Engineering posts about Authorization
Curated summaries and key learnings for engineers working with Authorization.
The Agent Access Model
The Agent Access Model (AAM) presents a novel approach to access control for agents in enterprise security, moving away from traditional trust models that rely on user identity and location. AAM...
Permission isn't purpose: Intent-based authorization in Omnigent
The article presents a detailed examination of intent-based authorization as implemented in the Omnigent platform, highlighting its role in enhancing security by binding user sessions to declared...
How Figma stays ahead of vulnerabilities with agents
The article outlines Figma's innovative approach to security by leveraging agents to monitor code quality and detect vulnerabilities throughout the software development lifecycle. It emphasizes the...
Blocking Slow-Burn Attacks: Contextual Policies in Omnigent
The article explores the vulnerabilities of AI agents to slow-burn attacks, where attackers exploit the agent's inability to recognize harmful sequences of actions that appear benign in isolation. It...
Unlocking the Cloudflare app ecosystem with OAuth for all
The article discusses Cloudflare's recent enhancement of its OAuth capabilities, allowing all customers to create and manage their own OAuth applications. It outlines the challenges faced during the...
Enhance Security and Trust: New Session Metadata in Sign in with Google
The article introduces new session metadata claims in Sign in with Google, specifically the 'auth_time' and 'amr' claims, designed to enhance security and provide deeper insights into user...
Managed OAuth for Access: make internal apps agent-ready in one click
The article outlines Cloudflare's implementation of Managed OAuth to enhance access for internal applications, allowing agents to authenticate seamlessly. It describes the challenges faced when...
Securing non-human identities: automated revocation, OAuth, and scoped permissions
The article addresses the critical need for securing non-human identities in software development, particularly in the context of agentic AI systems. It outlines the risks associated with credential...
Privacy-first connections: Empowering social experiences at Airbnb
The article outlines Airbnb's approach to enhancing user privacy through the implementation of context-aware profile IDs that decouple user identities from their public profiles. By separating...
Dynamic, identity-aware, and secure Sandbox auth
The article explores the implementation of dynamic, identity-aware authentication mechanisms for sandbox environments, emphasizing the use of outbound Workers to enhance security and control over...