DEV Community

#oauth

OAuth flow implementation details

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Supercharging DeepSeek Harness: Bringing Claude Pro/Max with One-Click Google/Gmail OAuth Login and Real-Time Quota Tracking

Supercharging DeepSeek Harness: Bringing Claude Pro/Max with One-Click Google/Gmail OAuth Login and Real-Time Quota Tracking

1
Comments
5 min read
Seven ways a remote MCP server gets authorization wrong

Seven ways a remote MCP server gets authorization wrong

Comments
5 min read
The confused deputy, or why "just forward the token" breaks your MCP server

The confused deputy, or why "just forward the token" breaks your MCP server

Comments
3 min read
OAuth 2.1 for MCP servers, done properly

OAuth 2.1 for MCP servers, done properly

Comments
4 min read
Error 400: redirect_uri_mismatch, explained character by character

Error 400: redirect_uri_mismatch, explained character by character

Comments
5 min read
Google OAuth 2.0 for Developers: Implementation, Security Best Practices, and Troubleshooting

Google OAuth 2.0 for Developers: Implementation, Security Best Practices, and Troubleshooting

Comments
13 min read
ANAF SPV E-Invoicing from Java/Spring Boot: OAuth2, JWT Access Tokens, and a Refresh Window That Never Rests

ANAF SPV E-Invoicing from Java/Spring Boot: OAuth2, JWT Access Tokens, and a Refresh Window That Never Rests

Comments
7 min read
Supabase OAuth redirects to localhost in production: the allow-list rule nobody reads

Supabase OAuth redirects to localhost in production: the allow-list rule nobody reads

1
Comments
4 min read
OAuth Consent Phishing: The Attack a Password Change Does Not Fix

OAuth Consent Phishing: The Attack a Password Change Does Not Fix

Comments
4 min read
Oauth 2.0 implementation for servicenow applications

Oauth 2.0 implementation for servicenow applications

Comments
8 min read
A provisioned Keycloak client inherits no PKCE pin, and the obvious fix is inert

A provisioned Keycloak client inherits no PKCE pin, and the obvious fix is inert

1
Comments
6 min read
A browser I never opened logged me in — as the wrong person

A browser I never opened logged me in — as the wrong person

1
Comments
3 min read
Refresh Token Rotation Under the Hood: How Auth0 Catches a Stolen Token Before It's Ever Replayed

Refresh Token Rotation Under the Hood: How Auth0 Catches a Stolen Token Before It's Ever Replayed

Comments
4 min read
Twitch Accepts Invalid Keys and Silently Discards Them — The Hidden Pitfalls of Integration and a 41-Second Recovery

Twitch Accepts Invalid Keys and Silently Discards Them — The Hidden Pitfalls of Integration and a 41-Second Recovery

Comments
10 min read
OAuth Failure Recovery: Why I Choose Safe Retries for Authorization and Callback Steps

OAuth Failure Recovery: Why I Choose Safe Retries for Authorization and Callback Steps

Comments
7 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.