WorkOS Blog

https://workos.com

Developer APIs/SDKs for Enterprise Ready features like Single Sign-On, Directory Sync, Audit Logging, and more. Get started for free.

フィード

記事のアイキャッチ画像
Introducing RFC 9728: Say hello to standardized OAuth 2.0 resource metadata
WorkOS Blog
OAuth 2.0 just got a major upgrade in how resources describe themselves — find out what RFC 9728 introduces and why it matters.
2日前
記事のアイキャッチ画像
Diagnosing SAML assertion failures: A step-by-step debugging guide
WorkOS Blog
From expired assertions to signature fails — a survival guide for anyone who's ever screamed at a SAML error message.
8日前
記事のアイキャッチ画像
On-premises and hybrid authentication: Challenges and best practices
WorkOS Blog
How to avoid common pitfalls and build resilient auth systems in on-prem and hybrid setups.
9日前
記事のアイキャッチ画像
The hidden pitfalls of SAML metadata: How to avoid downtime
WorkOS Blog
Misconfigured SAML metadata is one of the most overlooked causes of SSO failures. Learn how to spot hidden risks—and fix them before they break your login flow.
10日前
記事のアイキャッチ画像
Mastra.ai Quickstart - How to build a TypeScript agent in 5 minutes or less
WorkOS Blog
Mastra is a batteries‑included TypeScript framework for agentic apps. In this post, we'll use it to build an agentic app that can fetch data from GitHub in less than 5 minutes.
11日前
記事のアイキャッチ画像
oRPC: OpenAPI Remote Procedure Call for Type-Safe APIs
WorkOS Blog
oRPC (OpenAPI Remote Procedure Call) combines the familiarity of RPC with the industry-standard OpenAPI spec so that every request/response is fully typed from client to server. 
12日前
記事のアイキャッチ画像
Best practices for MCP secrets management
WorkOS Blog
Every outbound call from your MCP server carries credentials—API keys, database passwords, OAuth tokens, you name it. If those secrets leak, the blast radius extends far beyond your LLM demo. Learn to secure your MCP secrets.
12日前
記事のアイキャッチ画像
DBConnection pooling deep dive
WorkOS Blog
A deep dive on how pooled connections work in the Elixir DBConnection library.
12日前
記事のアイキャッチ画像
In-Memory Distributed State with Delta CRDTs
WorkOS Blog
How to utilize delta conflict-free replicated data types for managing distributed cache or configuration state on an Elixir cluster.
12日前
記事のアイキャッチ画像
Why your app needs refresh tokens—and how they work
WorkOS Blog
Session management is hard. Refresh tokens make it easier—and safer. This guide breaks down how they work, why you need them, and how to avoid common mistakes (with code included).
17日前
記事のアイキャッチ画像
IBM’s Agent Communication Protocol (ACP): A technical overview for software engineers
WorkOS Blog
IBM Research’s Agent Communication Protocol (ACP) provides autonomous agents with a common “wire format” for talking to each other. But how does it differ from MCP and A2A?
18日前
記事のアイキャッチ画像
SAML's signature problem: It’s not you, it’s XML
WorkOS Blog
A deep dive into the messy world of SAML signature verification bugs — complete with real examples, cautionary tales, and practical tips to keep your app out of trouble.
18日前
記事のアイキャッチ画像
Agent to agent, not tool to tool: an engineer’s guide to Google’s A2A protocol
WorkOS Blog
Think of MCP as “plug this model into my data” and A2A as “now let several specialised models talk to each other.”
22日前
記事のアイキャッチ画像
From 1.0.0 to 2025.4: Making sense of software versioning
WorkOS Blog
Confused by versioning? This guide breaks down the top strategies to help you pick the right one, keeping your project organized and your users in the loop.
23日前
記事のアイキャッチ画像
MCP, ACP, A2A, Oh my!
WorkOS Blog
Let’s explore the MCP, ACP and A2A protocols, understand what they do, and highlight how they differ and complement one another.
24日前
記事のアイキャッチ画像
WorkOS + Cloudflare MCP: Plug and Play Auth for Agentic AI Builders
WorkOS Blog
Until now, plugging your existing user authentication system into MCP servers was tricky. That’s where WorkOS and Cloudflare step in.
