← Every path

H2-CIAE · Core certification path

Identity and Access Engineering

H2 Certified Identity and Access Engineer

Who is who, and what they may do, for both people and machines: OIDC and OAuth done to spec, passkeys, workload identity, secrets with a real vault, and authorization as code.

6 courses · 21 lessons · ~36 h of guided work

Assumes Foundation

What you leave with

An SSO estate on Zitadel with passkeys and SCIM, SPIFFE identities for workloads, OpenBao issuing short-lived secrets, and an OPA/Cedar policy engine deciding access.

IdP
Zitadel
Protocols
OIDC / OAuth 2.1
Workload id
SPIFFE / SPIRE
Secrets
OpenBao
Authz
OPA / Cedar

Syllabus

6 courses · every lesson graded · minutes are guided work

  1. Course 01

    OIDC and OAuth to spec

    The protocols correctly, not cargo-culted: authorization code with PKCE, the token types, and the redirect and scope traps that become breaches.

    4 lessons · ~7 h

    1. 01The flowsAuthorization code with PKCE, client credentials, device code; which one for which caller.120 min
    2. 02TokensID versus access versus refresh; validation, audience, expiry, and what a leaked one does.90 min
    3. 03Zitadel in practiceAn app, a project, scoped grants, and a login that returns a Bearer JWT.120 min
    4. 04The trapsredirect_uri validation, scope creep, and the localhost trap that a WAF rule flags.90 min

    Course checkImplement a compliant OIDC login and a machine-to-machine flow; a checker probes for the common mistakes.

    You leave withA working OIDC login and a client-credentials flow on Zitadel, with PKCE, correct redirect validation and scoped tokens.

  2. Course 02

    Passkeys and step-up

    Kill the password: WebAuthn passkeys as the primary factor, with step-up authentication for the actions that deserve friction.

    3 lessons · ~5 h

    1. 01WebAuthnRegistration and authentication ceremonies; what the authenticator proves and what it does not.120 min
    2. 02Recovery without a backdoorA recovery path that does not undo the security of the passkey.90 min
    3. 03Step-upRe-authentication on a sensitive action, scoped to that action only.90 min

    Course checkShip passkey sign-in with a recovery path and a step-up challenge on a sensitive action.

    You leave withPasskey registration and sign-in, a recovery flow that is not a backdoor, and step-up on a high-risk action.

  3. Course 03

    SSO and lifecycle

    One login across products, and joiners-movers-leavers handled automatically so access ends when employment does.

    3 lessons · ~6 h

    1. 01SSO across appsTwo apps behind one identity; session and logout that actually propagate.120 min
    2. 02SCIM provisioningUsers and groups synced from a source of truth; a deprovision that revokes on time.120 min
    3. 03Roles and grantsProduct-scoped roles; the one writer that owns grants; no parallel grant paths.90 min

    Course checkWire SSO for two apps and provision plus deprovision a user through SCIM; prove access is gone within the SLA.

    You leave withSSO across two applications and SCIM provisioning that removes access automatically when a user is deactivated.

  4. Course 04

    Workload identity

    Machines need identity too. SPIFFE IDs and short-lived certificates so a service proves what it is without a shared secret.

    3 lessons · ~5 h

    1. 01Why workload identityThe static-secret problem; what SPIFFE replaces and how.90 min
    2. 02SPIRE in the clusterAttestation, SVIDs, and a service that gets its identity at start-up.120 min
    3. 03Service-to-service authTwo workloads authenticating by identity; rotation with no downtime.90 min

    Course checkGive two services SPIFFE identities and let them authenticate to each other with no static credential anywhere.

    You leave withSPIFFE/SPIRE issuing identities to workloads, mutual authentication with no shared secret, and rotation under load.

  5. Course 05

    Secrets and custody

    OpenBao as the source of secrets: dynamic credentials, transit encryption, and the Shamir unseal you have actually performed.

    4 lessons · ~7 h

    1. 01The secret problemStatic secrets versus dynamic; blast radius of each.90 min
    2. 02OpenBao in practiceDynamic database credentials, leases, and revocation on demand.120 min
    3. 03Transit and unsealTransit encryption for a service, and a manual Shamir unseal after a pod restart, done correctly.120 min
    4. 04RotationRotate a root credential with the service running; prove no outage.90 min

    Course checkStand up a vault, issue a dynamic database credential, and perform an unseal from shares after a restart.

    You leave withOpenBao issuing short-lived database credentials, a transit key encrypting fields, and an unseal runbook you executed.

  6. Course 06

    Authorization as code

    Move access decisions out of scattered if-statements into a policy engine that is testable, auditable and the same everywhere.

    4 lessons · ~7 h

    1. 01Why externalize authzScattered checks versus one engine; what becomes possible when policy is data.90 min
    2. 02Policy as codeOPA/Rego or Cedar policies for a real service; unit tests over the policy.120 min
    3. 03Enforcement pointsWhere the engine sits: gateway, sidecar, in-process; the trade-offs.90 min
    4. 04AuditEvery decision logged with its reason; answering who could access what, as of when.90 min

    Course checkExternalize a service's authorization into policy, cover it with tests, and prove a denied request is denied for the right reason.

    You leave withAn OPA or Cedar policy engine deciding access for a service, with a policy test suite and an audit trail of decisions.

Certification course

H2 Certified Identity and Access Engineer

$499 · one price · courses + 90-day labs + exam

Onboard a new tenant with SSO, provision and deprovision a user through SCIM, rotate a workload's identity under load, and prove least privilege across the estate, in one exercise.

Opens when Foundation is complete and the 6 course checks are passed. One proctored attempt, plus a free retake if you fail by a margin. The credential is an Open Badges 3.0 credential, signed and verifiable.

Counts toward H2-CTSE. Certified T-Shaped Security Expert is the credential of the whole T: hold all seven core credentials and it is awarded automatically, free, with no extra exam.

Create an account to enrol