Articles tagged with oauth.
Better Auth 1.7.7 stops OAuth state values being redeemed as magic-link tokens. What went wrong, how to upgrade, and how…
Keycloak 26.8 moves token exchange delegation to preview: users consent, FGAP V2 gates the agent, and the delegated token carries…
A non-human identity is an identity used by software, not a person. How AI agents fit, why one shared bot…
MCP authorization is optional and stdio servers should skip OAuth. A decision tree for when to use API keys, OAuth,…
Okta Agent Gateway puts policy inline between AI agents and MCP tools. Here is what it adds, and why MCP…
Microsoft Entra Agent ID gives AI agents directory identities. Here is how blueprints, FIC and agent OBO map to Keycloak…
MCP OAuth flaw GHSA-qx49-fqc8-xw99: a malicious server could steal client secrets and PKCE verifiers from the MCP Python SDK. Upgrade,…
CVE-2026-97846 lets Keycloak standard token exchange issue an unbound Bearer token for an mTLS-bound client. What it breaks, who is…
CVE-2026-59822 let any fabricated Bearer token open a LiteLLM MCP session. The two separate bugs one pull request closed, and…
AWS now hosts the OAuth consent portal for Bedrock AgentCore agents. What it removes, what it actually couples, and where…
Get tutorials, product updates, and Keycloak tips delivered to your inbox.