DEV Community

#authorization

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
A valid token is not an AI agent audit trail

A valid token is not an AI agent audit trail

Comments
1 min read
Who mints the first Biscuit? PingFederate, token exchange and a hybrid model

Who mints the first Biscuit? PingFederate, token exchange and a hybrid model

Comments
6 min read
Step-up MFA, attenuation, and what's honestly not done

Step-up MFA, attenuation, and what's honestly not done

Comments
6 min read
Attenuating Biscuit tokens and signing the delegation chain

Attenuating Biscuit tokens and signing the delegation chain

Comments
5 min read
Local policy, shared facts: the receiver's Datalog authorizer

Local policy, shared facts: the receiver's Datalog authorizer

Comments
4 min read
Delegating authority across companies with Biscuit tokens

Delegating authority across companies with Biscuit tokens

Comments
5 min read
AI agents that inherit your OAuth token break least privilege

AI agents that inherit your OAuth token break least privilege

Comments 1
1 min read
Deploying Ory Keto - Open-Source Permission and Access Control Server

Deploying Ory Keto - Open-Source Permission and Access Control Server

6
Comments
12 min read
Authorization at the Object Level: Testing for BOLA Before Someone Else Does

Authorization at the Object Level: Testing for BOLA Before Someone Else Does

Comments
4 min read
OAuth on MCP is not the same as authorizing each tool call

OAuth on MCP is not the same as authorizing each tool call

Comments
1 min read
Read permission is not export permission

Read permission is not export permission

Comments
1 min read
API Security: The Attack Surface That Grows Without a Firewall

API Security: The Attack Surface That Grows Without a Firewall

Comments
2 min read
ABAC in Production: What Actually Breaks

ABAC in Production: What Actually Breaks

Comments
4 min read
Pull the tenant from the auth context, not the request body

Pull the tenant from the auth context, not the request body

Comments 1
1 min read
Never trust a client-supplied tenant ID

Never trust a client-supplied tenant ID

Comments
1 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.