Engineering
Non-Human Identity Is Now the Majority of Your Identities
Start with a counting exercise. It takes ten minutes and usually ends an argument.
Engineering
Start with a counting exercise. It takes ten minutes and usually ends an argument.
Engineering
Somewhere in your codebase there's a folder called auth. It probably started as a weekend's work — a users table, bcrypt, a session cookie, maybe a JWT if whoever wrote it had opinions. Nobody scheduled a design review for it. It wasn't on the roadmap as "build an identity platform." It was a login
Engineering
Most distributed systems get to be hard in one dimension at a time.
Engineering
The query that starts this project is four lines long:
Engineering
Nobody plans this project. It arrives — a provider gets acquired and the roadmap changes, pricing moves somewhere the finance team won't follow, a compliance requirement lands that the current platform can't satisfy, or the architecture stopped fitting three years ago and everyone finally admits it.
Engineering
There's a genuine debate happening right now among people building agentic systems, and it's worth having honestly rather than resolving it with a hot take. MCP (Model Context Protocol) gives an agent a standardized way to discover and call tools. A2A (Agent-to-Agent protocol) gives an agent a stand
Engineering
If you've built or secured a regular API, you already understand resource servers: the thing that holds the data, checks an incoming token, and decides whether to hand the data over. An MCP server is that same idea, aimed at a different kind of visitor — not a browser tab or a mobile app operated by
Engineering
The meeting had been going for forty minutes and the spreadsheet had one unfilled column.
Engineering
The pitch for JWTs is always the same: stateless authentication. No session store. No database lookup on every request. Just verify a signature and read the claims. Your API servers become stateless, which means they scale horizontally without a shared session backend.
Engineering
Almost every article on this subject explains what a JWT is, explains what an opaque token is, notes that JWTs are stateless and opaque tokens are revocable, and stops. That comparison is accurate and nearly useless, because it describes a property you'll read about once and skips the six properties
Engineering
Put the two flows side by side at the protocol level and they look almost identical. Same assertion format. Same XML signature over the same elements. Same trust model — you configured the IdP's certificate, you check the signature, you accept the statement. If you diffed two Response documents from
Engineering
Here's a claim that sounds wrong until you've operated one: an identity platform is not primarily a cryptography system, a protocol implementation, or a database application. It's a cache coherence problem wearing a security costume.