#KEYCLOAK DevDay 2026: From Pods to Permissions: Token Exchange Meets Kubernetes Service Identity

S👉 This talk is from KEYCLOAK DevDay Community Conference 2026: https://keycloak-day.dev Speaker: Sven-Torben Janus #Token #Exchange has become a foundational pattern for secure service-to-service authentication in Keycloak. With the recent Standard Token Exchange introduced, implementing least-privilege delegation across services is more streamlined than ever. In this talk, we take it a step further: leveraging Kubernetes projected service account tokens to authenticate workloads to Keycloak. Using trusted JWKS clients and external token validation (introduced in Keycloak 26.4 as a preview), services can authenticate without shared secrets - enabling cleaner and more secure integration in cloud-native environments. Thanks for watching! Don't forget to subscribe 🔔 to my channel (if not already done) and give this video some thumbs up 👍 (aka "like"). Tell me about your experiences and thoughts about this topic in the comments. I'm looking forward to it! Thank YOU! --- I'm Niko - and I'm your Expert for Keycloak IAM & SSO and an independent freelance software consultant, developer and trainer. I'm here to help - you, your team and your company. How can I support you? Just get in contact: 🌎 Website: https://www.n-k.de 🔗 LinkedIn:   / dasniko   🚧 GitHub Profile: https://github.com/dasniko 🦣 Mastodon: https://mastodon.cloud/@dasniko 🎥 YouTube Channel:    / @dasniko   All things Java, All-End (Frontend, Backend, Fullstack Deployments), Authentication, Security 🔐, IAM, Keycloak, Containers, DevOps, Cloud ☁️, Serverless, On-Premise Please understand that YouTube Comments are not a good place to get support in case of questions and errors. There are forums and groups out there (see links above) which are the right place to ask!

#KEYCLOAK DevDay 2026: Replacing Keycloak's Infinispan Caches with Redis/Valkey
▶︎

#KEYCLOAK DevDay 2026: Replacing Keycloak's Infinispan Caches with Redis/Valkey

Passkeys Explained: Are They Actually Better Than Passwords?
▶︎

Passkeys Explained: Are They Actually Better Than Passwords?

#KEYCLOAK DevDay 2026: Mobile apps authentication with Keycloak - navigating the pitfalls
▶︎

#KEYCLOAK DevDay 2026: Mobile apps authentication with Keycloak - navigating the pitfalls

Android 17 sucks. So I put Linux on a phone.
▶︎

Android 17 sucks. So I put Linux on a phone.

Passwordless Login mit Keycloak, Andreas Grill
▶︎

Passwordless Login mit Keycloak, Andreas Grill

#KEYCLOAK DevDay 2026: Scaling Trust: Building Multi-Region mTLS for Keycloak | Luis Rubiera
▶︎

#KEYCLOAK DevDay 2026: Scaling Trust: Building Multi-Region mTLS for Keycloak | Luis Rubiera

#KEYCLOAK DevDay 2026: The Passkey Journey | Steffen Ritter
▶︎

#KEYCLOAK DevDay 2026: The Passkey Journey | Steffen Ritter

Billionaire's WARNING: I'm SELLING. The Crash Is Already Here!
▶︎

Billionaire's WARNING: I'm SELLING. The Crash Is Already Here!

The Moment That Changed Software Development!
▶︎

The Moment That Changed Software Development!

#KEYCLOAK DevDay 2026: Implementing the Phantom Token Pattern with Keycloak | Thomas Darimont
▶︎

#KEYCLOAK DevDay 2026: Implementing the Phantom Token Pattern with Keycloak | Thomas Darimont

The Hard Fall of Porsche
▶︎

The Hard Fall of Porsche

New Entra ID Conditional Access Features June 2026
▶︎

New Entra ID Conditional Access Features June 2026

7 Authentication Concepts Every Developer Should Know
▶︎

7 Authentication Concepts Every Developer Should Know

Conan O’Brien Mocks Trump At Harvard Commencement | Crowd Erupts During Viral Speech
▶︎

Conan O’Brien Mocks Trump At Harvard Commencement | Crowd Erupts During Viral Speech

ENPAL COMPLETELY DISASSEMBLED: Why we almost lost our faith!
▶︎

ENPAL COMPLETELY DISASSEMBLED: Why we almost lost our faith!

#KEYCLOAK DevDay 2026: From Zero to Keycloak: Scaling Identity at Gusto | Espen Roth & Ankur Agrawal
▶︎

#KEYCLOAK DevDay 2026: From Zero to Keycloak: Scaling Identity at Gusto | Espen Roth & Ankur Agrawal

Let’s Handle 1 Million Requests per Second, It’s Scarier Than You Think!
▶︎

Let’s Handle 1 Million Requests per Second, It’s Scarier Than You Think!

#KEYCLOAK DevDay 2026: DPoP in Practice: Preventing Token Replay Attacks | Halil Özkan & Eren Kan
▶︎

#KEYCLOAK DevDay 2026: DPoP in Practice: Preventing Token Replay Attacks | Halil Özkan & Eren Kan

System Design Explained: APIs, Databases, Caching, CDNs, Load Balancing & Production Infra
▶︎

System Design Explained: APIs, Databases, Caching, CDNs, Load Balancing & Production Infra

#KEYCLOAK DevDay 2026 - AI, MCP and Security | Domink Guhr
▶︎

#KEYCLOAK DevDay 2026 - AI, MCP and Security | Domink Guhr