#KEYCLOAK DevDay 2026: Implementing the Phantom Token Pattern with Keycloak | Thomas Darimont
👉 This talk is from KEYCLOAK DevDay Community Conference 2026: https://keycloak-day.dev Most Keycloak users rely on enriched access tokens. This approach is efficient but often overexposes information, especially when those tokens are exposed to external parties. The Phantom Token Pattern offers an alternative: combining privacy-preserving opaque-style minimal tokens with backend tokens. This talk introduces the concept, explains how it aligns with Keycloak’s capabilities, and demonstrates how to implement it using lightweight tokens and an API gateway. Discover how to enhance privacy and control in your token architecture without compromising performance. Thanks for watching! Don't forget to subscribe 🔔 to my channel (if not already done) and give this video some thumbs up 👍 (aka "like"). Tell me about your experiences and thoughts about this topic in the comments. I'm looking forward to it! Thank YOU! --- I'm Niko - and I'm your Expert for Keycloak IAM & SSO and an independent freelance software consultant, developer and trainer. I'm here to help - you, your team and your company. How can I support you? Just get in contact: 🌎 Website: https://www.n-k.de 🔗 LinkedIn: / dasniko 🚧 GitHub Profile: https://github.com/dasniko 🦣 Mastodon: https://mastodon.cloud/@dasniko 🎥 YouTube Channel: / @dasniko All things Java, All-End (Frontend, Backend, Fullstack Deployments), Authentication, Security 🔐, IAM, Keycloak, Containers, DevOps, Cloud ☁️, Serverless, On-Premise Please understand that YouTube Comments are not a good place to get support in case of questions and errors. There are forums and groups out there (see links above) which are the right place to ask!

#KEYCLOAK DevDay 2026: Replacing Keycloak's Infinispan Caches with Redis/Valkey

#KEYCLOAK DevDay 2026: How to apply Keycloak to AI agents/Agent AI - Updates and future plans

System Design Explained: APIs, Databases, Caching, CDNs, Load Balancing & Production Infra

#KEYCLOAK DevDay 2026: Scaling Trust: Building Multi-Region mTLS for Keycloak | Luis Rubiera

MFA, Passwordless Authentication and the Lost Phone by Niko Köbler

#KEYCLOAK DevDay 2026: DPoP in Practice: Preventing Token Replay Attacks | Halil Özkan & Eren Kan

#KEYCLOAK DevDay 2026: The Passkey Journey | Steffen Ritter

#KEYCLOAK DevDay 2026: Mobile apps authentication with Keycloak - navigating the pitfalls

Build a Full-Stack GenAI Project in 4 Hours (FastAPI, React, Supabase)

7 Authentication Concepts Every Developer Should Know

#KEYCLOAK DevDay 2026: Dynamic Features for Modular Keycloak Extensions | Frank Tripp

Billionaire's WARNING: I'm SELLING. The Crash Is Already Here!

Keynote: After the AI Hype – What’s Real, and What’s Next - Richard Campbell - 2026

Andrej Karpathy: From Vibe Coding to Agentic Engineering w/ Stephanie Zhan

Agentforce NOW codeLive: Connect Claude to Headless 360 with Salesforce Hosted MCP Servers

How Instagram Scaled Postgres to 2 Billion Users

How to Design APIs Like a Senior Engineer (REST, GraphQL, Auth, Security)

#KEYCLOAK DevDay 2026 - AI, MCP and Security | Domink Guhr

#KEYCLOAK DevDay 2026: From Zero to Keycloak: Scaling Identity at Gusto | Espen Roth & Ankur Agrawal

