WorkOS Blog
https://workos.com
Developer APIs/SDKs for Enterprise Ready features like Single Sign-On, Directory Sync, Audit Logging, and more. Get started for free.
フィード

Agent to agent, not tool to tool: an engineer’s guide to Google’s A2A protocol
WorkOS Blog
Think of MCP as “plug this model into my data” and A2A as “now let several specialised models talk to each other.”
1日前

From 1.0.0 to 2025.4: Making sense of software versioning
WorkOS Blog
Confused by versioning? This guide breaks down the top strategies to help you pick the right one, keeping your project organized and your users in the loop.
2日前

MCP, ACP, A2A, Oh my!
WorkOS Blog
Let’s explore the MCP, ACP and A2A protocols, understand what they do, and highlight how they differ and complement one another.
3日前

WorkOS + Cloudflare MCP: Plug and Play Auth for Agentic AI Builders
WorkOS Blog
Until now, plugging your existing user authentication system into MCP servers was tricky. That’s where WorkOS and Cloudflare step in.
3日前

ArkType: A high-performance runtime type validation for TypeScript
1

WorkOS Blog
ArkType is a TypeScript-first runtime validation library built to erase the boundary between static type safety and runtime enforcement.
5日前

How to handle JWT in Python
WorkOS Blog
Everything you need to know to implement and validate JWTs securely in Python — from signing to verifying with JWKS, with code examples and best practices throughout.
5日前

Prisma ORM for TypeScript - A technical primer
WorkOS Blog
Prisma is one of the most popular Object-Relational Mappers (ORMs) in the TypeScript/JavaScript ecosystem due to its robust type-safety guarantees and seamless integration with frameworks like Next.js.
9日前

Security risks of iframes: Protecting your app from potential attacks
1

WorkOS Blog
Iframes might seem convenient, but they come with serious security risks like XSS, session hijacking, and phishing. This article breaks down why iframes can put your site at risk and how to protect it.
9日前

Smithery AI: A central hub for MCP servers
WorkOS Blog
Smithery AI is a registry and management platform for Model Context Protocol (MCP) servers.
11日前

HMAC vs. RSA vs. ECDSA: Which algorithm should you use to sign JWTs?
WorkOS Blog
Confused about which algorithm to use for signing JWTs? We analyze everything about HMAC, RSA, and ECDSA—so you can choose the perfect algorithm for your security needs.
11日前

Generative AI at the edge with Cloudflare Workers
WorkOS Blog
Large language models are reshaping how we build apps—but is your infrastructure ready for them?
12日前

Securing your app with Risk-Based Authentication and AI
WorkOS Blog
Learn how Risk-Based Authentication (RBA) and AI can transform your app’s security, with best practices and insights to protect against evolving threats.
15日前

How to build a game-building agent system with CrewAI
WorkOS Blog
A hands-on guide with patterns, agents, and executable examples
16日前

Top Ruby gems for authentication & authorization
WorkOS Blog
Looking to secure your Ruby on Rails app? Discover the top gems for authentication and authorization that will protect your users. From seamless sign-ins to granular user permissions, these gems have got you covered.
17日前

How to build Login with LinkedIn using Python and WorkOS
WorkOS Blog
Step-by-step tutorial that walks you through the necessary steps to add Login with LinkedIn to your app using Python and WorkOS.
18日前

How to build Login with Slack using Node and WorkOS
WorkOS Blog
Step-by-step tutorial that walks you through the necessary steps to add Login with Slack to your app using Node and WorkOS.
19日前

How to build Login with GitLab using Node and WorkOS
WorkOS Blog
Step-by-step tutorial that walks you through the necessary steps to add Login with GitLab to your app using Node and WorkOS.
22日前

Credential stuffing vs. brute force attacks: Key differences and how to stop them
WorkOS Blog
Learn how credential stuffing and brute force attacks work and how you can defend your systems with advanced protection tools like WorkOS Radar.
22日前

How to build Login with LinkedIn using Node and WorkOS
WorkOS Blog
Step-by-step tutorial that walks you through the necessary steps to add Login with LinkedIn to your app using Node and WorkOS.
23日前

How to choose the right authorization model for your SaaS
WorkOS Blog
Not sure which authorization model is best for your SaaS app? Our latest article breaks down the top approaches—from simple roles to Fine-Grained Authorization—helping you choose the right fit for your app's security and user management.
24日前

