<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="/feed.rss.xml" type="text/xsl" media="screen"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Aaron Parecki</title>
    <description/>
    <link>https://speakerdeck.com/aaronpk</link>
    <atom:link rel="self" type="application/rss+xml" href="https://speakerdeck.com/aaronpk.rss"/>
    <lastBuildDate>2020-03-31 11:37:47 -0400</lastBuildDate>
    <item>
      <title>OAuth for MCP - Internet Identity Workshop October 2025</title>
      <description></description>
      <media:content url="https://files.speakerdeck.com/presentations/7fbeccc24d59496e928223a75f5079d8/preview_slide_0.jpg?37498831" type="image/jpeg" medium="image"/>
      <content:encoded></content:encoded>
      <pubDate>Wed, 22 Oct 2025 00:00:00 -0400</pubDate>
      <link>https://speakerdeck.com/aaronpk/oauth-for-mcp-internet-identity-workshop-october-2025</link>
      <guid>https://speakerdeck.com/aaronpk/oauth-for-mcp-internet-identity-workshop-october-2025</guid>
    </item>
    <item>
      <title>The State of OAuth 2025 - Identiverse</title>
      <description>https://identiverse.com/idv25/session/?idvid=2812734</description>
      <media:content url="https://files.speakerdeck.com/presentations/6719e0b2fc994d2cbfb2bb143443623e/preview_slide_0.jpg?35375186" type="image/jpeg" medium="image"/>
      <content:encoded>https://identiverse.com/idv25/session/?idvid=2812734</content:encoded>
      <pubDate>Wed, 04 Jun 2025 00:00:00 -0400</pubDate>
      <link>https://speakerdeck.com/aaronpk/the-state-of-oauth-2025-identiverse</link>
      <guid>https://speakerdeck.com/aaronpk/the-state-of-oauth-2025-identiverse</guid>
    </item>
    <item>
      <title>OAuth for MCP</title>
      <description></description>
      <media:content url="https://files.speakerdeck.com/presentations/8657854d812448779158412745d7e949/preview_slide_0.jpg?37258312" type="image/jpeg" medium="image"/>
      <content:encoded></content:encoded>
      <pubDate>Fri, 23 May 2025 00:00:00 -0400</pubDate>
      <link>https://speakerdeck.com/aaronpk/oauth-for-mcp</link>
      <guid>https://speakerdeck.com/aaronpk/oauth-for-mcp</guid>
    </item>
    <item>
      <title>IIW 39 - OAuth 101</title>
      <description></description>
      <media:content url="https://files.speakerdeck.com/presentations/34c44ff052664bfbbc17fdef0e0a3a73/preview_slide_0.jpg?32433271" type="image/jpeg" medium="image"/>
      <content:encoded></content:encoded>
      <pubDate>Tue, 29 Oct 2024 00:00:00 -0400</pubDate>
      <link>https://speakerdeck.com/aaronpk/iiw-39-oauth-101</link>
      <guid>https://speakerdeck.com/aaronpk/iiw-39-oauth-101</guid>
    </item>
    <item>
      <title>OAuth in Native Apps - OAuth Security Workshop</title>
      <description>Slides from my presentation on OAuth in Native Apps at the OAuth Security Workshop. Unfortunately the embedded videos don't play in the PDF version. I extracted the video clips and posted them here: https://aaronparecki.com/2024/04/11/23/oauth-native-apps-osw-2024</description>
      <media:content url="https://files.speakerdeck.com/presentations/725df527e0dd4dc59bb9b1fc44e358e3/preview_slide_0.jpg?36116602" type="image/jpeg" medium="image"/>
      <content:encoded>Slides from my presentation on OAuth in Native Apps at the OAuth Security Workshop. Unfortunately the embedded videos don't play in the PDF version. I extracted the video clips and posted them here: https://aaronparecki.com/2024/04/11/23/oauth-native-apps-osw-2024</content:encoded>
      <pubDate>Thu, 11 Apr 2024 00:00:00 -0400</pubDate>
      <link>https://speakerdeck.com/aaronpk/oauth-in-native-apps-oauth-security-workshop</link>
      <guid>https://speakerdeck.com/aaronpk/oauth-in-native-apps-oauth-security-workshop</guid>
    </item>
    <item>
      <title>Targeted Logout - OAuth Security Workshop 2023</title>
      <description>Presented at the OAuth Security Workshop