24日前
記事のアイキャッチ画像
ArkType: A high-performance runtime type validation for TypeScript
WorkOS Blog
ArkType is a TypeScript-first runtime validation library built to erase the boundary between static type safety and runtime enforcement.
1ヶ月前
記事のアイキャッチ画像
How to handle JWT in Python
WorkOS Blog
Everything you need to know to implement and validate JWTs securely in Python — from signing to verifying with JWKS, with code examples and best practices throughout.
1ヶ月前
記事のアイキャッチ画像
Prisma ORM for TypeScript - A technical primer
WorkOS Blog
Prisma is one of the most popular Object-Relational Mappers (ORMs) in the TypeScript/JavaScript ecosystem due to its robust type-safety guarantees and seamless integration with frameworks like Next.js.
1ヶ月前
記事のアイキャッチ画像
Security risks of iframes: Protecting your app from potential attacks
WorkOS Blog
Iframes might seem convenient, but they come with serious security risks like XSS, session hijacking, and phishing. This article breaks down why iframes can put your site at risk and how to protect it.
1ヶ月前
記事のアイキャッチ画像
Smithery AI: A central hub for MCP servers
WorkOS Blog
Smithery AI is a registry and management platform for Model Context Protocol (MCP) servers.
1ヶ月前
記事のアイキャッチ画像
HMAC vs. RSA vs. ECDSA: Which algorithm should you use to sign JWTs?
WorkOS Blog
Confused about which algorithm to use for signing JWTs? We analyze everything about HMAC, RSA, and ECDSA—so you can choose the perfect algorithm for your security needs.
1ヶ月前
記事のアイキャッチ画像
Generative AI at the edge with Cloudflare Workers
WorkOS Blog
Large language models are reshaping how we build apps—but is your infrastructure ready for them?
1ヶ月前
記事のアイキャッチ画像
Securing your app with Risk-Based Authentication and AI
WorkOS Blog
Learn how Risk-Based Authentication (RBA) and AI can transform your app’s security, with best practices and insights to protect against evolving threats.
1ヶ月前
記事のアイキャッチ画像
How to build a game-building agent system with CrewAI
WorkOS Blog
A hands-on guide with patterns, agents, and executable examples
1ヶ月前
記事のアイキャッチ画像
Top Ruby gems for authentication & authorization
WorkOS Blog
Looking to secure your Ruby on Rails app? Discover the top gems for authentication and authorization that will protect your users. From seamless sign-ins to granular user permissions, these gems have got you covered.
1ヶ月前
記事のアイキャッチ画像
How to build Login with LinkedIn using Python and WorkOS
WorkOS Blog
Step-by-step tutorial that walks you through the necessary steps to add Login with LinkedIn to your app using Python and WorkOS.
1ヶ月前
記事のアイキャッチ画像
March Updates
WorkOS Blog
Spring Launch Week: WorkOS Vault, Connect, and more new features
1ヶ月前
記事のアイキャッチ画像
How to build Login with Slack using Node and WorkOS
WorkOS Blog
Step-by-step tutorial that walks you through the necessary steps to add Login with Slack to your app using Node and WorkOS.
1ヶ月前
記事のアイキャッチ画像
How to build Login with GitLab using Node and WorkOS
WorkOS Blog
Step-by-step tutorial that walks you through the necessary steps to add Login with GitLab to your app using Node and WorkOS.
1ヶ月前
記事のアイキャッチ画像
Credential stuffing vs. brute force attacks: Key differences and how to stop them
WorkOS Blog
Learn how credential stuffing and brute force attacks work and how you can defend your systems with advanced protection tools like WorkOS Radar.
1ヶ月前
記事のアイキャッチ画像
How to build Login with LinkedIn using Node and WorkOS
WorkOS Blog
Step-by-step tutorial that walks you through the necessary steps to add Login with LinkedIn to your app using Node and WorkOS.
1ヶ月前
記事のアイキャッチ画像
How to choose the right authorization model for your SaaS
WorkOS Blog
Not sure which authorization model is best for your SaaS app? Our latest article breaks down the top approaches—from simple roles to Fine-Grained Authorization—helping you choose the right fit for your app's security and user management.
