authorization
2 posts — newest first.
-
OAuth, OIDC, and JWT: Who Are You, and What Are You Allowed to Do?
Three terms people use interchangeably and shouldn't: OAuth delegates access, OIDC proves identity, JWT is the token format. Mixing them up causes real bugs.
-
Identity was the easy half. Agent authorization is becoming an audit-trail problem.
NIST, a Senate bill and the MCP roadmap converge on one requirement: prove which agent did what, for whom, under whose grant. Your traces do not.