{"id":604,"date":"2026-08-11T12:11:16","date_gmt":"2026-08-11T12:11:16","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=604"},"modified":"2026-08-11T12:11:16","modified_gmt":"2026-08-11T12:11:16","slug":"sso","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/sso\/","title":{"rendered":"SSO Explained: How Single Sign-On Really Works"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: SSO\n     Shared glossary design system. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">Single sign-on lets people use one set of credentials, held by one identity provider, to reach every application they are entitled to, instead of a separate password for each.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Access &amp; identity<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>SSO means a user authenticates once with a central identity provider, which then vouches for them to each application. The application never sees the password. For a company it means one place to enforce <a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">MFA<\/a>, one place to revoke access when someone leaves, and one audit trail of who signed in to what.<\/p>\n<\/div>\n\n<p>The security value is not convenience. It is that access is granted and removed in one place, which is what makes offboarding reliable.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#flow\">How SSO works<\/a><\/li>\n    <li><a href=\"#protocols\">SAML and OIDC<\/a><\/li>\n    <li><a href=\"#not\">What SSO does not cover<\/a><\/li>\n    <li><a href=\"#osto\">How Osto handles access<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"flow\">How SSO works<\/h2>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 380\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Single sign-on sequence: user requests the app, is redirected to the identity provider, authenticates with password and MFA, the provider returns a signed assertion, and the app grants access.\">\n  <defs><marker id=\"ssA\" markerWidth=\"9\" markerHeight=\"9\" refX=\"7\" refY=\"4.5\" orient=\"auto\"><path d=\"M0,0 L9,4.5 L0,9 z\" fill=\"#4a52a8\"\/><\/marker><\/defs>\n\n  <rect x=\"20\" y=\"26\" width=\"180\" height=\"44\" rx=\"12\" fill=\"#e9ecfa\"\/>\n  <text x=\"110\" y=\"54\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13.5\" font-weight=\"700\" fill=\"#4a52a8\">User<\/text>\n  <line x1=\"110\" y1=\"70\" x2=\"110\" y2=\"348\" stroke=\"#dfe3f5\" stroke-width=\"2\" stroke-dasharray=\"5 5\"\/>\n\n  <rect x=\"290\" y=\"26\" width=\"180\" height=\"44\" rx=\"12\" fill=\"#1c267a\"\/>\n  <text x=\"380\" y=\"54\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13.5\" font-weight=\"700\" fill=\"#ffffff\">Identity provider<\/text>\n  <line x1=\"380\" y1=\"70\" x2=\"380\" y2=\"348\" stroke=\"#dfe3f5\" stroke-width=\"2\" stroke-dasharray=\"5 5\"\/>\n\n  <rect x=\"560\" y=\"26\" width=\"180\" height=\"44\" rx=\"12\" fill=\"#e2eff7\"\/>\n  <text x=\"650\" y=\"54\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13.5\" font-weight=\"700\" fill=\"#2f6a89\">Application<\/text>\n  <line x1=\"650\" y1=\"70\" x2=\"650\" y2=\"348\" stroke=\"#dfe3f5\" stroke-width=\"2\" stroke-dasharray=\"5 5\"\/>\n\n  <line x1=\"110\" y1=\"108\" x2=\"644\" y2=\"108\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#ssA)\"\/>\n  <text x=\"377\" y=\"98\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\"><tspan font-weight=\"700\" fill=\"#4a52a8\">1<\/tspan>  Opens the application<\/text>\n\n  <line x1=\"650\" y1=\"152\" x2=\"386\" y2=\"152\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#ssA)\"\/>\n  <text x=\"518\" y=\"142\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\"><tspan font-weight=\"700\" fill=\"#4a52a8\">2<\/tspan>  Redirects: prove who you are<\/text>\n\n  <line x1=\"380\" y1=\"196\" x2=\"116\" y2=\"196\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#ssA)\"\/>\n  <text x=\"248\" y=\"186\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\"><tspan font-weight=\"700\" fill=\"#4a52a8\">3<\/tspan>  Password and MFA, once<\/text>\n\n  <line x1=\"110\" y1=\"240\" x2=\"374\" y2=\"240\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#ssA)\"\/>\n  <text x=\"242\" y=\"230\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\"><tspan font-weight=\"700\" fill=\"#4a52a8\">4<\/tspan>  Credentials verified<\/text>\n\n  <line x1=\"380\" y1=\"284\" x2=\"644\" y2=\"284\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#ssA)\"\/>\n  <text x=\"512\" y=\"274\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\"><tspan font-weight=\"700\" fill=\"#4a52a8\">5<\/tspan>  Signed assertion, no password<\/text>\n\n  <line x1=\"650\" y1=\"328\" x2=\"116\" y2=\"328\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#ssA)\"\/>\n  <text x=\"383\" y=\"318\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\"><tspan font-weight=\"700\" fill=\"#4a52a8\">6<\/tspan>  Access granted<\/text>\n\n  <rect x=\"240\" y=\"344\" width=\"280\" height=\"26\" rx=\"13\" fill=\"#f4f5fd\"\/>\n  <text x=\"380\" y=\"361\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#4a52a8\">Next app: steps 1, 2, 5 and 6 only<\/text>\n<\/svg>\n<\/div>\n<figcaption><span class=\"swipe\">Swipe to see the full diagram. <\/span>Read top to bottom. Step 3 happens once per session, which is why the second and third application never prompt again.<\/figcaption>\n<\/figure>\n\n<h2 id=\"protocols\" class=\"c-sage\">SAML and OIDC<\/h2>\n\n<p>Two protocols do almost all of this. Both let an identity provider vouch for a user; they differ in age and in what they were designed for.