1ヶ月前
記事のアイキャッチ画像
Zod for TypeScript: A must-know library for AI development
WorkOS Blog
Ever wondered why one TypeScript validation library keeps appearing in every major AI platform's documentation?
1ヶ月前
記事のアイキャッチ画像
WorkOS, Next.js, and CVE-2025-29927
WorkOS Blog
Over the weekend, security researchers responsibly disclosed CVE-2025-29927, a vulnerability in Next.js that allows an attacker to bypass Next.js middleware entirely.
1ヶ月前
記事のアイキャッチ画像
Advice for coding with AI
WorkOS Blog
More folks are picking up coding than ever before thanks to advancements in AI. Here are the top tips for ensuring a smooth experience.
1ヶ月前
記事のアイキャッチ画像
How AI Agents authenticate and access systems
WorkOS Blog
The rise of AI agents creates a fundamental tension in system design. On one hand, these agents need frictionless access to be effective; on the other, security demands robust controls and limitations.
1ヶ月前
記事のアイキャッチ画像
Beyond the basics: Why device fingerprinting is mission-critical in 2025
WorkOS Blog
This article explores what happens when fingerprinting goes beyond the basics—how companies use it, how to stay privacy-compliant, and what’s next.
1ヶ月前
記事のアイキャッチ画像
An introduction to WebAuthn
WorkOS Blog
Learn what WebAuthn is, how it works, its benefits, its challenges, and how you can implement it in your app.
2ヶ月前
記事のアイキャッチ画像
n8n: The workflow automation tool for the AI age
WorkOS Blog
As a self-hostable, open-source automation platform, n8n lets you orchestrate logic, connect services, and scale pipelines with minimal boilerplate.
2ヶ月前
記事のアイキャッチ画像
New widgets available for user profiles and organization switching
WorkOS Blog
We just released four new widgets to make your life easier: user profile, user sessions, user security, and organization switcher. They are now available for free to all AuthKit customers.
2ヶ月前
記事のアイキャッチ画像
New enterprise login integrations in AuthKit
WorkOS Blog
With AuthKit enterprise logins are now easier than ever. We are announcing the addition of key B2B login providers, like LinkedIn, Slack, Xero, and more, giving your users seamless access to your platform with the credentials they already use.
2ヶ月前
記事のアイキャッチ画像
Custom Metadata, External ID, and JWT Templates
WorkOS Blog
Expand your WorkOS integration by customizing attributes on users, orgs, and session tokens.
2ヶ月前
記事のアイキャッチ画像
WorkOS Vault: Advanced Encryption for Sensitive Data
WorkOS Blog
Discover how Vault makes protecting sensitive data easier, faster, and more cost-effective—without the headache.
2ヶ月前
記事のアイキャッチ画像
How to deploy Laravel apps with enterprise-ready authentication
WorkOS Blog
Learn how to set up a Laravel 12 project with WorkOS AuthKit and deploy it seamlessly to Laravel Cloud, leveraging zero-config hosting and enterprise-grade authentication features.
2ヶ月前
記事のアイキャッチ画像
Getting Started with Claude Desktop and custom MCP servers using the TypeScript SDK
WorkOS Blog
The Model Context Protocol (MCP) is an open specification that simplifies connecting AI models (like Claude) to external tools and data sources.
2ヶ月前
記事のアイキャッチ画像
WorkOS Connect
WorkOS Blog
Enable 3rd-party authentication via “Sign in with [Your App],” Identity Delegation, and Machine to Machine tokens.
2ヶ月前
記事のアイキャッチ画像
SAMLStorm: Critical Authentication Bypass in xml-crypto and Node.js libraries
WorkOS Blog
Any service using xml-crypto or a Node.js SAML implementation using it, should update immediately to the latest version. WorkOS customers are safe and were not impacted.
2ヶ月前
記事のアイキャッチ画像
GAIA Benchmark: evaluating intelligent agents
WorkOS Blog
The GAIA (“Generalized AI Agent” benchmark) helps us evaluate AI agent performance across complex tasks
2ヶ月前
記事のアイキャッチ画像
Introducing Manus: The general AI agent
WorkOS Blog
Manus is a fully autonomous AI system designed to run asynchronously in the cloud—no repeated prompts, no babysitting.
