Featured
-
Why We Only Catch "Rogue" AI Agents by Accident: The Agent Identity Gap
• 14 min readThree frontier labs disclosed that their AI agents breached real companies. None were caught in real time. The problem is not model behavior—it is that the agent is using your identity.
-
Browser-Based Agents Are Impersonating You: The Agent Identity Problem
• 23 min readBrowser-based agents inherit your session, your cookies, and your identity, with no distinction visible to the service provider. Here's why that's a problem we've already solved once, and what needs to happen next.
-
Is Authorization Code Grant Type Secure Enough?
• 10 min readIs Authorization Code Grant Type Secure Enough?
-
OAuth2 Token Exchange in Practice
• 14 min readOAuth2 Token Exchange in Practice
Recent Posts
-
Unwrapping MCP Security: A Walkthrough with the PayPal MCP Server
• 11 min readA walkthrough of connecting Claude Desktop to PayPal’s remote MCP server over HTTP, highlighting the full OAuth 2.0 flow with Postman from discovery to authorization
-
Unwrapping MCP: A Walkthrough with the GitHub MCP Server
• 10 min readMCP explained from the inside out, starting with a real developer workflow then unwrapping the protocol layer by layer: roles, messages, connection lifecycle, and STDIO transport.
-
Protected Resource Metadata Is the Missing Piece in OAuth 2.0 Discovery
• 9 min readOAuth 2.0 could automate client registration and AS discovery, but clients still had to hardcode which authorization server protects a given resource. Protected Resource Metadata fixes that. Here's how PRM completes the dynamic integration story, and why AI agents made it urgent.
-
mTLS and OAuth2 — Certificate-Bound Tokens
• 11 min readmTLS and OAuth2 — Certificate-Bound Tokens