Introducing auth.md — an open protocol that lets agents register for your service.
Grant agents time-limited access to OAuth connections using Pipes and MCP.
Develop with WorkOS entirely from your terminal, with agent-ready tooling built in.
A practical guide to encrypted storage, OAuth connection management, and session-scoped access for autonomous agents
How to scope what an AI agent can do on a user's behalf, and why the answer is never the user's full permission set.
A practical security audit for backend engineers building or inheriting agentic systems, covering identity, token design, delegation, and the patterns that fail in production
What you're actually signing up for when a customer's IdP doesn't speak SCIM.
Everything you need to know to implement and validate JWTs securely in .NET: from token creation and JWKS verification to ASP.NET Core middleware integration, with code examples and best practices throughout.
Prompt injection ends when the session closes. Memory poisoning persists across sessions, activates weeks later, and is nearly invisible to detect.
Why OAuth works the way it does: authorization codes, token expiry, and PKCE explained from first principles.
A four-phase playbook for moving off Auth0, Cognito, Clerk, or Firebase without a 2 AM incident.
Set up roles and permissions, verify session JWTs, and protect your FastAPI routes with dependency injection.
Your existing logging infrastructure is necessary but not sufficient. Here's what's missing and why it matters.
MCP servers have a different attack surface than traditional APIs. Here are the five risks that matter most, grounded in OWASP's agentic AI guidelines, with concrete mitigations for each.
Your route guard does not protect your server functions. A complete guide to authorization in TanStack Start, from roles and permissions to enterprise RBAC and fine-grained access control.
Tools, MCP servers, skills, orchestrators, and why auth runs through all of them.
Key insights from Boris Cherny's Acquired Unplugged interview on building Claude Code, the death of traditional roles, and why the golden age of the generalist is here.
Ben Gilbert and David Rosenthal shared what makes companies endure for generations at Acquired Unplugged, hosted by WorkOS CEO Michael Grinich.
Please try a different search
Our global team is growing and we’re hiring all types of roles.
WorkOS builds developer tools for quickly adding enterprise features to applications.
We use cookies for analytics and advertising. See our cookie policy for details.