#identity

Wiki 6

  • Agents as first-class identities Giving agents their own key pairs and signed event trails instead of running them through a shared bot account β€” attribution survives, but effort still doesn't
  • don't sign in with google (the smart ape, 2026) A friend's three-year SaaS dies overnight when Google suspends his account β€” the thread walks through cascading SaaS lockout, four post-password-reset attack vectors, and a triage rule for when SSO is actually fine
  • Ephemeral Credentials Short-lived credentials (≀1 day) where rotation is structural rather than scheduled β€” minted per session, expire on their own
  • Google OAuth domain-takeover flaw (Truffle Security, Jan 2025) Buying a dead startup's domain for $12 lets you re-create old employee emails on Workspace and log into the dead company's Slack/Notion/Zoom via "Sign in with Google" β€” initially marked won't-fix, $1,337 bounty after public pressure
  • Inverted claim onboarding Onboarding pattern where the AI agent registers first and a human "claims" it via OTP; until then, the agent has a one-recipient cap
  • SSO concentration risk SSO trades distributed risk for concentrated risk β€” same expected loss in theory, dramatically worse failure mode in practice when the IdP terminates the relationship