Identity
OAuth 2.0 and OIDC, SSO and SCIM, phishing-resistant authentication, and the enterprise identity lifecycle.
- "Phishing-resistant authentication: MFA that actually holds up" · Note · "We have MFA" is the most common false confidence in authentication. SMS codes, TOTP apps, and push approvals all count as multi factor, and all of them fail against a phishing page…
- "OAuth 2.0 and OIDC in production: flows, tokens, and the mistakes that repeat" · Note · OAuth 2.0 is an authorization framework that the industry uses for authentication anyway, usually by bolting OpenID Connect on top. The specs are readable, the libraries are mature, and…
- "SSO and SCIM: the enterprise identity lifecycle nobody designs for" · Note · Enterprise buyers ask for SSO on the first sales call, and most engineering teams treat it as the whole identity problem. SSO is sign in — a single arrow pointing into your application.…