Blog
Notes from the people building it
Protocols, architecture decisions and the awkward parts of selling to enterprise buyers. Written for engineers who have to ship the thing, not specify it.
TopicsEngineeringProtocolsProductEnterpriseSecurity
Archive
Everything else we have published, newest first.
2026
- Passkeys in B2B: the real risk is recovery6 August 2026
- The day RBAC stops scaling: role explosion and what comes after6 August 2026
- SCIM Deprovisioning Is a Promise Your App Probably Breaks6 August 2026
- Sentry's Greg Pstrucha on why a better prompt won't fix your agent's code6 August 2026
- Stateless JWTs have a logout problem — and enterprise customers will find it6 August 2026
- Stop Using Email as a Primary Key—Before It Bites You6 August 2026
- TIME serves bots a different website, and User-Agent is now a billing identity6 August 2026
- What SAML actually asks of you5 August 2026
- Approval fatigue is agent governance's next attack surface5 August 2026
- How to install and use the Paycux plugin in Claude, ChatGPT, and Codex5 August 2026
- Nicholas Arcolano on why 10x the tokens buys only 2x the output5 August 2026
- Paul Klein on collapsing the agent stack into one platform5 August 2026
- Philip Rathle on why AI agents keep reaching for a knowledge graph5 August 2026
- Tailscale's Remy Guercio on what comes after token maxing5 August 2026
- Ron Efroni on giving agents a deterministic place to run5 August 2026
- Zed's Anant Goel on evals, agent context, and the limits of git5 August 2026
- Introducing Atlas, your AI coworker4 August 2026
- Audit Logs Are a Product Feature, Not a Compliance Checkbox4 August 2026
- A practical guide to customizing AuthKit: Hints, branding, and org-specific signup rules4 August 2026
- How to add multi-tenant authentication to your TanStack Start SaaS4 August 2026
- Anyone can generate a blog post. Making it publishable is the work.4 August 2026
- What we learned in six months of making AI the default at Paycux4 August 2026
- SCIM PATCH semantics, and why your handler is probably wrong3 August 2026
- API keys vs. OAuth: How to manage both without building two systems3 August 2026
- Add authentication to your Astro site with AuthKit3 August 2026
- Testing Paycux in CI/CD: A practical guide3 August 2026
- How to build an MCP app on the 2026-07-28 spec with Paycux AuthKit31 July 2026
- The outage that comes with a date printed on it30 July 2026
- How to build a stateless MCP server on 2026-07-28, secured with AuthKit30 July 2026
- Dwarkesh Patel on the AI decade, in conversation with Michael Grinich30 July 2026
- A prompt that finds deep logic bugs, and the pipeline we built around it30 July 2026
- What "App-in-a-Box" actually means for B2B SaaS auth (and when you want one)29 July 2026
- Enterprise readiness, B2B SaaS CIAM, and Self-Serve SSO/SCIM are the same problem29 July 2026
- From data scarcity to abundance: Dr. Fei-Fei Li on how AI actually got here29 July 2026
- Top CIAM providers in 202629 July 2026
- Rotating identity provider metadata without an outage28 July 2026
- CIAM vs. IAM: What's the difference, and why it matters for B2B SaaS28 July 2026
- Shipping SDK changes across seven languages in under 30 minutes28 July 2026
- Building an autonomous UI quality program27 July 2026
- How to offer BYOK to your enterprise customers27 July 2026
- The real cost of building one OAuth integration27 July 2026
- Account linking, and the merge you cannot undo24 July 2026
- SAML security checklist for SaaS developers24 July 2026
- AuthKit now syncs identity provider email changes automatically23 July 2026
- Why SCIM needs OAuth 2.0 Client Credentials, not just bearer tokens23 July 2026
- How to add Radar to a custom AuthKit UI23 July 2026
- Paycux is now a plugin for ChatGPT and Claude23 July 2026
- The hidden cost of your own login box22 July 2026
- How to let users approve AI agents without leaving your app22 July 2026
- The Paycux access model: Who gets into your organization, and how22 July 2026
- Teaching your API to onboard AI agents22 July 2026
- JIT provisioning or SCIM: they answer different questions20 July 2026
- OAuth mix-up attacks and RFC 9207: The issuer check that never made it to token exchange20 July 2026
- SAML security best practices for SaaS developers20 July 2026
- Changing an email address is an identity event17 July 2026
- How to add multi-tenant authentication to your Next.js SaaS17 July 2026
- OAuth's rough month: What five recent vulnerabilities say about token trust17 July 2026
- Continuous access evaluation and B2B SaaS. Here's what to build.16 July 2026
- Secrets management tools compared: AWS Secrets Manager, HashiCorp Vault, Doppler, and Paycux Vault16 July 2026
- Service disruption on July 16, 202616 July 2026
- Adding MFA to your TanStack Start app16 July 2026
- What removal from a group should actually do15 July 2026
- Envelope encryption explained: Why you probably shouldn't implement it yourself15 July 2026
- MCP interceptors: The primitive that decides what an agent is allowed to do15 July 2026
- AI identity breaches are rising. Here's how B2B SaaS teams reduce the risk.14 July 2026
- The audit log events enterprise buyers will actually ask about14 July 2026
- MCP authorization patterns: Per-tool scopes, consent, and least privilege14 July 2026
- Bootstrapping a new app with Paycux AuthKit: Zero to authenticated in 5 minutes13 July 2026
- How to build a Claude Code connector secured with Paycux AuthKit13 July 2026
- WebMCP for Documentation13 July 2026
- What's new in SCIM 2.0: Pagination, events, and device schema13 July 2026
- Invitations are a state machine, and most are a boolean11 July 2026
- Directory sync is reconciliation, not import8 July 2026
- Tailscale's Remy Guercio on the shift from token maxing to ROI maxing8 July 2026
- Lifestyles of the AI-Native: Paycux at the AI Engineer World's Fair 20267 July 2026
- Webhook idempotency is a storage decision6 July 2026
- Role inheritance, and the four things people mean by it3 July 2026
- Widgets API: Build any Paycux-powered UI without the back-end hop3 July 2026
- Step-up authentication: Re-verify users before high-risk operations2 July 2026
- API keys have a lifecycle, and most products only build the first step1 July 2026
- Paycux MCP: Manage your Paycux account from any AI agent1 July 2026
- API Gateway: Managed auth and security for your API30 June 2026
- Projects and per-environment branding: Organize your products and brand them independently29 June 2026
- Caching a permission check without caching a mistake26 June 2026
- Social login in React Router v7: Google, GitHub, and Microsoft26 June 2026
- Roles your tenth customer will not outgrow24 June 2026
- Modelling roles when one person belongs to four organisations22 June 2026
- The token bill is an identity problem22 June 2026
- The audit log is append-only. Someone asked to be forgotten.19 June 2026
- SAML attribute mapping: A complete developer guide19 June 2026
- How to secure agentic commerce transactions18 June 2026
- The biggest MCP spec update ships July 28: What changes for AI agent authentication18 June 2026
- Choosing a session lifetime you can defend17 June 2026
- Encrypting PII in a Node.js app with Paycux Vault16 June 2026
- How to secure your MCP server with OAuth resource indicators16 June 2026
- Password hash migration: Formats, salting, and silent rehashing16 June 2026
- Cryptographic key isolation in multi-tenant SaaS15 June 2026
- Your users signed in with Google. That doesn't mean you can call their Google Calendar.15 June 2026
- React Router v7 authorization: A developer's guide for 202615 June 2026
- Rotating a webhook secret without dropping an event12 June 2026
- AI identity is your next security blind spot12 June 2026
- LLM token theft: how attackers drain your AI startup's bottom line12 June 2026
- What the security questionnaire is really asking10 June 2026
- The 2026 AI agent auth checklist: 9 things to audit before you ship10 June 2026
- How to manage API keys, tokens, and secrets for AI agents10 June 2026
- Delegated access for AI agents: The intersection rule explained10 June 2026
- Memory and context poisoning: Don't let attackers rewrite your AI agent's memory9 June 2026
