Firebase API Keys: Got a Callback From A Potential Client
I originally wrote this post about six months ago. Variations of this story have been published many times this year.
Read article: Firebase API Keys: Got a Callback From A Potential Client40 articles tagged Authentication.
I originally wrote this post about six months ago. Variations of this story have been published many times this year.
Read article: Firebase API Keys: Got a Callback From A Potential ClientThere is a basic assumption hiding inside many identity architectures in that if someone authenticated successfully, they should continue to have access.
Read article: Continuous Access Evaluation: Maybe We Should Stop Trusting Yesterday’s AuthenticationOAuth2 has a fairly straightforward model. A client authenticates to an authorization server, obtains an access token, and uses that token to access a protected resource.
Read article: OAuth2 JWT Bearer Tokens (RFC-7523): When a JWT Becomes Your OAuth2 CredentialThere is a glamorous side to identity management, if any of this actually constitutes glamorous.
Read article: SCIM: System for Cross-Domain Identity ManagementThe Model Context Protocol, or MCP, has quickly become one of the most important pieces of infrastructure in the emerging Agentic AI ecosystem.
Read article: Model Context Protocol: MCP, OAuth2, and the Identity Problem of Agentic AIFor years, identity protocols have used phrases such as Holder of Key, Proof of Possession, Key Binding, and Bearer almost interchangeably.
Read article: Holder of Key vs. Proof of Possession: Two Sides of Cryptographic IdentityIf you’ve ever read a specification like WebAuthn, DID Core, SD-JWT VC, BBS Signatures, OID4VCI, or OID4VP, you’ve probably encountered references to P-256, secp256k1, Ed25519, or BLS12–381.
Read article: Elliptic Curve Groups: The Mathematical Engine Behind Modern Digital IdentityWebAuthn is actually the tip of a much larger iceberg. Like the SD-JWT VC spec, it is built upon several W3C, FIDO Alliance, and IETF specifications. Together, these define a complete passwordless authentication ecosystem.
Read article: WebAuthN: Passwordless LoginsAuthentication is one of the most fundamental concepts in application security. Most developers spend considerable time designing how authenticated users are represented, authorized, and managed. Surprisingly, much less attention is given to the opposite state of users who have not authenticated at…
Read article: Understanding Unauthenticated Traffic: How Applications and APIs Represent The Unauthenticated UserMulti-Factor Authentication (MFA) is the security control that can make, or break, your business. If there’s one cybersecurity control that consistently separates organizations that get breached from those that don’t, it’s Multi-Factor Authentication (or, to be precise, MFA, done correctly).
Read article: Multi-Factor Authentication (MFA): Don’t Let Your CyberSecurity Insurance Claim Get Denied On…