Zod for TypeScript: A must-know library for AI development
WorkOS Blog
Ever wondered why one TypeScript validation library keeps appearing in every major AI platform's documentation?
24日前

WorkOS, Next.js, and CVE-2025-29927
WorkOS Blog
Over the weekend, security researchers responsibly disclosed CVE-2025-29927, a vulnerability in Next.js that allows an attacker to bypass Next.js middleware entirely.
25日前

Advice for coding with AI
WorkOS Blog
More folks are picking up coding than ever before thanks to advancements in AI. Here are the top tips for ensuring a smooth experience.
25日前

How AI Agents authenticate and access systems
WorkOS Blog
The rise of AI agents creates a fundamental tension in system design. On one hand, these agents need frictionless access to be effective; on the other, security demands robust controls and limitations.
25日前

Beyond the basics: Why device fingerprinting is mission-critical in 2025
WorkOS Blog
This article explores what happens when fingerprinting goes beyond the basics—how companies use it, how to stay privacy-compliant, and what’s next.
25日前

An introduction to WebAuthn
WorkOS Blog
Learn what WebAuthn is, how it works, its benefits, its challenges, and how you can implement it in your app.
1ヶ月前

n8n: The workflow automation tool for the AI age
WorkOS Blog
As a self-hostable, open-source automation platform, n8n lets you orchestrate logic, connect services, and scale pipelines with minimal boilerplate.
1ヶ月前

New widgets available for user profiles and organization switching
WorkOS Blog
We just released four new widgets to make your life easier: user profile, user sessions, user security, and organization switcher. They are now available for free to all AuthKit customers.
1ヶ月前

New enterprise login integrations in AuthKit
WorkOS Blog
With AuthKit enterprise logins are now easier than ever. We are announcing the addition of key B2B login providers, like LinkedIn, Slack, Xero, and more, giving your users seamless access to your platform with the credentials they already use.
1ヶ月前

Custom Metadata, External ID, and JWT Templates
WorkOS Blog
Expand your WorkOS integration by customizing attributes on users, orgs, and session tokens.
1ヶ月前

WorkOS Vault: Advanced Encryption for Sensitive Data
WorkOS Blog
Discover how Vault makes protecting sensitive data easier, faster, and more cost-effective—without the headache.
1ヶ月前

How to deploy Laravel apps with enterprise-ready authentication
WorkOS Blog
Learn how to set up a Laravel 12 project with WorkOS AuthKit and deploy it seamlessly to Laravel Cloud, leveraging zero-config hosting and enterprise-grade authentication features.
1ヶ月前

Getting Started with Claude Desktop and custom MCP servers using the TypeScript SDK
WorkOS Blog
The Model Context Protocol (MCP) is an open specification that simplifies connecting AI models (like Claude) to external tools and data sources.
1ヶ月前

WorkOS Connect
WorkOS Blog
Enable 3rd-party authentication via “Sign in with [Your App],” Identity Delegation, and Machine to Machine tokens.
1ヶ月前

SAMLStorm: Critical Authentication Bypass in xml-crypto and Node.js libraries
WorkOS Blog
Any service using xml-crypto or a Node.js SAML implementation using it, should update immediately to the latest version. WorkOS customers are safe and were not impacted.
1ヶ月前

GAIA Benchmark: evaluating intelligent agents
WorkOS Blog
The GAIA (“Generalized AI Agent” benchmark) helps us evaluate AI agent performance across complex tasks
1ヶ月前

Introducing Manus: The general AI agent
WorkOS Blog
Manus is a fully autonomous AI system designed to run asynchronously in the cloud—no repeated prompts, no babysitting.
1ヶ月前

The ABCs of token security: JWS, JWE, JWK, and JWKS explained
WorkOS Blog
Confused by all the token jargon? This article simplifies JWS, JWE, JWK, and JWKS, showing you how each one ensures your data stays secure and trustworthy.
1ヶ月前

Defending OAuth: Common attacks and how to prevent them
WorkOS Blog
OAuth vulnerabilities can be tricky, but we’re here to help! Learn about common attacks and how to protect your app with simple tips from RFC 9700.
1ヶ月前

Composio.dev overview
WorkOS Blog
Composio.dev is a developer-focused integration platform that simplifies how AI agents and large language models (LLMs) connect with external applications and services.
1ヶ月前