- Directory sync beyond SCIM: Why "we support SCIM" isn't enough9 June 2026
- How to handle JWT in .NET9 June 2026
- Your audit action names are a public API8 June 2026
- At-least-once, out of order, and the state you rebuild anyway5 June 2026
- Clearing up (my own) OAuth misunderstandings4 June 2026
- Recovery codes are a second factor, so treat them like one3 June 2026
- Why AI agent audit logs are different from application logs3 June 2026
- AI agents now make up the majority of web traffic: What developers need to change3 June 2026
- Migrating identity providers without a flag day: A zero-downtime playbook3 June 2026
- How to implement RBAC authorization in Python APIs with Paycux3 June 2026
- What Acquired's hosts learned from studying the greatest companies in history2 June 2026
- The building blocks of an AI agent2 June 2026
- Key takeaways from Boris Cherny on building Claude Code2 June 2026
- The security risks specific to MCP servers, and how to address them2 June 2026
- TanStack Start authorization and RBAC: A developer's guide for 20262 June 2026
- Every regional system has a global part29 May 2026
- Paycux skills is in the Claude plugin marketplace29 May 2026
- auth.md — One week later: who's shipped, who's writing, what's next28 May 2026
- How to build a custom SDK generator with oagen28 May 2026
- Migrating auth at scale: What changes above 200K users28 May 2026
- TanStack Start authentication: A developer's guide for 202628 May 2026
- Sessions, tokens, and the refresh you keep getting wrong27 May 2026
- How to secure AI agent delegation and multi-agent communication27 May 2026
- Stainless alternatives: What to use now that the SDK generator is shutting down27 May 2026
- Top 7 enterprise SSO providers for B2B SaaS apps in 202626 May 2026
- Sender-constrained tokens: Why mTLS and DPoP exist, and what killed Token Binding26 May 2026
- Paycux vs. Auth0 vs. Clerk: The best auth platform for B2B SaaS in 202626 May 2026
- Magic links, and the four places they leak25 May 2026
- AgentMail at MCP Night 4: email as an identity layer for agents25 May 2026
- MCP Night 4 demo recap: AgentCard — one-time cards for agent payments25 May 2026
- MCP Night 4 demo recap: Expo's Evan Bacon puts the iOS simulator in the browser25 May 2026
- Generative UI for agents: Rhys Sullivan's MCP Night 4 lightning demo25 May 2026
- MCP Night 4 panel recap: what six months of agents actually changed25 May 2026
- MCP Night 4 recap: agent auth, auth.md, and the rise of agentic registration25 May 2026
- Resource Indicators in OAuth 2.0: A guide to RFC 870722 May 2026
- Agent experience: How to design products that agents can actually use21 May 2026
- Agent Registration with Auth.md21 May 2026
- Google OAuth's strict redirect URI matching: A guide for multi-tenant apps21 May 2026
- Migrating from a homegrown SSO implementation to Paycux21 May 2026
- Email verification proves one thing, and it is not identity20 May 2026
- Inside the Paycux Applied AI Showcase20 May 2026
- Bearer tokens vs sender-constraining tokens: Why possession alone isn't enough20 May 2026
- How to add API key support to your app20 May 2026
- Keycloak's experimental SCIM API: What's in it and what's still missing20 May 2026
- JIT provisioning explained: Automated user onboarding for enterprise apps19 May 2026
- Building a mental model of identity providers from scratch19 May 2026
- Multi-tenant session management: Isolation patterns that actually work19 May 2026
- Rotating a signing key when somebody else does the verifying18 May 2026
- How to add human approval to async AI agent actions18 May 2026
- Claude Day: What happened when 39 teams let non-engineers drive18 May 2026
- How to build flexible authorization for multi-tenant B2B SaaS18 May 2026
- Machine identity for AI agents: Which credential to issue and when15 May 2026
- Audit logs a security team will accept13 May 2026
- The developer's guide to AI agent authentication and authorization12 May 2026
- How Rex went from zero to enterprise ready in weeks12 May 2026
- Rate limiting will not stop credential stuffing on its own11 May 2026
- Common Entra ID SAML errors and how to fix them11 May 2026
- How Product Design is Evolving with AI11 May 2026
- How to handle JWT in PHP11 May 2026
- Not every non-human request is an attacker8 May 2026
- Handwritten SDKs Are Dead8 May 2026
- How to add enterprise SSO to your CLI8 May 2026
- PKCE vs Device Flow: Which OAuth flow is best for CLI auth?8 May 2026
- Securing agentic apps: How to contain AI agent prompt injection7 May 2026
- JWT best practices: A guide to secure authentication7 May 2026
- Choosing bot signals by what you would do about them6 May 2026
- The best providers for MCP server authentication in 20266 May 2026
- The 10 enterprise features every B2B SaaS needs (and how to ship them fast)6 May 2026
- The self-driving codebase: Building Horizon at Paycux6 May 2026
- Building an MCP server from a REST API5 May 2026
- Building authentication in React Router applications: The complete guide for 20265 May 2026
- How does SCIM Schema Discovery work4 May 2026
- April Updates1 May 2026
- A blog bot that pitches its own posts: building a Slack-native publishing system on Cloudflare Workers and Durable Workflows1 May 2026
- Designing an MCP server from a REST API30 April 2026
- Picking a password hash: A developer's guide to argon2, bcrypt, and scrypt30 April 2026
- Synchronous vs. asynchronous authorization updates: How to choose30 April 2026
- Authorisation for agents29 April 2026
- AI agents vs service accounts: Key differences and what to do about them29 April 2026
- Custom SCIM schemas: Where identity provisioning meets authorization29 April 2026
- The 5 best Firebase Auth alternatives in 202629 April 2026
- Paycux joins Stripe Projects: Auth from the CLI, no payment wall29 April 2026
- OAuth's On-Behalf-Of flow for AI agents28 April 2026
- How to add auth to your Rust CLI using Paycux28 April 2026
- Impossible travel, and the users it accuses27 April 2026
- How to handle JWT in Ruby27 April 2026
- AI agents and the multi-hop delegation problem27 April 2026
- Getting somebody back to the page they actually wanted24 April 2026
- Everything you should know about NIST's AI Agent Standards Initiative24 April 2026
- Paycux vs Clerk: Which one is better for B2B?24 April 2026
- What it takes to get FedRAMP authorized: Lessons from companies that did it23 April 2026
- The OAuth device flow, and the phone call it invites22 April 2026
- Best practices for AI agent access control22 April 2026
- Building authentication in Java applications: The complete guide for 202622 April 2026
- Your docs have a new audience22 April 2026
- Fetch Notion pages without OAuth using Paycux Pipes21 April 2026
- How to verify JWTs in a Next.js App Router app21 April 2026
- Best practices for secure user authentication21 April 2026
- DPoP (RFC 9449) explained: How sender-constrained OAuth tokens make token theft a non-event20 April 2026
- 5 best Stytch alternatives in 202620 April 2026
- The OWASP Top 10 for LLM applications: What developers shipping AI features need to know20 April 2026
- Vibe code everything except your auth20 April 2026
- Securing agentic apps: How to stop your AI agents from misusing their own tools16 April 2026
- Gadget chains: How low-severity bugs combine across dependencies to become critical16 April 2026
- Building authentication in Go applications: The complete guide for 202616 April 2026
- How to handle JWT in Java16 April 2026
- Multi-tenant from day one, without the rewrite15 April 2026
- Abhi Aiyer on building mastra and the future of AI agent frameworks15 April 2026
- AI is both weapon and target: Noam Schwartz on the new threat landscape15 April 2026
- Ameya Bhatawdekar on building AI evaluations at Braintrust15 April 2026
- Andrew McLeod on how Certn uses AI for background checks15 April 2026
- How AppsFlyer built AI into their platform15 April 2026
- From workforce management to AI orchestration: Assembled CEO John Wang on the jevons paradox of customer support15 April 2026
- Augment Code CEO Matt McClernan on the shift from copilots to agent orchestration15 April 2026
- Two decades of automation, now supercharged by AI15 April 2026
