DEV Community

#oauth

OAuth flow implementation details

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
MCP for tour guides: building a remote MCP server with ~100 tools and OAuth

MCP for tour guides: building a remote MCP server with ~100 tools and OAuth

Comments
6 min read
A Deactivated User With a Live Token: Reading Concrete CMS CVE-2026-85387 as a Revocation Gap

A Deactivated User With a Live Token: Reading Concrete CMS CVE-2026-85387 as a Revocation Gap

Comments
3 min read
How exactly would you validate the OAuth scope in Apigee? Which policy or condition would you use?

How exactly would you validate the OAuth scope in Apigee? Which policy or condition would you use?

5
Comments
2 min read
The OAuth Grants Nobody Reviews: Governing Third-Party SaaS Access

The OAuth Grants Nobody Reviews: Governing Third-Party SaaS Access

Comments
4 min read
How to secure a Jakarta EE client application with OIDC (using pac4j)

How to secure a Jakarta EE client application with OIDC (using pac4j)

Comments
8 min read
OAuth for AI Agents: Why General-Purpose Agents Strain the Integration Model

OAuth for AI Agents: Why General-Purpose Agents Strain the Integration Model

Comments 1
10 min read
What Is the MCP Python SDK OAuth Flaw? (Sept 29, 2026)

What Is the MCP Python SDK OAuth Flaw? (Sept 29, 2026)

Comments
2 min read
OAuth Is Not "Login." I Found That Out the Hard Way in Production

OAuth Is Not "Login." I Found That Out the Hard Way in Production

Comments
11 min read
How to secure a JAX-RS client application with OIDC (using pac4j)

How to secure a JAX-RS client application with OIDC (using pac4j)

Comments
13 min read
PingFederate as a Token Courier: Linking Entra with the Reference ID Adapter

PingFederate as a Token Courier: Linking Entra with the Reference ID Adapter

Comments
2 min read
Introspection and Delegations: Authorising Agents Per User, Per Operation

Introspection and Delegations: Authorising Agents Per User, Per Operation

Comments
3 min read
Securing the Token Vault: Encrypted State, Refresh Rotation and Safe Logs

Securing the Token Vault: Encrypted State, Refresh Rotation and Safe Logs

Comments
2 min read
What we learned putting social media APIs behind a hosted MCP server

What we learned putting social media APIs behind a hosted MCP server

Comments
3 min read
Introducing IdentiFlows.dev: A Visual Reference for Identity Flows

Introducing IdentiFlows.dev: A Visual Reference for Identity Flows

Comments
3 min read
The MCP Session Refresh Gotcha: Why "Token Expired" and "Session Expired" Are Not the Same Bug

The MCP Session Refresh Gotcha: Why "Token Expired" and "Session Expired" Are Not the Same Bug

1
Comments
6 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.