logoalt Hacker News

miguelspizzatoday at 8:40 PM2 repliesview on HN

SAML is bad, but OAuth and OIDC are showing major cracks with identity and agents. Go to any major company right now and ask them how they are dealing with authenticating agents/what an agent identity even is.

The XSW part of the article was new to me though and kinda shocking


Replies

jeroenhdtoday at 8:57 PM

RFC8628 has been out for eight years, OAuth isn't standing in the way of bots anymore.

OAuth/OIDC is a problem if you're trying to shove a bot-shaped peg into a browser-shaped hole, but we don't need a new protocol to solve that.

TZubiritoday at 8:50 PM

It's probably for the better that they're having trouble with it, if trouble actually means increased workload.

If my security system is showing friction when there's a wave of agentic slop, I'd say that's a win.