- Composable computers for agents: A conversation with Daytona CEO Ivan Burazin15 April 2026
- From Google voice to AI-first communication: Dialpad's Brian Peterson on leading AI adoption15 April 2026
- The AI factory for open models: Rob Ferguson on Fireworks AI at HumanX 202615 April 2026
- GraphQL meets the agent era: Matt Debergalis on APIs, MCP, and enterprise AI15 April 2026
- Homer Wang on building TinyFish and the future of AI agents15 April 2026
- Jyoti Bansal on how harness is rethinking AI for software delivery15 April 2026
- Linda Tong on how Webflow is bringing AI to web development15 April 2026
- Maxim Fateev on why durable execution matters for AI agents15 April 2026
- Mazy Dar on building the future of video understanding at here15 April 2026
- Modern analytics in the age of agents15 April 2026
- Ojus Save on how render is rethinking cloud for AI workloads15 April 2026
- Paul Dhaliwal on building Code Conductor and the future of AI-assisted development15 April 2026
- Pricing as product-market fit: Cosmo Wolfe on billing after the Stripe-Metronome acquisition15 April 2026
- Self-driving production: Autonomous agents for incident response15 April 2026
- Software still does things we don't expect15 April 2026
- The 5 best AWS Cognito alternatives for B2B SaaS in 202614 April 2026
- Understanding state, nonce, and PKCE14 April 2026
- Cryptographic origin binding: How passkeys make phishing structurally impossible9 April 2026
- Multi-tenant permissions done right: What Slack, Notion, and Linear can teach us9 April 2026
- Building authentication in Node.js applications: The complete guide for 20269 April 2026
- OAuth governance and consent phishing: What engineers need to know9 April 2026
- Rotating an encryption key without rewriting your database8 April 2026
- JWT algorithm confusion attacks: How they work and how to prevent them8 April 2026
- Securing agentic apps: How to vet the tools your AI agents depend on8 April 2026
- Top 5 PropelAuth alternatives for secure authentication in 20268 April 2026
- Adversary-in-the-middle attacks: The threat that makes your MFA useless7 April 2026
- The 5 best identity and access management providers to power your SaaS app in 20267 April 2026
- RS256 vs HS256: A deep dive into JWT signing algorithms7 April 2026
- Securing agentic apps: Give your AI agents their own credentials6 April 2026
- SAML's rough quarter: Five critical vulnerabilities in four months6 April 2026
- Building authentication in Laravel applications: The complete guide for 20263 April 2026
- Authorising a CLI on a machine you do not control2 April 2026
- The developer's guide to CLI authentication2 April 2026
- How attackers are bypassing MFA using AI in 20262 April 2026
- Passkeys stop phishing. Your MFA fallbacks undo it.2 April 2026
- The Axios npm supply chain attack: What every developer needs to know1 April 2026
- MFA for AI agents: Why traditional authentication falls short1 April 2026
- Rainbow table attacks: What they are and how to prevent them1 April 2026
- Top 5 MFA providers for securing your app in 20261 April 2026
- Per-customer encryption keys, and what they actually buy31 March 2026
- The architecture of governable AI agents: Constrain first, observe always31 March 2026
- Logging AI agents into web apps: From cookie hacks to proper OAuth31 March 2026
- March Updates31 March 2026
- Connect your app to GitLab without building OAuth30 March 2026
- Impossible travel: What it is, how it works, and how to defend against it30 March 2026
- The OWASP Top 10 for agentic applications: What developers building with AI agents need to know30 March 2026
- Redirect URIs for local, staging, and production: Secure patterns and anti-patterns27 March 2026
- Scopes vs. claims: What they are, how they differ, and when to use each27 March 2026
- Token replay attacks: What they are, why MFA won't save you, and how to defend against them27 March 2026
- Everything your team needs to know about MCP in 202626 March 2026
- How to validate the JWT aud claim and why it matters25 March 2026
- Data residency is a routing problem before it is a storage one24 March 2026
- Debug JWTs in your browser with the Paycux JWT Debugger24 March 2026
- How to add Sign in with Slack to your app using Paycux24 March 2026
- The developer's guide to authentication security24 March 2026
- MCP's 2026 roadmap makes enterprise readiness a top priority23 March 2026
- Top 5 authentication solutions for secure React Router apps in 202623 March 2026
- x402 vs. Stripe MPP: How to choose payment infrastructure for AI agents and MCP tools in 202623 March 2026
- Azure Entra nested groups and Directory Sync: Limitations and workarounds20 March 2026
- Securing a FastAPI Server with Paycux AuthKit20 March 2026
- Widget Skills: Paycux-powered UIs, generated for your stack20 March 2026
- Common CORS errors and how to fix them19 March 2026
- Pipes MCP: Session-scoped authorization for AI agents19 March 2026
- Agent Experience: Build without leaving your terminal18 March 2026
- How to validate the JWT iss claim and why it matters18 March 2026
- Model Routing vs Tool Routing: How to give your AI agents superpowers18 March 2026
- Making SSO setup something the customer can finish alone17 March 2026
- AuthKit Analytics: Understand user growth at a glance17 March 2026
- Why MiniMax M2.5 is the most popular model on OpenRouter right now17 March 2026
- How to preserve your AI context across devices, outages, and model providers17 March 2026
- Prompt injection attacks: What are they and how to defend against them17 March 2026
- Compression is one of the core patterns of this era of LLMs16 March 2026
- Using Cursor Bugbot to autoreview and fix Claude Code PRs16 March 2026
- Use Excalidraw Skills so your agents can describe themselves16 March 2026
- Multiple apps, one shared authentication layer16 March 2026
- The best thing about using OpenClaw: Constant improvement via ChatOps16 March 2026
- How I dropped my OpenClaw cost of ownership 17x with OpenRouter16 March 2026
- Designing scopes for a server an agent will call13 March 2026
- MCP vs. REST: What's the right way to connect AI agents to your API?13 March 2026
- Best SCIM providers for automated user provisioning in 202612 March 2026
- API security best practices for the age of AI agents11 March 2026
- Scoped credentials for software that acts on your behalf10 March 2026
- The developer’s guide to JWKS10 March 2026
- How to add auth to your Replit app with Paycux10 March 2026
- Create Salesforce leads from your app without building OAuth9 March 2026
- How to add Sign in with Apple to your app using Paycux6 March 2026
- Claude Cowork workshop with Anthropic: Building a complete GTM pipeline in one session5 March 2026
- How to add auth to your Lovable app5 March 2026
- February Updates4 March 2026
- Send Slack notifications from your app without building OAuth4 March 2026
- Writing my first evals4 March 2026
- Can an AI agent set up your product?3 March 2026
- The developer's guide to strong passwords3 March 2026
- Paycux raises $100M Series C, hits $2B valuation2 March 2026
- Building authentication in Rails web applications: The complete guide for 202627 February 2026
- Top 5 authentication solutions for secure Java apps in 202626 February 2026
- Top 5 NextAuth alternatives for secure authentication in 202625 February 2026
- The engineering work hiding inside SOC 2 readiness24 February 2026
- The best authorization platforms for managing AI agent permissions in 202624 February 2026
- How to add Sign in with Vercel to your app using Paycux23 February 2026
- Building authentication in Python web applications: The complete guide for 202620 February 2026
- Top 5 authentication solutions for secure .NET apps in 202619 February 2026
- The cutover hour, written down in advance17 February 2026
- Paycux FGA: The authorization layer for AI agents17 February 2026
- Building authentication in Next.js App Router: The complete guide for 202617 February 2026
- Top 5 authentication solutions for secure Go apps in 202616 February 2026
- Protecting against Login CSRF attacks: How Paycux keeps your users secure13 February 2026
- Paycux vs. BetterAuth vs. Clerk: Which should you choose?13 February 2026
