Introducing auth.md — an open protocol that lets agents register for your service.
Grant agents time-limited access to OAuth connections using Pipes and MCP.
Develop with WorkOS entirely from your terminal, with agent-ready tooling built in.
A four-phase playbook for moving off Auth0, Cognito, Clerk, or Firebase without a 2 AM incident.
Set up roles and permissions, verify session JWTs, and protect your FastAPI routes with dependency injection.
Your existing logging infrastructure is necessary but not sufficient. Here's what's missing and why it matters.
MCP servers have a different attack surface than traditional APIs. Here are the five risks that matter most, grounded in OWASP's agentic AI guidelines, with concrete mitigations for each.
Your route guard does not protect your server functions. A complete guide to authorization in TanStack Start, from roles and permissions to enterprise RBAC and fine-grained access control.
Tools, MCP servers, skills, orchestrators, and why auth runs through all of them.
Key insights from Boris Cherny's Acquired Unplugged interview on building Claude Code, the death of traditional roles, and why the golden age of the generalist is here.
Ben Gilbert and David Rosenthal shared what makes companies endure for generations at Acquired Unplugged, hosted by WorkOS CEO Michael Grinich.
WorkOS skills are now in Claude's plugin marketplace. Here's what that means for how developers discover and adopt API tooling.
A practical guide to migrating auth at scale — the CLI workflow, transparent proxy approach for 15+ SSO connections, and webhook sequencing above 200K users.
A week after we shipped auth.md, developers have published spec-compliant files, partners have endorsed it, and the ecosystem is aligning.
How to build a custom, language-aware SDK generator from an OpenAPI spec using oagen's typed intermediate representation.
Your beforeLoad guard does not protect your server functions. A complete guide to authentication in TanStack Start, from server functions and sessions to enterprise SSO.
When Agent A delegates to Agent B, whose permissions apply? Whose audit trail records the action? And what happens when Agent B is compromised?
Anthropic's acquisition of Stainless means the hosted SDK generator is going away. Here's what to reach for instead.
Please try a different search
Our global team is growing and we’re hiring all types of roles.
WorkOS builds developer tools for quickly adding enterprise features to applications.
We use cookies for analytics and advertising. See our cookie policy for details.