Identity & access, hands-on
See how systems decide who gets in.
Every tutorial shows the login that works. Here you break it. Steal a session, forge a token, walk in on an unmanaged device, then watch the system catch each one and explain why.
The path runs from one app's cookie to Zero Trust: decisions that weigh device posture and risk, and re-check trust mid-session rather than once at the door. No security background needed.
No account · Nothing stored · Real protocols, simulated safely
Open a lab
These run right now. No setup.
The full path
Three rungs, 13 labs. 2 are live now; the rest land in this order, each assuming the rung before it.
Basic
Core concepts, then identity on one server: proving who you are to a single application.
Intermediate
Identity across parties: delegation, federation, and stronger credentials.
4OAuth 2.0soon
5OpenID Connectsoon
6MFA / Step-Upsoon
7Passkeys / WebAuthnsoon
8Authorizationsoon
Advanced
Identity as a continuous, risk-aware system. This is where Zero Trust lives.
9Device Trustsoon
10Adaptive Accesssoon
11Workload Identitysoon
12Continuous Verificationsoon
13Audit & Explainabilitysoon