- Top 5 authentication solutions for secure Django apps in 202612 February 2026
- Top 5 authentication solutions for secure FastAPI apps in 202612 February 2026
- Top 5 authentication solutions for secure Flask apps in 202612 February 2026
- Top 5 authentication solutions for secure Laravel apps in 202611 February 2026
- Turning security questionnaires into a maintained asset10 February 2026
- The shift from apps with AI to AI with apps: Why your next app should live inside Claude10 February 2026
- Top 5 authentication solutions for secure Remix apps in 20269 February 2026
- Top 5 authentication solutions for secure Node.js apps in 20266 February 2026
- January Updates30 January 2026
- Top 5 authentication solutions for secure Rails apps in 202630 January 2026
- Why authentication doesn't need to stay local: The new data residency pattern29 January 2026
- Secure MCP Servers in Minutes with XMCP and Paycux AuthKit29 January 2026
- Planning a migration off your own authentication27 January 2026
- MCP Apps are here: Rendering interactive UIs in AI clients27 January 2026
- Integrate Google Drive in your app without OAuth using Paycux Pipes27 January 2026
- Tailscale is building the AI gateway for a world where agents need identity27 January 2026
- Top 5 authentication solutions for secure React apps in 202627 January 2026
- Sync Google Calendar events without OAuth using Paycux Pipes26 January 2026
- Top 5 authentication solutions for secure TanStack Start apps in 202623 January 2026
- Fetch Linear issue data without OAuth using Paycux Pipes22 January 2026
- Top 5 authentication solutions for secure Next.js apps in 202621 January 2026
- Fetch GitHub repo data without OAuth using Paycux Pipes20 January 2026
- How to sync users from Okta to your Laravel app16 January 2026
- Engineering leadership at Paycux: Product, people, and impact15 January 2026
- How to add SSO to your homegrown auth in a day15 January 2026
- Paycux Pipes: Third-party integrations without the headache15 January 2026
- 10 takeaways from AWS re:Invent 202514 January 2026
- Ben Gilbert and David Rosenthal from Acquired on what makes companies last14 January 2026
- Baseten is betting big on open source models14 January 2026
- Browserbase is deleting hundreds of years of busy work14 January 2026
- Ciroos is building AI SREs that can actually fix things14 January 2026
- Cleric is building an AI that actually understands your production outages14 January 2026
- Depot is making builds fast enough for the AI era14 January 2026
- How to handle JWT in JavaScript14 January 2026
- Incident.io is redefining what an incident can be14 January 2026
- Intercom went from skeptics to believers on AI14 January 2026
- Latacora is security for startups without the unicorn hire14 January 2026
- Modal is building AI infrastructure that doesn't get in the way14 January 2026
- PlanetScale is riding the Postgres wave (while still loving MySQL)14 January 2026
- Stedi is making EDI less terrible14 January 2026
- Taylor Otwell built Laravel for himself. Millions of developers followed.14 January 2026
- Tiger Data sees agents as the new developer14 January 2026
- Vercel is watching developers become 10x more productive14 January 2026
- You can vibe code features. You cannot vibe trust.14 January 2026
- Beyond request-response: How MCP servers are learning to collaborate13 January 2026
- What is Private Key JWT: Deep dive into asymmetric client authentication12 January 2026
- Understanding URL-mode elicitation in MCP9 January 2026
- Authorization for RAG at Scale: Why You Shouldn't Sync Every Document8 January 2026
- Customer and user onboarding for real-world B2B SaaS8 January 2026
- Fireworks.ai: The PyTorch Team's Bet on Inference as the New Runtime8 January 2026
- December Updates7 January 2026
- The enterprise infrastructure layer behind successful AI applications7 January 2026
- How MCP Clients Find Your Auth Server (Without You Telling Them)7 January 2026
- Feature Flags as a Change Management Strategy for B2B Apps6 January 2026
2025
- Private Key JWT vs Client Secret: Choosing the right OAuth authentication for confidential clients22 December 2025
- MCP auth for AI agents: How to register a Python OAuth client using CIMD15 December 2025
- Chrome DevTools: Bringing Browser State to Your Coding Agent12 December 2025
- Datadog: SQL Is the New Bash for AI Agents12 December 2025
- MCP Night The Holiday Edition Keynote: MCP Turns One, Joins the Linux Foundation12 December 2025
- Microsoft: MCP Auth Without the Configuration Nightmare12 December 2025
- Supabase: Natural Language to SQL, Holiday Edition12 December 2025
- The Agentic AI Foundation: Competitors Building the AI Standard Together12 December 2025
- Cloudflare: Code Mode Cuts Token Usage by 81%11 December 2025
- Top RBAC providers for multi-tenant SaaS in 202511 December 2025
- Cross App Access (XAA): The enterprise way to govern AI app integrations10 December 2025
- The Linux Foundation Launches the Agentic AI Foundation—MCP Finds Its Permanent Home10 December 2025
- Paycux MCP Night: The Holiday Special10 December 2025
- Dynamic Client Registration (DCR) in MCP: What it is, why it exists, and when to still use it9 December 2025
- Client ID Metadata Documents (CIMD): How OAuth client registration works in MCP8 December 2025
- How AI makes OAuth 2.0 and OIDC non-negotiable for SaaS apps5 December 2025
- Amazon Nova Forge: Custom foundation models are no longer just for tech giants4 December 2025
- Auth0 FGA vs. Paycux FGA: Two Different Approaches to Fine-Grained Authorization4 December 2025
- MCP Async Tasks: Building long-running workflows for AI Agents4 December 2025
- November Updates4 December 2025
- Arcade for AI Agent Security: Features, Pricing, and Alternatives3 December 2025
- The developer’s guide to SaaS multi-tenant architecture3 December 2025
- CIMD vs DCR: The new default for MCP Client Registration in 20252 December 2025
- Duality AI: Building Reality-Grade Digital Twins for AI and Robotics1 December 2025
- FGA : How Paycux is rethinking authorization for the next generation of SaaS1 December 2025
- What is OAuth 2.0?1 December 2025
- How to design an RBAC model for multi-tenant SaaS28 November 2025
- Authorization in Python: Best practices and patterns that won’t bite you later27 November 2025
- MCP 2025-11-25 is here: async Tasks, better OAuth, extensions, and a smoother agentic future26 November 2025
- MCP auth: The difference between a bridge and a backdoor25 November 2025
- The best providers for authenticating AI agents via OAuth and OIDC in 202524 November 2025
- The best SAML providers for B2B SaaS in 202520 November 2025
- One-Time Passwords (OTPs) explained: What they are, how they work, and when to use them19 November 2025
- Paycux partners with Entra Agent ID19 November 2025
- How to handle JWT in Go18 November 2025
- The developer’s guide to SAML authentication17 November 2025
- API Keys vs M2M Applications: Differences, use cases, and how to decide14 November 2025
- The developer’s guide to HTTP error codes12 November 2025
- Obsidian Security for AI Agent Security: Features, Pricing, and Alternatives12 November 2025
- Aim Security vs Paycux: Choosing the Right Agentic Security Platform11 November 2025
- Bedrock Data for AI Agent Security: Features, Pricing, and Alternatives11 November 2025
- Credo AI for Agentic Security: Features, Governance, and Alternatives11 November 2025
- Noma Security vs Paycux: Choosing the Right Platform for Agentic Security11 November 2025
- The hidden costs of open source SSO: Why enterprise readiness requires more than free code11 November 2025
- Zenity for AI Agent Security: Features, Pricing, and Alternatives11 November 2025
- Concentric AI vs Paycux: Data Governance vs Identity for Agentic Security10 November 2025
- Duality for AI Agent Security: Features, Pricing, and Alternatives10 November 2025
- HiddenLayer vs Paycux for agentic security: Choosing the right foundation10 November 2025
- Immuta for AI Agent Security: Features, Pricing, and Alternatives10 November 2025
- Jazz Security for AI Agent Security: Features, Pricing, and Alternatives10 November 2025