https://events.oauth.net/2023/08/oauth-security-workshop-2023-2gZNVdvPH0XS</description>
      <media:content url="https://files.speakerdeck.com/presentations/d9f81ebc84a74685ba0df0c01298b582/preview_slide_0.jpg?26830805" type="image/jpeg" medium="image"/>
      <content:encoded>Presented at the OAuth Security Workshop

https://events.oauth.net/2023/08/oauth-security-workshop-2023-2gZNVdvPH0XS</content:encoded>
      <pubDate>Thu, 24 Aug 2023 00:00:00 -0400</pubDate>
      <link>https://speakerdeck.com/aaronpk/targeted-logout-oauth-security-workshop-2023</link>
      <guid>https://speakerdeck.com/aaronpk/targeted-logout-oauth-security-workshop-2023</guid>
    </item>
    <item>
      <title>Enterprise-Ready: Going Beyond MVP</title>
      <description>Ready to move beyond MVP in the journey of adding enterprise-ready identity in your SaaS app? With the must-have functionality in place, you're ready to make your app stand out, get noticed by enterprise customers, and handle user provisioning and automation that can scale!

Slides from Devday23

https://developerday.com/events/devday23-wic</description>
      <media:content url="https://files.speakerdeck.com/presentations/1caf89fecfe74ca38d30205fabdc49fe/preview_slide_0.jpg?26084123" type="image/jpeg" medium="image"/>
      <content:encoded>Ready to move beyond MVP in the journey of adding enterprise-ready identity in your SaaS app? With the must-have functionality in place, you're ready to make your app stand out, get noticed by enterprise customers, and handle user provisioning and automation that can scale!

Slides from Devday23

https://developerday.com/events/devday23-wic</content:encoded>
      <pubDate>Wed, 17 May 2023 00:00:00 -0400</pubDate>
      <link>https://speakerdeck.com/aaronpk/enterprise-ready-going-beyond-mvp</link>
      <guid>https://speakerdeck.com/aaronpk/enterprise-ready-going-beyond-mvp</guid>
    </item>
    <item>
      <title>App Integrity Attestations for OAuth - OAuth Security Workshop 2022</title>
      <description>Currently, the security of native apps in OAuth is contingent upon registering the app's callback URL with the operating system, preferably as an app-claimed HTTPS URL. While this provides some level of assurance of the app's identity, it is by no means foolproof.

Authenticating whether a particular instance of a public client in OAuth is a legitimate instance remains a challenge. 

This session will explore the possibility of using Apple and Android’s “app attestation” APIs as a form of OAuth client authentication. These APIs are able to leverage on-device private keys and a certificate chain to provide an additional level of confidence that the app making an HTTP request is the same code that was shipped in the app stores.</description>
      <media:content url="https://files.speakerdeck.com/presentations/2c3125d7547644a9b41516e73b0cf8fb/preview_slide_0.jpg?21343174" type="image/jpeg" medium="image"/>
      <content:encoded>Currently, the security of native apps in OAuth is contingent upon registering the app's callback URL with the operating system, preferably as an app-claimed HTTPS URL. While this provides some level of assurance of the app's identity, it is by no means foolproof.

Authenticating whether a particular instance of a public client in OAuth is a legitimate instance remains a challenge. 

