Back to articles

Tag archive

#auth

E
Jul 20, 2026

Every token validation hit our origin. Now the JWKS lives on the edge.

The two documents a service reads to validate one of our JWTs — the discovery doc and the JWKS — are the most-requested, least-secret things we serve, and every fetch used to come all the way back to origin. Caching them on Cloudflare was the easy part. The hard part is that a stale public-key cache must never reject a valid token, and here's the rotation-safe ordering that makes an aggressively-cached JWKS safe.

Jul 20, 20264 min read0 reactions0 comments
L
Jul 17, 2026

Las tres vidas de mi clave de firma JWT

Una sola clave privada firma todos los tokens que emite nuestro servidor de autenticación, y a lo largo de su vida se ha mudado dos veces: nació dentro del proceso, fue desterrada a una bóveda de la que no puede salir y luego se reencarnó en un tipo de clave completamente distinto, más pequeño y más rápido. Cada mudanza ocurrió en un emisor en producción, con tokens en circulación.

Jul 17, 20265 min read1 reactions0 comments
T
Jul 17, 2026

The three lives of my JWT signing key

One private key signs every token our auth server issues, and it has moved twice in its life: born inside the process, exiled to a vault it can't leave, then reincarnated as a smaller, faster kind of key entirely. Each move happened on a live issuer with tokens in flight. Here's what custody and algorithm changes actually take, and the quiet regression that rode in on a "more secure" commit.

Jul 17, 20264 min read2 reactions1 comments
A
Jul 6, 2026

An identity provider told us who you were, and we believed it

Single sign-on means trusting the identity provider. We trusted it for one thing too many: we resolved returning federated users by the email in the assertion, so any connection could assert someone else's address and land on their account. The fix wasn't more validation. It was changing the identity join key from email to a per-provider subject the asserting party can't forge.

Jul 6, 20264 min read1 reactions0 comments
E
Jul 6, 2026

El scale-to-zero no sabe contar hasta uno

Azure Container Apps prometía que dejáramos de pagar por un clúster de autenticación inactivo. Calculamos el coste de la migración y la descartamos, no por el precio ni por los arranques en frío, sino porque al serverless le falta el único número que una backplane de autenticación con elección de líder realmente necesita.

Jul 6, 20264 min read1 reactions0 comments