Atlas works alongside your team in Slack to answer questions, automate tasks, and help everyone do their best work.
We are launching a remote MCP server that gives AI agents the same access to WorkOS as your dashboard login.
A managed gateway that handles API key verification, token decoding, and authorization so your backend does not have to.
Build a Next.js app with AuthKit sign-in, then gate a destructive action behind a fresh re-authentication using auth_time and max_age.
For thirty years we handed access tokens to our own servers without much worry, because our servers didn't take instructions from strangers. Agents do.
A step-by-step guide to PKCE-based sign-in with the WorkOS iOS SDK's PublicClient.
In AI agent governance, most MCP servers run as local processes that never cross the network boundary older shadow-IT tools were built to watch. The risk changed too: from data leaving through an unsanctioned app to actions taken through one.
In AI agent governance, the analogy holds for access and response speed but breaks on motive. Google DeepMind's review of a million agent trajectories found most incidents come from overeagerness, not malice.
Town co-founder Jean-Denis Greze talks to Michael Grinich at AI Engineer World's Fair 2026 about draft-only agents, earning trust, and shared data silos.
Ravenna co-founder Kevin Coleman talks to Michael Grinich at AI Engineer World's Fair 2026 about resource-level approvals, determinism, and agent integrations.
Traversal PM Eric Schwartz on data platforms, routing models by severity, and the permission ladder toward self-driving production, from AI Engineer 2026.
Agent CLIs turned every department into a builder. The control point for the tools they ship is credential issuance, not code review. Here's the paved path.
Consumer passkey guidance optimizes for the login. In B2B, the enrollment and recovery story is what decides whether passkeys actually work. Here's the gap.
A Shai-Hulud wave plants hooks in .claude/settings.json and .vscode/tasks.json, so opening a repo runs the payload. Agent config is executable surface now.
An AI agent registered a second GitHub account to endorse its own malicious pull request. Account creation is the control point, and CAPTCHAs are not it.
TIME forks its content per crawler and logs each bot read as a billable ad impression. The routing key for that whole ledger is a header any client can type.
Stateless JWTs stay valid until they expire, so logout isn't instant. Here's why enterprise SCIM makes that a compliance problem — and how to really fix it.
SCIM tells you a user is gone, but sessions, refresh tokens, and API keys often outlive deprovisioning. Here's why offboarding needs more than a user row.
Please try a different search
Our global team is growing and we’re hiring all types of roles.
WorkOS builds developer tools for quickly adding enterprise features to applications.
We use cookies for analytics and advertising. See our cookie policy for details.