Heather Flanagan
- Editor contributions to the IDPro Body of Knowledge
- Standards work across IETF and the identity community
- Writing and education on federation and identity standards
Bio
Heather Flanagan works at the intersection of standards, writing, and the identity community. She has contributed to the IDPro Body of Knowledge and to standards efforts across the IETF and federation community, and is known for making complex identity standards legible to practitioners. Her consulting and writing focus on federation, governance, and the human side of standards.
Profile built from public IDPro, IETF, and personal-site records.
Where their work shows up
The IDPro Body of Knowledge is one of the few vendor-neutral attempts to define what an identity practitioner should actually know, which makes it a useful complement to our fundamentals guides and glossary. Her federation standards work touches SAML 2.0 and the trust frameworks that make cross-organization federation work.
Related on Start with Identity
- BlogA loose PHP comparison let attackers sign in as WordPress admin through SAML
Two unauthenticated bypasses in the miniOrange SAML 2.0 Single Sign On plugin, CVE-2026-61979 and CVE-2026-15981, treat OpenSSL's error return as a valid signat
- BlogAgent identity just got a protocol, which is the easy half
Okta shipped Agent SSO and got Cross App Access adopted into MCP the same month a GitHub issue was shown to reach CI secrets in Claude Code and Gemini CLI. The
- BlogEMVCo drafts one credential standard so merchants stop building per-wallet integrations
EMVCo published a draft framework for verifiable digital credentials in card-based payments, aimed at giving merchants one consistent data structure to authenti
- GlossaryIdentity Provider (IdP)
A system that authenticates users and issues assertions or tokens vouching for their identity to other applications. In federated single sign-on, the identity p
- GlossarySocial Login
Letting users sign in with an existing account from a provider like Google or Apple, usually over OIDC. Reduces signup friction but ties accounts to third-party
- ExpertDirector of Identity Standards
Aaron Parecki is one of the most accessible voices in OAuth and OpenID Connect. He maintains oauth.net, wrote OAuth 2.0 Simplified, and is an active contributor