
            "content_html": "<p>Curity is proud to take part of this year’s <a href=\"https://thefutureidentity.com/events/europe/fid-festival/\">Future Identity Festival</a>, taking place on November 10–11, 2025, in London. The event brings together leaders and innovators in digital identity, cybersecurity and data privacy to explore how identity is shaping the connected world.</p>\n<p>You can find us at Stand 13, where the Curity team will be ready to discuss how an identity-first approach enables organizations to build trusted digital experiences and enable growth. As part of the conference program Curity identity specialist Gary Archer will deliver a talk <em>Securing AI Agents: Identity Strategies for Safe API Access</em> on Monday, November 10th, from 16:05 to 16:25 on the Future Identity Festival Stage.</p>\n<p>In his session, Gary will explore how best practices for connecting AI agents to APIs are evolving. As organizations adopt AI-driven tools and workflows, new security challenges arise. The talk will summarize the essential security building blocks that every organization should put in place for the emerging AI era.</p>\n<p>We look forward to seeing you in London!</p>",
            "url": "https://curity.io/news/curity-future-identity-festival/",
            "title": "Curity at Future Identity Festival 2025",
            "date_modified": "2025-10-27T10:18:14.548Z"
        },
        {
            "id": "https://curity.io/news/curity-if-kuppingercole-webinar-api-product/",
            "content_html": "<p>Modern enterprises rely on APIs to connect systems, enable innovation and build new digital experiences. Yet many organizations still treat APIs as isolated endpoints rather than strategic products that leads to fragmented governance and growing security risks.</p>\n<p>Curity, in partnership with KuppingerCole and If P&#x26;C Insurance, will host a webinar on November 13, 2025, exploring how to build APIs that are secure, scalable and designed for growth. The session will focus on how combining Identity and Access Management (IAM) with API infrastructure transforms endpoints into trusted business platforms.</p>\n<p>Attendees will learn:</p>\n<ul>\n<li>Why leading organizations manage APIs as products with clear ownership, documentation and onboarding.</li>\n<li>How IAM ensures consistent, secure access across ecosystems, partners and client applications.</li>\n<li>How innovations such as passwordless authentication, attribute-based access and verifiable credentials are reshaping developer experience.</li>\n<li>Real-world lessons from If P&#x26;C Insurance, a valued Curity customer, on successfully implementing an API platform strategy.</li>\n</ul>\n<p>Join to learn how aligning IAM with API management helps organizations innovate securely and confidently. <a href=\"https://www.kuppingercole.com/events/endpoints-to-business-products\">Learn more and register here</a>.</p>",
            "url": "https://curity.io/news/curity-if-kuppingercole-webinar-api-product/",
            "title": "Curity Partners with KuppingerCole and If P&C for Webinar on API Product Strategy",
            "date_modified": "2025-10-08T10:41:35.315Z"
        },
        {
            "id": "https://curity.io/news/curity-naoplay-apitime-webinar/",
            "content_html": "<p>We are pleased to announce that Eric Geens from Curity will participate in episode five of <a href=\"https://curity.io/company/partners/naoplay/\">our partner Naoplay</a>’s APItime webinar series - <em>Orchestrer l’identité sans exposer vos APIs (Orchestrate identity without exposing your APIs)</em>. The live session takes place on October 21, 2025, at 13:15 CEST and will be conducted in French.</p>\n<p>The discussion will explore the evolving challenges of Customer Identity and Access Management (CIAM). The webinar host and Eric will revisit the fundamentals, walk through the orchestration of user journeys across multiple systems and explain how the phantom token protects backends without compromising user experience.</p>\n<p>This concise and practical format is designed for architects, tech leads and security leaders looking to connect smooth digital experiences with robust identity architectures.</p>\n<p><a href=\"https://www.youtube.com/watch?v=eG2nKSnooD8\">Visit the YouTube page to follow the countdown and set a reminder for the live session.</a></p>",
            "url": "https://curity.io/news/curity-naoplay-apitime-webinar/",
            "title": "Curity Joins Naoplay’s APItime Webinar on CIAM",
            "date_modified": "2025-09-26T06:35:42.161Z"
        },
        {
            "id": "https://curity.io/news/curity-welcomes-johanna-alvemur-and-sutton-maxwell/",
