Na-Mii Dev Team

About Author

Articles by Na-Mii Dev Team

The first in a five-part series on how MCP is changing for real-world use, and what those changes mean for teams building and securing agent systems.
Learn how 3-legged OAuth works by building a GitHub OAuth flow and tracing authorization, consent, codes, tokens, and state.
Aembit adds an OpenAI Workload Identity Federation Credential Provider, replacing static sk-proj-… keys with short-lived, identity-bound tokens.
AI agents need identity controls, scoped access, and runtime enforcement before they are trusted with production systems.
A new protocol proposes a clearer way to connect agent identity, delegated authority and human approval for sensitive actions.
Aembit’s new Credential Provider automates Claude API Workload Identity Federation, retiring static keys for short-lived tokens.
The MCP authorization spec sets a new standard for securing non-human AI agents – with lessons for anyone building autonomous, scalable systems.
An exercise ended with frontier models inside a platform’s production systems, exposing a hard truth about what agents can do with credentials that systems trust.
Compare 10 identity security vendors for AI agents, including where each fits and what buyers should examine before choosing.
AI agents are workloads, but traditional workload identity alone can miss the user, task, and runtime context needed to govern dynamic agent access.
As AI agents begin calling tools and APIs, OAuth moves from background plumbing to a core access-control question.
AI agents need more than working credentials. They need verifiable identity, task-scoped access, and clear attribution.