- Nightfall AI vs Paycux: Data Protection vs Access Control for Agentic Security10 November 2025
- Relyance AI for AI Agent Security: Features, Pricing, and Alternatives10 November 2025
- Skyflow for AI Agent Security: Features, Pricing, and Alternatives10 November 2025
- Tumult Labs: Differential Privacy for AI Agents10 November 2025
- What is Agnost AI? An MCP server analytics platform10 November 2025
- Why building SCIM is hard10 November 2025
- Haize Labs: AI Safety Testing7 November 2025
- The hidden cost of password sharing and how to prevent it6 November 2025
- Scaling user provisioning with SCIM bulk operations and filtering5 November 2025
- Cerbos for AI Agent Security: Features, Pricing, and Alternatives4 November 2025
- Guardrails AI for AI agent security: Features, pricing, and alternatives4 November 2025
- Keycard for AI Agent Security: Features, Pricing, and Alternatives4 November 2025
- Oso for AI Agent Security: Features, Pricing, and Alternatives4 November 2025
- Pomerium for AI Agent Security: Features, Pricing, and Alternatives4 November 2025
- Protect AI for AI Agent Security: Features, Pricing, and Alternatives4 November 2025
- Session revocation explained: Protect your users, systems, and AI agents4 November 2025
- Straiker for AI Agent Security: Features, Pricing, and Alternatives4 November 2025
- Strata Identity for AI Agent Security: Features, Pricing, and Alternatives4 November 2025
- Astrix Security vs. Paycux: Non-Human Identity Meets Enterprise Authentication3 November 2025
- Clerk vs Paycux: Agent Identity Meets Enterprise Authentication3 November 2025
- Descope for AI Agent Security: Features, Pricing, and Alternatives3 November 2025
- Google Vertex AI vs. Paycux: ML Platform Meets Enterprise Authentication3 November 2025
- How to sync users from Okta to your Python app3 November 2025
- October Updates3 November 2025
- Okta for AI Agent Security: Features, Pricing, and Paycux Alternatives3 November 2025
- OpenAI vs. Paycux: Securing the AI Platform Layer vs. Securing Your Application3 November 2025
- Promptfoo vs. Paycux: Security Testing Meets Enterprise Authentication3 November 2025
- Semgrep for AI Agent Security: Features, Pricing, and Alternatives3 November 2025
- Snyk for AI Agent Security: Features, Pricing, and Alternatives3 November 2025
- Stripe Seat Sync: A simpler way to build seat-based billing with Paycux3 November 2025
- The Future of Agent Identity Is Already Here: Tobin South at ERC31 October 2025
- The Feature You'll Rebuild Three Times: Authorization at Scale: Pavan Kulkarni at ERC31 October 2025
- Understanding SAML Request Signing and Response Encryption31 October 2025
- Beyond the Hype: What Actually Works for Production AI Systems30 October 2025
- CTO Panel: AI is Transforming Engineering Teams Faster Than Expected30 October 2025
- Paycux API Keys: Let your customers build integrations without building the infrastructure30 October 2025
- SCIM for AI: Inside the new IETF draft for agent and agentic application provisioning30 October 2025
- Augment Code: Context Is the New Compiler29 October 2025
- The Bring Your Own Cloud Movement: Nuon's Solution for Enterprise AI Deployment29 October 2025
- When PLG Meets Enterprise: Drew Houston on Building Dropbox from Viral Growth to $2.5B in Revenue29 October 2025
- How to add OAuth to your MCP server29 October 2025
- Metronome's Lightning Demo: Building Enterprise-Ready Monetization in Real Time29 October 2025
- Sentry's Lightning Demo: When AI Meets Error Resolution29 October 2025
- The Productivity Paradox: When AI Tools Make Things Worse Before They Make Them Better28 October 2025
- Security in the Age of AI: Old Problems Meet New Risks28 October 2025
- Inside Paycux27 October 2025
- MCP.shop Demo: How Paycux Powers Identity and Auth for AI Agents27 October 2025
- Michael Grinich's ERC 2025 Opening Keynote: Crossing the Enterprise Chasm in the Age of AI27 October 2025
- Enterprise Ready Conference 2025 Recap22 October 2025
- Service disruption on October 20, 202520 October 2025
- MCP Registry Architecture: A Technical Overview15 October 2025
- LLMs are très bien at localization13 October 2025
- Understanding MFA fatigue attacks: How they work and how to defend against them9 October 2025
- The developer’s guide to MCP auth7 October 2025
- SAML certificates explained: How they work and how to manage them3 October 2025
- How to migrate from Auth0 to Paycux1 October 2025
- AI agent access control: How to manage permissions safely30 September 2025
- September Updates30 September 2025
- Paycux Launch Week Recap: Fall 202529 September 2025
- Paycux Slack App: Real-time visibility into your feature flag changes26 September 2025
- Bring your own email provider to Paycux25 September 2025
- Localization: AuthKit in 90 Languages24 September 2025
- AuthKit for Convex: Zero-configuration authentication for real-time applications23 September 2025
- AuthKit adds support for multiple roles22 September 2025
- Best practices for securing MCP model-agent interactions19 September 2025
- Are CA-signed certificates necessary for SAML security?18 September 2025
- Air-gapping and authentication: How Paycux supports secure & isolated environments17 September 2025
- Paycux Enterprise MCP Hackathon Debrief17 September 2025
- Top 5 Auth0 alternatives in 202516 September 2025
- How to add SSO, MFA, and Passwordless authentication to your .NET app12 September 2025
- What is PKCE and why every OAuth app should use it11 September 2025
- Why OAuth is the right fit for the MCP Registry9 September 2025
- MCP-UI: A Technical Overview of Interactive Agent Interfaces8 September 2025
- MFA best practices8 September 2025
- Product Engineering at Paycux8 September 2025
- From PRD to Prototype in One Prompt: How Notion's MCP Server Transforms Product Development3 September 2025
- MCP Night 2.0 Panel Discussion: The Future of AI Integration3 September 2025
- August Updates2 September 2025
- From Pain Points to Solutions: How VSCode Solved MCP's Biggest Developer Challenges2 September 2025
- The top 3 SCIM providers for 20252 September 2025
- MCP Night 2.0 Demo Recap: How Cursor Users Are Embracing the Model Context Protocol29 August 2025
- MCP Night 2.0 Demo Recap: XMCP Framework - The Fastest Way to Build MCP Servers29 August 2025
- MCP Night 2.0 Demo Recap: Block's Goose - The Layered Tool Pattern29 August 2025
- How to implement “Sign out everywhere”29 August 2025
- MCP Night 2.0 Demo Recap: Mux28 August 2025
- MCP-UI: Breaking the Text Wall in AI Interactions27 August 2025
- OAuth 2.0 vs OAuth 2.1: What changed, why it matters, and how to upgrade27 August 2025
- The complete guide to MCP security: How to secure MCP servers & clients22 August 2025
- How Paycux solved enterprise auth for MCP servers21 August 2025
- The hidden cost of bad sign-ups (and how to stop them)20 August 2025
- How to add auth to your Apple app in order to be listed in the Apple Store in 202519 August 2025
- MCP vs. A2A: Which AI agent protocol should you use?18 August 2025
- The best 5 SSO providers to power your SaaS app in 202515 August 2025
- How to integrate Okta SAML SSO and SCIM in one day14 August 2025
- How to support any SAML or OIDC identity provider with only one integration13 August 2025
- How to enable B2B SaaS features for specific customers12 August 2025
- How to revoke sessions and sign users out everywhere with the Paycux Sessions API12 August 2025
- Designing the AI-Proof Interview11 August 2025
- Introduction to MCP authentication8 August 2025
- How to secure your AI app from fraud7 August 2025
- Paycux MCP Night 2.0 Recap7 August 2025
- Understanding MCP features: Tools, Resources, Prompts, Sampling, Roots, and Elicitation6 August 2025
- MFA vs SSO: Why enterprises need both for stronger security5 August 2025
- OIDC vs SAML: How a two-decade-old protocol still dominates identity federation4 August 2025
- How well are reasoning LLMs performing? A look at o1, Claude 3.7, and DeepSeek R14 August 2025
- How to sync users from Google Workspace to a Ruby on Rails app using Paycux1 August 2025
- First-Class Paycux Auth Support Comes to Convex31 July 2025
- July Updates31 July 2025
- Scaling B2B SaaS with SCIM: Automating user provisioning for enterprise growth31 July 2025
