Tag: Authentication

Secrets managers still matter. But AI agents and workloads are changing when stored credentials make sense.
Broad credentials made sense when fixed application logic stood between users and actions, but AI agents have changed that equation.
What began as a way for agents to call tools is expanding into infrastructure for longer-running, governed interactions across enterprise systems.
When one identity acts for another, the token model determines what downstream systems can actually see, trust, and audit.
Centralized authorization eliminates repeated user consent, but autonomous agents still need runtime policy, short-lived credentials, and audit.
OAuth is an authorization framework that defines how to grant access. JWT is a token format that defines how to package and transmit claims. They solve different problems, and most production systems use both.
OAuth 2.0 and OIDC solve fundamentally different problems.
OAuth 2.1 eliminates implicit flow, mandates PKCE, and requires exact redirect matching.
What it takes to implement it, and why real-world environments make it hard to finish.