2 ms·
It seems that maybe the direction things are heading in is having desktop apps that can take over the computer, and prompt you to sign in yourself when auth is
by babyshake 2y ago
It seems that maybe the direction things are heading in is having desktop apps that can take over the computer, and prompt you to sign in yourself when auth is needed. Which would limit the usefulness of something like MCP as the interface becomes the UI, not APIs. But I'd be curious what other approaches to auth seem to be promising.
- Terretta 2y ago> what other approaches to auth seem to be promising Speaking on behalf of a regulated enterprise, more SaaS (who may be interested to support MCP so AIs can use their SaaS, not just people), should — for both people and agentic tools — be OIDC first, without charging an "SSO Tax". "Sign in with" is now effectively ubiquitous, gets you out of the business of user credentials liability and password management flows, and for businesses ticks the same boxes as SAML SSO if you build in (extra work, granted) a DNS validation and domain name match. In the USA, for B2B, some 85% of SMB are able to "Sign in with Microsoft" (HN tends to ignore this customer base), a majority of the rest can "Sign in with Google". By "wallet share" for B2C, you need "Sign in with Apple" and the rest are again "Sign in with Google". I am not with, nor using, WorkOS, but appreciate this paragraph in their OIDC vs. SAML explainer: Use OIDC to: add enterprise SSO to your app in a dramatically easier way, most IdPs support it. It’s also an obvious choice if you’re already using OAuth 2.0 to access users' data (for example, to access a user’s Google files or Facebook profile data). https://workos.com/blog/oidc-vs-saml https://workos.com/blog/oidc-vs-saml Once you've done this, as WorkOS mentions you can use this from browser perspective to access other APIs such as social sites, but for things like MCP (we're all building TRON!) if you're building from services perspective, you can build to let agents leverage “OAuth 2.0 Device Authorization Grant” or similar, and for bonus points “OAuth 2.0 Token Exchange”. https://www.rfc-editor.org/rfc/rfc8628 https://www.rfc-editor.org/rfc/rfc8628 https://datatracker.ietf.org/doc/html/rfc8693 https://datatracker.ietf.org/doc/html/rfc8693 Even consumer users understand these device login flows by now since they use SaaS from TV sets: https://www.netflix.com/tv8 https://www.netflix.com/tv8 https://myaccount.microsoft.com/devicelogin https://myaccount.microsoft.com/devicelogin