MCP's July 2026 spec rewrite went stateless and made Client ID Metadata Documents the standard, not audience-bound tokens, which have been mandatory since mid-2025. What actually changed since December 2025, and the checklist that replaces the old one.
API security in four layers, ordered by risk reduction per hour: authorization first, then tokens, then surface and design, then machine and agent identity. A map of every API security guide published here, plus a working order to follow.
In a monolith you check who someone is once. In microservices, every hop has to ask again. Here is how I design authentication and authorization across services: edge auth, per-service verification, workload identity with SPIFFE, and centralized policy.
Every CTO re-litigates build vs buy for authentication every 18 months, and the framing is broken. The real question isn't build or buy. It's which parts of identity are commodity and which parts are your actual product.
A founder's guide to the difference between authentication and authorization in 2026, with passkeys, agent auth, JWT pitfalls, and the mistakes I see at scale.
Five credential management platforms compared on PKI lifecycle, FIDO2 and passwordless, post-quantum readiness, NIST 800-63 assurance levels and real pricing.
The complete CIAM provider directory, not a ranking: 34 identity platforms across six categories, with current ownership, published free tiers, and fit.
SAML 2.0 has been frozen since 2005 and still carries enterprise SSO, because that is what large IT organisations standardised on. Here is the protocol, the assertion flow, and the parts that go wrong.
SCIM automates user provisioning and de-provisioning across cloud apps through a standard JSON schema and REST API. Here is how SCIM 2.0 actually works, how it differs from SSO, and why de-provisioning is the part that matters most.
JWT is a format, OAuth is delegation, OIDC is authentication on top of OAuth, and SAML is the XML predecessor enterprises still require. Here is how they fit together and which one your use case needs.
Authentication, identity verification, and identification answer three different security questions. Confusing them is how products end up with weak controls.