WorkOS Emulate runs the WorkOS API on your own machine, so your tests can seed real data, drive full login flows, and force failures without touching prod.
Agents that call third-party APIs on behalf of users normally hold the OAuth access token. Here is where that token leaks, and how to get delegated access without it.
Sierra's MCP gateway iceberg is a field report on agent auth: identity, per-tool scopes, consent, and audit are the submerged mass, and they ship off the shelf.
Box CEO Aaron Levie at WorkOS init() on why engineering adopted agents first, what a bank must settle before an agent sends a wire, and why he backs FDE roles.
Braelyn put DOOM on her init() badge. Others built a Tamagotchi, voice assistants and a flight tracker. Here's the ESP32 badge and how 500 got ready in time.
How I use ChatGPT tasks to organize persistent Pi sessions, connect MCP tools, bridge gaps with computer use, and deliver work without losing context.
At WorkOS init(), Stripe's Rami Banna had a coding agent provision a WorkOS account and credentials via Stripe Projects, then showed the Provisioning API.
Matt Carey of Cloudflare showed a durable Pi agent in a Durable Object at WorkOS init(), then gave it a stateful workspace and the Kitesurf browser to drive.
WorkOS init() 2026 at SFJAZZ Center: live previews of Airlock, Atlas and Passport, plus talks from Aaron Levie, Nikita Shamgunov, Claire Vo, swyx and more.
At WorkOS init(), Anthony Giuliano of Neon at Databricks demoed DressCode, an AI stylist app whose Neon backend is configured in a single neon.ts file.
Microsoft calls identity "the primary control plane for defense." If you sell to enterprises, your sign-in page is part of that control plane. Here's what the 2026 report means for how you authenticate users, and agents.
Map WorkOS organizations to your customers, keep workspaces in your own database, and handle org switching, cross-tenant guests and internal admins in a Next.js app.
Take a Vite and React app from localhost to production with httpOnly cookie refresh, a custom Authentication API domain, preview deployments, and a Node API that verifies every request.
AI coding agents put internal screenshots from more than 300 organizations on public GitHub. No model broke. The agents used permissions nobody meant to give them, to finish a task nobody thought was risky.
More than 100 security vendors now plug into the Claude Compliance API. Here's what it teaches any AI product selling to enterprises about audit logs: what to record, who can export it and where it goes.
Citrix has patched an actively exploited memory overflow in the SAML handling of NetScaler ADC and Gateway. It is the fourth NetScaler SAML vulnerability this year, and the pattern says a lot about where authentication code breaks.
Figma's remote MCP server admits clients by the client_name they send during dynamic client registration. Why that check proves nothing, what CIMD fixes and what it doesn't, and what to gate on instead.
OpenAI saw 16,000 extraction requests from more than 4,000 accounts in two days, about four each. Per-key quotas can't see an actor shaped like a crowd. Account controls can.
Please try a different search
Our global team is growing and we’re hiring all types of roles.
WorkOS builds developer tools for quickly adding enterprise features to applications.
We use cookies for analytics and advertising. See our cookie policy for details.