Sign in

Balázs Orbán

@balazsorban.com
323 followers 46 following 8 posts

tech lead at Unite AS. created @authjs.dev. previously @vercel.com, Next.js core, auth. work in progress.

PostsRepliesMedia
Balázs Orbán @balazsorban.com · 09/08/2026
I would love to see Al/dev companies create REAL metrics/reports on how Al is resulting in not just increased output but Alps matching or higher quality software than before. What are good ways to track this? Am I missing something?
000
Balázs Orbán @balazsorban.com · 05/05/2025
I've already seen tools that generate MCP servers. So... Why can't the LLM just do it by itself then?
010
Balázs Orbán @balazsorban.com · 05/05/2025
I'm genuinely curious, as right now it just feels like we are putting a non-deterministic layer on top of strict API specifications that are not AI-only, so anyone can integrate with them. Wasn't the point of AI to overtake human work? Now we are just writing code for it? 🤔
120
Balázs Orbán @balazsorban.com · 05/05/2025
Are there any public benchmarks/studies that prove/explain how and why MCP servers are better than giving an LLM your OpenAPI, etc. specs?
311
Balázs Orbán @balazsorban.com · 14/11/2024
OAuth = email+password, but delegated to someone who cares about it more than you could.
050
Balázs Orbán @balazsorban.com · 14/11/2024
(They are trying to discover an open redirect vulnerability in your app)
110
Balázs Orbán @balazsorban.com · 14/11/2024
Hi, this means someone is actually trying to hack your users, but Auth.js is mitigating them. Maybe time for setting up a firewall/bot protection!
100
Balázs Orbán @balazsorban.com · 12/11/2024
💚
000
Reposted by Balázs Orbán
Sebastian Markbåge @sebmarkbage.calyptus.eu · 10/11/2024
If you use auth with refresh tokens that have automatic reuse detection. I.e. if an auth token is expired, you can request a new one using the refresh token only once. How do YOU on your site deal with the race condition where opening multiple tabs/requests at once logs the user out? Not at all?
15997