<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>AuthFI Blog</title>
    <link>https://blog.authfi.io</link>
    <description>Engineering notes on identity, access and the fabric that runs them.</description>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 18:25:03 GMT</lastBuildDate>
    <atom:link href="https://blog.authfi.io/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>What is AI agent identity?</title>
      <link>https://blog.authfi.io/blog/ai-agents/what-is-ai-agent-identity</link>
      <guid isPermaLink="true">https://blog.authfi.io/blog/ai-agents/what-is-ai-agent-identity</guid>
      <description>An AI agent that borrows a person&apos;s token or a shared API key cannot be limited, audited or stopped on its own. Here is what an identity for an agent consists of.</description>
      <pubDate>Tue, 06 Oct 2026 09:00:00 GMT</pubDate>
      <dc:creator>Sourabh Singh</dc:creator>
      <category>AI agents</category>
      <enclosure url="https://media.authfi.io/blog/post-covers/cover_what_is_ai_agent_identity_eb4a3b6470.webp" type="image/webp" length="0" />
    </item>
    <item>
      <title>The agent boundary: deciding what an AI agent may touch</title>
      <link>https://blog.authfi.io/blog/ai-agents/the-agent-boundary</link>
      <guid isPermaLink="true">https://blog.authfi.io/blog/ai-agents/the-agent-boundary</guid>
      <description>An agent will try whatever its input tells it to. A boundary limits what it can reach, for how long, and where the limit is enforced so the agent cannot argue with it.</description>
      <pubDate>Tue, 29 Sep 2026 09:00:00 GMT</pubDate>
      <dc:creator>Sourabh Singh</dc:creator>
      <category>AI agents</category>
      <enclosure url="https://media.authfi.io/blog/post-covers/cover_the_agent_boundary_bf98079c79.webp" type="image/webp" length="0" />
    </item>
    <item>
      <title>Authenticating MCP servers and tool calls</title>
      <link>https://blog.authfi.io/blog/ai-agents/authenticating-mcp-servers-and-tools</link>
      <guid isPermaLink="true">https://blog.authfi.io/blog/ai-agents/authenticating-mcp-servers-and-tools</guid>
      <description>Where authentication sits in an agent&apos;s tool call, how OAuth-based authorisation works for MCP, and why a token must never be passed through to the API behind a tool.</description>
      <pubDate>Tue, 22 Sep 2026 09:00:00 GMT</pubDate>
      <dc:creator>Sourabh Singh</dc:creator>
      <category>AI agents</category>
      <enclosure url="https://media.authfi.io/blog/post-covers/cover_authenticating_mcp_servers_and_tools_1a3f4b4839.webp" type="image/webp" length="0" />
    </item>
    <item>
      <title>Human approval for agent actions: when to ask and how</title>
      <link>https://blog.authfi.io/blog/ai-agents/human-approval-for-agent-actions</link>
      <guid isPermaLink="true">https://blog.authfi.io/blog/ai-agents/human-approval-for-agent-actions</guid>
      <description>Some actions should not be an agent&apos;s decision alone. How to pick them, and how to design approval requests that people actually read before they answer.</description>
      <pubDate>Thu, 10 Sep 2026 09:00:00 GMT</pubDate>
      <dc:creator>Sourabh Singh</dc:creator>
      <category>AI agents</category>
      <enclosure url="https://media.authfi.io/blog/post-covers/cover_human_approval_for_agent_actions_3ef2dbf9ab.webp" type="image/webp" length="0" />
    </item>
    <item>
      <title>Zero-code SSO for legacy apps with an eBPF proxy</title>
      <link>https://blog.authfi.io/blog/zero-code/zero-code-sso-with-an-ebpf-proxy</link>
      <guid isPermaLink="true">https://blog.authfi.io/blog/zero-code/zero-code-sso-with-an-ebpf-proxy</guid>
      <description>How to put single sign-on in front of an old internal app without changing it, and why the identity headers it receives must be stripped and re-stamped at the boundary.</description>
      <pubDate>Thu, 03 Sep 2026 09:00:00 GMT</pubDate>
