72°F

Aaron Parecki

  • Articles
  • Notes
  • Photos

#Oauth

  • Aaron Parecki

    Hi, I'm Aaron Parecki. I write about OAuth here, and I give talks about OAuth 2.0. Below you'll find my recent posts about various OAuth-related things, including talks I'm giving. I've also written two community resources about OAuth:

    OAuth 2.0 Simplified is a guide to OAuth 2.0 focused on writing clients that gives a clear overview of the spec at an introductory level.

    In 2017, I published a longer version of this guide as a book, available on oauth.com as well as a print version. The book guides you through building an OAuth server, and covers many details that are not part of the spec. I published this book in conjunction with Okta.

    Portland, Oregon
    Sat, Feb 4, 2017 11:35am -08:00 #oauth #oauth2
  • Okta expands Cross App Access ecosystem to secure AI agent connections - SiliconANGLE (siliconangle.com)
    Wed, Jun 24, 2026 9:37am -07:00 #okta #xaa #oauth
  • No more blind trust: Identity controls for AI agents | resource | SC Media (www.scworld.com)
    Tue, Jun 23, 2026 12:39pm -07:00 #okta #oauth #xaa
  • Announcing Keycard Support for ID-JAG and Cross-App Access from Okta — Keycard (www.keycard.ai)
    Tue, Jun 23, 2026 12:07pm -07:00 #okta #oauth #xaa
  • Okta partners with MintMCP to govern how agents connect to enterprise apps | MintMCP Blog (www.mintmcp.com)
    Tue, Jun 23, 2026 7:51am -07:00 #xaa #oauth #okta #mcp
  • Okta advances the industry standard for secure AI agent connections with expanding Cross App Access ecosystem (www.okta.com)
    Tue, Jun 23, 2026 7:51am -07:00 #oauth #okta #xaa
  • Zero-Touch OAuth: How MCP Enterprise-Managed Authorization Is Solving the AI Agent Auth Crisis - DEV Community (dev.to)
    Mon, Jun 22, 2026 4:59pm -07:00 #xaa #mcp #okta #oauth
  • Enterprise-Managed MCP Auth Changes the Game — What Teams and Server Builders Should Do Now - Influzer.ai (www.influzer.ai)
    Mon, Jun 22, 2026 4:57pm -07:00 #xaa #okta #mcp #oauth
  • MCP Enterprise Authorization Goes Stable: Zero-Touch SSO for Okta, Anthropic, VS Code (www.techtimes.com)
    Sat, Jun 20, 2026 1:53pm -07:00 #xaa #oauth #okta #mcp
  • MCP gets its missing enterprise authorization layer - The New Stack (thenewstack.io)
    Thu, Jun 18, 2026 1:10pm -07:00 #mcp #xaa #oauth #okta
  • Aaron Parecki
    Enterprise AI just got a lot more secure. Anthropic launched a beta of "Enterprise Managed Auth" in Claude, so you can now connect Claude seamlessly to MCP servers through your enterprise IdP like Okta!

    Now employees no longer have to connect MCP servers manually and wait for a series of OAuth and login prompts. Once you log in to Claude from Okta, all the preconfigured MCP servers are already connected! It's not every day you get to improve both usability and security!

    This is an application of the Cross App Access pattern, defined in the Identity Assertion JWT Authorization Grant being standardized in the OAuth working group at the IETF.

    Seeing adoption from a massive player like Claude is a huge validation of the effort! It's been fantastic to work with the folks at Anthropic over the past year on this Paul Carleton and Den Delimarsky. And of course this wouldn't be possible without the collaboration with my co-authors on the spec Karl McGuinness and Brian Campbell!

    https://claude.com/blog/enterprise-managed-auth

    https://www.youtube.com/watch?v=5kTDt9ewTwE
    San Francisco, California, USA • 66°F
    Thu, Jun 18, 2026 12:35pm -07:00 #oauth #mcp #xaa #enterprisesecurity
  • OAuth for the Model Context Protocol
    Jun
    16
    June 16, 2026 11:30am - 12:30pm (-0700)
    Mandalay Bay
    Las Vegas, Nevada, US
    Identiverse 2026
    permalink #mcp #oauth #okta
  • Identiverse
    Jun
    15
    Jun
    …
    Jun
    18
    June 15-18, 2026
    4 days
    Mandalay Bay
    Las Vegas, Nevada, US
    permalink #okta #identiverse #oauth #mcp
  • Portland (PDX) to Las Vegas (LAS)
    June 14, 2026 from 5:50pm to 8:15pm (-0700)
    Alaska Flight 531
    Mc Carran Intl in Las Vegas
    permalink #okta #identiverse #mcp #oauth
  • Cross-Domain API Access: Beyond the "Obvious" Shortcuts

