Co-founder @keycardai. 🛠️ @passportjs. ❤️ HTTP 401-403. #openid #oauth #wimse #mcp #x402

San Francisco, CA
Language is both the oldest technology and the newest technology. This is what makes AI so magical, indicating its potential.
3
141
Reading Claude’s written English feels a bit like reading English from over a century ago. The same language, but yet distinctly different. Some emergent new culture shift.
1
216
I find myself switching to terminal command lines, and mistakenly typing prompts. How long till the shell is just an LLM?
3
11
984
I love auto mode, but sometimes worry it’s just YOLO mode renamed.
1
2
252
The discussions around agentic coding (factories, slop, etc) parallel the same discussions about how to effectively build software with humans. Agents work at machine speed, which magnifies the problems.
2
9
318
Anytime static credentials are used, they put a limit on achieving zero-standing privilege. Credentials and permissions need to be negotiated dynamically. Challenge-response mechanisms exist for this today but are underutilized. That needs to change.
2
2
10
589
Prediction: existing systems of record - which are apps in disguise - will get disrupted by new systems of record that don’t attempt to be harnesses, but rather consumed easily from any harness
Prediction: systems of record will need to become AI harnesses or face replacement by agents
3
320
Humans exist in the physical world, and need to prove there identity in the digital world. Crossing those two spaces creates friction that SSO reduces. Agents exist natively in the digital world, and can be constantly authenticated without that friction.
2
4
511
There still is (should be?) friction when agents cross over into the human world (human-in-the-loop) - but that friction has little to do with agent authentication.
1
1
130
Auth to remote MCP servers should be treated identically to any other HTTP resource. Nothing being defined need be MCP specific, especially now that the protocol is moving to a stateless approach.
6
1
12
838
Recommended thread. AI is still early, with agents still awaiting their moment that chatbots had nearly 4 years ago when ChatGPT landed. UX and workflow innovation will unlock tremendous latent potential.
If you’re trying to understand the dynamic of real world agent adoption this post is a great place to start. Everyone got so hooked on talking to chatbots that there’s limited recognition still that working with an agent is much more like managing someone in a process vs. just asking an ai some questions and getting a response back. “prompting an agent is closer to writing a spec than asking a question. you have to scope the task extensively and define what "done" looks like.” Ultimately, the real upside of agents is when you start to change the underlying workflow itself instead of just treating it as another system you ask questions of. This means getting the agents the right data to work with, crossing organizational boundaries, and evolving the human in the loop steps for when people actually review the work. All of this has to change about today’s processes for the big upside to occur. The end result is that it’s most likely that the vast majority of token usage in an enterprise will be agents that are “deployed” to go execute tasks inside of workflows.
2
552
All these distributable package formats have me feeling like this is the CD-ROM era of AI.
Introducing Agent Plugins, an open standard for extending agents. Supports Agent Skills and MCP, with more to come. Built in collaboration with: @awsdevelopers, @code, @cursor_ai, @github, and @openaidevs. vercel.com/blog/introducing-…
1
5
1,051
Collaboration has always been about meaningful participation and contribution to a joint effort. AI is raising that bar: gruhn.me/blog/2026-08-03/
2
406
30,000 feet in the air, connected to a satellite at 200 Mbps with 35 ms latency, chatting with an artificially intelligent machine. No flying cars, but still pretty sci-fi. Will see if the AI machine is also on a satellite in a couple years.
2
1
11
738
Jared Hanson retweeted
MCP goes stateless on July 28. Per-session initialization disappears. Good for scaling. It also removes the checkpoint where most teams have been treating authorization as solved. The initialize handshake was never defined as an auth boundary. A lot of deployments are built as if it was. Every tool call is now independent. That is actually the right shape for per-action authorization. Each call needs to carry its own proof. The session was always the wrong unit for that problem.
1
809
If you’re not personally editing what you publish under your name, you sound the same as everyone else publishing AI written articles.
7
10
1,268
Publishing your prompts would be more insightful.
1
2
667
AI writing is different than AI engineering. Average code is usually desirable. Average prose is not.
2
3
620