      <dc:creator>Sourabh Singh</dc:creator>
      <category>Zero-Code</category>
      <enclosure url="https://media.authfi.io/blog/post-covers/cover_zero_code_sso_with_an_ebpf_proxy_cd419d7d79.webp" type="image/webp" length="0" />
    </item>
    <item>
      <title>What is zero-code authentication?</title>
      <link>https://blog.authfi.io/blog/zero-code/what-is-zero-code-authentication</link>
      <guid isPermaLink="true">https://blog.authfi.io/blog/zero-code/what-is-zero-code-authentication</guid>
      <description>Zero-code authentication puts sign-in and access checks in front of a service instead of inside it. How sidecars, proxies and kernel interception compare, and when to use an SDK.</description>
      <pubDate>Wed, 26 Aug 2026 09:00:00 GMT</pubDate>
      <dc:creator>Sourabh Singh</dc:creator>
      <category>Zero-Code</category>
      <enclosure url="https://media.authfi.io/blog/post-covers/cover_what_is_zero_code_authentication_83247a54a0.webp" type="image/webp" length="0" />
    </item>
    <item>
      <title>Service-to-service authentication: mTLS and workload identity</title>
      <link>https://blog.authfi.io/blog/zero-code/service-to-service-authentication</link>
      <guid isPermaLink="true">https://blog.authfi.io/blog/zero-code/service-to-service-authentication</guid>
      <description>How services prove who they are to each other with mTLS, workload identity and short-lived certificates, and why a shared static API key is the wrong tool for the job.</description>
      <pubDate>Tue, 18 Aug 2026 09:00:00 GMT</pubDate>
      <dc:creator>Sourabh Singh</dc:creator>
      <category>Zero-Code</category>
      <enclosure url="https://media.authfi.io/blog/post-covers/cover_service_to_service_authentication_36f7510826.webp" type="image/webp" length="0" />
    </item>
    <item>
      <title>Passkeys explained: how they work and how to roll them out</title>
      <link>https://blog.authfi.io/blog/identity/passkeys-explained</link>
      <guid isPermaLink="true">https://blog.authfi.io/blog/identity/passkeys-explained</guid>
      <description>How passkeys work under WebAuthn, the difference between synced and device-bound passkeys, and a rollout plan that covers fallback and recovery from day one.</description>
      <pubDate>Tue, 11 Aug 2026 09:00:00 GMT</pubDate>
      <dc:creator>Sourabh Singh</dc:creator>
      <category>Identity</category>
      <enclosure url="https://media.authfi.io/blog/post-covers/cover_passkeys_explained_bca8ba5b82.webp" type="image/webp" length="0" />
    </item>
    <item>
      <title>SAML vs OIDC: which to use for single sign-on</title>
      <link>https://blog.authfi.io/blog/identity/saml-vs-oidc</link>
      <guid isPermaLink="true">https://blog.authfi.io/blog/identity/saml-vs-oidc</guid>
      <description>SAML 2.0 and OpenID Connect both deliver single sign-on, in different shapes. How each one works, when to pick which, and what it takes to run both side by side.</description>
      <pubDate>Tue, 04 Aug 2026 09:00:00 GMT</pubDate>
      <dc:creator>Sourabh Singh</dc:creator>
      <category>Identity</category>
      <enclosure url="https://media.authfi.io/blog/post-covers/cover_saml_vs_oidc_b911e32f66.webp" type="image/webp" length="0" />
    </item>
    <item>
      <title>Account recovery without account takeover</title>
      <link>https://blog.authfi.io/blog/identity/account-recovery-without-account-takeover</link>
      <guid isPermaLink="true">https://blog.authfi.io/blog/identity/account-recovery-without-account-takeover</guid>
      <description>Recovery is the weakest door into most accounts. Design rules for a recovery email that helps a locked-out person without handing an attacker a second way in.</description>
      <pubDate>Tue, 28 Jul 2026 09:00:00 GMT</pubDate>
      <dc:creator>Sourabh Singh</dc:creator>
      <category>Identity</category>
      <enclosure url="https://media.authfi.io/blog/post-covers/cover_account_recovery_without_account_takeover_734e7da2be.webp" type="image/webp" length="0" />