What are Cursor Rules?
WorkOS Blog
Cursor Rules are instructions or system prompts passed to the large language models (LLMs) that Cursor uses. Learn how to leverage them effectively.
1ヶ月前

Spot the bots: How to track malicious activity with JavaScript tagging
WorkOS Blog
Tired of bots wreaking havoc on your website? Learn how JavaScript tagging can help you track suspicious behavior and stop malicious activity in its tracks.
1ヶ月前

When database security is not enough: How the cloud makes application-level encryption a must
WorkOS Blog
Learn why traditional database encryption just doesn’t cut it anymore and why application-level encryption is the real hero for data security.
1ヶ月前

What is Claude Code? An agentic developer tool
WorkOS Blog
Anthropic’s release of Claude Code, built on the 3.7 Sonnet model, marks a significant step in AI-assisted development.
1ヶ月前

Identity tokens vs Access tokens: understanding the key differences
WorkOS Blog
Modern authentication flows use tokens to convey information about a user and whether that user is allowed to interact with specific resources.
1ヶ月前

What is the Model Context Protocol (MCP)?
WorkOS Blog
Anthropic developed the Model Context Protocol (MCP), an open standard that connects AI assistants to systems where data actually lives—content repositories, business tools, development environments, and more.
1ヶ月前

OAuth best practices: We read RFC 9700 so you don’t have to
WorkOS Blog
In January 2025, the IETF published RFC 9700: Best Current Practice for OAuth 2.0 Security. We read it and summarized the best practices you should follow to keep your OAuth implementation safe.
1ヶ月前

FGA vs ABAC: Understanding the differences
WorkOS Blog
Choosing between FGA and ABAC can be tricky, but it doesn’t have to be. In this article, we break down both models to help you decide which one works best for your needs.
1ヶ月前

JWT storage 101: How to keep your tokens secure
WorkOS Blog
Want to keep your JWTs safe from attackers? This guide covers the best practices for securely storing your tokens and ensuring your app's security.
2ヶ月前

How it felt to reach Product-market fit (PMF) at WorkOS—and what no one tells you
WorkOS Blog
Today, I want to share the emotional side of hitting PMF at WorkOS, plus some advice I’ve learned the hard way from growing the company to where it is today.
2ヶ月前

How to add granular permissions to your API using OAuth scopes
WorkOS Blog
Learn how to enhance your API's security with granular permissions using OAuth scopes, allowing you to control access precisely and protect user data effectively. This guide covers the basics of OAuth scopes, implementing fine-grained permissions, and best practices for secure API management.
2ヶ月前

What is the aud claim in identity, authentication, and authorization?
WorkOS Blog
The “aud” claim tells the system which recipient the token is meant for.
2ヶ月前

How to add custom claims to JWTs
WorkOS Blog
Your auth system can issue a JWT with user details, enabling API routes to decode and use claims without extra queries.
2ヶ月前

Tenant isolation in multi-tenant systems: What you need to know
WorkOS Blog
Multiple customers, one software instance—sounds tricky, right? Find out how multi-tenancy ensures secure, separate access for everyone and why it matters.
2ヶ月前

OAuth 2.0 and OpenID Connect: The evolution from authorization to identity
WorkOS Blog
OAuth 2.0 set the standard for delegated authorization, but OpenID Connect (OIDC) compliments this protocol by adding user authentication
2ヶ月前

What Is API Authentication? A guide to OAuth 2.0, JWT, and key methods
WorkOS Blog
API authentication ensures that only authorized requests access protected resources. It’s a mechanism for verifying credentials against predetermined rules to reject unauthorized traffic.
2ヶ月前

Context is king: tools for feeding your code and website to LLMs
WorkOS Blog
LLMs excel at automating code and content tasks, but their accuracy depends on the context you provide—especially as your codebase evolves. Learn key tools and techniques to keep your AI assistants up to date.
2ヶ月前

Securing AI agents: authentication patterns for Operator and computer using models
WorkOS Blog
Operator models can use the computer the way humans do. This unlocks new capabilities like shopping, researching and performing tasks on our behalf, but raises important security and compliance ramifications.
2ヶ月前

Identity federation vs identity delegation
WorkOS Blog
Identity and access management have many terms, and it’s not always clear what they mean. Many people are confused about the differences between identity federation and identity delegation. Read this article to understand each one once and for all.
2ヶ月前

