Torsten Lodderstedt
- Editor of the OAuth 2.0 Security Best Current Practice and RFC 6819, the OAuth threat model
- Contributor to the OpenID Foundation FAPI working group and co-chair of eKYC and IDA
- Project lead for Germany's EU Digital Identity Wallet at SPRIND
- Former CTO of yes.com, a German open-banking scheme
Bio
Torsten Lodderstedt edits the OAuth 2.0 Security Best Current Practice and edited RFC 6819, the OAuth threat model. He has contributed heavily to the OpenID Foundation's FAPI work, led consumer identity at Deutsche Telekom, served as CTO of the open-banking scheme yes.com, and now leads Germany's EU Digital Identity Wallet project at SPRIND.
Profile built from public IETF, OpenID Foundation, and employer records.
Where their work shows up
Two things in this field depend on his work. FAPI is what open banking and other high-assurance deployments profile OAuth down to: sender-constrained tokens, mutual TLS, pushed authorization requests. And the OAuth security BCP is the document that quietly deprecated the implicit grant and made PKCE universal, which is most of what changed between OAuth 2.0 and OAuth 2.1. His current work on the EUDI wallet applies the same discipline to wallet-based identity.
Related on Start with Identity
- GlossaryDigital Identity Wallet
An app or service that stores a holder's decentralized identifiers and verifiable credentials and manages consent when presenting them. Government wallets such
- CVEKeycloak client policy enforcement flaw
A 2026 Keycloak client-policy enforcement bug. Client policies are how you ban implicit flow, require PKCE, or force FAPI. If they do not fire, the realm's writ
- GlossaryPAR
Pushed Authorization Requests (RFC 9126). The client sends authorization parameters directly to the server over a back channel first, hardening the flow against
- GlossaryPSD2
Revised Payment Services Directive. EU regulation requiring Strong Customer Authentication for electronic payments and enabling open banking. SCA mandates two-f
- ExpertChairman
Nat Sakimura has chaired the OpenID Foundation for many years and is a primary author of the OpenID Connect specifications and the FAPI security profile used by
- ExpertCo-author of TLS 1.0 and the W3C DID specification
Christopher Allen co-authored the IETF TLS 1.0 specification, co-authored the W3C Decentralized Identifiers specification, and in 2016 published The Path to Sel