    </item>
    <item>
      <title>Workforce identity vs customer identity: what differs</title>
      <link>https://blog.authfi.io/blog/identity/workforce-vs-customer-identity</link>
      <guid isPermaLink="true">https://blog.authfi.io/blog/identity/workforce-vs-customer-identity</guid>
      <description>Employees and customers both sign in, but the users, scale, lifecycle and sign-in methods differ. Here is how the two compare and when one platform fits both.</description>
      <pubDate>Tue, 21 Jul 2026 09:00:00 GMT</pubDate>
      <dc:creator>Sourabh Singh</dc:creator>
      <category>Identity</category>
      <enclosure url="https://media.authfi.io/blog/post-covers/cover_workforce_vs_customer_identity_7340bda32c.webp" type="image/webp" length="0" />
    </item>
    <item>
      <title>Why every secret key lives in one place</title>
      <link>https://blog.authfi.io/blog/security/why-every-secret-key-lives-in-one-place</link>
      <guid isPermaLink="true">https://blog.authfi.io/blog/security/why-every-secret-key-lives-in-one-place</guid>
      <description>Signing keys, SSH authorities, SAML certificates and sealed secrets belong behind one key service. How envelope encryption and rotation with a grace window work.</description>
      <pubDate>Tue, 14 Jul 2026 09:00:00 GMT</pubDate>
      <dc:creator>Sourabh Singh</dc:creator>
      <category>Security</category>
      <enclosure url="https://media.authfi.io/blog/post-covers/cover_why_every_secret_key_lives_in_one_place_7c30033f1e.webp" type="image/webp" length="0" />
    </item>
    <item>
      <title>Replacing long-lived SSH keys with short-lived certificates</title>
      <link>https://blog.authfi.io/blog/security/short-lived-ssh-certificates</link>
      <guid isPermaLink="true">https://blog.authfi.io/blog/security/short-lived-ssh-certificates</guid>
      <description>SSH keys copied to servers outlive the people who made them. Certificates signed by a CA expire in minutes, name who may log in and leave a record. How they work.</description>
      <pubDate>Tue, 07 Jul 2026 09:00:00 GMT</pubDate>
      <dc:creator>Sourabh Singh</dc:creator>
      <category>Security</category>
      <enclosure url="https://media.authfi.io/blog/post-covers/cover_short_lived_ssh_certificates_41230287fc.webp" type="image/webp" length="0" />
    </item>
    <item>
      <title>Step-up authentication: a stronger factor only when it matters</title>
      <link>https://blog.authfi.io/blog/security/step-up-authentication</link>
      <guid isPermaLink="true">https://blog.authfi.io/blog/security/step-up-authentication</guid>
      <description>Step-up authentication asks for a stronger or fresher factor only before sensitive actions. Which actions to cover, how fresh a session must be, and how to avoid MFA fatigue.</description>
      <pubDate>Tue, 30 Jun 2026 09:00:00 GMT</pubDate>
      <dc:creator>Sourabh Singh</dc:creator>
      <category>Security</category>
      <enclosure url="https://media.authfi.io/blog/post-covers/cover_step_up_authentication_9f0a2ae3eb.webp" type="image/webp" length="0" />
    </item>
    <item>
      <title>How this blog runs on Cloudflare Workers</title>
      <link>https://blog.authfi.io/blog/engineering/running-the-blog-on-cloudflare-workers</link>
      <guid isPermaLink="true">https://blog.authfi.io/blog/engineering/running-the-blog-on-cloudflare-workers</guid>
      <description>This blog is a Next.js app on Cloudflare Workers with a Strapi CMS. Pages are pre-rendered, cached at the edge and regenerated only when a webhook says content changed.</description>
      <pubDate>Tue, 23 Jun 2026 09:00:00 GMT</pubDate>
      <dc:creator>Sourabh Singh</dc:creator>
      <category>Engineering</category>
      <enclosure url="https://media.authfi.io/blog/post-covers/cover_running_the_blog_on_cloudflare_workers_d88960b7cf.webp" type="image/webp" length="0" />
