86°F

Aaron Parecki

  • Articles
  • Notes
  • Photos
  • Aaron Parecki
    I'm heading home from 10 days in Vienna/London tomorrow and my stomach still hasn't actually caught up from the jet lag
    London, England, GBR • 80°F
    2 likes 1 repost 2 replies
    Tue, Jul 28, 2026 8:33pm +01:00 #travel
  • Aaron Parecki
    Today is the day, MCP is launching the next version of the spec! The 2026-07-28 version brings a bunch of exciting changes like statelessness, but I'm focused on the boring auth side of things that nobody wants to deal with!

    • Issuer validation (RFC 9207)
    • Refresh token and offline_access recommendations
    • Scope clarifications
    • Syncing with RFC 8414 .well-known URI

    In the mean time, there's been a ton of excitement around MCP's Enterprise-Managed Auth extension, with a beta program running in Claude and Okta and new MCP servers shipping support by the day!

    Join me at the MCP spec release party in London tonight to learn about what's new in enterprise MCP security!

    https://luma.com/klu2tegz
    London, England, GBR • 83°F
    Tue, Jul 28, 2026 2:19pm +01:00 #mcp #oauth #okta #ai
  • Aaron Parecki
    Figuring out how AI agents get access to enterprise apps gets messy fast.

    Static API keys and repeated OAuth flows look fine in a demo, but they completely break down at scale.

    Lately, much of my work in the IETF OAuth Working Group has focused on solving this exact bottleneck.

    By leveraging the Cross-App Access pattern, built on the Identity Assertion JWT Authorization Grant, we can fundamentally change how agents interact with your stack:

    • No more manual OAuth dance: Agents get seamless, scoped access to connected apps entirely behind the scenes.
    • Centralized IT control: Enterprise admins get the clear visibility, security boundaries, and policy control they actually need.

    I’m joining Jiquan Ngiam, CEO of MintMCP, to discuss how this plays out in practice. JQ runs over 20 agents on MintMCP's platform, so we’ll explore what MCP Enterprise-Managed Authorization looks like when deployed across tools like Salesforce, GitHub, and Confluence.

    If you work in identity, security, or are currently figuring out how to safely deploy AI agents in your enterprise, come join the conversation.

    Free and live on Zoom, Jul 9 at 9am Pacific: https://luma.com/va1tfrnf
    Portland, Oregon, USA • 79°F
    Wed, Jul 8, 2026 6:12pm -07:00 #xaa #oauth #okta
  • Aaron Parecki
    Enterprise AI just got a lot more secure. Anthropic launched a beta of "Enterprise Managed Auth" in Claude, so you can now connect Claude seamlessly to MCP servers through your enterprise IdP like Okta!

    Now employees no longer have to connect MCP servers manually and wait for a series of OAuth and login prompts. Once you log in to Claude from Okta, all the preconfigured MCP servers are already connected! It's not every day you get to improve both usability and security!

    This is an application of the Cross App Access pattern, defined in the Identity Assertion JWT Authorization Grant being standardized in the OAuth working group at the IETF.

    Seeing adoption from a massive player like Claude is a huge validation of the effort! It's been fantastic to work with the folks at Anthropic over the past year on this Paul Carleton and Den Delimarsky. And of course this wouldn't be possible without the collaboration with my co-authors on the spec Karl McGuinness and Brian Campbell!

    https://claude.com/blog/enterprise-managed-auth

    https://www.youtube.com/watch?v=5kTDt9ewTwE
    San Francisco, California, USA • 66°F
    Thu, Jun 18, 2026 12:35pm -07:00 #oauth #mcp #xaa #enterprisesecurity
  • Aaron Parecki
    The "Agent Verified" signup flow from WorkOS is exactly what I've been telling the agent platforms they should be doing with Cross App Access! Very cool to see this launch! 👏

    https://workos.com/auth-md/docs/flows/verified

    "The agent's provider — OpenAI, Anthropic, Cursor, or any trusted agent platform — attests to the user's identity at registration time. Your service verifies the attestation and issues credentials synchronously, no human interaction required."

