RSS.Social

Christian Posta

follow: @[email protected]

Posts

Human-in-the-loop Authorization Patterns for Agents

APIs for Probabilistic Callers

Credential Brokering Patterns for AI Agents Part 2: Protecting the Token Vault with AWS KMS

Credential Brokering Patterns for AI Agents Part 1: Don't Give the Agent the Keys

Okta SAML and Keycloak for ID-JAG Cross App Access

What 'is' Agent Identity? Human? Workload? A new Layer?

The Differences Between Microservices and AI Agents

Avoiding MCP Confused Deputy With AAuth

Avoiding MCP Confused Deputy With AAuth

Inbound Auth for Agentcore With Agentgateway

Inbound Auth for Agentcore With Agentgateway

Connecting SaaS MCP Servers to Enterprise With Agentgateway

Connecting SaaS MCP Servers to Enterprise With Agentgateway

Deep Dive AAuth (Agent Auth) - Identity and Access Management for AI Agents

Deep Dive AAuth (Agent Auth) - Identity and Access Management for AI Agents

A Guide to Microsoft Entra Agent ID on Kubernetes

A Guide to Microsoft Entra Agent ID on Kubernetes

Enterprise MCP SSO With Microsoft Entra and Agentgateway

Explaining OAuth Delegation, 'On Behalf Of', and Agent Identity for AI Agents

Avoid stdio! MCP Servers In Enterprise Should Be Remote

API Keys Are a Bad Idea for Enterprise LLM, Agent, and MCP Access

Mitigate Prompt Injection Attacks With A2AS and Agentgateway

Building an MCP Gateway with Apigee API Gateway

Understanding Sessions in Agent to Agent Communication

MCP Authorization Patterns for Upstream API Calls

Authenticating MCP OAuth Clients With SPIFFE and SPIRE

Implementing MCP Dynamic Client Registration With SPIFFE and Keycloak

Configuring A2A OAuth User Delegation

Enterprise Challenges With MCP Adoption

MCP Authorization With Dynamic Client Registration

Agent Discovery, Naming, and Resolution - the Missing Pieces to A2A

Understanding MCP Authorization, Step by Step, Part Three

Understanding MCP Authorization, Step by Step, Part Two

Understanding MCP Authorization, Step by Step, Part One

Agent Identity and Access Management - Can SPIFFE Work?

Will AI Agents Force Us to Finally Do Auth Right?

AI Agent Delegation - You Can’t Delegate What You Don’t Control

Bridging Agent Autonomy and Human Oversight with OIDC CIBA

Agent Identity - Impersonation or Delegation?

APIs and AI Agents Follow the Same Layered Pattern

Do AI Agents Need Their Own Identity?

AI Reliability Engineering (AIRE) - Creating Dependable Humans