Ddmandreevindmandreev.hashnode.dev·7h ago · 5 min readIssuerd: a Keycloak-compatible IAM in Rust — one binary, 3,907 OIDC conformance checks, zero failuresIf you've operated Keycloak in production, you know the tax: a JVM that wants gigabytes before it serves a single login, container startup measured in tens of seconds, and clustering that means Infini00
ARAnton Rostinantonships.hashnode.dev·3d ago · 9 min readSocial media API approval: OAuth, review, and publishingGoogle OAuth verification and Meta app review were in different states on 27 September 2026. Neither screen establishes YouTube API audit approval or a successful public post. Screenshots by Anton Ros00
DKDave Kurianinotf-kit.hashnode.dev·3d ago · 7 min readWhat runs before withSupabase in an MCP pipeline?If an MCP client calls your Supabase function, which checks run before withSupabase({ auth: 'user' }), and which run after it? The Supabase changelog for @supabase/middleware 1.0 (30 September 2026) a00
MMihai_LeanZeroinleanzero.hashnode.dev·4d ago · 23 min readCall a Forge App REST API with OAuth 2.0 (3LO)A Forge app REST API is called from outside Jira with an OAuth 2.0 (3LO) access token. This tutorial does it end to end with curl, against LeanZero Management, the free planning app we make for Jira C00
4F404 Foundersin404-founders.com·Sep 30 · 2 min readMalicious MCP Servers Can Redirect OAuth Credentials in Affected Python SDK ClientsMalicious MCP Servers Can Redirect OAuth Credentials in Affected Python SDK Clients Cycode disclosed an OAuth trust-boundary flaw in the official MCP Python SDK on September 28, 2026. An attacker-cont00
Aa21aiina21ai.hashnode.dev·Sep 30 · 6 min readSecuring the Model Context Protocol (MCP) in Enterprise Agent Networks: OAuth 2.1 Scope Binding, Sandboxed Tool Execution, and Dynamic Schema ValidationIn 2026, the widespread adoption of the Model Context Protocol (MCP) has revolutionized how autonomous artificial intelligence agents interact with enterprise data sources, internal REST APIs, and thi00
SLSarika Lalinsarikalal.hashnode.dev·Sep 27 · 7 min readData Is Gold: How Do We Let It Move Safely?Modern software is expected to integrate. A school information system may need to exchange data with an LMS, payment processor, CRM, communication platform, identity provider, government system or ano00
SBSayok Boseinsayok.hashnode.dev·Sep 24 · 24 min readAI Agents Need Their Own Identity. Mine Were Using... Erm... Mine.We built three AI agents. All three logged in as a human being. Me. Here is what we found when we went looking for a better idea, what the options cost, and the order we would buy them in. We have not33KMM
MMMayank Mahajaninmayankdev.hashnode.dev·Sep 24 · 10 min readHow I Built a Unified Authentication System with Password, Google OAuth & GitHubBuilding Unified Authentication in Node.js: Password + Google OAuth + GitHub While building a custom authentication system with Google OAuth, GitHub OAuth, and traditional email/password authenticatio00
SHSanskriti Harmukhinvultr.hashnode.dev·Sep 23 · 13 min readDeploying Ory Hydra: An Open-Source OAuth 2.0 and OpenID Connect ServerOry Hydra is an open-source OAuth 2.0 Authorization Server and OpenID Connect (OIDC) provider. Unlike identity platforms that bundle user management, Hydra delegates authentication to a separate login00