H2-CIAE · Core certification path
Identity and Access Engineering
H2 Certified Identity and Access Engineer
Who is who, and what they may do, for both people and machines: OIDC and OAuth done to spec, passkeys, workload identity, secrets with a real vault, and authorization as code.
6 courses · 21 lessons · ~36 h of guided work
Assumes Foundation
What you leave with
An SSO estate on Zitadel with passkeys and SCIM, SPIFFE identities for workloads, OpenBao issuing short-lived secrets, and an OPA/Cedar policy engine deciding access.
- IdP
- Zitadel
- Protocols
- OIDC / OAuth 2.1
- Workload id
- SPIFFE / SPIRE
- Secrets
- OpenBao
- Authz
- OPA / Cedar
Syllabus
6 courses · every lesson graded · minutes are guided work
Course 01
OIDC and OAuth to spec
The protocols correctly, not cargo-culted: authorization code with PKCE, the token types, and the redirect and scope traps that become breaches.
4 lessons · ~7 h
- 01The flowsAuthorization code with PKCE, client credentials, device code; which one for which caller.120 min
- 02TokensID versus access versus refresh; validation, audience, expiry, and what a leaked one does.90 min
- 03Zitadel in practiceAn app, a project, scoped grants, and a login that returns a Bearer JWT.120 min
- 04The trapsredirect_uri validation, scope creep, and the localhost trap that a WAF rule flags.90 min
Course checkImplement a compliant OIDC login and a machine-to-machine flow; a checker probes for the common mistakes.
You leave withA working OIDC login and a client-credentials flow on Zitadel, with PKCE, correct redirect validation and scoped tokens.
Course 02
Passkeys and step-up
Kill the password: WebAuthn passkeys as the primary factor, with step-up authentication for the actions that deserve friction.
3 lessons · ~5 h
- 01WebAuthnRegistration and authentication ceremonies; what the authenticator proves and what it does not.120 min
- 02Recovery without a backdoorA recovery path that does not undo the security of the passkey.90 min
- 03Step-upRe-authentication on a sensitive action, scoped to that action only.90 min
Course checkShip passkey sign-in with a recovery path and a step-up challenge on a sensitive action.
You leave withPasskey registration and sign-in, a recovery flow that is not a backdoor, and step-up on a high-risk action.
Course 03
SSO and lifecycle
One login across products, and joiners-movers-leavers handled automatically so access ends when employment does.
3 lessons · ~6 h
- 01SSO across appsTwo apps behind one identity; session and logout that actually propagate.120 min
- 02SCIM provisioningUsers and groups synced from a source of truth; a deprovision that revokes on time.120 min
- 03Roles and grantsProduct-scoped roles; the one writer that owns grants; no parallel grant paths.90 min
Course checkWire SSO for two apps and provision plus deprovision a user through SCIM; prove access is gone within the SLA.
You leave withSSO across two applications and SCIM provisioning that removes access automatically when a user is deactivated.
Course 04
Workload identity
Machines need identity too. SPIFFE IDs and short-lived certificates so a service proves what it is without a shared secret.
3 lessons · ~5 h
- 01Why workload identityThe static-secret problem; what SPIFFE replaces and how.90 min
- 02SPIRE in the clusterAttestation, SVIDs, and a service that gets its identity at start-up.120 min
- 03Service-to-service authTwo workloads authenticating by identity; rotation with no downtime.90 min
Course checkGive two services SPIFFE identities and let them authenticate to each other with no static credential anywhere.
You leave withSPIFFE/SPIRE issuing identities to workloads, mutual authentication with no shared secret, and rotation under load.
Course 05
Secrets and custody
OpenBao as the source of secrets: dynamic credentials, transit encryption, and the Shamir unseal you have actually performed.
4 lessons · ~7 h
- 01The secret problemStatic secrets versus dynamic; blast radius of each.90 min
- 02OpenBao in practiceDynamic database credentials, leases, and revocation on demand.120 min
- 03Transit and unsealTransit encryption for a service, and a manual Shamir unseal after a pod restart, done correctly.120 min
- 04RotationRotate a root credential with the service running; prove no outage.90 min
Course checkStand up a vault, issue a dynamic database credential, and perform an unseal from shares after a restart.
You leave withOpenBao issuing short-lived database credentials, a transit key encrypting fields, and an unseal runbook you executed.
Course 06
Authorization as code
Move access decisions out of scattered if-statements into a policy engine that is testable, auditable and the same everywhere.
4 lessons · ~7 h
- 01Why externalize authzScattered checks versus one engine; what becomes possible when policy is data.90 min
- 02Policy as codeOPA/Rego or Cedar policies for a real service; unit tests over the policy.120 min
- 03Enforcement pointsWhere the engine sits: gateway, sidecar, in-process; the trade-offs.90 min
- 04AuditEvery decision logged with its reason; answering who could access what, as of when.90 min
Course checkExternalize a service's authorization into policy, cover it with tests, and prove a denied request is denied for the right reason.
You leave withAn OPA or Cedar policy engine deciding access for a service, with a policy test suite and an audit trail of decisions.
Certification course
H2 Certified Identity and Access Engineer
$499 · one price · courses + 90-day labs + exam
Onboard a new tenant with SSO, provision and deprovision a user through SCIM, rotate a workload's identity under load, and prove least privilege across the estate, in one exercise.
Opens when Foundation is complete and the 6 course checks are passed. One proctored attempt, plus a free retake if you fail by a margin. The credential is an Open Badges 3.0 credential, signed and verifiable.
Counts toward H2-CTSE. Certified T-Shaped Security Expert is the credential of the whole T: hold all seven core credentials and it is awarded automatically, free, with no extra exam.
Create an account to enrol