NIST strengthens safeguards for SSO and API tokens

The US National Institute of Standards and Technology has finalised new guidance aimed at reducing theft, forgery and misuse of digital tokens that underpin single sign-on, cloud federation and API access.

NIST Interagency Report 8587, released on September 15, sets out implementation recommendations for federal agencies and cloud service providers handling identity tokens, access tokens and assertions. The document focuses on how organisations should protect signing keys, verify tokens, manage their lifecycles and limit the damage if credentials are stolen or abused.

The guidance was developed with the Cybersecurity and Infrastructure Security Agency’s Joint Cyber Defense Collaborative and supports Executive Order 14306. It builds on NIST Special Publication 800-53, the federal catalogue of security and privacy controls, while translating broader requirements into practical measures for identity providers, authorisation servers, cloud platforms and customers.

NIST said tokens are central to access management because they can carry cryptographically protected information about a user, workload or permitted resources. They also allow users to move between applications through single sign-on without repeatedly authenticating. The same convenience can create exposure if attackers obtain valid tokens or the keys used to create them.

The report therefore recommends stronger controls around cryptographic signing keys, including secure storage, protected use and automated rotation. The final version makes those recommendations less prescriptive than the draft, placing greater emphasis on security outcomes and organisational capabilities. It also separates guidance on how keys should be stored from how they should be used when creating tokens and assertions.

NIST also revised its approach to signing-key validity periods after public feedback. Rather than tying validity primarily to deployment models, the final report links the duration more closely to system classification and the sensitivity of transactions. Automated key management and rotation remain central recommendations, reflecting the risk that a compromised signing key can allow an attacker to manufacture apparently legitimate credentials.

Token verification and lifecycle controls are another major focus. Organisations are urged to ensure tokens are properly validated, scoped to intended uses and revoked or invalidated when necessary. The report adds references to standards that can support revocation and the sharing of signals about compromised or suspicious tokens across services.

Workload identities receive expanded treatment in the final publication. NIST recommends short-lived tokens for software workloads rather than dependence on static credentials and long-lived secrets, reducing the period during which stolen credentials remain useful. The report also includes high-level considerations for artificial intelligence systems and for migration to post-quantum cryptography, although NIST said it does not provide a comprehensive implementation framework for either area.

The recommendations apply directly to federal agencies and the cloud providers serving them, but NIST said the material can also be used by organisations operating token-based access systems. Ryan Galluzzo, NIST’s Digital Identity Program Lead, said organisations using tokens as part of access-management infrastructure could use the publication for implementation guidance.

The final report follows a December 2025 public draft. NIST and CISA received nearly 250 comments from more than 20 contributors, along with feedback gathered through the Joint Cyber Defense Collaborative and a January webinar. Those submissions led to changes covering key protection, validity periods, workload identities and references to standards and protocols.

The urgency of the guidance is underscored by attacks in which compromised token infrastructure has enabled access without stealing user passwords. NIST cites an incident in which foreign actors used forged tokens derived from a stolen commercial signing key to enter government email systems, with more than 60,000 emails taken from one agency.

NIST’s recommendations place responsibilities on both providers and customers. Cloud providers are expected to design services with secure defaults, strong key protection, configurability and monitoring, while consuming organisations must configure those services appropriately, understand how trust relationships are established and maintain controls that can detect or contain misuse.



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


Loading next story…
Just in:
HKUST Welcomes the Prime Minister of Uzbekistan Strengthening Partnerships in Education, Research, and Talent Development // UAE recall covers 6,933 Lexus luxury SUVs // PhonePe scales AI across payments and operations // OpenAI enlists contractors to review ChatGPT chats // India steers 18th BRICS summit deftly, keeps anti-West rhetoric at bay // WRISE Prestige Marks Two Years in Hong Kong with Strong Growth and Unveils the Evolution of the Intelligent Wealth Consultant // UAE rolls out seven-emirate Grand Tour package // Netflix, Amazon and YouTube establish streaming policy bloc // The Costly Mistakes Foreign Buyers Keep Making in Dubai // Singapore and Korean Clinicians Call for More Individualised, Evidence-Based Postnatal Care as Women Enter Motherhood Later in Life // VX Logistics Transforms Fresh Fruit and Vegetables Industry through Application of AI and World-first Robot // SOCAR sets year-end decision on $7bn Türkiye expansion // Markets have split America in two // NIST strengthens safeguards for SSO and API tokens // SWISS REJU Wins “Exquisite Body-Sculpting Reputable Brand Award” from HK01, Following Exceptional User Reviews and Recognition // DXB adds five-minute international driving permit service // US widens 50% tariffs on Canadian imports // BRICS elevates Global South development priorities // Senate blocks CLARITY Act despite White House data // DHL Express sees rise in heavyweight shipments in Asia Pacific as businesses circumvent unpredictability //