Blog
Clear explanations and practical notes on identity and security.
Latest
-
Passkeys Won. Your Rollout Probably Didn't
A deep dive into passkeys, how they work, and implementation best practices.
-
Your API Doesn't Know Who Guards It (And Why That's a Problem)
Sometimes, your API needs to know where to point requests so they can authenticate. This is crucial for proper authentication in the AI era.
-
CIMD vs. DCR - Which One Should Register Your Agents?
DCR was the answer to "how can we let a client register itself". CIMD is the answer to "what happens when that client talks to ten thousand servers it's never met."
-
Why Token Exchange Is the Most Underrated Grant Type in OAuth
HOW ARE WE NOT TALKING ABOUT THIS MORE
-
OAuth Tokens
A deep dive into OAuth tokens, their types and uses.
-
Decentralized Identities
Your identity doesn't belong to you.. Yet.
-
Authentication and Authorization
Authentication vs. Authorization explained with examples.
-
When to use PKCE
PKCE is not "OAuth for public clients." It's what OAuth should have been all along.
-
The Emerging Third Pillar of IAM
There's a third pillar of IAM emerging, and it's all anyone seems to be capable of talking about anymore, whether they realize it or not.
-
SCIM Is Not What You Think It Is
Most people who've heard of SCIM describe it as "the protocol that syncs users." That's not wrong, exactly. But it's incomplete enough to cause real problems when you're building a provisioning pipeline and suddenly wondering why your app has ghost accounts, delayed deprovisioning, and a sync that only kind of works.
-
What is Digital Identity? A Beginners Guide
Welcome to Identity Explained. Learn what digital identity is, why it matters in 2026, and how to protect your online presence. Start here.