Atlas works alongside your team in Slack to answer questions, automate tasks, and help everyone do their best work.
We are launching a remote MCP server that gives AI agents the same access to WorkOS as your dashboard login.
A managed gateway that handles API key verification, token decoding, and authorization so your backend does not have to.
MCP authorization is the OAuth 2.1 flow that lets an AI agent call a protected MCP server on a user's behalf. Here is how it works, step by step, under the 2026-07-28 spec.
Delegated agent sessions are now capped by the user and the agent definition at once, which closes a gap we couldn't close a few months ago.
Go from no auth to a full hosted sign-in flow, either in one command or step by step.
Coding agents were built to guard a filesystem. The blast radius that matters now is in your CRM.
Service principals and CI/CD federation skip the access reviews that catch humans. The OIDC trust policy string is what actually decides who reaches production.
FusionAuth 1.69 adds an AI agent entity type and lifecycle webhooks. Whether that answers the question your auditors ask depends on whose events they are.
MCP standardized how an agent asks for more permission. It has no vocabulary yet for asking whether the human behind the token is still there.
Instagram now limits the reach of AI profiles that skip its AI-generated label. Non-human disclosure just became an enforced account attribute with penalties.
Okta's Agent SSO went GA on the Cross App Access standard. The IdP brokers the connection, but your app still has to validate the grant and issue the token.
How WorkOS engineers make agents babysitting agents safe: a headless surface to supervise through, scoped jobs, visible costs, and a human on the merge button.
Relay proxies an agent's third-party API calls and injects the credential at the boundary, so prompt injection has no token to steal and nowhere to send it.
Which providers rotate refresh tokens, which return expires_in, which give you a grace period, and which revoke on reuse. One row per provider, verified against provider documentation in August 2026.
Concurrent refreshes don't just fail. They can disconnect the user entirely. Here are four layers of defense, cheapest first, and why the Redis lock everyone reaches for isn't the one keeping you safe.
Field notes from running the WorkOS internal-tools showcase twice: five talks, live demos only, one Q&A, a sequenced lineup, and a contingency for every demo.
A walk through the Pipes credential vault: envelope encryption, key context, what a compromised key reaches, and how key rotation happens without re-consent.
Please try a different search
Our global team is growing and we’re hiring all types of roles.
WorkOS builds developer tools for quickly adding enterprise features to applications.
We use cookies for analytics and advertising. See our cookie policy for details.