You are here |
aaronparecki.com | ||
| | | |
blog.christianposta.com
|
|
| | | | The Model Context Protocol has created quite the buzz in the AI ecosystem at the moment, but as enterprise organizations look to adopt it, they are confronted with a hard truth: it lacks important security functionality. Up until now, as people experiment with Agentic AI and tool support, they've mostly adopted the MCP stdio transport, which means you end up with a 1:1 deployment of MCP server and MCP client. What organizations need is a way to deploy MCP servers remotely and leverage authorization to give resource owner's access to their data safely. | |
| | | |
marcolabarile.me
|
|
| | | | A brief introduction to OAuth 2.0 and OpenID Connect that allows you to quickly choose the best flow for your application. | |
| | | |
neilmadden.blog
|
|
| | | | In "Towards a standard for bearer tokenURLs", I described a URL scheme that can be safely used to incorporate a bearer token (such as an OAuth access token) into a URL. That blog post concentrated on the technical details of how that would work and the security properties of the scheme. But as Tim Dierks... | |
| | | |
alinacierdem.com
|
|
| |