NIST and CISA finalize guidance on protecting access tokens
NIST IR 8587 sets out implementation recommendations for federal agencies and cloud providers managing identity tokens.
Event / data period: 2026-09-15
Published: · Updated:
The National Institute of Standards and Technology and the US Cybersecurity and Infrastructure Security Agency published the final NIST IR 8587 on 15 September 2026. The guidance gives federal agencies and cloud service providers implementation recommendations for protecting identity and access tokens against forgery, theft and misuse.
It addresses identity-provider and authorization-server architecture, key management, token verification and lifecycle controls. NIST says the report covers single sign-on, federation and API access scenarios and was revised after public feedback on its draft.
Data
Security development
Information and scope published by the source.
- · Occurred
NIST IR 8587 published
NIST and CISA published final implementation guidance on protecting identity and access tokens from forgery, theft and misuse.
Methodology
Figures and dates are reproduced as stated by the source; no additional forecast is made.
Updated:
Subjects and places
Subject proposals
- Crime, law and justiceSuggested
- Preserved editorial category/topic; broad candidate onlywww.nist.gov ↗