While it won't solve for SPA, the SPIFFE project (https://spiffe.io/) aims to deliver short-lived keys and certificates to workloads at runtime to allow them to establish channel authentication (mTLS) and encryption, and to generate & validate JWT tokens for individual message authentication.
Comments
While it won't solve for SPA, the SPIFFE project (https://spiffe.io/) aims to deliver short-lived keys and certificates to workloads at runtime to allow them to establish channel authentication (mTLS) and encryption, and to generate & validate JWT tokens for individual message authentication.