Articles for people who
ship the stack
Original rewrites on React, Node.js, TypeScript and AI — practical notes from the same engineering practice behind our operator software. Article bodies are in English.
Tagged: authorization
Secure MCP: when an AI agent gets keys to your systems
Treat Model Context Protocol tools as capabilities, not endpoints—separate authn from authz, fix confused deputies, minimize tool output, and assume the model is powerful and untrusted.
2709 wordsRead articleMapping the Auth Vocabulary: API Keys, Sessions, JWT, OAuth2, OIDC, SSO
Learn how API keys, sessions, JWTs, OAuth2, OpenID Connect and SSO fit together by sorting each one under a single question: who is calling, or what may they do.
2323 wordsRead articleBenchmark the Failure Path: Next.js, Remix and Stale Authorization Data
A case study of how a stale-permission bug reframes a Next.js versus Remix decision, and how to evaluate frameworks on mutations, cache lifetimes and debuggability.
2058 wordsRead articleRole-Based Access Control in Express with JWT and Two Middlewares
Learn how to enforce role-based access in an Express API by pairing JWT authentication middleware with a reusable authorize() guard, and when to answer 401 versus 403.
1024 wordsRead articleWhy Next.js Server Actions Need Authorization Inside Every Function Body
A dissected account-takeover case shows how unauthenticated Next.js Server Actions expose privileged operations, and where the authorization check has to live to stop it.
994 wordsRead articleAuthentication vs Authorization: Where Each One Belongs in Your Code
Learn how authentication and authorization differ in implementation, HTTP status codes, and system architecture to prevent common security bugs.
1335 wordsRead article
About these articles
Request a 24h estimate
Need the same stack in a production operator layer? Send the brief — estimate within 24 hours.