2ヶ月前
記事のアイキャッチ画像
The ABCs of token security: JWS, JWE, JWK, and JWKS explained
WorkOS Blog
Confused by all the token jargon? This article simplifies JWS, JWE, JWK, and JWKS, showing you how each one ensures your data stays secure and trustworthy.
2ヶ月前
記事のアイキャッチ画像
Defending OAuth: Common attacks and how to prevent them
WorkOS Blog
OAuth vulnerabilities can be tricky, but we’re here to help! Learn about common attacks and how to protect your app with simple tips from RFC 9700.
2ヶ月前
記事のアイキャッチ画像
Composio.dev overview
WorkOS Blog
Composio.dev is a developer-focused integration platform that simplifies how AI agents and large language models (LLMs) connect with external applications and services.
2ヶ月前
記事のアイキャッチ画像
What are Cursor Rules?
WorkOS Blog
Cursor Rules are instructions or system prompts passed to the large language models (LLMs) that Cursor uses. Learn how to leverage them effectively.
2ヶ月前
記事のアイキャッチ画像
Spot the bots: How to track malicious activity with JavaScript tagging
WorkOS Blog
Tired of bots wreaking havoc on your website? Learn how JavaScript tagging can help you track suspicious behavior and stop malicious activity in its tracks.
2ヶ月前
記事のアイキャッチ画像
When database security is not enough: How the cloud makes application-level encryption a must
WorkOS Blog
Learn why traditional database encryption just doesn’t cut it anymore and why application-level encryption is the real hero for data security.
2ヶ月前
記事のアイキャッチ画像
What is Claude Code? An agentic developer tool
WorkOS Blog
Anthropic’s release of Claude Code, built on the 3.7 Sonnet model, marks a significant step in AI-assisted development.
2ヶ月前
記事のアイキャッチ画像
Identity tokens vs Access tokens: understanding the key differences
WorkOS Blog
Modern authentication flows use tokens to convey information about a user and whether that user is allowed to interact with specific resources.
2ヶ月前
記事のアイキャッチ画像
What is the Model Context Protocol (MCP)?
WorkOS Blog
Anthropic developed the Model Context Protocol (MCP), an open standard that connects AI assistants to systems where data actually lives—content repositories, business tools, development environments, and more.
2ヶ月前
記事のアイキャッチ画像
OAuth best practices: We read RFC 9700 so you don’t have to
WorkOS Blog
In January 2025, the IETF published RFC 9700: Best Current Practice for OAuth 2.0 Security. We read it and summarized the best practices you should follow to keep your OAuth implementation safe.
2ヶ月前
記事のアイキャッチ画像
FGA vs ABAC: Understanding the differences
WorkOS Blog
Choosing between FGA and ABAC can be tricky, but it doesn’t have to be. In this article, we break down both models to help you decide which one works best for your needs.
2ヶ月前
記事のアイキャッチ画像
JWT storage 101: How to keep your tokens secure
WorkOS Blog
Want to keep your JWTs safe from attackers? This guide covers the best practices for securely storing your tokens and ensuring your app's security.
2ヶ月前
記事のアイキャッチ画像
How it felt to reach Product-market fit (PMF) at WorkOS—and what no one tells you
WorkOS Blog
Today, I want to share the emotional side of hitting PMF at WorkOS, plus some advice I’ve learned the hard way from growing the company to where it is today.
2ヶ月前
記事のアイキャッチ画像
How to add granular permissions to your API using OAuth scopes
WorkOS Blog
Learn how to enhance your API's security with granular permissions using OAuth scopes, allowing you to control access precisely and protect user data effectively. This guide covers the basics of OAuth scopes, implementing fine-grained permissions, and best practices for secure API management.
2ヶ月前
記事のアイキャッチ画像
What is the aud claim in identity, authentication, and authorization?
WorkOS Blog
The “aud” claim tells the system which recipient the token is meant for.
2ヶ月前
記事のアイキャッチ画像
How to add custom claims to JWTs
WorkOS Blog
Your auth system can issue a JWT with user details, enabling API routes to decode and use claims without extra queries.
2ヶ月前
記事のアイキャッチ画像
Tenant isolation in multi-tenant systems: What you need to know
WorkOS Blog
Multiple customers, one software instance—sounds tricky, right? Find out how multi-tenancy ensures secure, separate access for everyone and why it matters.
