Evidence search
Search
Search titles, summaries, topics, providers, authors, and the full open-access corpus.
Results for “oauth”
5 publicationsBind OAuth tokens to the client that presents them
DPoP can make possession of an access token insufficient for use, provided the issuer, client and resource server implement the same proof and key-binding contract.
Identity & access · IETF / Google · By Cloud Security DeskRestrict device code sign-in without breaking approved clients
Restrict device-code authentication through an explicit client and resource policy, and test the tracked sessions that can outlive the initial browser approval.
Identity & access · Microsoft / IETF · By Cloud Security DeskWorkload federation across clouds needs separate trust decisions
Cross-cloud federation adds trust decisions, not a portable permission system. Map each credential and resource grant before moving a runtime workload.
Identity & access · AWS / Google Cloud / Microsoft Entra · By Cloud Security DeskWhere fine tuning data needs a trust boundary
A training dataset can preserve its checksum and still teach the wrong behavior. Admission controls need to separate origin, transformation, approved use and the model change they produce.
AI systems · By Cloud Security DeskKeep MCP tokens bound to the intended resource
Keep token audiences, user consent, and downstream tool authority separate when reviewing a protected HTTP MCP service.
AI systems · MCP · By Cloud Security Desk