DEV Community

# oauth

OAuth flow implementation details

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
Fixing AADSTS700082: refresh tokens expiring after 12 hours in Azure Entra External ID

Fixing AADSTS700082: refresh tokens expiring after 12 hours in Azure Entra External ID

Comments 1
6 min read
Add Refresh Tokens to Your Hono OIDC Server (with Token Rotation)

Add Refresh Tokens to Your Hono OIDC Server (with Token Rotation)

Comments
8 min read
OAuth2 Account Takeovers: Building a Bulletproof Social Login Architecture

OAuth2 Account Takeovers: Building a Bulletproof Social Login Architecture

Comments
3 min read
The Silent Backdoor in Enterprise Security: Why Unmanaged OAuth Tokens Are the New High-Risk Vector

The Silent Backdoor in Enterprise Security: Why Unmanaged OAuth Tokens Are the New High-Risk Vector

2
Comments
2 min read
Salesforce OAuth Security & ECA Compliance: Complete Guide for AppExchange ISVs

Salesforce OAuth Security & ECA Compliance: Complete Guide for AppExchange ISVs

Comments
9 min read
Google OAuth 2.0 PKCE flow in a React/Next.js app — no backend, no client secret

Google OAuth 2.0 PKCE flow in a React/Next.js app — no backend, no client secret

7
Comments
8 min read
OAuth vs OAuth 2.0 Explained Simply for Beginners

OAuth vs OAuth 2.0 Explained Simply for Beginners

Comments
2 min read
Identity Is Not Trust: Why Agent Authentication Alone Won't Secure AI Payments

Identity Is Not Trust: Why Agent Authentication Alone Won't Secure AI Payments

1
Comments
5 min read
Add a Consent Screen to Your OIDC Authorization Server with Hono

Add a Consent Screen to Your OIDC Authorization Server with Hono

1
Comments
9 min read
Vercel got hacked because an employee clicked 'Allow' on an OAuth prompt. We all do this.

Vercel got hacked because an employee clicked 'Allow' on an OAuth prompt. We all do this.

3
Comments
3 min read
The Vercel/Context.ai Breach Wasn't a Vulnerability. It Was a Delegation Path.

The Vercel/Context.ai Breach Wasn't a Vulnerability. It Was a Delegation Path.

Comments
7 min read
Why your MCP server should serve OAuth Protected Resource Metadata — AuthKit + RFC 9728

Why your MCP server should serve OAuth Protected Resource Metadata — AuthKit + RFC 9728

Comments 1
4 min read
Building Secure APIs for AI Systems: Architecture, Threat Models, and Best Practices

Building Secure APIs for AI Systems: Architecture, Threat Models, and Best Practices

1
Comments 1
3 min read
How to set up refresh-token-only OAuth for a multi-tenant Apify Actor (Gmail, 10 minutes)

How to set up refresh-token-only OAuth for a multi-tenant Apify Actor (Gmail, 10 minutes)

Comments
5 min read
Why I picked refresh-token-only OAuth for a multi-tenant Apify Actor

Why I picked refresh-token-only OAuth for a multi-tenant Apify Actor

Comments
5 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.