<\/p>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th><\/th><th>SAML 2.0<\/th><th>OpenID Connect<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>Format<\/strong><\/td><td>XML assertion<\/td><td>JSON web token<\/td><\/tr>\n    <tr><td><strong>Built for<\/strong><\/td><td>Browser-based enterprise applications<\/td><td>Web, mobile and API clients<\/td><\/tr>\n    <tr><td><strong>Built on<\/strong><\/td><td>Its own specification<\/td><td>OAuth 2.0<\/td><\/tr>\n    <tr><td><strong>Common in<\/strong><\/td><td>Established B2B SaaS and internal tools<\/td><td>Newer applications and consumer sign-in<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">SSO and MFA are not alternatives<\/p>\n  <p>SSO decides where authentication happens. MFA decides how strong that authentication is. SSO without MFA concentrates risk, because one password now opens every application at once.<\/p>\n<\/div>\n\n<h2 id=\"not\" class=\"c-apri\">What SSO does not cover<\/h2>\n\n<div class=\"trio\">\n  <div class=\"tcard a\">\n    <p class=\"n\">Systems outside it<\/p>\n    <p>Direct database access, SSH into production and legacy admin panels usually sit outside the identity provider.<\/p>\n  <\/div>\n  <div class=\"tcard b\">\n    <p class=\"n\">Tools bought by teams<\/p>\n    <p>Anything signed up for on a card, without IT involvement, has its own password and its own offboarding gap.<\/p>\n  <\/div>\n  <div class=\"tcard c\">\n    <p class=\"n\">Service accounts<\/p>\n    <p>Machine identities and API keys are not people and do not pass through the sign-in flow at all.<\/p>\n  <\/div>\n<\/div>\n\n<h2 id=\"osto\">How Osto handles access<\/h2>\n\n<p>Osto&#8217;s IAM module manages identity and access across the stack, and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/ztna\/\">ZTNA<\/a> closes the gap SSO leaves. Internal resources sit behind a private domain and stay unreachable unless the Osto endpoint agent is installed and MFA is satisfied, which covers the systems that were never wired into an identity provider in the first place. Sign-in events also land in the same platform as endpoint and cloud activity, so a suspicious authentication can be correlated with what happened next.<\/p>\n\n<p class=\"related\"><strong>Product documentation:<\/strong> Setup guides and technical reference are available in the <a href=\"https:\/\/docs.osto.one\/\" target=\"_blank\" rel=\"noopener\">Osto documentation<\/a>.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Free security assessment<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Cover the systems SSO never reached<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Osto gates internal resources behind ZTNA with agent and MFA enforcement, and manages identity across the stack.<\/p>\n  <a href=\"https:\/\/osto.one\/contact\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 30px;border-radius:12px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Get a free security assessment<\/span><\/a>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:transparent;color:#ffffff;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:600;font-size:16px;text-decoration:none;border:1.5px solid rgba(255,255,255,.5);border-radius:12px;padding:13px 28px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#ffffff;\">Book a platform walkthrough<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:14px 0 0;\">Deploys in hours &middot; No dedicated security team required &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What does SSO stand for?<\/summary>\n  <p>Single sign-on. A user authenticates once with a central identity provider, which then vouches for them to each connected application without asking for credentials again.<\/p>\n<\/details>\n\n<details>\n  <summary>Is SSO more secure than separate passwords?<\/summary>\n  <p>Generally yes, because MFA is enforced in one place, access is revoked in one place, and applications never receive the password. It does concentrate risk in the identity provider, which is why phishing-resistant MFA on that account matters.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the difference between SSO and federation?<\/summary>\n  <p>SSO describes the user experience of authenticating once. Federation is the trust relationship between an identity provider and a service provider that makes it possible. SAML and OIDC are federation protocols.<\/p>\n<\/details>\n\n<details>\n  <summary>Do auditors ask about SSO?<\/summary>\n  <p>Yes. <a href=\"https:\/\/www.osto.one\/resources\/blog\/soc-2-readiness-checklist\/\">Security questionnaires and auditors<\/a> ask whether SSO is enforced, which systems sit outside it, and how access is removed when someone leaves. The systems outside SSO are usually where findings come from.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">MFA<\/a> &middot; IAM &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/ztna\/\">Zero Trust Network Access<\/a> &middot; RBAC &middot; SAML &middot; Passwordless Authentication<\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Single sign-on lets people use one set of credentials, held by one identity provider, to reach every application they are\u2026<\/p>\n","protected":false},"author":8,"featured_media":605,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[191,192],"class_list":["post-604","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-single-sign-on","tag-sso"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/604","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=604"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/604\/revisions"}],"predecessor-version":[{"id":606,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/604\/revisions\/606"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/605"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=604"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=604"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=604"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}