We spoke @voxxedamsterdam about a topic that some people find controversial - don't use JWTs for authorization. What do you think? https://t.co/OOTd6FVlfy
The SpiceDB Playground just got an update. You can try SpiceDB directly in your browser (no install required) making it easy to explore fine-grained authorization and permissions modeling with real examples.
Explore example schemas, write and test your own schema, run real permission checks, experiment with relationships and access patterns in real time and more!
Check it out, https://t.co/8mtyhBRL7i, or learn more on the blog, https://t.co/jrZqb4kFMT.
“This video teaches viewers why authorization—the system that determines who or what is allowed to do specific actions—is becoming one of the most critical infrastructure layers in the AI era.”
Thank you @Scobleizer for talking all things permissions in the Ai era.
It might not be sexy, but everyone uses authorization technology.
Here I sit with the founder/CEO, Jake Moshenko, of https://t.co/k4nTjG67Kw
This video teaches viewers why authorization—the system that determines who or what is allowed to do specific actions—is becoming one of the most critical infrastructure layers in the AI era.
While authorization has traditionally been a back-end enterprise concern, the rise of AI agents, agent swarms, autonomous tools, robotics, and eventually brain-computer interfaces makes it a frontline issue for both businesses and consumers.
The interview explains how authorization is evolving from a “boring IT function” into foundational infrastructure for the agentic future.
We updated our Timeline of Model Context Protocol (MCP) Security Breaches post to include the latest security breaches. You can read more about major MCP-related breaches and security failures - what happened, what data was exposed, why it happened, and what they reveal about the new threat surface LLMs bring into organizations. https://t.co/Wr0QLbdLKf
Wrestling with permissions, roles, or access control complexity? Take a second and try out AuthZed Cloud - we're offering $700 in credits so you can see what scalable, modern authorization infrastructure can do for your applications. Try it out, https://t.co/nzvoH1ggQh
In SF this weekend? Join us at the JetBrains Codex Hackathon - we will be onsite helping teams with agent authorization as well as participating as judges. 1st place winners receive a $3000 cash award. Learn more here and join us, https://t.co/wWsuK8LxXj
Your coding agent needs better permissions, and so does the code it writes - that is why today we are introducing SpiceBox, fine-grained permissions for AI coding agents, and spicedb-dev, authorization expertise for your coding agent. Both tools are open source, learn more on our blog, https://t.co/nAkvTlxhgY
AI is moving fast but most teams are still relying on authorization models that weren’t built for it. AI initiatives are stalling not because of technical complexity but because the permissions layer wasn't designed for it.
We wrote more about why you need to think about modernizing authorization in the AI era here, https://t.co/PNO0d1MrXB
If this is top of mind for you, join us today for SpiceDB Community Day where we will explore how to implement permissions for AI workflows (hear from Manuel de la Peña of @Docker talk about Permission-Aware RAG and Mark Fogle of @clawtocracy talk about how SpiceDB Stops Agentic Oversharing) and get a SpiceDB Update too. You can register or tune in here at 10 am PT, https://t.co/0eoPlNNAo9
The AuthZed Cloud Datastore, Unlocked - As of today, we've unlocked the ability for customers of the AuthZed Cloud platform to scale operations themselves. AuthZed is stepping out of the way, not only to provide more visibility but to also give customers operational independence.
Read more on the blog, https://t.co/wFOQelRTIH, and try it out in AuthZed Cloud, https://t.co/FXrjWdwCDo, today!
Check out the February SpiceDB release. We introduced:
-Postgres Foreign Data Wrapper
-Query Planner
-Keyword in Permissions
Learn more yourself here, https://t.co/b564cojw16
Access control will soon need to track:
-Which documents an agent accessed
-What an agent requested versus received
-When permissions changed mid-task
-How agent capabilities map to user permissions
Agents will request access dynamically. Systems will make just-in-time decisions. Ambient context that constantly shifts as agents work and permissions update, doesn't fit the policy engine model.
Policy Engines Don't Work for AI Authorization. https://t.co/vXzKLZLv25
Introducing the SpiceDB Foreign Data Wrapper (FDW) for PostgreSQL, a new experimental way to bring real-time authorization context from SpiceDB into Postgres queries, all without duplicating data, rewriting policies, or embedding authorization logic where it doesn't belong. Read more here and try it out yourself, https://t.co/IpuaPm09KG.
About 15 minutes until go time - join us live where we will be talking about what permissions agents should have and why. What do you want an agent to access when it is acting on behalf of you or as an employee? https://t.co/ID65V7r1NS
What is an Agent Identity? Is it a representation of me or does it stand on its own? Join AuthZed tomorrow (Tuesday) at 8:30 am PT / 11:30 am ET to learn more about falsehoods people believe about agent authorization. Register here, https://t.co/ID65V7r1NS
Happy Permission Checks Year! We're starting out 2026 by giving individuals at organizations the fast path to implementing the same authorization technology used by companies like OpenAI, Workday, Turo and more. We're giving away $700 worth of credit to try out AuthZed Cloud and see the value of a scalable authorization solution. This credit is enough to fund weeks of authorization. Learn more and apply here, https://t.co/DklLlWHQoI
MCP is not secure. Security is left to the implementers.
https://t.co/nSgyKah0hk
The common thread isn’t sophisticated zero day exploits. It’s authorization failures. Over-privileged tokens, missing access controls, inadequate isolation and supply chain trust assumptions that didn’t hold up.
AI agents need authorization, not just access.
At #KubeCon, AuthZed’s SpiceDB showed how to secure non-human identities with fine-grained, low-latency permissions.
Think: AI with traceability, accountability & human-in-the-loop control.
#AIsecurity#Authorization#SpiceDB