            "content_html": "<p>We are thrilled to welcome two exceptional leaders to the Curity leadership team.</p>\n<p>Johanna Alvemur joins us as Chief Human Resources Officer (CHRO), bringing deep expertise in building strong, people-centered organizations and fostering cultures of innovation. Her leadership will be instrumental as Curity continues to grow and expand globally.</p>\n<p>Sutton Maxwell steps into the role of Chief Revenue Officer (CRO), overseeing our commercial operation — from demand generation to customer success. With a proven track record across the identity and security space, Sutton brings the experience and vision needed to fuel Curity’s next phase of growth.</p>\n<p>These appointments mark an exciting step forward as Curity continues to scale and deliver identity-centric solutions to organizations worldwide.</p>\n<p>Gustaf Sahlman, CEO of Curity comments:</p>\n<blockquote>\n<p>Welcoming Johanna and Sutton marks an important step in Curity’s growth journey. Their experience in shaping strong organizations and driving revenue will help us scale globally, innovate faster and continue delivering exceptional value to our customers.</p>\n</blockquote>",
            "url": "https://curity.io/news/curity-welcomes-johanna-alvemur-and-sutton-maxwell/",
            "title": "Curity Welcomes Johanna Alvemur and Sutton Maxwell",
            "date_modified": "2025-09-23T09:39:20.176Z"
        },
        {
            "id": "https://curity.io/news/curity-identity-server-10-5/",
            "content_html": "<p>We’re pleased to announce the release of the Curity Identity Server 10.5. This version brings stronger security, broader protocol support and a smoother admin experience. With these updates, organizations gain more flexibility and reliability in managing digital identities, while administrators benefit from improved usability and efficiency.</p>\n<p>Here are some highlights:</p>\n<h3>Configurable Denial of Service (DoS) Protection with Built-in Safeguards</h3>\n<p>10.5 adds configurable Denial of Service (DoS) protection, enabling administrators to defend against overload and malicious traffic without depending on external tools. In addition, enhanced connection limits and timeout settings provide operators with fine-grained control to contain rogue clients.</p>\n<p><img src=\"https://images.ctfassets.net/tldhjvq55hjd/5pfNW9I542aFJA3lZwdMec/a8ce35c99581d2d65babb875bbf0481d/curity-release_10-5_1.png\" alt=\"curity-release 10-5 1\"></p>\n<h3>New SAML Account Manager Attribute Provider</h3>\n<p>A new SAML Attribute Provider makes it possible to retrieve account data as SAML attributes, enabling richer and more precise identity assertions.</p>\n<h3>Expanded OAuth and OpenID Connect Support</h3>\n<p>OAuth and OpenID Connect have been enhanced with support for the Token Exchange grant type for Dynamically Registered Clients (DCR), providing flexibility for complex delegated authorization scenarios.</p>\n<h3>Enhanced GraphQL Security Controls and Event Publishing</h3>\n<p>Administrators can now restrict introspection and HTTP GET mutations in GraphQL to further harden security. In addition, all user management GraphQL operations now publish events, simplifying integration with monitoring tools and event-driven systems.</p>\n<h3>Admin Web UI Enhancements</h3>\n<p>The Admin Web UI introduces several upgrades that make customization and navigation easier. The Look and Feel editor now previews custom CSS and highlights mapped elements in real time, while application detail pages for the Self Service Portal have been redesigned with clearer sections and direct links to documentation.</p>\n<p>Beyond the interface, the release also delivers expanded telemetry in the Email Sender plugin, more user-friendly OTP input components, updated licensing and broader database compatibility.</p>\n<p><a href=\"https://developer.curity.io/release/10.5.0/release-notes\">Read the release notes</a> to learn more.</p>\n<p>The 10.6 train will leave the station on November 3, 2025</p>\n<h3>Release Webinar</h3>\n<p><img src=\"https://images.ctfassets.net/tldhjvq55hjd/4rdb6bytfaMokOHfvzbqFh/183b1690ca543eb67ccd272f6122aacd/curity-website-news-webinar.png\" alt=\"curity-website-news-webinar\"></p>\n<p>Join us on Thursday, September 25, at 11:00 CEST for a release webinar where our product management team will walk through the highlights of Curity Identity Server 10.5. <a href=\"https://curity-io.zoom.us/webinar/register/WN_OmYrCgG5RRaaansqeIOy2w\">Register for the webinar here</a>.</p>",
            "url": "https://curity.io/news/curity-identity-server-10-5/",
            "title": "New Release: Curity Identity Server 10.5",