- Anthropic’s Computer Use versus OpenAI’s Computer Using Agent (CUA)30 July 2025
- How to add auth to your Go CLI using Paycux30 July 2025
- What are SAML assertions?30 July 2025
- Generative AI and enterprise identity fraud: How to defend against AI-powered impersonation attacks29 July 2025
- Vibecoding a complex combobox component29 July 2025
- MFA vs. Passwordless authentication28 July 2025
- How to add auth to your Python CLI using Paycux25 July 2025
- The complete guide to user management for B2B SaaS25 July 2025
- How backup MFA codes work: Your safety net for Two-Factor Authentication24 July 2025
- How to Make Your Lovable App Enterprise Ready24 July 2025
- Enterprise AI Agent Playbook: What Anthropic and OpenAI Reveal About Building Production-Ready Systems23 July 2025
- UX best practices for MFA23 July 2025
- Enterprise ready MCP servers: How to secure, scale, and deploy for real-world AI22 July 2025
- Why most enterprise AI projects fail — and the patterns that actually work22 July 2025
- SAML explained simply: What is it and how it works21 July 2025
- XMCP + AuthKit: The Fastest Way to Secure MCP Tools and Servers21 July 2025
- Identity & SSO compliance: Why it matters and how to get it right17 July 2025
- How to add MFA to your homegrown auth using Paycux16 July 2025
- OAuth 2.0 Authorization Code Grant: What it is & how it works16 July 2025
- What are MITM attacks & how to prevent them15 July 2025
- Understanding Roots in Model Context Protocol (MCP)14 July 2025
- What is an AI agent?14 July 2025
- How to add auth to your Node.js CLI using Paycux11 July 2025
- Agentic AI Examples10 July 2025
- From blocking bots to optimizing for LLMs: How the web flipped its script10 July 2025
- Why SMS is not a secure Multi-Factor Authentication (MFA) method9 July 2025
- How Single Sign-On (SSO) works – and how to add it to your app8 July 2025
- The Vercel MCP + Paycux AuthKit template: deploy secure MCP servers globally in 5 minutes8 July 2025
- How B2B auth is different than Consumer auth7 July 2025
- How to build agent-friendly products3 July 2025
- What is the difference between causal, predictive, generative, and agentic AI?2 July 2025
- How to make your site LLM-friendly without inviting abuse1 July 2025
- How to build AI agents30 June 2025
- June Updates30 June 2025
- Authenticate CLI tools seamlessly with OAuth Device Flow27 June 2025
- Introducing AuthKit Add-ons26 June 2025
- Enterprise Ready authentication for Supabase, powered by Paycux25 June 2025
- Introducing Feature Flags: Enterprise Ready feature management for B2B apps24 June 2025
- Introducing custom CSS for AuthKit: Unlock full styling flexibility23 June 2025
- MCP elicitation: Request user input at runtime20 June 2025
- Scaling up: How to launch your product with an Enterprise Plan19 June 2025
- Common pitfalls of MFA and how to avoid them17 June 2025
- MCP Authorization in 5 easy OAuth specs16 June 2025
- Identity for AI: Who Are Your Agents and What Can They Do?13 June 2025
- Query caching using Nest.js and Typeorm13 June 2025
- What does Enterprise Ready mean for AI?13 June 2025
- Introducing the Paycux MCP Documentation Server12 June 2025
- SCIM: The hidden growth engine behind tools like Slack and Figma11 June 2025
- AI isn't magic. Context chaining is.10 June 2025
- Why AI still needs you: Exploring Human-in-the-Loop systems6 June 2025
- How AI agents connect to systems: A technical guide5 June 2025
- How to implement an organization switcher with Paycux and React4 June 2025
- Understanding bearer tokens: What are they and how to use them securely3 June 2025
- May updates2 June 2025
- Securing AI agents: A guide to authentication, authorization, and defense2 June 2025
- How MCP servers work: Components, logic, and architecture30 May 2025
- OpenAI's Codex wants to become your AI coworker29 May 2025
- What is free trial abuse -- and how can you stop it?29 May 2025
- Device Authorization Grant: Solving OAuth for screens without keyboards28 May 2025
- Flipping the flow: How MCP sampling lets servers ask the AI for help23 May 2025
- Why building your own BYOK is a trap22 May 2025
- Email deliverability troubleshooting guide22 May 2025
- Your codebase is now addressable: Codex, Jules, and the Rise of agentic parallel coding20 May 2025
- Agno: The agent framework for Python teams20 May 2025
- Why implementing SAML from scratch is a terrible idea20 May 2025
- Security threats in SPAs and how to defend against them19 May 2025
- How to sync users from Entra ID to your app using Node and Paycux15 May 2025
- MCP Night 2025: When the AI infra community overflowed the Exploratorium in San Francisco14 May 2025
- OAuth 2.1: What’s new, what’s gone, and how to migrate securely14 May 2025
- Secure by design: How engineers should build and consume APIs13 May 2025
- What is NIST and why should developers care?12 May 2025
- Introducing RFC 9728: Say hello to standardized OAuth 2.0 resource metadata8 May 2025
- Diagnosing SAML assertion failures: A step-by-step debugging guide2 May 2025
- On-premises and hybrid authentication: Challenges and best practices1 May 2025
- April Updates30 April 2025
- The hidden pitfalls of SAML metadata: How to avoid downtime30 April 2025
- Mastra.ai Quickstart - How to build a TypeScript agent in 5 minutes or less29 April 2025
- DBConnection pooling deep dive28 April 2025
- In-Memory Distributed State with Delta CRDTs28 April 2025
- oRPC: OpenAPI Remote Procedure Call for Type-Safe APIs28 April 2025
- Why your app needs refresh tokens—and how they work23 April 2025
- IBM’s Agent Communication Protocol (ACP): A technical overview for software engineers22 April 2025
- SAML's signature problem: It’s not you, it’s XML22 April 2025
- Agent to agent, not tool to tool: an engineer’s guide to Google’s A2A protocol18 April 2025
- From 1.0.0 to 2025.4: Making sense of software versioning17 April 2025
- Paycux + Cloudflare MCP: Plug and Play Auth for Agentic AI Builders16 April 2025
- ArkType: A high-performance runtime type validation for TypeScript14 April 2025
- How to handle JWT in Python14 April 2025
- Prisma ORM for TypeScript - A technical primer10 April 2025
- Security risks of iframes: Protecting your app from potential attacks10 April 2025
- HMAC vs. RSA vs. ECDSA: Which algorithm should you use to sign JWTs?8 April 2025
- Smithery AI: A central hub for MCP servers8 April 2025
- Generative AI at the edge with Cloudflare Workers7 April 2025
- Securing your app with Risk-Based Authentication and AI4 April 2025
- How to build a game-building agent system with CrewAI3 April 2025
- Top Ruby gems for authentication & authorization2 April 2025
- How to build Login with LinkedIn using Python and Paycux1 April 2025
- How to build Login with Slack using Node and Paycux31 March 2025
- March Updates31 March 2025
- Credential stuffing vs. brute force attacks: Key differences and how to stop them28 March 2025
- How to build Login with GitLab using Node and Paycux28 March 2025
- How to build Login with LinkedIn using Node and Paycux27 March 2025
- How to choose the right authorization model for your SaaS26 March 2025
- Zod for TypeScript: A must-know library for AI development26 March 2025
- Advice for coding with AI25 March 2025
- Beyond the basics: Why device fingerprinting is mission-critical in 202525 March 2025
- How AI Agents authenticate and access systems25 March 2025
- Paycux, Next.js, and CVE-2025-2992725 March 2025
- An introduction to WebAuthn24 March 2025
- n8n: The workflow automation tool for the AI age24 March 2025
- New widgets available for user profiles and organization switching21 March 2025
- New enterprise login integrations in AuthKit20 March 2025
- Custom Metadata, External ID, and JWT Templates19 March 2025
- How to deploy Laravel apps with enterprise-ready authentication18 March 2025
- Paycux Vault: Advanced Encryption for Sensitive Data18 March 2025
- Getting Started with Claude Desktop and custom MCP servers using the TypeScript SDK17 March 2025
- Paycux Connect17 March 2025
- SAMLStorm: Critical Authentication Bypass in xml-crypto and Node.js libraries14 March 2025
- GAIA Benchmark: evaluating intelligent agents13 March 2025
- Introducing Manus: The general AI agent13 March 2025