How to stop bots with honeypots
WorkOS Blog
Honeypots are traps you can set up at your website to catch bots. Read how you can implement one and what are the best practices to follow.
2ヶ月前

The best feature flag providers for apps in 2025
WorkOS Blog
This article examines five leading feature toggle providers in 2025—LaunchDarkly, Optimizely, Unleash, Bucket, Split.io, and Eppo—each offering unique benefits for different technical and organizational requirements.
2ヶ月前

AI agents are taking over: How autonomous software changes research and work
WorkOS Blog
Interest in AI agents is exploding, and they're already transforming how we work and perform research. Learn how.
2ヶ月前

How encryption works in a Data Vault using EKM
WorkOS Blog
Keeping data safe, especially sensitive data like PII, is an increasingly difficult project. Read about Data Vaults and EKM and how enterprises can use them to ensure data integrity and confidentiality.
2ヶ月前

What is the difference between Radix and shadcn-ui?
WorkOS Blog
Radix and shadcn-ui are both component libraries for React, but which should you choose?
2ヶ月前

Session management best practices
WorkOS Blog
If you think you’re done when you authenticate a user, think again. Proper session management can make or break your app, both security and UX-wise. We gathered some industry best practices to help you get started.
2ヶ月前

Relationship-based vs policy-based authorization: what's the difference and how do they work together?
WorkOS Blog
Authorization rules can be expressed as policies, relationships, or both. Read how each one works, their pros and cons, and find the best for your case.
2ヶ月前

EKM vs KMS: An introduction to key management
WorkOS Blog
Keeping your data safe by encrypting them is crucial, but how do you keep the encryption keys safe? Read what EKM and KMS are and how they work together to do exactly that.
2ヶ月前

Top AI Agent frameworks and platforms in 2025
WorkOS Blog
AI agent frameworks and platforms empower developers to build software that can reason, remember, and act independently. Which should you choose?
2ヶ月前

Understanding the OAuth 2.0 Client Credentials flow
WorkOS Blog
Learn how to use OAuth for secure machine-to-machine communication with the Client Credentials flow.
2ヶ月前

What is Arcade.dev? An LLM tool calling platform
WorkOS Blog
Large Language Models (LLMs) excel at producing text, but many applications need them to do more: raise GitHub issues, star a repository, or send Twilio messages in real time.
2ヶ月前

RBAC best practices
WorkOS Blog
Ensure the right people have the right access. Check out our RBAC best practices guide and avoid common pitfalls.
2ヶ月前

How to build RBAC with WorkOS and Node
WorkOS Blog
Step-by-step tutorial that walks you through the necessary steps to add role-based access control (RBAC) to your app using WorkOS and Node.
2ヶ月前

The battle against bots: How to detect and stop them
WorkOS Blog
Bots are everywhere. How can you distinguish the bad from the good, and how can you stop them? Read our guide for practical steps on how to stop bots and protect your app.
2ヶ月前

Scaling up: Why Fine-Grained Authorization is key as your product moves upmarket
WorkOS Blog
When your goal is selling to enterprises, sooner or later, you will have to leave RBAC for a fine-grained authorization model. Read more about why that is and how you can make the move.
2ヶ月前

What is federated identity?
WorkOS Blog
Learn what federated identity is, how it works, its pros and cons, and how it differs from SSO and social logins.
2ヶ月前

Which auth providers support SCIM?
WorkOS Blog
Do you plan on outsourcing SCIM and you don't know where? Read this article for a list of auth providers that support SCIM and a comparison of the features they offer.
2ヶ月前

Passwordless authentication: your options explained
WorkOS Blog
Do you want to add passwordless authentication to your app and don’t know where to start? Read our guide for an overview of the top available methods, their pros and cons, and which one might be the best for you.
3ヶ月前

Email deliverability and spam prevention: why your emails aren’t getting delivered and how to fix it
WorkOS Blog
Do your emails end up in spam? Read this guide to see what you can do to optimize your email deliverability and avoid the spam folder.
3ヶ月前

How to run DeepSeek locally
WorkOS Blog
DeepSeek R1 is an open-source LLM for conversational AI, coding, and problem-solving. Here's how to run it locally.
3ヶ月前

What is Authentik?
WorkOS Blog
Authentik is an open-source Identity Provider (IdP) that allows you to self-host user authentication, single sign-on (SSO), and access controls.
3ヶ月前

