Engineering posts about Authorization

Curated summaries and key learnings for engineers working with Authorization.

Cloudflare
27m

The Agent Access Model

The Agent Access Model (AAM) presents a novel approach to access control for agents in enterprise security, moving away from traditional trust models that rely on user identity and location. AAM...

Databricks
8m

Permission isn't purpose: Intent-based authorization in Omnigent

The article presents a detailed examination of intent-based authorization as implemented in the Omnigent platform, highlighting its role in enhancing security by binding user sessions to declared...

Figma
21m

How Figma stays ahead of vulnerabilities with agents

The article outlines Figma's innovative approach to security by leveraging agents to monitor code quality and detect vulnerabilities throughout the software development lifecycle. It emphasizes the...

Databricks
7m

Blocking Slow-Burn Attacks: Contextual Policies in Omnigent

The article explores the vulnerabilities of AI agents to slow-burn attacks, where attackers exploit the agent's inability to recognize harmful sequences of actions that appear benign in isolation. It...

Cloudflare
9m

Unlocking the Cloudflare app ecosystem with OAuth for all

The article discusses Cloudflare's recent enhancement of its OAuth capabilities, allowing all customers to create and manage their own OAuth applications. It outlines the challenges faced during the...

Google
5m

Enhance Security and Trust: New Session Metadata in Sign in with Google

The article introduces new session metadata claims in Sign in with Google, specifically the 'auth_time' and 'amr' claims, designed to enhance security and provide deeper insights into user...

Cloudflare
11m

Managed OAuth for Access: make internal apps agent-ready in one click

The article outlines Cloudflare's implementation of Managed OAuth to enhance access for internal applications, allowing agents to authenticate seamlessly. It describes the challenges faced when...

Cloudflare
11m

Securing non-human identities: automated revocation, OAuth, and scoped permissions

The article addresses the critical need for securing non-human identities in software development, particularly in the context of agentic AI systems. It outlines the risks associated with credential...

Airbnb
8m

Privacy-first connections: Empowering social experiences at Airbnb

The article outlines Airbnb's approach to enhancing user privacy through the implementation of context-aware profile IDs that decouple user identities from their public profiles. By separating...

Cloudflare
12m

Dynamic, identity-aware, and secure Sandbox auth

The article explores the implementation of dynamic, identity-aware authentication mechanisms for sandbox environments, emphasizing the use of outbound Workers to enhance security and control over...