    Cross-domain access is everywhere in today's software landscape. Whether you look at enterprise SaaS applications, AI agents interacting with user data across multiple platforms, or "integrated experiences" pulling information from a calendar, a chat tool, and a wiki—everything eventually needs to talk across boundaries.
    continue reading...
    1 like
    Wed, May 27, 2026 4:35pm -07:00 #oauth #okta #xaa #id-jag #ai
  • Aaron Parecki
    The "Agent Verified" signup flow from WorkOS is exactly what I've been telling the agent platforms they should be doing with Cross App Access! Very cool to see this launch! 👏

    https://workos.com/auth-md/docs/flows/verified

    "The agent's provider — OpenAI, Anthropic, Cursor, or any trusted agent platform — attests to the user's identity at registration time. Your service verifies the attestation and issues credentials synchronously, no human interaction required."

    In Cross App Access terms:

    • The "agent platform/provider" is the ID-JAG issuer, because users are already signed in to those platforms when they use agents
    • The "service" is the ID-JAG consumer (the Resource AS), and issues an access token if the ID-JAG is trusted and valid

    You can test this out in the Cross App Access sandbox today! https://xaa.dev/
    Portland, Oregon, USA • 79°F
    Thu, May 21, 2026 7:12pm -07:00 #oauth #xaa #ai #okta
  • San Jose (SJC) to Portland (PDX)
    May 1, 2026 from 9:38am to 11:28am (-0700)
    Alaska Flight 2274
    Portland Intl in Portland
    permalink #iiw #okta #oauth #openid
  • Internet Identity Workshop
    Apr
    28
    Apr
    29
    Apr
    30
    April 28-30, 2026
    3 days
    Computer History Museum
    Mountain View, California, US
    permalink #iiw #oauth #openid #okta
  • Portland (PDX) to San Jose (SJC)
    April 27, 2026 from 9:07pm to 10:59pm (-0700)
    Alaska Flight 3344
    Norman Y Mineta San Jose Intl in San Jose
    permalink #iiw #oauth #openid #okta
  • Mountain View
    Apr
    27
    Apr
    …
    Apr
    30
    April 27-30, 2026
    4 days
    Mountain View
    Mountain View, California, US
    permalink #iiw #oauth #openid #okta
  • Evolution, not Revolution: How MCP is Reshaping OAuth
    Apr
    2
    April 2, 2026 12:20pm - 12:45pm (-0400)
    New York Marriott Marquis
    New York, New York, US
    MCP Dev Summit New York
    Watch Video
    permalink #mcp #oauth #xaa
older

Hi, I'm Aaron Parecki, Director of Identity Standards at Okta, and co-founder of IndieWebCamp. I maintain oauth.net, write and consult about OAuth, and participate in the OAuth Working Group at the IETF. I also help people learn about video production and livestreaming. (detailed bio)

I've been tracking my location since 2008 and I wrote 100 songs in 100 days. I've spoken at conferences around the world about owning your data, OAuth, quantified self, and explained why R is a vowel. Read more.

  • Director of Identity Standards at Okta
  • IndieWebCamp Founder
  • OAuth WG Editor
  • OpenID Board Member

  • 🎥 YouTube Tutorials and Reviews
  • 🏠 We're building a triplex!
  • ⭐️ Life Stack
  • ⚙️ Home Automation
  • All
  • Articles
  • Bookmarks
  • Notes
  • Photos
  • Replies
  • Reviews
  • Trips
  • Videos
  • Contact
© 1999-2026 by Aaron Parecki. Powered by p3k. This site supports Webmention.
Except where otherwise noted, text content on this site is licensed under a Creative Commons Attribution 3.0 License.
IndieWebCamp Microformats Webmention W3C HTML5 Creative Commons
WeChat ID
aaronpk_tv