    In Cross App Access terms:

    • The "agent platform/provider" is the ID-JAG issuer, because users are already signed in to those platforms when they use agents
    • The "service" is the ID-JAG consumer (the Resource AS), and issues an access token if the ID-JAG is trusted and valid

    You can test this out in the Cross App Access sandbox today! https://xaa.dev/
    Portland, Oregon, USA • 79°F
    Thu, May 21, 2026 7:12pm -07:00 #oauth #xaa #ai #okta
  • Aaron Parecki
    my head feels like a blender that has been filled past the "do not fill above" line
    Portland, Oregon, USA • 61°F
    3 likes 1 reply
    Tue, May 19, 2026 11:01am -07:00
  • Aaron Parecki
    Found my todo list for 2026 https://kylegabriel.com/projects/2020/06/automated-hydroponic-system-build.html
    Alaska Flight 18 PDX to JFK in Ulysses, Pennsylvania • 62°F
    5 likes 2 replies
    Mon, Mar 30, 2026 2:28pm -04:00 #hydroponics
  • Aaron Parecki
    TIL about UIScreenshotService which enables iOS apps to provide a high res PDF screenshot of the app content when the user uses the system screenshot action! Chrome uses this to give a full export of the page!
    Alaska Flight 18 PDX to JFK in Forsyth, Montana • 48°F
    7 likes 1 repost 1 reply
    Mon, Mar 30, 2026 9:55am -06:00 #ios
  • Aaron Parecki
    I'm impressed, Cathay Pacific transferred my vegetarian meal request to the new flight they moved me to after the incoming flight was late and missed the connection. Normally airlines say oh well you didn't reserve the meal 72 hours before the flight.
    Cathay Pacific Flight 884 HKG to LAX in 赤鱲角, 新界, HKG • 81°F
    7 likes 1 repost
    Wed, Mar 25, 2026 4:23pm +08:00 #travel
  • Aaron Parecki
    Happy final Daylight Savings Time Eve to all our friends in British Columbia! I hope we can join you on the other side soon!
    Portland, Oregon, USA • 53°F
    16 likes 7 reposts 1 reply
    Sat, Mar 7, 2026 9:02pm -08:00 #time #dst
  • Aaron Parecki
    I'm setting up a temporary laptop for my next trip and it's shocking how much faster the cross-device passkey flow is compared to looking up and hand typing my long 1Password passwords
    Portland, Oregon • 46°F
    13 likes 1 repost 2 replies
    Thu, Mar 5, 2026 7:26pm -08:00 #security #passkey
  • Aaron Parecki
    If you’re struggling to get AI agents past enterprise security reviews, join me tomorrow for a session on how Cross App Access (XAA) brings managed authorization to MCP!

    I'll be joined by Sohail Pathan to show off our Cross App Access playground and give a live demo of how the protocol works!

    Tomorrow - February 18, 2026 (8 AM PT)

    👉 https://www.brighttalk.com/webcast/14899/661521?utm_source=apk_social&utm_medium=brighttalk&utm_campaign=661521
    Portland, Oregon • 43°F
    1 repost
    Tue, Feb 17, 2026 3:17pm -08:00 #okta #oktadev #xaa #mcp #oauth #enterprisesecurity
  • Aaron Parecki
    Inspired by some #indieweb folks creating /caw pages on their websites, I made one of my own! Here you can listen to the most recent crow recorded from my house:

    https://aaronparecki.com/caw/
    Portland, Oregon • 49°F
    17 likes 3 reposts
    Fri, Feb 13, 2026 2:30pm -08:00 #caw #indieweb
  • Aaron Parecki
    Apparently I missed the introduction of the 4.4mm TRRRS audio jack 10 years ago and just now discovered it. What a cool idea.
    Redwood City, California • 51°F
    5 likes 3 replies
    Mon, Jan 26, 2026 7:35pm -08:00 #audio
  • Aaron Parecki
    "I'll just check my critical thinking and nuke it in the microwave" has to be my favorite quote from this Business Insider video on Trader Joe's white-labeled food
    Portland, Oregon • 43°F
    4 likes 3 replies
    Mon, Jan 12, 2026 8:59pm -08:00
  • Aaron Parecki
    Me looking at my todo list on a Sunday night after having done at least a couple things today, yet somehow it looks more like a list of what I did *not* do today.
    Portland, Oregon • 47°F
    6 likes
    Sun, Jan 11, 2026 7:21pm -08:00
  • Aaron Parecki
    oh no, due to a series of misclicks, I just accidentally archived the most recent 100 emails in my inbox.

