Educational sandbox. Every flow, token, and scenario here is simulated. Not for production.
These labs are hands-on. Open on a desktop or tablet.
Identity & access, hands-on

See how systems decide who gets in.

Every tutorial shows the login that works. Here you break it. Steal a session, forge a token, walk in on an unmanaged device, then watch the system catch each one and explain why.

The path runs from one app's cookie to Zero Trust: decisions that weigh device posture and risk, and re-check trust mid-session rather than once at the door. No security background needed.

No account · Nothing stored · Real protocols, simulated safely

Open a lab

These run right now. No setup.

The full path

Three rungs, 13 labs. 2 are live now; the rest land in this order, each assuming the rung before it.

Basic

Core concepts, then identity on one server: proving who you are to a single application.

Intermediate

Identity across parties: delegation, federation, and stronger credentials.

4OAuth 2.0soon 5OpenID Connectsoon 6MFA / Step-Upsoon 7Passkeys / WebAuthnsoon 8Authorizationsoon
Advanced

Identity as a continuous, risk-aware system. This is where Zero Trust lives.

9Device Trustsoon 10Adaptive Accesssoon 11Workload Identitysoon 12Continuous Verificationsoon 13Audit & Explainabilitysoon