Published
September 15, 2026
Author(s)
Ryan Galluzzo, Andrew Regenscheid, Stephanie Nelson
Abstract
This report provides implementation guidance to help federal agencies and cloud service providers (CSPs) protect tokens and assertions from forgery, theft, and misuse. Building on updates to NIST SP 800-53 (Release 5.1.1), it outlines principles for CSPs and consuming agencies, details architectural considerations for identity providers and authorization servers, and recommends enhancements to key management, token verification, and life cycle controls. The report addresses threats demonstrated in recent high-profile attacks, emphasizes the importance of secure by design practices, configurability, interoperability, and continuous monitoring, and provides specific technical recommendations to safeguard single sign-on, federation, and application programming interface (API) access scenarios.
Citation
NIST Interagency/Internal Report (NISTIR) - 8587
Keywords
access management, federation, key management, single sign-on, token management
Citation
Galluzzo, R. , Regenscheid, A. and Nelson, S. (2026), NISTIR 8587 Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers, NIST Interagency/Internal Report (NISTIR), National Institute of Standards and Technology, Gaithersburg, MD, [online], https://doi.org/10.6028/NIST.IR.8587, https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=962217 (Accessed September 16, 2026)
Additional citation formats
Issues
If you have any questions about this publication or are having problems accessing it, please contact [email protected].