logoalt Hacker News

notaharvardmbatoday at 5:25 PM1 replyview on HN

oauth, saml, oidc accomplish the same thing in a way more mature way, so if you’re already using SSO just do that instead of adding another point of failure..


Replies

mjg59today at 5:30 PM

No they don't - you're still giving the agent a static token that can be exfiltrated and used elsewhere.

show 1 reply