The Authentication Server should be deployed behind your application’s infrastructure and should not be directly exposed to the Internet. See Figure 1. This model provides additional security and also provides greater programmatic control over Authentication Server behavior.
.png?sv=2026-02-06&spr=https&st=2026-10-01T07%3A28%3A56Z&se=2026-10-01T07%3A39%3A56Z&sr=c&sp=r&sig=wvRvwS%2FdV2AYkUjQ05sZbkzzPJI3d6s3YKG%2F4OGi3X8%3D)
Figure 1 Deployment Architecture
The API Server handles session management. To use your application infrastructure to handle session management, write a custom API Server session plugin. If your application infrastructure uses a static rules engine or a risk scoring system, your application infrastructure can use those systems to determine which Nok Nok authentication policy to select.