Forem

# oauth

OAuth flow implementation details

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
OAuth ate your secrets

OAuth ate your secrets

Comments
7 min read
Vercel got hacked because an employee clicked 'Allow' on an OAuth prompt. We all do this.
Cover image for Vercel got hacked because an employee clicked 'Allow' on an OAuth prompt. We all do this.

Vercel got hacked because an employee clicked 'Allow' on an OAuth prompt. We all do this.

3
Comments
3 min read
Authentication in MERN Apps: JWT, bcrypt, Redis, and OAuth2
Cover image for Authentication in MERN Apps: JWT, bcrypt, Redis, and OAuth2

Authentication in MERN Apps: JWT, bcrypt, Redis, and OAuth2

Comments
10 min read
The Vercel/Context.ai Breach Wasn't a Vulnerability. It Was a Delegation Path.

The Vercel/Context.ai Breach Wasn't a Vulnerability. It Was a Delegation Path.

Comments
7 min read
Why your MCP server should serve OAuth Protected Resource Metadata — AuthKit + RFC 9728

Why your MCP server should serve OAuth Protected Resource Metadata — AuthKit + RFC 9728

Comments 1
4 min read
The Vercel Breach: When Your AI Tool's OAuth Becomes the Attack Vector

The Vercel Breach: When Your AI Tool's OAuth Becomes the Attack Vector

Comments
5 min read
Building Secure APIs for AI Systems: Architecture, Threat Models, and Best Practices
Cover image for Building Secure APIs for AI Systems: Architecture, Threat Models, and Best Practices

Building Secure APIs for AI Systems: Architecture, Threat Models, and Best Practices

1
Comments 1
3 min read
[Lime #1] OAuth Login
Cover image for [Lime #1] OAuth Login

[Lime #1] OAuth Login

Comments
6 min read
Supabase Auth OAuth in Flutter — Google, GitHub, and Apple Sign-In End-to-End

Supabase Auth OAuth in Flutter — Google, GitHub, and Apple Sign-In End-to-End

1
Comments
5 min read
Getting CLI authentication right: the complete guide to all 4 methods
Cover image for Getting CLI authentication right: the complete guide to all 4 methods

Getting CLI authentication right: the complete guide to all 4 methods

Comments
15 min read
My OAuth token expired mid-job. Took 2 hours to figure out why.

My OAuth token expired mid-job. Took 2 hours to figure out why.

Comments
2 min read
Building a Production-Ready OAuth Server for a VS Code Extension — Token Lifecycle, Auto-Refresh & Edge Rate Limiting
Cover image for Building a Production-Ready OAuth Server for a VS Code Extension — Token Lifecycle, Auto-Refresh & Edge Rate Limiting

Building a Production-Ready OAuth Server for a VS Code Extension — Token Lifecycle, Auto-Refresh & Edge Rate Limiting

Comments
9 min read
Building Apps That Act on Behalf of OSC Users (OAuth + PKCE in 50 Lines)
Cover image for Building Apps That Act on Behalf of OSC Users (OAuth + PKCE in 50 Lines)

Building Apps That Act on Behalf of OSC Users (OAuth + PKCE in 50 Lines)

1
Comments
6 min read
Building a Google OAuth CLI in Rust with PKCE (and surviving the borrow checker)

Building a Google OAuth CLI in Rust with PKCE (and surviving the borrow checker)

Comments
3 min read
OAuth Isn't Magic — Here's What Actually Happens When You Click 'Sign In with Google'

OAuth Isn't Magic — Here's What Actually Happens When You Click 'Sign In with Google'

Comments
3 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.