Atlas works alongside your team in Slack to answer questions, automate tasks, and help everyone do their best work.
We are launching a remote MCP server that gives AI agents the same access to WorkOS as your dashboard login.
A managed gateway that handles API key verification, token decoding, and authorization so your backend does not have to.
How workos mcp install configures Claude Code, Codex, and Cursor, why configured is not the same as authenticated, and the failure modes worth knowing.
Ad hoc webhooks got provisioning updates delivered in real time, but never agreed on a shape. Here's what RFC 9967 formally standardizes, what it doesn't fix, and when it's actually worth adopting.
A practical, testable list of controls for letting AI agents act on your users' data without handing them the keys.
Everything you need to know to sign, verify, and validate JWTs in Elixir, from Joken and JOSE to JWKS caching with OTP, Phoenix plugs, and production best practices.
A year ago, two competing IETF drafts were racing to define how SCIM represents AI agents. Here's what changed, and why the companies behind them are now writing one draft together.
CoPhish showed that an agent-building platform can itself become an OAuth phishing vector. Here's what that means for anyone building MCP servers or agent platforms, how to configure against it, and what Entra Agent ID and WorkOS Agent Auth reveal about where the industry is headed.
Two critical vulnerabilities, one root cause, and the piece of MCP that is supposed to close this gap.
A new registry audit counted servers, not security controls. The number matters more than it sounds like it should.
A first look at how the official Model Context Protocol SDK is turning the 2026-07-28 spec's authorization hardening into code, and what it means for anyone running an MCP server.
The same token type is solving two unrelated problems. Knowing which one you are in decides what you build.
Design AI agent authorization policies with fixed rules and runtime checks. See how Airlock handles allowed operations, sensitive content, and human approval.
What is WorkOS Airlock? See how intent-based access control governs AI agent calls, where Pipes fits, and how the email demo turns policy into action.
The case against MCP is right about ergonomics and quiet about authorization. Here is what has to exist before direct API access is a safe default.
Why the cookie swap every framework recommends does not transfer, what each SDK actually hands you, and why the exit path is safer here than it was.
The 2026-07-28 spec tells you exactly what to do. These are the code shapes that ignore it.
Please try a different search
Our global team is growing and we’re hiring all types of roles.
WorkOS builds developer tools for quickly adding enterprise features to applications.
We use cookies for analytics and advertising. See our cookie policy for details.