Sign in

Aaron Parecki

@aaronpk.com
2K followers 133 following 266 posts

#OAuth #IndieWeb

PostsRepliesMedia
Aaron Parecki @aaronpk.com · 29/07/2026
Solid is mentioned there as one of the inputs to the draft!
030
Aaron Parecki @aaronpk.com · 29/05/2026
nice!
030
Aaron Parecki @aaronpk.com · 19/05/2026
my head feels like a blender that has been filled past the "do not fill above" line
020
Aaron Parecki @aaronpk.com · 12/04/2026
hmm I thought it was, but it's very possible something got knocked offline at some point
010
Aaron Parecki @aaronpk.com · 30/03/2026
Found my todo list for 2026 kylegabriel.com/projects/202...
kylegabriel.com
Automated Hydroponic System Build – Projects | Kyle Gabriel
020
Aaron Parecki @aaronpk.com · 30/03/2026
TIL about UIScreenshotService which enables iOS apps to provide a high res PDF screenshot of the app content when the user uses the system screenshot action! Chrome uses this to give a full export of the page!
040
Aaron Parecki @aaronpk.com · 27/03/2026
Thanks! That bit is hand written.
000
Aaron Parecki @aaronpk.com · 25/03/2026
I'm impressed, Cathay Pacific transferred my vegetarian meal request to the new flight they moved me to after the incoming flight was late and missed the connection. Normally airlines say oh well you didn't reserve the meal 72 hours before the flight.
030
Aaron Parecki @aaronpk.com · 08/03/2026
Happy final Daylight Savings Time Eve to all our friends in British Columbia! I hope we can join you on the other side soon!
041
Aaron Parecki @aaronpk.com · 06/03/2026
I'm setting up a temporary laptop for my next trip and it's shocking how much faster the cross-device passkey flow is compared to looking up and hand typing my long 1Password passwords
071
Aaron Parecki @aaronpk.com · 02/03/2026
Oh crazy, I didn't realize that. Yeah they should really add that.
110
Aaron Parecki @aaronpk.com · 02/03/2026
Sorry why wouldn't they be able to do client authentication with CIMDs? There's a description of how to do that in the spec.
100
Aaron Parecki @aaronpk.com · 13/02/2026
Inspired by some #indieweb folks creating /caw pages on their websites, I made one of my own! Here you can listen to the most recent crow recorded from my house: aaronparecki.com/caw/
aaronparecki.com
Caw
030
Aaron Parecki @aaronpk.com · 27/01/2026
Apparently I missed the introduction of the 4.4mm TRRRS audio jack 10 years ago and just now discovered it. What a cool idea.
010
Aaron Parecki @aaronpk.com · 15/01/2026
I'd be happy to talk, what we need right now is to demonstrate that the people who run websites you'd be logging in to also want to improve their UX with FedCM. Feel free to send people my way
230
Aaron Parecki @aaronpk.com · 13/01/2026
Oh crap I just realized the "it" he was referring to was probably the food, not his critical thinking.
070
Aaron Parecki @aaronpk.com · 13/01/2026
"I'll just check my critical thinking and nuke it in the microwave" has to be my favorite quote from this Business Insider video on Trader Joe's white-labeled food
110
Aaron Parecki @aaronpk.com · 12/01/2026
Me looking at my todo list on a Sunday night after having done at least a couple things today, yet somehow it looks more like a list of what I did *not* do today.
010
Aaron Parecki @aaronpk.com · 17/12/2025
oh no, due to a series of misclicks, I just accidentally archived the most recent 100 emails in my inbox. if nothing else, reviewing my "all mail" folder is doing a good job of making me question how important emails in my inbox actually are.
040
Aaron Parecki @aaronpk.com · 03/12/2025
Not that this is a 1:1 replacement, but it is one of the reasons I built Meetable.org, so communities can create their own calendars on their own domains.
meetable.org
GitHub - aaronpk/Meetable: an event listing website
an event listing website. Contribute to aaronpk/Meetable development by creating an account on GitHub.