            "date_modified": "2025-09-22T11:10:11.758Z"
        },
        {
            "id": "https://curity.io/news/nfw-2025/",
            "content_html": "<p>Curity is proud to partner with Nordic FinTech Week 2025, taking place on September 24–25 in Copenhagen. The event is one of the largest finance and fintech conferences in the Nordic region, bringing together industry leaders, policymakers, and innovators to explore the future of financial services.</p>\n<p>Our CEO Gustaf Sahlman will deliver the keynote <em>Identity, the Digital Kill Switch – Why Digital Sovereignty Is More Critical Than Ever</em> on September 24 at 15:50 (Nordic Malstrøm Stage), highlighting why identity is now the frontline of trust, regulation and resilience.</p>\n<p>On the same stage at 16:10, our CCO Stefan Nilsson will join the panel <em>Digital Identity: Powering Europe’s Next Digital Leap</em>, exploring how cutting-edge identity technologies can drive growth, strengthen compliance, and build customer trust across the EU.</p>\n<p>Curity’s CRO Sutton Maxwell will also join the roundtable <em>The Future of Digital Identity – The Perfect Storm</em> on September 25 at 10:15.</p>\n<p>Ahead of the event, read our CTO Jacob Ideskog’s blog post - <a href=\"https://nfweek.com/2025/09/08/the-unseen-balance-innovation-security-and-the-power-of-identity/\">The Unseen Balance: Innovation, Security, and the Power of Identity</a> - exploring how Nordic fintechs can sustain their leadership by anchoring rapid innovation in identity.</p>\n<p>We look forward to seeing you in Copenhagen!</p>",
            "url": "https://curity.io/news/nfw-2025/",
            "title": "Meet Curity at Nordic FinTech Week 2025 in Copenhagen",
            "date_modified": "2025-09-16T13:04:56.610Z"
        },
        {
            "id": "https://curity.io/news/curity-and-loihde-join-forces/",
            "content_html": "<p>Curity, a leading provider of API-first identity management, is proud to announce a strategic partnership with Loihde, a Finnish technology group specializing in cybersecurity, physical security, and digital development. The partnership combines Curity’s Customer Identity and Access Management (CIAM) capabilities with Loihde’s deep regional expertise and managed security services.</p>\n<p>With Loihde’s local delivery expertise and the Curity Identity Server, customers in sectors like finance, energy, telecommunications, and manufacturing gain a complete CIAM solution. They benefit from secure login journeys, smooth integration, and around-the-clock support in Finnish. The partnership helps reduce risk, speed up projects, and meet strict security and compliance needs, all while improving the overall user experience.</p>\n<p>Petteri Aatola, Vice President of IAM &#x26; Cloud at Loihde, commented:</p>\n<blockquote>\n<p>Through this partnership, Loihde can offer a complete CIAM stack backed by Curity’s proven identity solution. It’s a perfect fit for clients who demand security, agility, and local support.</p>\n</blockquote>\n<p>For customers, this means faster and more secure implementation of digital identity security, with Finnish-language support, on-site integration services, and continuous monitoring. Whether deployed on-premises or in the cloud, the joint offering reduces project risk and simplifies complex authentication flows.</p>\n<p>For Curity, the collaboration strengthens its presence in the Nordics and supports broader adoption through Loihde’s established enterprise relationships. Solution architects from both companies have already launched a reference architecture workshop for a client, and the companies maintain an ongoing collaboration with a Finnish telco.</p>\n<p>Stefan Nilsson, Chief Commercial Officer at Curity:</p>\n<blockquote>\n<p>We’re thrilled to partner with Loihde, a trusted leader in Finland’s digital and security landscape. Their local expertise and strong customer relationships make them an ideal match. Together, we’re helping organizations implement secure, scalable CIAM solutions that meet both technical and regulatory requirements.</p>\n</blockquote>\n<p>This partnership brings significant value to customers, partners, and end users alike: secure login journeys, resilient operations, and simplified CIAM deployments.</p>",
            "url": "https://curity.io/news/curity-and-loihde-join-forces/",
            "title": "Curity and Loihde Join Forces to Deliver Complete CIAM Solutions in Finland ",
            "date_modified": "2025-09-01T06:14:14.915Z"
        },
        {
            "id": "https://curity.io/news/curity-savyint-partner-identity-api-security-apac/",