Defending against bad actors: WorkOS Radar vs Castle vs Auth0 vs Stytch vs Arcjet
WorkOS Blog
Which products can help you safeguard your app against bots and hackers and how do they compare? Learn what you should look for and what features each vendor offers.
3ヶ月前

What is Ente Auth?
WorkOS Blog
Ente Auth is a modern, secure, and user-friendly two-factor authentication (2FA) solution designed to safeguard online accounts with minimal hassle.
3ヶ月前

Shadcn-ui: What is it, and why do you care?
WorkOS Blog
shadcn-ui is a set of reusable React components focused on accessibility, customization, and developer control. It stands out from typical UI libraries by allowing you to own the code directly, thereby reducing external dependencies and version lock-ins.
3ヶ月前

Breaking the AI Mold: China's DeepSeek-R1 pushes local and open AI forward
WorkOS Blog
Announced just this week, DeepSeek-R1 is positioned as a direct competitor to incumbent LLM creators’ flagship models, promising robust reasoning, mathematics, and coding capabilities.
3ヶ月前

Google OAuth vulnerability can expose sensitive data of failed startups
WorkOS Blog
Read about how failed startups that used Google SSO might be susceptible to leaking sensitive information of employees.
3ヶ月前

How to build SAML SSO with WorkOS, JumpCloud, and Node
WorkOS Blog
Step-by-step tutorial that walks you through the necessary steps to add SSO to your app using SAML, JumpCloud, Node, and WorkOS.
3ヶ月前

Understanding Zero Trust security
WorkOS Blog
Learn what Zero Trust security is and how it came to be (spoiler alert: Chinese state-sponsored hackers are involved).
3ヶ月前

How WorkOS Radar does rate limiting with device fingerprinting
WorkOS Blog
Radar can detect threats even when they switch up or spoof their IP address. Here's how.
3ヶ月前

How do you know when you’ve hit product-market fit?
WorkOS Blog
How will you know once you've found Product Market Fit? Through these signs, which also tell you that you're ready to go upmarket after enterprise customers.
3ヶ月前

How WorkOS Radar's bot detection works
WorkOS Blog
Every day, countless bots attempt to breach applications by exploiting authentication systems. Here's how WorkOS Radar stops them.
3ヶ月前

How WorkOS Radar really works
WorkOS Blog
How does WorkOS Radar really work? How do you install and set it up and what does it reveal?
3ヶ月前

What is device fingerprinting and how does it work?
WorkOS Blog
Your device leaves a unique trail of digital breadcrumbs whenever you open a web browser. These aren't cookies that you can delete – they're subtle signals from your hardware and software that combine to create something far more permanent: your device fingerprint.
3ヶ月前

How to build SAML SSO with WorkOS, Okta, and Python
WorkOS Blog
Step-by-step tutorial that walks you through the necessary steps to add SSO to your app using SAML, Okta, Python, and WorkOS.
3ヶ月前

How to build SAML SSO with WorkOS, Okta, and Ruby
WorkOS Blog
Step-by-step tutorial that walks you through the necessary steps to add SSO to your app using SAML, Okta, Ruby, and WorkOS.
3ヶ月前

How to build a user management dashboard with WorkOS and Node
WorkOS Blog
Step-by-step tutorial on how to add basic user management functionality to your app using Node.js and WorkOS.
3ヶ月前

Best practices for secrets management
WorkOS Blog
This guide explains best practices for keeping your secrets where they belong—secured away from public code and prying eyes.
3ヶ月前

How to implement row-level security with WorkOS FGA and Postgres: tutorial and code
WorkOS Blog
Your support ticketing system contains sensitive data from multiple organizations and customers. How do you ensure users only see tickets they're authorized to view?
3ヶ月前

How to build SAML SSO with WorkOS, Okta, and Go
WorkOS Blog
Step-by-step tutorial that walks you through the necessary steps to add SSO to your app using SAML, Okta, Go, and WorkOS.
3ヶ月前

How to build Log in with Google using Go and WorkOS
WorkOS Blog
Step-by-step tutorial that walks you through the necessary steps to add Log in with Google to your app using Go and WorkOS.
3ヶ月前

We shipped our auth server to your browser with WASM. Here's how it's going
WorkOS Blog
Picture this: you've built a powerful authorization system based on Google's Zanzibar design, capable of handling complex permission relationships at scale. Now you want to let developers try it out. How can you let them experiment freely without spinning up countless backend environments?
4ヶ月前