Good example why tightly scoped, time-limited, intent-driven grants are necessary for LLM->tool calls. It's crazy that we're still doing this "keys to the kingdom" approach - it's a huge ticking time bomb.
It's the reason I've been working on https://t.co/6pOq7F5PeX
MCP community is starting to look this way as well, but nowhere near fast enough!
Has anyone else noticed an interesting - and perhaps game-changing - side effect of agentic coding?
Because implementation is so much faster, I’ve found myself relying far less on long-lived branches. Instead of multiple features evolving in parallel and eventually colliding during merges, it’s often faster to finish one change, merge it, and move on to the next.
I’m not suggesting branching goes away, but it feels like the economics of branching have changed. When branches are shorter-lived, merge conflicts and coordination overhead drop significantly, and the development process becomes much more linear. I hadn’t expected how much of a productivity boost - and mental relief - that would be.
Has anyone else experienced this, or do you see it differently?
built a ics calendar feed of slack tides in the area, enriched by weather data, filtered for waking hours. Just added to my aggregate calendar and no need to ever look those up again! #vibecoding is fun!
(let me know if you need it and I'll share privately)
I like what @GeminiApp is doing with Daily Briefs etc, but these features are buggy as heck and lack integration. :( Like not being able to recall the briefs or the follow up conversations from anywhere. Crazy they would put it out like this.
BREAKING: The Model Context Protocol team has promoted its Enterprise-Managed Authorisation extension to stable status, adding a centralized way for organizations to control access to MCP servers through their identity provider. The project states the aim is to replace per-server consent prompts with a zero-touch flow in which users sign in once and then access approved servers without further setup. https://t.co/AKBvoldEEI
We've been tracking the emerging MCP Enterprise-Managed Authorization direction closely, and shipped a concrete AgentPass implementation path for it.
In a nutshell: enterprise MCP auth tells a provider who is calling and under what enterprise identity context. AgentPass adds the runtime authorization layer: is this agent allowed to take this specific action, for this job, resource, customer, approval, and JIT grant?
This week we added:
- Enterprise JWT validation for MCP gateway calls
- Claim mapping into AgentPass authorization events
- Scope/group/client/issuer checks before tool execution
- Provider authorization receipts that bind the decision to enterprise identity context
- Provider-side verification before execution
- JWKS caching and key rotation support
- A hosted Cloudflare demo showing both allow and denial paths
The denial path is important: even if a receipt is validly signed, the provider can reject execution when enterprise bindings do not match its trust policy. That is the line we think matters for real provider MCP adoption.
MCP auth gets the connection under control. AgentPass makes the action auditable, scoped, and enforceable.
Repo: https://t.co/6pOq7F5PeX
@MunshiPremChnd This is great, but it's not going far enough. EMA gets agents connected. https://t.co/oc36Kk4Shg keeps tool execution scoped, approved, and auditable. Integrates with EMA.
AI agents need runtime guardrails, not just better prompts.
I just published @dinpd/ai-agent-guard: a small TS package for gating agent tool calls before execution.
Covers spend caps, tool loops, PII egress, approvals, and audit logs.
https://t.co/0FId2LWnDi
@Tesla - how hard is it to add a “right turns mostly route” preference to navigation? Shouldn’t be that hard. Will save 1.5 min x 4 left turns = 6 mins on an average drive.
AgentID is now AgentPass.
I’m adding a DevOps/SRE use case:
Agents should be able to inspect prod.
But changing prod should require scoped JIT authority, live evidence, human approval, provider receipts, audit, and rollback control.
https://t.co/ya11iTB2q9
I’m starting to work on AgentID: open-source authz for AI agent tool calls.
The idea is simple: define and enforce what agents can do: identity, action, blast radius, JIT approval, audit, and drift.
https://t.co/fKnYT5yvMq
Did anyone else have the experience of @googlefi claiming that the device wasn't activated properly or on time, in order to avoid crediting the promo amount?
@googlefi
- are you purposefully making it difficult to get the credits on the new phones? I hope not, but it sure seems that way when everything works when connecting new phone, only to see the credit due on the bill 3 months later because it "wasn't activated properly"! :((((
I’m totally for the first amendment, but people should be held responsible for their words and any misinformation they help spread! At least the algo should pick up on the quality of the info, not on likes @X