Start with Identity
Protocols & Standards

Torsten Lodderstedt

Editor, OAuth 2.0 Security Best Current Practice · SPRIND · 18+ years in identity
Focus areas
OAuth SecurityFAPIOpen BankingEUDI Wallet
Notable work
  • Editor of the OAuth 2.0 Security Best Current Practice and RFC 6819, the OAuth threat model
  • Contributor to the OpenID Foundation FAPI working group and co-chair of eKYC and IDA
  • Project lead for Germany's EU Digital Identity Wallet at SPRIND
  • Former CTO of yes.com, a German open-banking scheme

Bio

Torsten Lodderstedt edits the OAuth 2.0 Security Best Current Practice and edited RFC 6819, the OAuth threat model. He has contributed heavily to the OpenID Foundation's FAPI work, led consumer identity at Deutsche Telekom, served as CTO of the open-banking scheme yes.com, and now leads Germany's EU Digital Identity Wallet project at SPRIND.

Profile built from public IETF, OpenID Foundation, and employer records.

Where their work shows up

Two things in this field depend on his work. FAPI is what open banking and other high-assurance deployments profile OAuth down to: sender-constrained tokens, mutual TLS, pushed authorization requests. And the OAuth security BCP is the document that quietly deprecated the implicit grant and made PKCE universal, which is most of what changed between OAuth 2.0 and OAuth 2.1. His current work on the EUDI wallet applies the same discipline to wallet-based identity.

Built from public information only. This is an independent profile and is not an endorsement by, or affiliation with, the person listed. Corrections: [email protected].