Tag

oauth

Articles tagged with oauth.

security

Better Auth 1.7.7: OAuth State vs Magic-Link Tokens

Better Auth 1.7.7 stops OAuth state values being redeemed as magic-link tokens. What went wrong, how to upgrade, and how…

Guilliano Molaire Guilliano Molaire 11 min read
auth-patterns

Keycloak 26.8 Token Exchange Delegation for AI Agents

Keycloak 26.8 moves token exchange delegation to preview: users consent, FGAP V2 gates the agent, and the delegated token carries…

Guilliano Molaire Guilliano Molaire 15 min read
Definition and Basics

Non-Human Identity (NHI) for AI Agents on Keycloak

A non-human identity is an identity used by software, not a person. How AI agents fit, why one shared bot…

Guilliano Molaire Guilliano Molaire 10 min read
auth-patterns

MCP Authorization Decision Tree: When to Use Keycloak

MCP authorization is optional and stdio servers should skip OAuth. A decision tree for when to use API keys, OAuth,…

Guilliano Molaire Guilliano Molaire 9 min read
comparisons

Okta Agent Gateway vs Keycloak for MCP Authorization

Okta Agent Gateway puts policy inline between AI agents and MCP tools. Here is what it adds, and why MCP…

Guilliano Molaire Guilliano Molaire 12 min read
comparisons

Microsoft Entra Agent ID vs Keycloak for AI Agent Identity

Microsoft Entra Agent ID gives AI agents directory identities. Here is how blueprints, FIC and agent OBO map to Keycloak…

Guilliano Molaire Guilliano Molaire 13 min read
security

MCP Python SDK OAuth Flaw: Pin the Issuer on Keycloak

MCP OAuth flaw GHSA-qx49-fqc8-xw99: a malicious server could steal client secrets and PKCE verifiers from the MCP Python SDK. Upgrade,…

Guilliano Molaire Guilliano Molaire 12 min read
security

CVE-2026-97846: Keycloak Token Exchange Drops mTLS Binding

CVE-2026-97846 lets Keycloak standard token exchange issue an unbound Bearer token for an mTLS-bound client. What it breaks, who is…

Guilliano Molaire Guilliano Molaire 11 min read
security

CVE-2026-59822: LiteLLM’s MCP Auth Bypass, and the Second Bug in the Same Fix

CVE-2026-59822 let any fabricated Bearer token open a LiteLLM MCP session. The two separate bugs one pull request closed, and…

Guilliano Molaire Guilliano Molaire 11 min read
comparisons

AgentCore Identity Consent Portal vs Keycloak for AI Agent OAuth

AWS now hosts the OAuth consent portal for Bedrock AgentCore agents. What it removes, what it actually couples, and where…

Guilliano Molaire Guilliano Molaire 9 min read

Stay ahead on identity & security

Get tutorials, product updates, and Keycloak tips delivered to your inbox.

© 2026 Skycloak. All Rights Reserved. Design by Yasser Soliman