2ヶ月前
記事のアイキャッチ画像
OAuth 2.0 and OpenID Connect: The evolution from authorization to identity
WorkOS Blog
OAuth 2.0 set the standard for delegated authorization, but OpenID Connect (OIDC) compliments this protocol by adding user authentication
2ヶ月前
記事のアイキャッチ画像
What Is API Authentication? A guide to OAuth 2.0, JWT, and key methods
WorkOS Blog
API authentication ensures that only authorized requests access protected resources. It’s a mechanism for verifying credentials against predetermined rules to reject unauthorized traffic.
2ヶ月前
記事のアイキャッチ画像
Context is king: tools for feeding your code and website to LLMs
WorkOS Blog
LLMs excel at automating code and content tasks, but their accuracy depends on the context you provide—especially as your codebase evolves. Learn key tools and techniques to keep your AI assistants up to date.
2ヶ月前
記事のアイキャッチ画像
Securing AI agents: authentication patterns for Operator and computer using models
WorkOS Blog
Operator models can use the computer the way humans do. This unlocks new capabilities like shopping, researching and performing tasks on our behalf, but raises important security and compliance ramifications.
2ヶ月前
記事のアイキャッチ画像
Identity federation vs identity delegation
WorkOS Blog
Identity and access management have many terms, and it’s not always clear what they mean. Many people are confused about the differences between identity federation and identity delegation. Read this article to understand each one once and for all.
3ヶ月前
記事のアイキャッチ画像
How to stop bots with honeypots
WorkOS Blog
Honeypots are traps you can set up at your website to catch bots. Read how you can implement one and what are the best practices to follow.
3ヶ月前
記事のアイキャッチ画像
The best feature flag providers for apps in 2025
WorkOS Blog
This article examines five leading feature toggle providers in 2025—LaunchDarkly, Optimizely, Unleash, Bucket, Split.io, and Eppo—each offering unique benefits for different technical and organizational requirements.
3ヶ月前
記事のアイキャッチ画像
AI agents are taking over: How autonomous software changes research and work
WorkOS Blog
Interest in AI agents is exploding, and they're already transforming how we work and perform research. Learn how.
3ヶ月前
記事のアイキャッチ画像
How encryption works in a Data Vault using EKM
WorkOS Blog
Keeping data safe, especially sensitive data like PII, is an increasingly difficult project. Read about Data Vaults and EKM and how enterprises can use them to ensure data integrity and confidentiality.
3ヶ月前
記事のアイキャッチ画像
What is the difference between Radix and shadcn-ui?
WorkOS Blog
Radix and shadcn-ui are both component libraries for React, but which should you choose?
3ヶ月前
記事のアイキャッチ画像
Session management best practices
WorkOS Blog
If you think you’re done when you authenticate a user, think again. Proper session management can make or break your app, both security and UX-wise. We gathered some industry best practices to help you get started.
3ヶ月前
記事のアイキャッチ画像
Relationship-based vs policy-based authorization: what's the difference and how do they work together?
WorkOS Blog
Authorization rules can be expressed as policies, relationships, or both. Read how each one works, their pros and cons, and find the best for your case.
3ヶ月前
記事のアイキャッチ画像
EKM vs KMS: An introduction to key management
WorkOS Blog
Keeping your data safe by encrypting them is crucial, but how do you keep the encryption keys safe? Read what EKM and KMS are and how they work together to do exactly that.
3ヶ月前
記事のアイキャッチ画像
Top AI Agent frameworks and platforms in 2025
WorkOS Blog
AI agent frameworks and platforms empower developers to build software that can reason, remember, and act independently. Which should you choose?
3ヶ月前
記事のアイキャッチ画像
Understanding the OAuth 2.0 Client Credentials flow
WorkOS Blog
Learn how to use OAuth for secure machine-to-machine communication with the Client Credentials flow.
3ヶ月前
記事のアイキャッチ画像
What is Arcade.dev? An LLM tool calling platform
WorkOS Blog
Large Language Models (LLMs) excel at producing text, but many applications need them to do more: raise GitHub issues, star a repository, or send Twilio messages in real time.
