Solving the Missing Trust Anchor in Dynamic Client Registration with CIMD
OAuth originally assumed clients would be pre-registered at an authorization server.
OAuth originally assumed clients would be pre-registered at an authorization server.
Hi all,
Cross-domain access is everywhere in today's software landscape. Whether you look at enterprise SaaS applications, AI agents interacting with user data across multiple platforms, or "integrated experiences" pulling information from a calendar, a chat tool, and a wiki—everything eventually needs to talk across boundaries.
The new MCP authorization spec is here! Today marks the one-year anniversary of the Model Context Protocol, and with it, the launch of the new 2025-11-25 specification.
In October, I launched an instance of Meetable for the MCP Community. They've been using it to post working group meetings as well as in-person community events. In just 2 months it already has 41 events listed!
Today I just launched support for BlueSky as a new authentication option in IndieLogin.com!
The IETF OAuth Working Group has adopted the Client ID Metadata Document specification!
I just released some updates for Meetable, my open source event listing website.
Every time I take a Lyft from the San Francisco airport to downtown going up 101, I notice the billboards. The billboards on 101 are always such a good snapshot in time of the current peak of the Silicon Valley hype cycle. I've decided to capture photos of the billboards every time I am there, to see how this changes over time.
I've seen a lot of complaints about how MCP isn't ready for the enterprise.