search
OAuth
Trends
- 1OpenID Foundation Publishes Identity Management for Agentic AI▼Identity Management for Agentic AI [pdf] (2025)
The OpenID Foundation has released a 2025 white paper on identity management for agentic AI, addressing how autonomous AI agents should be authenticated, authorized and held accountable when acting on behalf of users. The paper, published as a PDF on the OpenID.net site, is drawing attention from developers and security professionals debating whether existing identity standards like OAuth can cope with machine-driven agents.
- 2OpenID Foundation Publishes Guidance on Identity Management for Agentic AI●OpenID Foundation: Identity Management for Agentic AI [pdf] (2025)
The OpenID Foundation has released a 2025 white paper on identity management for agentic AI, addressing how autonomous software agents can be authenticated and authorized when acting on behalf of users. The paper examines the gaps existing identity standards like OAuth and OpenID Connect leave when AI agents, rather than people, initiate actions across services. Developers and security professionals are weighing how current identity infrastructure can adapt to machine-driven agents.
- 3OpenID Foundation publishes guide on identity for agentic AI●OpenID Foundation: Identity Management for Agentic AI [pdf]
The OpenID Foundation has released a paper on identity management for agentic AI, addressing how autonomous AI agents should authenticate and be authorized when acting on behalf of users. The document examines how existing standards like OAuth and OpenID Connect can extend to machine agents that independently make decisions and take actions, a growing concern as companies deploy AI agents with access to sensitive systems and credentials.
- 4Critical CVSS 9.8 flaw reported in OAuth SSO plugin▼🚨 CVE-2026-97274 — CVSS 9.8 CRITICAL Unauthenticated Bypass Vulnerability in OAuth Single Sign On – SSO (OAuth Client) 🔎
A critical vulnerability, CVE-2026-97274, has been disclosed in the OAuth Single Sign On – SSO (OAuth Client) plugin, carrying a CVSS score of 9.8. The flaw is described as an unauthenticated authentication bypass, meaning attackers would not need credentials to exploit it. Security communities are circulating the advisory as organisations using OAuth-based single sign-on assess their exposure.