I am hoping to keep it based around private/public keys and certificates- so having a CA we trust, having each server hold a certificate, having each client / web browser hold a certificate.
I am sure there was a simple approach but I seem to have gotten lost in okta, oauth, AWS and so on
I am no longer sure I get it and would value any pointers to reading folks may have