{
  "id": 7768741,
  "title": "NIST strengthens safeguards for SSO and API tokens",
  "url": "https://urgent.news/2026/09/16/nist-strengthens-safeguards-for-sso-and-api-tokens",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-16T08:07:17.000Z",
  "source": {
    "name": "Arabian Post",
    "slug": "arabian-post",
    "url": "https://thearabianpost.com/nist-strengthens-safeguards-for-sso-and-api-tokens/"
  },
  "original_language": "en",
  "account": "The US National Institute of Standards and Technology (NIST) has finalized new guidance aimed at strengthening security for single sign-on (SSO), cloud federation and API access. The updated guidance, released on September 15, focuses on protecting identity tokens, access tokens and assertions used by federal agencies and cloud service providers.\n\nThe report, NIST Interagency Report 8587, recommends stronger controls for cryptographic signing keys, including secure storage, protected use and automated rotation. It also emphasizes the need for proper validation, scoping and revocation of tokens. Workload identities receive expanded treatment, with NIST recommending the use of short-lived tokens for software workloads.\n\nOrganisations are encouraged to implement secure defaults, strong key protection, configurability and monitoring for token-based access systems. The guidance applies to both providers and customers, with cloud providers expected to design secure services and consuming organisations responsible for configuring and maintaining controls. NIST received over 250 comments from various contributors, leading to changes in key protection, validity periods, workload identities and references to standards and protocols.",
  "summary": "The US National Institute of Standards and Technology has finalised new guidance aimed at reducing theft, forgery and misuse of digital tokens that underpin single sign-on, cloud federation and API access. NIST Interagency Report 8587, released on September 15, sets out implementation recommendations for federal agencies and cloud service providers handling identity tokens, access tokens and…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}