    if nothing else, reviewing my "all mail" folder is doing a good job of making me question how important emails in my inbox actually are.
    Portland, Oregon • 57°F
    4 likes 1 reply
    Tue, Dec 16, 2025 7:42pm -08:00 #email
  • Aaron Parecki
    The new MCP spec just dropped! 🎉

    There's too many new things to get into everything, but there are two big changes I am most excited about 👀

    📝 Client ID Metadata Documents (CIMD) - a simpler way to manage client registrations, clients describe themselves with a URL they control
    🔐 Enterprise-Managed Authorization extension (aka Cross App Access) - eliminate the OAuth redirect and get tokens for an MCP server by requesting them from the enterprise IdP

    It's been great working on this with folks like Den Delimarsky, Paul Carleton, David Soria Parra, Nick Cooper, Tyler Leonhardt, and more!

    Read more about what these mean for you in my full post
    👉 https://aaronparecki.com/2025/11/25/1/mcp-authorization-spec-update
    Portland, Oregon • 44°F
    1 like
    Tue, Nov 25, 2025 3:11pm -08:00 #oauth #cimd #xaa #mcp
  • Aaron Parecki
    Inspired by a question from @thisismissem.social, I wrote up a document describing how to apply DPoP (RFC9449) to the OAuth Device Flow (RFC8628).

    https://datatracker.ietf.org/doc/draft-parecki-oauth-dpop-device-flow/
    Portland, Oregon, USA • 55°F
    7 likes 3 reposts 1 reply
    Sat, Sep 20, 2025 7:18am -07:00 #oauth #dpop #ietf
  • Aaron Parecki

    The IETF OAuth Working Group has adopted the Identity Assertion Authorization Grant specification!

    This specification provides a mechanism for an application to use an identity assertion to obtain an access token for a third-party API by coordinating through a common enterprise identity provider

    This is the basis of Cross App Access (XAA), providing IT admins better visibility and control of app-to-app connections by configuring the connections in their enterprise IdP.

    While it will still be a while before it is an RFC, this is an important step in the standards process, as this is the first time the document is "official"! This signifies that the working group agrees that the problem is worth solving, and agrees on the general direction of the spec.

    Thanks to everyone for your contributions and feedback so far!

    And thanks to my co-authors Karl McGuinness and Brian Campbell!

    Portland, Oregon, USA • 77°F
    1 like
    Mon, Sep 8, 2025 5:00pm -07:00 #oauth #ietf #okta #xaa
older

Hi, I'm Aaron Parecki, Director of Identity Standards at Okta, and co-founder of IndieWebCamp. I maintain oauth.net, write and consult about OAuth, and participate in the OAuth Working Group at the IETF. I also help people learn about video production and livestreaming. (detailed bio)

I've been tracking my location since 2008 and I wrote 100 songs in 100 days. I've spoken at conferences around the world about owning your data, OAuth, quantified self, and explained why R is a vowel. Read more.

  • Director of Identity Standards at Okta
  • IndieWebCamp Founder
  • OAuth WG Editor
  • OpenID Board Member

  • 🎥 YouTube Tutorials and Reviews
  • 🏠 We're building a triplex!
  • ⭐️ Life Stack
  • ⚙️ Home Automation
  • All
  • Articles
  • Bookmarks
  • Notes
  • Photos
  • Replies
  • Reviews
  • Trips
  • Videos
  • Contact
© 1999-2026 by Aaron Parecki. Powered by p3k. This site supports Webmention.
Except where otherwise noted, text content on this site is licensed under a Creative Commons Attribution 3.0 License.
IndieWebCamp Microformats Webmention W3C HTML5 Creative Commons
WeChat ID
aaronpk_tv