            "content_html": "<p>We’re excited to announce our new strategic partnership with Saviynt, a leading IT product company specializing in information security, payment security and open banking. Started in July 2025, this collaboration will strengthen identity management, user authentication and API security in Open Banking across Vietnam and the broader APAC region.</p>\n<p>Aligned with Vietnam’s strategy to build a modern digital economy and supported by regulations laying the foundation for open banking, Savyint and Curity collaborate to deliver IAM and API management (APIM) solutions that ensure flexibility, security and compliance with open banking standards.</p>\n<p>The partnership focuses on developing highly secure IAM and APIM solutions for the financial and banking sector, adhering to global security and identity standards including OAuth2, OpenID Connect (OIDC), and FAPI – aligned with PSD2, mTLS, and others.</p>\n<p>Joint solution highlights:</p>\n<ul>\n<li>A flexible, modern authentication system supporting over 30 methods (multi-factor authentication, App2App, SSO, passwordless, Passkey/FIDO2), customizable to meet specific market needs.</li>\n<li>Integration of a consent management module based on OAuth2, utilizing Strong Customer Authentication (SCA) as mandated by PSD2.</li>\n<li>HSM integration via PKCS#11 standard with various HSMs like Kryptus, Entrust nCipher, Thales, etc., without reliance on third-party plugins.</li>\n<li>Support for Phantom Tokens and Token Handler to enhance security in digital environments.</li>\n<li>Development of an APIM infrastructure (separated from IAM based on a Neo-security architecture), compatible with various API Gateways.</li>\n<li>API Security Module: Compliant with international standards such as OAuth 2.0, OpenID Connect, FAPI 1.0 &#x26; 2.0, DCR, PSD2/PSD3, and the EU’s API Security Framework, and integrated with HSM via PKCS#11. This module employs best practices for API security, including centralized API Gateway for managing traffic flows, integrated centralized OAuth server to secure client authentication, user authentication and token signing</li>\n<li>Use of JSON Web Key Sets (JWKS) for distributing public keys from the OAuth server</li>\n<li>Zero Trust architecture design, where all API requests are treated as untrusted by default and must undergo strict authentication and authorization before access is granted.</li>\n</ul>\n<p>Brad Palmer, Chief Operating Officer &#x26; Executive Vice President of Savyint, stated:</p>\n<blockquote>\n<p>Our partnership with Curity enables Savyint to deploy advanced IAM solutions that meet the stringent requirements of open banking in Vietnam. With flexible authentication methods, consent management and HSM integration, together with Curity, we will build a secure, transparent, and efficient ecosystem.</p>\n</blockquote>\n<p>Stefan Nilsson, Chief Commercial Officer at Curity, added:</p>\n<blockquote>\n<p>We are excited to collaborate with Savyint to advance open banking in Vietnam. Partnering with Savyint allows us to apply Curity’s global IAM expertise to local markets with precision, fostering secure and scalable open banking frameworks.</p>\n</blockquote>\n<p>About Savyint</p>\n<p><a href=\"https://savyint.com/\">Savyint</a> is an IT security company based in Sydney, Australia with an R&#x26;D center in Hanoi and international offices in Singapore, Dubai, Ho Chi Minh City (Vietnam) and Sofia (Bulgaria).</p>\n<p>With over 20 years of experience, Savyint is among the world’s leading IT companies, providing software platforms, system solutions, and services for digital transformation. Its expertise includes open banking, information security and FinTech, particularly in the Finance &#x26; Banking, FSI, Government, Manufacturing, Telecommunications, Healthcare, Education and Media sectors.</p>",
            "url": "https://curity.io/news/curity-savyint-partner-identity-api-security-apac/",
            "title": "Curity and Savyint Partner to Advance Identity and API Security for Open Banking in APAC",
            "date_modified": "2025-08-15T11:58:25.726Z"
        },
        {
            "id": "https://curity.io/news/curity-identity-server-10-4/",
