Forem

# oauth

OAuth flow implementation details

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
RFC 8693 Deep Dive: Token Exchange
Cover image for RFC 8693 Deep Dive: Token Exchange

RFC 8693 Deep Dive: Token Exchange

4
Comments
10 min read
How Access and Refresh Tokens Work
Cover image for How Access and Refresh Tokens Work

How Access and Refresh Tokens Work

1
Comments
3 min read
JWT Algorithm Confusion Attacks: CVE-2026-22817, CVE-2026-27804, and CVE-2026-23552 Fix Guide

JWT Algorithm Confusion Attacks: CVE-2026-22817, CVE-2026-27804, and CVE-2026-23552 Fix Guide

2
Comments
6 min read
OpenID Connect Core 1.0 Deep Dive: Understanding the "Authentication" Layer on top of OAuth 2.0
Cover image for OpenID Connect Core 1.0 Deep Dive: Understanding the "Authentication" Layer on top of OAuth 2.0

OpenID Connect Core 1.0 Deep Dive: Understanding the "Authentication" Layer on top of OAuth 2.0

4
Comments
15 min read
ChatGPT Can Read Your Corporate Email — And You Probably Already Gave It Permission

ChatGPT Can Read Your Corporate Email — And You Probably Already Gave It Permission

4
Comments
5 min read
AWS Amplify + Amazon Cognito + AWS CDK: A Complete Setup Guide
Cover image for AWS Amplify + Amazon Cognito + AWS CDK: A Complete Setup Guide

AWS Amplify + Amazon Cognito + AWS CDK: A Complete Setup Guide

16
Comments
3 min read
RFC 8705 Deep Dive: Turning Access Tokens into "Unstealable Tokens" with mTLS
Cover image for RFC 8705 Deep Dive: Turning Access Tokens into "Unstealable Tokens" with mTLS

RFC 8705 Deep Dive: Turning Access Tokens into "Unstealable Tokens" with mTLS

3
Comments 1
21 min read
Strengthening OAuth 2.0 with FAPI 2.0
Cover image for Strengthening OAuth 2.0 with FAPI 2.0

Strengthening OAuth 2.0 with FAPI 2.0

3
Comments
4 min read
RFC 6749 Deep Dive: Understanding OAuth 2.0 Design Decisions from the Specification
Cover image for RFC 6749 Deep Dive: Understanding OAuth 2.0 Design Decisions from the Specification

RFC 6749 Deep Dive: Understanding OAuth 2.0 Design Decisions from the Specification

6
Comments
13 min read
Fix: `xurl` OAuth 2.0 Fails with "unauthorized_client" on X API

Fix: `xurl` OAuth 2.0 Fails with "unauthorized_client" on X API

1
Comments
3 min read
Securing Your App with Access and Refresh Tokens: A Practical Guide

Securing Your App with Access and Refresh Tokens: A Practical Guide

Comments
14 min read
Cloudflare Bot Fight Mode Breaks Zapier OAuth (And How to Fix It)

Cloudflare Bot Fight Mode Breaks Zapier OAuth (And How to Fix It)

7
Comments
3 min read
Week 6 OAuth2 Conceptual Quiz

Week 6 OAuth2 Conceptual Quiz

1
Comments
10 min read
Building a Secure MCP Server with Cloud Run, Rust, and Gemini CLI

Building a Secure MCP Server with Cloud Run, Rust, and Gemini CLI

Comments
9 min read
The Infrastructure Nobody Sees

The Infrastructure Nobody Sees

1
Comments
3 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.