Resources
Product Blog
Technical deep dives, architecture notes, and engineering write-ups from the SecureAuth product team.
Product Radar: August 2026
Everything we shipped in August, in one place. Rate limits and per-service grants for AI agents, delegated application assignment and embeddable sign-in for B2B and CIAM, risk-based prompts for the workforce, and more.
FAPI 2.0 certified: putting consumers in control of their data
When your bank lets a budgeting app see your transactions, you should be the one who says yes, decides how long that access lasts, and can take it back whenever you want. Open banking made that the expectation. FAPI, short for Financial-grade API, is how it actually works.
Agent API security: FAPI 2.0 is the floor
The software calling your APIs used to be a browser or a mobile app. More and more, it is an AI agent, acting for a person and making calls on its own, without anyone watching each step. That means route checks and bearer tokens are no longer enough on their own.
How we let agents reach real enterprise systems without over-permissioning them
A product update on recent weeks. Microsoft 365 Graph reached GA with SharePoint, OneDrive, and Teams access, eight connectors joined the catalog, and cost is now attributed by team. The theme is reach that stays governed.
Product Radar
Everything we shipped, in one place. Agent Authority for securing and governing AI agent access to enterprise systems, plus lower OTP costs on your own carrier, OTP fraud blocked by default, passkeys that survive a domain change, scoped Dashboard access and native OpenLDAP.
Agent Radar: MCP Gateway
Once an agent can act on your systems, who makes sure it does only what it should? Agent Authority exists to enforce that boundary: a runtime control plane and governance layer for deploying agents securely across an organization.
Your IdP authorized the connection, not the action
First in a three-part series. EMA and ID-JAG are a genuinely good open standard for governing the door, and they were never built to decide whether a specific action should run. Here is exactly where connection governance stops.
The Agent Authority pattern
Part 3 of 3. If SCIM cannot be the kill switch, something on your side of every vendor boundary must be. Agent Authority: token custody, per-call ticket exchange, and revocation measured in milliseconds.
Your agent does not log in. SCIM does not know that.
Part 2 of 3. SCIM is a wire protocol, not a guarantee, and your blast radius is the worst vendor in your stack. Why SCIM-based revocation cannot be the kill switch you need for agent tokens.
The new JML gap: agents outlive their humans
Part 1 of 3. Deprovisioning revokes the human in Okta, but the agent runtime on a personal laptop keeps refreshing cached tokens long after Monday. The new shape of the Joiner-Mover-Leaver problem.
Ready to secure your identity stack?
Talk to our team about how SecureAuth delivers continuous identity security across workforce, customer, and AI agent identities.