- The ABCs of token security: JWS, JWE, JWK, and JWKS explained13 March 2025
- Defending OAuth: Common attacks and how to prevent them12 March 2025
- Composio.dev overview11 March 2025
- What are Cursor Rules?11 March 2025
- Spot the bots: How to track malicious activity with JavaScript tagging10 March 2025
- When database security is not enough: How the cloud makes application-level encryption a must7 March 2025
- Identity tokens vs Access tokens: understanding the key differences7 March 2025
- What is Claude Code? An agentic developer tool7 March 2025
- February Updates6 March 2025
- OAuth best practices: We read RFC 9700 so you don’t have to6 March 2025
- FGA vs ABAC: Understanding the differences5 March 2025
- JWT storage 101: How to keep your tokens secure4 March 2025
- How it felt to reach Product-market fit (PMF) at Paycux—and what no one tells you3 March 2025
- How to add granular permissions to your API using OAuth scopes28 February 2025
- How to add custom claims to JWTs27 February 2025
- Tenant isolation in multi-tenant systems: What you need to know27 February 2025
- What is the aud claim in identity, authentication, and authorization?27 February 2025
- Context is king: tools for feeding your code and website to LLMs26 February 2025
- OAuth 2.0 and OpenID Connect: The evolution from authorization to identity26 February 2025
- Securing AI agents: authentication patterns for Operator and computer using models26 February 2025
- What Is API Authentication? A guide to OAuth 2.0, JWT, and key methods26 February 2025
- Identity federation vs identity delegation24 February 2025
- How to stop bots with honeypots21 February 2025
- AI agents are taking over: How autonomous software changes research and work20 February 2025
- How encryption works in a Data Vault using EKM20 February 2025
- The best feature flag providers for apps in 202520 February 2025
- What is the difference between Radix and shadcn-ui?20 February 2025
- Session management best practices19 February 2025
- Relationship-based vs policy-based authorization: what's the difference and how do they work together?18 February 2025
- EKM vs KMS: An introduction to key management17 February 2025
- Top AI Agent frameworks and platforms in 202514 February 2025
- RBAC best practices13 February 2025
- What is Arcade.dev? An LLM tool calling platform13 February 2025
- How to build RBAC with Paycux and Node12 February 2025
- The battle against bots: How to detect and stop them11 February 2025
- Scaling up: Why Fine-Grained Authorization is key as your product moves upmarket10 February 2025
- January Updates6 February 2025
- Which auth providers support SCIM?6 February 2025
- Passwordless authentication: your options explained31 January 2025
- Email deliverability and spam prevention: why your emails aren’t getting delivered and how to fix it30 January 2025
- How to run DeepSeek locally29 January 2025
- What is Authentik?28 January 2025
- Defending against bad actors: Paycux Radar vs Castle vs Auth0 vs Stytch vs Arcjet27 January 2025
- Breaking the AI Mold: China's DeepSeek-R1 pushes local and open AI forward23 January 2025
- Shadcn-ui: What is it, and why do you care?23 January 2025
- What is Ente Auth?23 January 2025
- Google OAuth vulnerability can expose sensitive data of failed startups22 January 2025
- How to build SAML SSO with Paycux, JumpCloud, and Node21 January 2025
- Understanding Zero Trust security20 January 2025
- How Paycux Radar does rate limiting with device fingerprinting17 January 2025
- How do you know when you’ve hit product-market fit?16 January 2025
- How Paycux Radar really works16 January 2025
- How Paycux Radar's bot detection works16 January 2025
- How to build SAML SSO with Paycux, Okta, and Python15 January 2025
- How to build SAML SSO with Paycux, Okta, and Ruby14 January 2025
- How to build a user management dashboard with Paycux and Node13 January 2025
- How to implement row-level security with Paycux FGA and Postgres: tutorial and code10 January 2025
- How to build SAML SSO with Paycux, Okta, and Go9 January 2025
- How to build Log in with Google using Go and Paycux7 January 2025
- AuthQuake: Microsoft's MFA system vulnerable to TOTP brute force attack3 January 2025
- How to build SAML SSO with Paycux, Entra ID, and Node3 January 2025
- We shipped our auth server to your browser with WASM. Here's how it's going3 January 2025
- How to build Log in with GitHub using Go and Paycux2 January 2025
2024
- December Updates31 December 2024
- How to build SAML SSO with Paycux, Okta, and Node31 December 2024
- The 5 best ABAC solutions for your SaaS in 202423 December 2024
- The 10 best RBAC open-source solutions in 202420 December 2024
- Seamless onboarding with the Paycux Admin Portal13 December 2024
- Auth0 SSO: Is it worth the high cost?12 December 2024
- Auth0 vs. Cognito vs. Paycux: Which is best in 2024?12 December 2024
- The 5 best user management software tools in 202412 December 2024
- Clerk pricing: How it works and compares to Paycux12 December 2024
- FGA’s meaning: definition, benefits, and real-world examples12 December 2024
- November Updates12 December 2024
- Paycux vs. Auth0 vs. Clerk: Which should you choose?12 December 2024
- Paycux vs. Auth0 vs. Frontegg: Which is best?12 December 2024
- Paycux vs. Auth0 vs. Stytch: Which is best?12 December 2024
- 5 best Auth0 alternatives in 2024: head-to-head11 December 2024
- The 5 best Clerk alternatives in 202411 December 2024
- RBAC vs. ACL: what's the difference and how do they work together?11 December 2024
- The 5 best Frontegg alternatives in 202411 December 2024
- 6 best user management services for 202411 December 2024
- The ultimate guide to user management in 202411 December 2024
- Access management: What it is and how it works10 December 2024
- Why Google Zanzibar shines at building authorization10 December 2024
- Failed authentication events: use cases and how-to6 December 2024
- How to build document access control with S3, Paycux FGA, and Lambda authorizers5 December 2024
- How to map role data from identity providers to roles in your app25 November 2024
- Entitlements sync between Stripe and your app22 November 2024
- Next.js B2B Starter Kit — fast-track your SaaS app from 0 to 122 November 2024
- Actions — customize AuthKit behavior in real-time21 November 2024
- Widgets — ready-made components for complete enterprise features21 November 2024
- How to build browser-based OAuth into your CLI with Paycux19 November 2024
- Introducing Radar — real-time protection against bots, fraud, abuse19 November 2024
- Passkeys, a safer and simpler alternative to passwords18 November 2024
- SCIM challenges: navigating the idiosyncrasies of different providers15 November 2024
- How SAML certificate renewal works - and what happens when it fails14 November 2024
- How to add social logins in your app with Paycux11 November 2024
- How SCIM deprovisioning works8 November 2024
- ReBAC vs RBAC: What's the difference and which should you choose?8 November 2024
- Top 5 Google Zanzibar open-source implementations in 20248 November 2024
- What is Universal Login and how does it work?8 November 2024
- What is an authentication token?7 November 2024
- What is the Okta Integration Network?7 November 2024
- How to add SSO to your app with Paycux6 November 2024
- How to secure RAG applications with Fine-Grained Authorization: tutorial with code5 November 2024
- Model your B2B SaaS with organizations1 November 2024
- What is the Azure AD or Entra ID app gallery and why should you care?31 October 2024
- The easiest way to implement SAML in any app30 October 2024
- Auth0 pricing: how it works and compares to Paycux23 October 2024
- Ruby SAML CVE-2024-45409: As bad as it gets and hiding in plain sight23 October 2024
- X.509 certificates: what they are & how to get one22 October 2024
- What is Enterprise SSO and why does it matter?15 October 2024
- September Updates1 October 2024
- Session management for frontend apps with AuthKit27 September 2024
- Secure authentication for frontend apps with PKCE20 September 2024
- What are fine-grained permissions?19 September 2024
- OAuth vs. OAuth 2: differences + what you need to know18 September 2024
