NIST - National Institute of Standards and Technology

09/15/2026 | Press release | Distributed by Public on 09/16/2026 03:10

NISTIR 8587 Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers

Published
September 15, 2026

Author(s)

Ryan Galluzzo, Andrew Regenscheid, Stephanie Nelson

Abstract

This report provides implementation guidance to help federal agencies and cloud service providers (CSPs) protect tokens and assertions from forgery, theft, and misuse. Building on updates to NIST SP 800-53 (Release 5.1.1), it outlines principles for CSPs and consuming agencies, details architectural considerations for identity providers and authorization servers, and recommends enhancements to key management, token verification, and life cycle controls. The report addresses threats demonstrated in recent high-profile attacks, emphasizes the importance of secure by design practices, configurability, interoperability, and continuous monitoring, and provides specific technical recommendations to safeguard single sign-on, federation, and application programming interface (API) access scenarios.
Citation
NIST Interagency/Internal Report (NISTIR) - 8587
Report Number
8587
Pub Type
NIST Pubs

Keywords

access management, federation, key management, single sign-on, token management

Citation

Galluzzo, R. , Regenscheid, A. and Nelson, S. (2026), NISTIR 8587 Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers, NIST Interagency/Internal Report (NISTIR), National Institute of Standards and Technology, Gaithersburg, MD, [online], https://doi.org/10.6028/NIST.IR.8587, https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=962217 (Accessed September 16, 2026)
Additional citation formats

Issues

If you have any questions about this publication or are having problems accessing it, please contact [email protected].

NIST - National Institute of Standards and Technology published this content on September 15, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on September 16, 2026 at 09:10 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]