Tag: security
All the articles with the tag "security".
-
Why We Only Catch "Rogue" AI Agents by Accident: The Agent Identity Gap
• 14 min readThree frontier labs disclosed that their AI agents breached real companies. None were caught in real time. The problem is not model behavior—it is that the agent is using your identity.
-
Unwrapping MCP Security: A Walkthrough with the PayPal MCP Server
• 11 min readA walkthrough of connecting Claude Desktop to PayPal’s remote MCP server over HTTP, highlighting the full OAuth 2.0 flow with Postman from discovery to authorization
-
Protected Resource Metadata Is the Missing Piece in OAuth 2.0 Discovery
• 9 min readOAuth 2.0 could automate client registration and AS discovery, but clients still had to hardcode which authorization server protects a given resource. Protected Resource Metadata fixes that. Here's how PRM completes the dynamic integration story, and why AI agents made it urgent.
-
mTLS for OAuth2 Client Authentication: A Stronger Alternative to Shared Secrets
• 13 min readShared secrets can be stolen, leaked, or brute-forced. mTLS-based client authentication uses certificates to prove private key possession. Learn how to apply TLS handshake–based authentication to meet OAuth 2.0 client authentication requirements.