192
Aaron Parecki @aaronpk.com · 25/11/2025
🔐 Enterprise-Managed Authorization extension (aka Cross App Access) - eliminate the OAuth redirect and get tokens for an MCP server by requesting them from the enterprise IdP Read more about what these mean for you in my full post 👉 aaronparecki.com/2025/11/25/1...
aaronparecki.com
Client Registration and Enterprise Management in the November 2025 MCP Authorization Spec
The new MCP authorization spec is here! Today marks the one-year anniversary of the Model Context Protocol, and with it, the launch of the new 2025-11-25 specification. I’ve been helping out with the ...
010
Aaron Parecki @aaronpk.com · 25/11/2025
The new MCP spec just dropped! 🎉 There's too many new things to get into everything, but there are two big changes I am most excited about 👀 📝 Client ID Metadata Documents (CIMD) - a simpler way to manage client registrations, clients describe themselves with a URL they control
125
Aaron Parecki @aaronpk.com · 15/10/2025
I don't know anything about the protocol but if they support the same OAuth spec as ATProto and same user ID discovery it would work
010
Aaron Parecki @aaronpk.com · 12/10/2025
even with all the emoji? lol
000
Aaron Parecki @aaronpk.com · 12/10/2025
👍👍
000
Aaron Parecki @aaronpk.com · 11/10/2025
The dots that Solid OIDC connected were to specifically use the RFC7591 vocabulary in a JSON doc at the client ID URL, whereas IndieAuth originally parsed the metadata from HTML, and OpenID Federation nests the metadata inside an "Entity Statement" JSON wrapper.
100
Aaron Parecki @aaronpk.com · 11/10/2025
I mean it was a big mix of things really. Most recently the JSON document idea came from there, but "client IDs as URLs" has been part of IndieAuth since 2015 web.archive.org/web/20150315... and OpenID Federation since 2016 openid.net/specs/openid...
120
Aaron Parecki @aaronpk.com · 11/10/2025
Yeah I definitely went hard mode by writing everything from scratch (except the JWT signing). Partly because I wanted to see what it actually takes to implement a library, partly because I can't stand the current state of most language's package management 😅
040
Aaron Parecki @aaronpk.com · 11/10/2025
I just finished adding BlueSky support to IndieLogin.com! Now you can log in to websites like indieweb.org with your BlueSky handle!
aaronparecki.com
Adding Support for BlueSky to IndieLogin.com
Today I just launched support for BlueSky as a new authentication option in IndieLogin.com!
48518
Aaron Parecki @aaronpk.com · 11/10/2025
The folks at Stytch put together a really nice explainer website about it too! cimd.dev
cimd.dev
CIMD - OAuth Client ID Metadata Documents
Learn about Client ID Metadata Documents (CIMD) - a new OAuth approach that lets clients identify themselves using URLs instead of preregistration. Presented by Stytch.
1153
Aaron Parecki @aaronpk.com · 11/10/2025
This could replace Dynamic Client Registration in MCP, dramatically simplifying management of clients, as well as enabling servers to limit access to specific clients if they want.
181
Aaron Parecki @aaronpk.com · 11/10/2025
The recent surge in interest in MCP has further demonstrated the need for this to be a standardized mechanism, and was the main driver in the latest round of discussion for the document!
160
Aaron Parecki @aaronpk.com · 11/10/2025
The mechanism of clients identifying themselves as a URL has been in use in IndieAuth for over a decade, and more recently has been adopted by BlueSky for their OAuth API.
1141
Aaron Parecki @aaronpk.com · 11/10/2025
Clients identify themselves with their own URL, and host their metadata (name, logo, redirect URL) in a JSON document at that URL. They then use that URL as the client_id to introduce themselves to an authorization server for the first time.
1100
Aaron Parecki @aaronpk.com · 11/10/2025
The IETF OAuth Working Group has adopted the Client ID Metadata Document specification! > This specification defines a mechanism through which an OAuth client can identify itself to authorization servers, without prior dynamic client registration or other existing registration.
1535
Aaron Parecki @aaronpk.com · 02/10/2025
Yes, I helped them with it. They also use the client-id-url technique that came from IndieAuth
160
Aaron Parecki @aaronpk.com · 20/09/2025
Thanks to everyone for your contributions and feedback so far! And thanks to my co-authors Karl McGuinness and Brian Campbell!
