An official website of the United States government
Here’s how you know
Official websites use .gov
A .gov website belongs to an official government organization in the United States.
Secure .gov websites use HTTPS
A lock (
) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.
NISTIR 8587 Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers
Published
Author(s)
Ryan Galluzzo, Andrew Regenscheid, Stephanie Nelson
Abstract
This report provides implementation guidance to help federal agencies and cloud service providers (CSPs) protect tokens and assertions from forgery, theft, and misuse. Building on updates to NIST SP 800-53 (Release 5.1.1), it outlines principles for CSPs and consuming agencies, details architectural considerations for identity providers and authorization servers, and recommends enhancements to key management, token verification, and life cycle controls. The report addresses threats demonstrated in recent high-profile attacks, emphasizes the importance of secure by design practices, configurability, interoperability, and continuous monitoring, and provides specific technical recommendations to safeguard single sign-on, federation, and application programming interface (API) access scenarios.
Galluzzo, R.
, Regenscheid, A.
and Nelson, S.
(2026),
NISTIR 8587 Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers, NIST Interagency/Internal Report (NISTIR), National Institute of Standards and Technology, Gaithersburg, MD, [online], https://doi.org/10.6028/NIST.IR.8587, https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=962217 (Accessed September 16, 2026)