- Everything you need to know about the nOAuth Microsoft Azure AD vulnerability16 September 2024
- The five different types of authentication16 September 2024
- Coarse-grained vs. fine-grained access control: which should you use?13 September 2024
- August Updates4 September 2024
- Top user management features for SaaS + implementation tips30 August 2024
- 7 Attribute-Based Access Control (ABAC) examples29 August 2024
- What is granular control? Benefits + examples27 August 2024
- 8 Role-Based Access Control (RBAC) examples in action23 August 2024
- Build vs. buy part II: ROI comparison between homegrown and pre-built solutions22 August 2024
- What is data access control?21 August 2024
- The 5 best Clerk alternatives in 202421 August 2024
- The 5 access control models: benefits + which to choose20 August 2024
- How to implement access control: step by step19 August 2024
- Top 7 API authentication methods and how to use them16 August 2024
- RBAC vs IAM: what's the difference and how do they work together?15 August 2024
- RBAC vs. FGA: What's the difference and how do they work together?13 August 2024
- The ultimate guide to OIDC providers (or building your own)12 August 2024
- July Updates1 August 2024
- Build vs buy part I: complexities of building SSO and SCIM in-house30 July 2024
- Introducing Role-Based Access Control (RBAC) for AuthKit23 July 2024
- June Updates1 July 2024
- Lessons in safe identity linking28 June 2024
- From four to five 9s of uptime by migrating to Kubernetes27 June 2024
- Why you should rethink your webhook strategy26 June 2024
- Auth in middleware, or how I learned to stop worrying and love the edge25 June 2024
- Migrating to Next.js App Router with zero downtime24 June 2024
- The 3 best alternatives to SAML SSO18 June 2024
- Single-tenant vs multi-tenant: which is best for your SaaS app?18 June 2024
- SSO vs OAuth: Key Differences You Must Know18 June 2024
- May Updates31 May 2024
- You Need a SCIM Server — Here’s the Easiest Way to Create One30 May 2024
- What is IDaaS and What is it Used For?28 May 2024
- SaaS authentication: the best method(s) to use for your app14 May 2024
- What is multi-tenancy? Pros, cons, and best practices8 May 2024
- What is identity provisioning and how does it work?3 May 2024
- April Updates1 May 2024
- Top 5 open source SSO solutions: pros, cons, and key tips1 May 2024
- What does deprovisioning mean? Top benefits and IdP strategies5 April 2024
- March Updates25 March 2024
- Launch Week Day 5: Impersonation22 March 2024
- Launch Week Day 4: Cloudflare Workers & Edge support21 March 2024
- Launch Week Day 3: Stream Paycux events to Datadog20 March 2024
- Launch Week Day 2: Roles19 March 2024
- Launch Week Day 1: Sessions18 March 2024
- OAuth vs OpenID: Understanding the Key Differences18 March 2024
- LDAP vs. SSO explained: key differences and use cases7 March 2024
- Active Directory SCIM - Can you sync Active Directory users and groups with SCIM?6 March 2024
- February Updates29 February 2024
- Introducing Test SSO, an easier way to integrate SSO into your app26 February 2024
- SCIM security: is the user provisioning protocol secure?23 February 2024
- SCIM for ADFS21 February 2024
- Creating stronger passwords with AuthKit8 February 2024
- What is Automated Provisioning?7 February 2024
- SAML vs SSO: Are They The Same Thing?2 February 2024
- SSO vs SSL: Does SSO work over SSL?2 February 2024
- SCIM protocol explained1 February 2024
- January Product Updates31 January 2024
- What is a SCIM Connector and Which One Should You Use?30 January 2024
- 5 examples of SCIM implementation24 January 2024
- The Top 3 SCIM Providers for 202419 January 2024
- What is a Directory Service?12 January 2024
- LDAP vs Active Directory: Differences + What You Need to Know8 January 2024
- Directory Sync: how to provision users into your SaaS app from Microsoft Entra, Google Workspace and more3 January 2024
2023
- 2023 Product Updates Recap29 December 2023
- SSO vs Federation: Key Differences + How They Work Together26 December 2023
- SAML 2.0 vs SAML 1.1 - What’s the difference between the SAML versions?22 December 2023
- SCIM vs SAML: What each does and how to use them together22 December 2023
- OAuth and JWT: How To Use Together + Best Practices18 December 2023
- November Product Updates5 December 2023
- What is seamless SSO by Microsoft? Everything you need to know5 December 2023
- Introducing AuthKit and User Management APIs28 November 2023
- What is a SCIM integration and should you build or buy it?16 November 2023
- The Best 5 SSO Providers to power your SaaS app in 202416 November 2023
- SCIM vs. LDAP: Key Differences + Which To Use13 November 2023
- SAML vs. LDAP: How to Choose The Right Protocol8 November 2023
- IdP vs. SP: What is a service provider and an identity provider?6 November 2023
- How to use SCIM with SSO: A Developer's Guide31 October 2023
- October Product Updates31 October 2023
- SFTP Integrations vs. Native APIs for User Provisioning30 October 2023
- Passport.js to Paycux migration guide25 October 2023
- What is SCIM Provisioning? Everything You Need to Know in 5 Minutes10 October 2023
- What is an Identity Provider?5 October 2023
- September Product Updates29 September 2023
- SCIM complexity explained: tackle group fragmentation14 September 2023
- August Product Updates31 August 2023
- Single Sign-On: Acronyms Demystified1 June 2023
2022
- Paycux 2022 Fall Release8 December 2022
- The Founder's Guide to Developer-led Growth23 November 2022
- Paycux 2022 Spring Release Recap11 July 2022
- Paycux raises $80m in Series B financing, acquires Modulz1 June 2022
- Paycux is Carbon Neutral13 May 2022
- Getting Started with the Paycux Multi-Factor Authentication API4 April 2022
- Paycux 2022 Winter Release Recap23 March 2022
- Frictionless Enterprise Customer Onboarding Using the Paycux Admin Portal28 February 2022
2021
- Directory Sync now maps custom attributes without custom code28 October 2021
- Can my app support SSO and password-based logins?19 October 2021
- Build vs. Buy: 5 Questions to Ask When You Need to Offer SSO or Directory Sync30 September 2021
- How to test Paycux webhooks locally with ngrok29 September 2021
- SP-initiated vs. IdP-initiated SSO: key differences explained23 September 2021
- How Our Engineering Team Communicates Asynchronously Through Writing21 September 2021
- What makes a good changelog?27 August 2021
- 5 lessons we learned adding dark mode to Paycux12 August 2021
- A Developer’s Guide to One-Time Passwords (OTPs)28 June 2021
- Optional Stacking in TypeScript11 May 2021
- 3 Approaches to Add Enterprise SSO to Your App28 April 2021
- A Developer’s Guide To Headless CMSs10 March 2021
- Paycux raises $15M to build “Stripe for enterprise-ready features”10 March 2021
- 9 components of great developer and API documentation17 February 2021
- How Zendesk used enterprise features to grow from $1 million to $1 billion in 12 years15 February 2021
2020
- A Guide to Enterprise Sales for Early-stage Founders23 December 2020
- RBAC vs. ABAC: What is the difference between access control models?23 December 2020
- How Twilio’s developer-led business model enabled a shift to enterprise sales23 December 2020
- User provisioning: Use it to increase efficiency and security23 December 2020
- What does federated mean in search, identity, and databases?23 December 2020
- How do magic links work and why should you use them?21 December 2020
- Paycux Fall Release Event Recap14 December 2020
- Paycux Technical Content Style Guide18 November 2020
- Authentication Protocols: Your Guide to the Basics14 October 2020
- How to build a webhook: guidelines and best practices4 October 2020
- Paycux Summer Release Event Recap24 September 2020
- A developer’s history of authentication5 September 2020
- Fun with SAML SSO vulnerabilities and footguns1 September 2020
- How Dropbox used land-and-expand to move upmarket and close big enterprise customers18 August 2020
- The Developer’s Guide to Audit Logs / SIEM27 July 2020
- Slack’s EKM and enterprise features won big clients6 July 2020
Ship the enterprise features, keep the afternoon
Everything we write about here is something the platform already does for you — sign-in, SSO, provisioning, roles and an audit trail behind one API.