            "content_html": "<p>We’re excited to announce the release of the Curity Identity Server 10.4, introducing significant enhancements to user experience and enterprise capabilities.</p>\n<p>Here are some of the highlights:</p>\n<h3>Self-Service Portal</h3>\n<p>The new Self-Service Portal allows users to manage their own email addresses, phone numbers, TOTP devices, passkeys and authorized applications. Built with modern React technology and the Token Handler pattern, it integrates seamlessly with existing user management profiles and supports customizable theming to match your brand. The portal includes sophisticated access control through a new authorization manager system, ensuring users can only access features permitted by administrators.</p>\n<p><img src=\"https://images.ctfassets.net/tldhjvq55hjd/3kQwmDW8UD7wcaIf3kpvYv/192294b37968381b8ea43e8c8e71fe31/curity-release_10-4_1.png\" alt=\"curity-release 10-4 1\"></p>\n<h3>SAML Identity Provider Profile</h3>\n<p>SAML Identity Provider capabilities have been expanded with a brand-new SAML IDP Profile. Like the Token Profile, it supports application integrations with Attribute Providers for data enrichment and offers both POST and Redirect bindings.</p>\n<h3>New Device Management GraphQL API</h3>\n<p>This new feature lets integrations manage devices bound to accounts, including TOTP devices and passkeys as well as mechanisms for verifying phone numbers and email addresses.</p>\n<h3>New User Interface for the UI Designer in the Admin UI</h3>\n<p>The Admin UI Designer now includes the Self-Service Portal, along with improvements that make the design experience simpler and more intuitive.</p>\n<p>Other enhancements include improved IP address handling for Cloudflare deployments, Admin UI refinements, and various bug fixes that boost stability and usability.</p>\n<p><a href=\"https://developer.curity.io/release/10.4.0/release-notes\">Read the release notes</a> to learn more.</p>\n<p>The 10.5 train will leave the station on September 22, 2025</p>\n<h3>Release Webinar</h3>\n<p><img src=\"https://images.ctfassets.net/tldhjvq55hjd/4rdb6bytfaMokOHfvzbqFh/183b1690ca543eb67ccd272f6122aacd/curity-website-news-webinar.png\" alt=\"curity-website-news-webinar\"></p>\n<p>Watch the release webinar <a href=\"https://developer.curity.io/release/10.4.0\">here</a>.</p>",
            "url": "https://curity.io/news/curity-identity-server-10-4/",
            "title": "New Release: Curity Identity Server 10.4",
            "date_modified": "2025-08-11T11:11:37.654Z"
        },
        {
            "id": "https://curity.io/news/curity-joins-kuppingercole-webinar-ai-for-b2b-iam/",
            "content_html": "<p>Curity is partnering with KuppingerCole for an expert-led webinar, <a href=\"https://www.kuppingercole.com/events/rules-of-b2b\">AI Rewrites the Rules of B2B Identity Access</a>, on October 2, 2025 at 4:00 PM CEST.</p>\n<p>As B2B ecosystems grow increasingly complex, identity and access management must evolve to meet new demands. This webinar will explore how AI and modern identity architecture are reshaping how organizations manage third-party access, secure APIs, and enforce Zero Trust principles.</p>\n<p><strong>Some of the key takeaways:</strong></p>\n<ul>\n<li>How AI is driving new approaches to B2B identity and access</li>\n<li>Best practices for securing API-driven partner ecosystems</li>\n<li>Implementing dynamic authorization and Zero Trust at scale</li>\n<li>Real-world insights from Curity’s standards-based IAM platform</li>\n</ul>\n<p>Whether you're managing third-party integrations, partner portals, or embedded finance use cases, this webinar will offer practical guidance on staying ahead of evolving B2B access challenges. Learn more and register for the webinar here: <a href=\"https://www.kuppingercole.com/events/rules-of-b2b\">https://www.kuppingercole.com/events/rules-of-b2b</a></p>",
            "url": "https://curity.io/news/curity-joins-kuppingercole-webinar-ai-for-b2b-iam/",
            "title": "Explore the Future of AI in B2B IAM with KuppingerCole and Curity",
            "date_modified": "2025-08-05T06:58:29.685Z"
        },
        {
            "id": "https://curity.io/news/livecast-mcp-security/",
            "content_html": "<p>As agent-based systems and AI-to-API communication formats evolve, the Model Context Protocol (MCP) is emerging as a game-changing standard. But with innovation comes uncertainty. MCP’s novelty and untested nature in enterprise environments introduce critical security concerns that demand immediate attention.</p>\n<p>Curity’s Gary Archer will join the Nordic APIs LiveCast on <a href=\"https://nordicapis.com/events/mcp-security/\">MCP Security</a> on August 13 to discuss these emerging threats. Drawing on his deep expertise in identity architecture and secure API integration, Gary will offer actionable insights on fortifying MCP-powered ecosystems, adopting token-based protections and implementing least privilege principles to reduce attack surfaces.</p>\n<p>Don’t miss this live webinar - <a href=\"https://nordicapis.com/events/mcp-security/\">register here</a>.</p>",
            "url": "https://curity.io/news/livecast-mcp-security/",
