Engineering posts about Authentication
Curated summaries and key learnings for engineers working with Authentication.
The Agent Access Model
The Agent Access Model (AAM) presents a novel approach to access control for agents in enterprise security, moving away from traditional trust models that rely on user identity and location. AAM...
Post-quantum authentication to origins is now supported
The article discusses Cloudflare's implementation of post-quantum authentication for its Authenticated Origin Pulls and Custom Origin Trust Store, aimed at securing connections against potential...
Permission isn't purpose: Intent-based authorization in Omnigent
The article presents a detailed examination of intent-based authorization as implemented in the Omnigent platform, highlighting its role in enhancing security by binding user sessions to declared...
How Figma stays ahead of vulnerabilities with agents
The article outlines Figma's innovative approach to security by leveraging agents to monitor code quality and detect vulnerabilities throughout the software development lifecycle. It emphasizes the...
Cloudflare DMARC Management is now generally available
The article details the general availability of Cloudflare's DMARC Management tool, aimed at enhancing email authentication for domains. It emphasizes the importance of DMARC, SPF, and DKIM in...
Enhance Security and Trust: New Session Metadata in Sign in with Google
The article introduces new session metadata claims in Sign in with Google, specifically the 'auth_time' and 'amr' claims, designed to enhance security and provide deeper insights into user...
Snap Cloud: A Backend for Spectacles, Powered by Supabase
Snap Cloud is a backend platform designed specifically for Spectacles developers, leveraging Supabase to provide essential backend services such as databases, file storage, and real-time...
Managed OAuth for Access: make internal apps agent-ready in one click
The article outlines Cloudflare's implementation of Managed OAuth to enhance access for internal applications, allowing agents to authenticate seamlessly. It describes the challenges faced when...
Securing non-human identities: automated revocation, OAuth, and scoped permissions
The article addresses the critical need for securing non-human identities in software development, particularly in the context of agentic AI systems. It outlines the risks associated with credential...
Dynamic, identity-aware, and secure Sandbox auth
The article explores the implementation of dynamic, identity-aware authentication mechanisms for sandbox environments, emphasizing the use of outbound Workers to enhance security and control over...
Cloudflare targets 2029 for full post-quantum security
Cloudflare has set a target of 2029 to achieve full post-quantum security, emphasizing the importance of transitioning to post-quantum authentication alongside encryption. The article outlines the...