WorkOS Emulate runs the WorkOS API on your own machine, so your tests can seed real data, drive full login flows, and force failures without touching prod.
Agents that call third-party APIs on behalf of users normally hold the OAuth access token. Here is where that token leaks, and how to get delegated access without it.
Sierra's MCP gateway iceberg is a field report on agent auth: identity, per-tool scopes, consent, and audit are the submerged mass, and they ship off the shelf.
Microsoft calls identity "the primary control plane for defense." If you sell to enterprises, your sign-in page is part of that control plane. Here's what the 2026 report means for how you authenticate users, and agents.
Map WorkOS organizations to your customers, keep workspaces in your own database, and handle org switching, cross-tenant guests and internal admins in a Next.js app.
Take a Vite and React app from localhost to production with httpOnly cookie refresh, a custom Authentication API domain, preview deployments, and a Node API that verifies every request.
AI coding agents put internal screenshots from more than 300 organizations on public GitHub. No model broke. The agents used permissions nobody meant to give them, to finish a task nobody thought was risky.
More than 100 security vendors now plug into the Claude Compliance API. Here's what it teaches any AI product selling to enterprises about audit logs: what to record, who can export it and where it goes.
Citrix has patched an actively exploited memory overflow in the SAML handling of NetScaler ADC and Gateway. It is the fourth NetScaler SAML vulnerability this year, and the pattern says a lot about where authentication code breaks.
igma's remote MCP server admits clients by the client_name they send during dynamic client registration. Why that check proves nothing, what CIMD fixes and what it doesn't, and what to gate on instead.
OpenAI saw 16,000 extraction requests from more than 4,000 accounts in two days, about four each. Per-key quotas can't see an actor shaped like a crowd. Account controls can.
Fairwind's rules read like an authorization spec for capability. Background checks, phishing-resistant MFA, security-team-only access and usage tracking map one to one onto identity primitives.
The MCP Python SDK, the Rust SDK (rmcp), and LiteLLM each accepted authentication input that nobody verified. Here is what broke, who is affected, and the checklist that closes the gap.
Microsoft says the actor behind JADEPUFFER, the first documented agentic ransomware operation, used two compromised Azure service principals to map a tenant and then delete storage accounts, a Key Vault, and app resources in about seven minutes. Here's what happened, why a deleted secret still works, and what to change in how you handle workload identities.
A new study found that coding agents in seven of eight popular harnesses deleted their own session traces when asked. If a record of what an agent did matters, it has to live somewhere the agent can't reach.
Diagnose failed assistant actions across host, MCP tool, backend, and source of record with privacy-conscious evidence, safe replay, and a ticket template.
ChatGPT is adding draft MCP Events support. Why a subscription is a credential, how revocation works, and what your MCP server must store.
A researcher reached an internal Microsoft service by setting a JWT's upn claim to admin. The missing signature was the door. The lookup key was the bug.
Please try a different search
Our global team is growing and we’re hiring all types of roles.
WorkOS builds developer tools for quickly adding enterprise features to applications.
We use cookies for analytics and advertising. See our cookie policy for details.