Engineering
OAuth vs OIDC: The Difference in One Claim
There's a code pattern that appears in production systems everywhere, written by competent engineers, that reliably produces a complete authentication bypass:
Engineering
There's a code pattern that appears in production systems everywhere, written by competent engineers, that reliably produces a complete authentication bypass:
Engineering
OAuth isn't one flow, it's a small family of them, and picking the wrong one for your application type is one of the most common ways teams end up with a security gap they didn't know they'd introduced. The right flow depends almost entirely on one question: what kind of application is asking for ac
Engineering
Ask a developer who's spent a frustrating afternoon debugging a redirect URI mismatch what they think of OAuth, and you'll usually get some version of the same complaint: too many parameters, too many steps, too many ways to get it subtly wrong. State, nonce, PKCE, scopes, grant types, token types,
Engineering
Most explanations of OAuth start with a sequence diagram full of boxes labeled "Resource Owner" and "Authorization Server," which is accurate and almost useless if you're trying to build an intuition for what's actually happening. Here's a version that starts with something everyone already understa
Engineering
Every OAuth deployment makes a decision about how clients prove who they are, and in most deployments the decision was made by whichever tutorial the first integrating engineer found. That's how you end up with client_secret_post everywhere, a spreadsheet of secrets, and a compliance finding four ye
Engineering
Start with a counting exercise. It takes ten minutes and usually ends an argument.
Engineering
Somewhere in your codebase there's a folder called auth. It probably started as a weekend's work — a users table, bcrypt, a session cookie, maybe a JWT if whoever wrote it had opinions. Nobody scheduled a design review for it. It wasn't on the roadmap as "build an identity platform." It was a login
Engineering
Most distributed systems get to be hard in one dimension at a time.
Engineering
The query that starts this project is four lines long:
Engineering
Nobody plans this project. It arrives — a provider gets acquired and the roadmap changes, pricing moves somewhere the finance team won't follow, a compliance requirement lands that the current platform can't satisfy, or the architecture stopped fitting three years ago and everyone finally admits it.
Engineering
There's a genuine debate happening right now among people building agentic systems, and it's worth having honestly rather than resolving it with a hot take. MCP (Model Context Protocol) gives an agent a standardized way to discover and call tools. A2A (Agent-to-Agent protocol) gives an agent a stand
Engineering
If you've built or secured a regular API, you already understand resource servers: the thing that holds the data, checks an incoming token, and decides whether to hand the data over. An MCP server is that same idea, aimed at a different kind of visitor — not a browser tab or a mobile app operated by