Atlas works alongside your team in Slack to answer questions, automate tasks, and help everyone do their best work.
We are launching a remote MCP server that gives AI agents the same access to WorkOS as your dashboard login.
A managed gateway that handles API key verification, token decoding, and authorization so your backend does not have to.
OpenAI saw 16,000 extraction requests from more than 4,000 accounts in two days, about four each. Per-key quotas can't see an actor shaped like a crowd. Account controls can.
Fairwind's rules read like an authorization spec for capability. Background checks, phishing-resistant MFA, security-team-only access and usage tracking map one to one onto identity primitives.
The MCP Python SDK, the Rust SDK (rmcp), and LiteLLM each accepted authentication input that nobody verified. Here is what broke, who is affected, and the checklist that closes the gap.
Microsoft says the actor behind JADEPUFFER, the first documented agentic ransomware operation, used two compromised Azure service principals to map a tenant and then delete storage accounts, a Key Vault, and app resources in about seven minutes. Here's what happened, why a deleted secret still works, and what to change in how you handle workload identities.
A new study found that coding agents in seven of eight popular harnesses deleted their own session traces when asked. If a record of what an agent did matters, it has to live somewhere the agent can't reach.
Diagnose failed assistant actions across host, MCP tool, backend, and source of record with privacy-conscious evidence, safe replay, and a ticket template.
ChatGPT is adding draft MCP Events support. Why a subscription is a credential, how revocation works, and what your MCP server must store.
A researcher reached an internal Microsoft service by setting a JWT's upn claim to admin. The missing signature was the door. The lookup key was the bug.
Compare the App Store’s launch with OpenAI plugins across discovery, trust, payments, portability, and gatekeeping, and see where the analogy fails today.
SAML's security record is as bad as Trail of Bits says. Here's why B2B SaaS teams still have to support it, and how to keep the XML out of their own code.
Cloudflare, Okta, Auth0 and Microsoft all offer MCP gateways now. A side-by-side comparison of where each one sits, how it handles auth and logging, and what your MCP server still needs to do.
Sign in with ChatGPT adds a scope that spends a user's subscription allowance inside your app. What to model before you put that button on your login page.
Microsoft took down a phishing service that used the OAuth device flow to get into 12,000 inboxes without stealing a single password. Here's what the attack means for teams that offer device-code sign-in.
How workos mcp install configures Claude Code, Codex, and Cursor, why configured is not the same as authenticated, and the failure modes worth knowing.
Ad hoc webhooks got provisioning updates delivered in real time, but never agreed on a shape. Here's what RFC 9967 formally standardizes, what it doesn't fix, and when it's actually worth adopting.
Please try a different search
Our global team is growing and we’re hiring all types of roles.
WorkOS builds developer tools for quickly adding enterprise features to applications.
We use cookies for analytics and advertising. See our cookie policy for details.