Skip to content
Cloud Security DeskSearch
Menu

Evidence search

Search

Search titles, summaries, topics, providers, authors, and the full open-access corpus.

Results for “oauth”

5 publications
Technical guideSource-based analysis

Bind OAuth tokens to the client that presents them

DPoP can make possession of an access token insufficient for use, provided the issuer, client and resource server implement the same proof and key-binding contract.

Identity & access · IETF / Google · By Cloud Security Desk
Technical guideSource-based analysis

Restrict device code sign-in without breaking approved clients

Restrict device-code authentication through an explicit client and resource policy, and test the tracked sessions that can outlive the initial browser approval.

Identity & access · Microsoft / IETF · By Cloud Security Desk
Technical guideSource-based analysis

Workload federation across clouds needs separate trust decisions

Cross-cloud federation adds trust decisions, not a portable permission system. Map each credential and resource grant before moving a runtime workload.

Identity & access · AWS / Google Cloud / Microsoft Entra · By Cloud Security Desk
Technical guideSource-based analysis

Where fine tuning data needs a trust boundary

A training dataset can preserve its checksum and still teach the wrong behavior. Admission controls need to separate origin, transformation, approved use and the model change they produce.

AI systems · By Cloud Security Desk
Technical guideSource-based analysis

Keep MCP tokens bound to the intended resource

Keep token audiences, user consent, and downstream tool authority separate when reviewing a protected HTTP MCP service.

AI systems · MCP · By Cloud Security Desk