3ヶ月前
記事のアイキャッチ画像
RBAC best practices
WorkOS Blog
Ensure the right people have the right access. Check out our RBAC best practices guide and avoid common pitfalls.
3ヶ月前
記事のアイキャッチ画像
How to build RBAC with WorkOS and Node
WorkOS Blog
Step-by-step tutorial that walks you through the necessary steps to add role-based access control (RBAC) to your app using WorkOS and Node.
3ヶ月前
記事のアイキャッチ画像
The battle against bots: How to detect and stop them
WorkOS Blog
Bots are everywhere. How can you distinguish the bad from the good, and how can you stop them? Read our guide for practical steps on how to stop bots and protect your app.
3ヶ月前
記事のアイキャッチ画像
Scaling up: Why Fine-Grained Authorization is key as your product moves upmarket
WorkOS Blog
When your goal is selling to enterprises, sooner or later, you will have to leave RBAC for a fine-grained authorization model. Read more about why that is and how you can make the move.
3ヶ月前
記事のアイキャッチ画像
What is federated identity?
WorkOS Blog
Learn what federated identity is, how it works, its pros and cons, and how it differs from SSO and social logins.
3ヶ月前
記事のアイキャッチ画像
January Updates
WorkOS Blog
Custom Logout URIs, Session Inactivity Timeouts, and AuthKit Next.js SDK v1.0
3ヶ月前
記事のアイキャッチ画像
Which auth providers support SCIM?
WorkOS Blog
Do you plan on outsourcing SCIM and you don't know where? Read this article for a list of auth providers that support SCIM and a comparison of the features they offer.
3ヶ月前
記事のアイキャッチ画像
Passwordless authentication: your options explained
WorkOS Blog
Do you want to add passwordless authentication to your app and don’t know where to start? Read our guide for an overview of the top available methods, their pros and cons, and which one might be the best for you.
3ヶ月前
記事のアイキャッチ画像
Email deliverability and spam prevention: why your emails aren’t getting delivered and how to fix it
WorkOS Blog
Do your emails end up in spam? Read this guide to see what you can do to optimize your email deliverability and avoid the spam folder.
3ヶ月前
記事のアイキャッチ画像
How to run DeepSeek locally
WorkOS Blog
DeepSeek R1 is an open-source LLM for conversational AI, coding, and problem-solving. Here's how to run it locally.
3ヶ月前
記事のアイキャッチ画像
What is Authentik?
WorkOS Blog
Authentik is an open-source Identity Provider (IdP) that allows you to self-host user authentication, single sign-on (SSO), and access controls.
3ヶ月前
記事のアイキャッチ画像
Defending against bad actors: WorkOS Radar vs Castle vs Auth0 vs Stytch vs Arcjet
WorkOS Blog
Which products can help you safeguard your app against bots and hackers and how do they compare? Learn what you should look for and what features each vendor offers.
3ヶ月前
記事のアイキャッチ画像
What is Ente Auth?
WorkOS Blog
Ente Auth is a modern, secure, and user-friendly two-factor authentication (2FA) solution designed to safeguard online accounts with minimal hassle.
4ヶ月前
記事のアイキャッチ画像
Shadcn-ui: What is it, and why do you care?
WorkOS Blog
shadcn-ui is a set of reusable React components focused on accessibility, customization, and developer control. It stands out from typical UI libraries by allowing you to own the code directly, thereby reducing external dependencies and version lock-ins.
4ヶ月前
記事のアイキャッチ画像
Breaking the AI Mold: China's DeepSeek-R1 pushes local and open AI forward
WorkOS Blog
Announced just this week, DeepSeek-R1 is positioned as a direct competitor to incumbent LLM creators’ flagship models, promising robust reasoning, mathematics, and coding capabilities.
4ヶ月前
記事のアイキャッチ画像
Google OAuth vulnerability can expose sensitive data of failed startups
WorkOS Blog
Read about how failed startups that used Google SSO might be susceptible to leaking sensitive information of employees.
4ヶ月前
記事のアイキャッチ画像
How to build SAML SSO with WorkOS, JumpCloud, and Node
WorkOS Blog
Step-by-step tutorial that walks you through the necessary steps to add SSO to your app using SAML, JumpCloud, Node, and WorkOS.
4ヶ月前