            "title": "Curity's Gary Archer Joining Nordic APIs LiveCast on MCP Security",
            "date_modified": "2025-07-24T14:17:38.198Z"
        },
        {
            "id": "https://curity.io/news/curity-at-api-security-unconference/",
            "content_html": "<p>We're excited to share that Curity will be participating in the inaugural <a href=\"https://nordicapis.com/events/the-api-security-unconference/\">API Security Unconference</a>, a new half-day event dedicated to API security challenges and solutions.</p>\n<p>Held in association with <a href=\"https://nordicapis.com/\">Nordic APIs</a>' long-standing <a href=\"https://nordicapis.com/events/platform-summit-2025/\">Platform Summit</a>, the UnConference invites API practitioners, architects, and security professionals to come together in an open, participant-driven format. Instead of scheduled talks, the agenda is shaped by attendees, making space for in-depth discussions, practical insights, and collaborative problem-solving.</p>\n<p>Curity identity specialists Daniel Lindau and Michal Trojanowski will be among the facilitators of the event, helping to guide and energize the conversation.</p>\n<p>Whether you're attending the Platform Summit or just looking to connect with peers passionate about securing APIs, the Unconference offers a unique and valuable way to kick off the week.</p>\n<p>Learn more about the event and ticket options here: <a href=\"https://nordicapis.com/events/the-api-security-unconference/\">https://nordicapis.com/events/the-api-security-unconference/</a></p>\n<p>We hope to see you there!</p>",
            "url": "https://curity.io/news/curity-at-api-security-unconference/",
            "title": "Join Curity at the API Security Unconference",
            "date_modified": "2025-06-19T06:44:19.757Z"
        },
        {
            "id": "https://curity.io/news/curity-identity-server-10-3/",
            "content_html": "<p>We’re excited to announce the release of the Curity Identity Server 10.3, featuring several new capabilities and improvements.</p>\n<p>Here are some of the highlights:</p>\n<h3>New Throttler Service</h3>\n<p>The work on the updated throttler service has been completed. There is now a new service that can be configured in the System settings that sets a default throttler throughout the system. This is used for sending emails, sms and for custom plugins that need throttling. It comes with the option to define custom throttlers for specific plugins or use a single one for the entire system.</p>\n<h3>Improved Parameter Options in JSON Data Source</h3>\n<p>The JSON data source has been updated with more options on how to send parameters in the request. This enables greater flexibility when working with custom REST APIs as data source backends.</p>\n<h3>Login Pages: New Symbols</h3>\n<p>Lastly the login pages have been updated with fresh new symbols. The old symbols are still shipped in the UI Builder project but are not used by default. See the upgrade guide for more information.</p>\n<p><a href=\"https://developer.curity.io/release/10.3.0/release-notes\">Read the release notes</a> to learn more.</p>\n<p>The 10.4 train will leave the station on Aug 11, 2025</p>\n<p><img src=\"https://images.ctfassets.net/tldhjvq55hjd/4rdb6bytfaMokOHfvzbqFh/183b1690ca543eb67ccd272f6122aacd/curity-website-news-webinar.png\" alt=\"curity-website-news-webinar\"></p>\n<p>The webinar for the 10.3 release will be available soon on the <a href=\"https://developer.curity.io/release/10.3.0\">release page</a>.</p>",
            "url": "https://curity.io/news/curity-identity-server-10-3/",
            "title": "New Release: Curity Identity Server 10.3",
            "date_modified": "2025-06-16T11:34:41.666Z"
        },
        {
            "id": "https://curity.io/news/curity-at-api-days-helsinki-2025/",
            "content_html": "<p>We are happy to announce that Curity's Judith Kahrer is taking part in the Apidays Helsinki &#x26; North event on June 3-4, 2025.</p>\n<p>Identity specialist Judith Kahrer will speak on June 4 at 4:20 PM in the API Architecture and Integration track. Her talk, <em>API Access Control Strategies Beyond JWT Bearer Tokens</em>, will explore the hidden risks of relying solely on JWTs and bearer tokens and highlight smarter, more resilient strategies to strengthen API security.</p>\n<p>Read more and register for the <a href=\"https://www.apidays.global/helsinki_and_north/\">Apidays Helsinki &#x26; North here</a>.</p>",
            "url": "https://curity.io/news/curity-at-api-days-helsinki-2025/",
            "title": "Curity's Judith Kahrer speaking at Apidays Helsinki & North 2025",
            "date_modified": "2025-05-27T12:12:39.507Z"
        }
    ]
}