Skip to content

standard

OpenID Connect

OpenID Connect is an identity protocol built on OAuth 2.0 that lets applications verify user identity via ID tokens issued by a trusted authorization server.

Known aliases

  • id_token
  • OIDC
  • OIDC SSO

Relationships

No evidence-backed relationships are recorded.

Current stories

build1 publisher

A static denylist stopped one more prompt injection than no protection in a coding-agent study

Bouras, Dai and Mechtaev found a static denylist let 46 of 75 prompt injections execute in a coding agent, against 3 under preflight-scoped capabilities. A same-day Google report of malware stealing OIDC tokens from GitHub Actions runners puts the outer limit on an agent in the CI job's permissions.

Publishers:dev.to

Reality

Evidence45
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence50

Earlier coverage

  1. Draft ORKS spec hands revocation of a leaked API key to whoever finds it

    Security · September 9, 2026 · 1 publisher

  2. A public OIDC client with PKCE replaces the cluster certificate that outlives its owner

    Product · September 9, 2026 · 1 publisher

  3. A pull request comment triggered a trusted workflow that published ten malicious npm versions

    Build · September 8, 2026 · 1 publisher

  4. Anonymisation trades away the property that made the test fixture useful

    Build · September 8, 2026 · 1 publisher

  5. CSA's Agentic Trust Framework maps agent autonomy to an auth stack you already run

    Product · September 6, 2026 · 1 publisher

  6. npm 10.8.2 publishes unauthenticated when you configure Trusted Publishing

    Build · September 6, 2026 · 1 publisher

  7. NVIDIA routes every cluster's identity check through one session-owning gateway

    Build · September 3, 2026 · 1 publisher

  8. GitGuardian finds a Shai-Hulud variant sweeping 469 credential paths across CI/CD and AI configs

    Security · September 3, 2026 · 1 publisher

  9. Bedrock's Sydney and Melbourne GPT-5.6 endpoints delegate the processing Region to AWS

    Build · September 2, 2026 · 1 publisher

  10. Someone has to own the authority chain before an agent's purchase order clears

    Leadership · September 1, 2026 · 1 publisher

  11. TeamCity's new OIDC plugin turns your build server into the credential issuer

    Build · September 1, 2026 · 1 publisher

  12. Google Cloud IAP fences staging for free until the client stops being a browser

    Build · September 1, 2026 · 1 publisher

  13. Putting the deploy command next to the app leaves CI one verb to call

    Build · August 31, 2026 · 1 publisher

  14. A missing attribute condition admits every identity its provider will vouch for

    Build · August 31, 2026 · 1 publisher

  15. Jenkins static AWS keys work from anywhere; the OIDC replacement fails in four known ways

    Build · August 27, 2026 · 1 publisher

  16. Kubernetes Secrets are a distribution problem, and the database is where it shows

    Product · August 24, 2026 · 1 publisher

  17. One unvalidated region string sent signed AWS API calls to attacker.com

    Product · August 24, 2026 · 1 publisher

  18. Dropping long-lived AWS keys is half an EKS migration; the cluster still gets a vote

    Build · August 22, 2026 · 1 publisher

  19. Partition, not consolidation: what a 43-minute Jenkins queue actually cost

    Build · August 21, 2026 · 1 publisher

  20. Reading OIDC tokens out of runner memory: ChainDrop and the poisoned build

    Security · August 21, 2026 · 1 publisher

  21. The /userinfo fallback that quietly made Auth0 a hard dependency on every request

    Build · August 20, 2026 · 1 publisher

  22. Basic Auth becomes a gateway problem: AgentCore's Lambda interceptor keeps the password away from the model

    Build · August 18, 2026 · 1 publisher

  23. trelix's most useful release detail is an exit code, not the audit log

    Build · August 15, 2026 · 1 publisher