60°F

Aaron Parecki

  • Articles
  • Notes
  • Photos
Aaron Parecki
@aaronpk
2261
Followers
318
Following
3775
Notes
4888
Photos
422
Articles

Hi, I'm Aaron Parecki, Director of Identity Standards at Okta, and co-founder of IndieWebCamp. I maintain oauth.net, write and consult about OAuth, and participate in the OAuth Working Group at the IETF. I also help people learn about video production and livestreaming. (detailed bio)

I've been tracking my location since 2008 and I wrote 100 songs in 100 days. I've spoken at conferences around the world about owning your data, OAuth, quantified self, and explained why R is a vowel. Read more.

  • Director of Identity Standards at Okta
  • IndieWebCamp Founder
  • OAuth WG Editor
  • OpenID Board Member

  • 🎥 YouTube Tutorials and Reviews
  • 🏠 We're building a triplex!
  • ⭐️ Life Stack
  • ⚙️ Home Automation

You can follow me from Mastodon or any other similar application that uses ActivityPub. Search for my profile (aaronpk@aaronparecki.com) from your instance, or use the use the "Remote Follow" feature below.

Error

We couldn't find your subscription endpoint.

  • Aaron Parecki
    Figuring out how AI agents get access to enterprise apps gets messy fast.

    Static API keys and repeated OAuth flows look fine in a demo, but they completely break down at scale.

    Lately, much of my work in the IETF OAuth Working Group has focused on solving this exact bottleneck.

    By leveraging the Cross-App Access pattern, built on the Identity Assertion JWT Authorization Grant, we can fundamentally change how agents interact with your stack:

    • No more manual OAuth dance: Agents get seamless, scoped access to connected apps entirely behind the scenes.
    • Centralized IT control: Enterprise admins get the clear visibility, security boundaries, and policy control they actually need.

    I’m joining Jiquan Ngiam, CEO of MintMCP, to discuss how this plays out in practice. JQ runs over 20 agents on MintMCP's platform, so we’ll explore what MCP Enterprise-Managed Authorization looks like when deployed across tools like Salesforce, GitHub, and Confluence.

    If you work in identity, security, or are currently figuring out how to safely deploy AI agents in your enterprise, come join the conversation.

    Free and live on Zoom, Jul 9 at 9am Pacific: https://luma.com/va1tfrnf
    Portland, Oregon, USA • 79°F
    Wed, Jul 8, 2026 6:12pm -07:00 #xaa #oauth #okta
  • Aaron Parecki
    Enterprise AI just got a lot more secure. Anthropic launched a beta of "Enterprise Managed Auth" in Claude, so you can now connect Claude seamlessly to MCP servers through your enterprise IdP like Okta!

    Now employees no longer have to connect MCP servers manually and wait for a series of OAuth and login prompts. Once you log in to Claude from Okta, all the preconfigured MCP servers are already connected! It's not every day you get to improve both usability and security!

    This is an application of the Cross App Access pattern, defined in the Identity Assertion JWT Authorization Grant being standardized in the OAuth working group at the IETF.

    Seeing adoption from a massive player like Claude is a huge validation of the effort! It's been fantastic to work with the folks at Anthropic over the past year on this Paul Carleton and Den Delimarsky. And of course this wouldn't be possible without the collaboration with my co-authors on the spec Karl McGuinness and Brian Campbell!

    https://claude.com/blog/enterprise-managed-auth

    https://www.youtube.com/watch?v=5kTDt9ewTwE
    San Francisco, California, USA • 66°F
    Thu, Jun 18, 2026 12:35pm -07:00 #oauth #mcp #xaa #enterprisesecurity
  • Aaron Parecki
    The "Agent Verified" signup flow from WorkOS is exactly what I've been telling the agent platforms they should be doing with Cross App Access! Very cool to see this launch! 👏

    https://workos.com/auth-md/docs/flows/verified

    "The agent's provider — OpenAI, Anthropic, Cursor, or any trusted agent platform — attests to the user's identity at registration time. Your service verifies the attestation and issues credentials synchronously, no human interaction required."

    In Cross App Access terms:

    • The "agent platform/provider" is the ID-JAG issuer, because users are already signed in to those platforms when they use agents
    • The "service" is the ID-JAG consumer (the Resource AS), and issues an access token if the ID-JAG is trusted and valid

    You can test this out in the Cross App Access sandbox today! https://xaa.dev/
    Portland, Oregon, USA • 79°F
    Thu, May 21, 2026 7:12pm -07:00 #oauth #xaa #ai #okta
  • Aaron Parecki
    my head feels like a blender that has been filled past the "do not fill above" line
    Portland, Oregon, USA • 61°F
    3 likes 1 reply
    Tue, May 19, 2026 11:01am -07:00
read more

How Does This Work?

Would you like to use your own domain to be part of the Fediverse? Rather than finding an existing Mastodon instance to join, you can turn your own website into an ActivityPub profile like this one! Some of these options are more complicated than others, but the links below will get you started in the right direction.

  • Micro.blog is a fully-hosted service you can run on a custom domain or subdomain, and provides ActivityPub integration out of the box.
  • Bridgy Fed converts your existing website to ActivityPub using Webmention, h-entry and Atom.
  • Install a plugin for your WordPress or Drupal website.
  • Nautilus is an open-source proxy server you can run independently from your website.
  • You can self-host a single-user instance of ActivityPub-compatible software like microblog.pub, WriteFreely, or Mastodon.

If you want to go full DIY, you can implement ActivityPub into your own website! I started by following Eugen's guide here.

Available Feeds

Alternatively, you can choose one of my feeds below and add it to your reader.

  • https://aaronparecki.com/ - HTML/Microformats
  • https://aaronparecki.com/feed.json - JSON Feed
  • https://aaronparecki.com/feed.xml - Atom Feed
  • https://aaronparecki.com/primary.jf2 - jf2 Feed

Hi, I'm Aaron Parecki, Director of Identity Standards at Okta, and co-founder of IndieWebCamp. I maintain oauth.net, write and consult about OAuth, and participate in the OAuth Working Group at the IETF. I also help people learn about video production and livestreaming. (detailed bio)

I've been tracking my location since 2008 and I wrote 100 songs in 100 days. I've spoken at conferences around the world about owning your data, OAuth, quantified self, and explained why R is a vowel. Read more.

  • Director of Identity Standards at Okta
  • IndieWebCamp Founder
  • OAuth WG Editor
  • OpenID Board Member

  • 🎥 YouTube Tutorials and Reviews
  • 🏠 We're building a triplex!
  • ⭐️ Life Stack
  • ⚙️ Home Automation
  • All
  • Articles
  • Bookmarks
  • Notes
  • Photos
  • Replies
  • Reviews
  • Trips
  • Videos
  • Contact
© 1999-2026 by Aaron Parecki. Powered by p3k. This site supports Webmention.
Except where otherwise noted, text content on this site is licensed under a Creative Commons Attribution 3.0 License.
IndieWebCamp Microformats Webmention W3C HTML5 Creative Commons
WeChat ID
aaronpk_tv