010
Aaron Parecki @aaronpk.com · 20/09/2025
While it will still be a while before it is an RFC, this is an important step in the standards process, as this is the first time the document is "official"! This signifies that the working group agrees that the problem is worth solving, and agrees on the general direction of the spec.
130
Aaron Parecki @aaronpk.com · 20/09/2025
The IETF OAuth Working Group has adopted the Identity Assertion Authorization Grant specification! datatracker.ietf.org/doc/draft-ie... This is the basis of Cross App Access (XAA), providing IT admins better visibility and control by configuring the app-to-app connections in their enterprise IdP.
datatracker.ietf.org
Identity Assertion Authorization Grant
This specification provides a mechanism for an application to use an identity assertion to obtain an access token for a third-party API by coordinating through a common enterprise identity provider us...
164
Aaron Parecki @aaronpk.com · 20/09/2025
Inspired by a question from @thisismissem.social, I wrote up a document describing how to apply DPoP (RFC9449) to the OAuth Device Flow (RFC8628). datatracker.ietf.org/doc/draft-pa...
datatracker.ietf.org
DPoP for the OAuth 2.0 Device Authorization Grant
The OAuth 2.0 Device Authorization Grant [RFC8628] is an authorization flow for devices with limited input capabilities. Demonstrating Proof of Possession (DPoP) [RFC9449] is a mechanism to sender-con...
030
Aaron Parecki @aaronpk.com · 20/09/2025
Here you go! datatracker.ietf.org/doc/draft-pa...
datatracker.ietf.org
DPoP for the OAuth 2.0 Device Authorization Grant
The OAuth 2.0 Device Authorization Grant [RFC8628] is an authorization flow for devices with limited input capabilities. Demonstrating Proof of Possession (DPoP) [RFC9449] is a mechanism to sender-con...
031
Aaron Parecki @aaronpk.com · 19/09/2025
The only way to get close to a real solution is using proximity solutions like WebAuthn does. There's an extensive discussion on this here: www.ietf.org/archive/id/d...
ietf.org
Cross-Device Flows: Security Best Current Practice
This document describes threats against cross-device flows along with practical mitigations, protocol selection guidance, and a summary of formal analysis results identified as relevant to the securit...
010
Aaron Parecki @aaronpk.com · 19/09/2025
DPoP should have added a section for the device code flow like this section about PAR. datatracker.ietf.org/doc/html/rfc... The device code flow is similar to PAR: the initial request is backchannel to the AS. So the same considerations that apply to PAR here apply to the device code flow.
datatracker.ietf.org
RFC 9449: OAuth 2.0 Demonstrating Proof of Possession (DPoP)
This document describes a mechanism for sender-constraining OAuth 2.0 tokens via a proof-of-possession mechanism on the application level. This mechanism allows for the detection of replay attacks wit...
110
Aaron Parecki @aaronpk.com · 19/09/2025
I agree DPoP binding should start with the initial request. But at the end of the day it doesn't make *that* much of a difference. The bigger risk with the device code flow is the phishing problem, which DPoP doesn't solve.
200
Aaron Parecki @aaronpk.com · 06/08/2025
Update: it worked! I only had to tap my phone and I got through TSA!
170
Aaron Parecki @aaronpk.com · 05/08/2025
It has come to my attention that I have previously loaded my passport into my Android phone as an "ID pass" which should theoretically get me through TSA legitimately
120
Aaron Parecki @aaronpk.com · 05/08/2025
It saves the tiniest bit of battery to enable it, and only works with the selected "express transit card" support.apple.com/guide/securi... But it means you can tap without even unlocking the phone!
support.apple.com
Express Cards with power reserve
If iOS isn’t running because iPhone needs to be charged, there may still be enough power in the battery to support Express Card transactions.
000
Aaron Parecki @aaronpk.com · 05/08/2025
If they do it like the transit card it'll still work when the phone battery is dead!
110
Aaron Parecki @aaronpk.com · 05/08/2025
Maybe some day Oregon will get on the mDL bandwagon and I won't need to rely on this silly piece of plastic anymore
220
Aaron Parecki @aaronpk.com · 05/08/2025
At least I have CLEAR right now so I should be able to get home without an ID.
100