    </item>
    <item>
      <title>Keeping identity data in your region</title>
      <link>https://blog.authfi.io/blog/engineering/keeping-identity-data-in-your-region</link>
      <guid isPermaLink="true">https://blog.authfi.io/blog/engineering/keeping-identity-data-in-your-region</guid>
      <description>Identity data is personal data. What counts as identity data, how regional planes and a global control plane divide the work, and what may reasonably cross a border.</description>
      <pubDate>Tue, 16 Jun 2026 09:00:00 GMT</pubDate>
      <dc:creator>Sourabh Singh</dc:creator>
      <category>Engineering</category>
      <enclosure url="https://media.authfi.io/blog/post-covers/cover_keeping_identity_data_in_your_region_21a7412ef7.webp" type="image/webp" length="0" />
    </item>
    <item>
      <title>Designing an audit record you can query</title>
      <link>https://blog.authfi.io/blog/engineering/an-audit-record-you-can-query</link>
      <guid isPermaLink="true">https://blog.authfi.io/blog/engineering/an-audit-record-you-can-query</guid>
      <description>An audit record should answer who did what, on whose behalf, from where and with what outcome. How to design the fields, make it tamper-evident and keep it searchable.</description>
      <pubDate>Tue, 09 Jun 2026 09:00:00 GMT</pubDate>
      <dc:creator>Sourabh Singh</dc:creator>
      <category>Engineering</category>
      <enclosure url="https://media.authfi.io/blog/post-covers/cover_an_audit_record_you_can_query_50ca2303ac.webp" type="image/webp" length="0" />
    </item>
    <item>
      <title>RBAC done properly: roles, bindings and least privilege</title>
      <link>https://blog.authfi.io/blog/product/rbac-roles-bindings-and-least-privilege</link>
      <guid isPermaLink="true">https://blog.authfi.io/blog/product/rbac-roles-bindings-and-least-privilege</guid>
      <description>Role-based access control decays unless it is maintained. How permissions, roles and bindings fit together, and how to find roles nobody holds or that grant nothing.</description>
      <pubDate>Tue, 02 Jun 2026 09:00:00 GMT</pubDate>
      <dc:creator>Sourabh Singh</dc:creator>
      <category>Product</category>
      <enclosure url="https://media.authfi.io/blog/post-covers/cover_rbac_roles_bindings_and_least_privilege_828cd4a8b6.webp" type="image/webp" length="0" />
    </item>
    <item>
      <title>Kubernetes access tied to a person&apos;s identity</title>
      <link>https://blog.authfi.io/blog/product/kubernetes-access-tied-to-identity</link>
      <guid isPermaLink="true">https://blog.authfi.io/blog/product/kubernetes-access-tied-to-identity</guid>
      <description>A shared kubeconfig tells the cluster nothing about who is calling. How OIDC, RBAC subjects and short-lived credentials tie Kubernetes access to a person or workload.</description>
      <pubDate>Tue, 26 May 2026 09:00:00 GMT</pubDate>
      <dc:creator>Sourabh Singh</dc:creator>
      <category>Product</category>
      <enclosure url="https://media.authfi.io/blog/post-covers/cover_kubernetes_access_tied_to_identity_7a1859786a.webp" type="image/webp" length="0" />
    </item>
    <item>
      <title>How to evaluate an identity provider: a checklist</title>
      <link>https://blog.authfi.io/blog/product/how-to-evaluate-an-identity-provider</link>
      <guid isPermaLink="true">https://blog.authfi.io/blog/product/how-to-evaluate-an-identity-provider</guid>
      <description>A vendor-neutral checklist for choosing an identity provider: protocols, sign-in methods, lifecycle, audit, data residency, key custody, AI agents and your exit plan.</description>
      <pubDate>Tue, 19 May 2026 09:00:00 GMT</pubDate>
      <dc:creator>Sourabh Singh</dc:creator>
      <category>Product</category>
      <enclosure url="https://media.authfi.io/blog/post-covers/cover_how_to_evaluate_an_identity_provider_e1fd8cee3b.webp" type="image/webp" length="0" />
    </item>
  </channel>
</rss>