Go to home page
23 Sep, 2026

Securing Modern Applications with the BFF Pattern and WSO2 Identity Server

As frontend architectures evolve toward SPAs and micro-frontends, securing them with traditional OAuth2/OIDC flows introduces real risks: tokens exposed in browsers, complex session management, and fragmented security boundaries. This talk presents a production-grade Backend-for-Frontend (BFF) architecture built on WSO2 Identity Server, designed to meet FAPI 2.0 security profiles for banking-grade applications.

Drawing from a real-world deployment, we'll explore how the BFF pattern shifts token custody away from the browser, leveraging PAR, PKCE, and private_key_jwt for robust authorization code flows. We'll dive into Redis-backed session management, the interplay between commonAuthId cookies and session identifiers, and back-channel logout for consistent session termination across distributed services.

Attendees will leave with a concrete blueprint for implementing a secure BFF layer with WSO2 IS, practical guidance on architecture tradeoffs, and lessons learned from deploying this pattern in a real banking environment — bridging the gap between OAuth2/OIDC theory and production security requirements.

Speakers

Cedric GUYOMARD

Cedric GUYOMARD

Security IAM Architect

AZQORE

Cédric is a security and identity access management (IAM) architect on the RSI team at AZQORE SA. He designs and builds solutions around WSO2 Identity Server and WSO2 API Manager, with deep expertise in OAuth2/OIDC and FAPI 2.0. His work spans BFF architecture, custom authenticator development, CI/CD pipelines, and infrastructure provisioning on Virtuozzo/Jelastic PaaS. He is currently deploying the bff-qore-banking project and working on LDAP/Active Directory integration, alongside custom authentication modules for AD password expiry handling. Cédric combines strong technical rigor with a focus on enterprise-grade security architecture, contributing to reusable internal developer tooling and documentation within the AZQORE design system.