This session will explore the possibility of using Apple and Android’s “app attestation” APIs as a form of OAuth client authentication. These APIs are able to leverage on-device private keys and a certificate chain to provide an additional level of confidence that the app making an HTTP request is the same code that was shipped in the app stores.</content:encoded>
      <pubDate>Fri, 06 May 2022 00:00:00 -0400</pubDate>
      <link>https://speakerdeck.com/aaronpk/app-integrity-attestations-for-oauth-oauth-security-workshop-2022</link>
      <guid>https://speakerdeck.com/aaronpk/app-integrity-attestations-for-oauth-oauth-security-workshop-2022</guid>
    </item>
    <item>
      <title>Intro to OAuth - IETF 110</title>
      <description>My presentation at the SAAG meeting at IETF 110</description>
      <media:content url="https://files.speakerdeck.com/presentations/0103a4ba894349a0a804485b92f7c9b2/preview_slide_0.jpg?17583020" type="image/jpeg" medium="image"/>
      <content:encoded>My presentation at the SAAG meeting at IETF 110</content:encoded>
      <pubDate>Thu, 11 Mar 2021 00:00:00 -0500</pubDate>
      <link>https://speakerdeck.com/aaronpk/intro-to-oauth-ietf-110</link>
      <guid>https://speakerdeck.com/aaronpk/intro-to-oauth-ietf-110</guid>
    </item>
    <item>
      <title>OAuth 101 - Internet Identity Workshop XXXI</title>
      <description>https://aaronparecki.com/2020/10/20/8/</description>
      <media:content url="https://files.speakerdeck.com/presentations/9adff4393583402f8a224132ab7632cc/preview_slide_0.jpg?16526885" type="image/jpeg" medium="image"/>
      <content:encoded>https://aaronparecki.com/2020/10/20/8/</content:encoded>
      <pubDate>Tue, 20 Oct 2020 00:00:00 -0400</pubDate>
      <link>https://speakerdeck.com/aaronpk/oauth-101-internet-identity-workshop-xxxi</link>
      <guid>https://speakerdeck.com/aaronpk/oauth-101-internet-identity-workshop-xxxi</guid>
    </item>
    <item>
      <title>What's New with OAuth and OpenID Connect - API Days Australia</title>
      <description>https://aaronparecki.com/2020/09/16/23/</description>
      <media:content url="https://files.speakerdeck.com/presentations/a64db190a47142bd8c8ab291d8cb968b/preview_slide_0.jpg?16289250" type="image/jpeg" medium="image"/>
      <content:encoded>https://aaronparecki.com/2020/09/16/23/</content:encoded>
      <pubDate>Tue, 15 Sep 2020 00:00:00 -0400</pubDate>
      <link>https://speakerdeck.com/aaronpk/whats-new-with-oauth-and-openid-connect-api-days-australia</link>
      <guid>https://speakerdeck.com/aaronpk/whats-new-with-oauth-and-openid-connect-api-days-australia</guid>
    </item>
    <item>
      <title>How to Think about OAuth Security - Disclosure 2020</title>
      <description>Slides from my talk at Disclosure Conference

https://disclosureconference.com/</description>
      <media:content url="https://files.speakerdeck.com/presentations/47c144987d1a4f64bc55209eaadc8e39/preview_slide_0.jpg?16159391" type="image/jpeg" medium="image"/>
      <content:encoded>Slides from my talk at Disclosure Conference

https://disclosureconference.com/</content:encoded>
      <pubDate>Wed, 02 Sep 2020 00:00:00 -0400</pubDate>
      <link>https://speakerdeck.com/aaronpk/how-to-think-about-oauth-security-disclosure-2020</link>
      <guid>https://speakerdeck.com/aaronpk/how-to-think-about-oauth-security-disclosure-2020</guid>
    </item>
    <item>
      <title>OAuth 2.1 - OAuth Security Workshop</title>
      <description>https://aaronparecki.com/2020/07/22/9/</description>
      <media:content url="https://files.speakerdeck.com/presentations/4ecf97f8525946caa098210ab02e5c4f/preview_slide_0.jpg?15893094" type="image/jpeg" medium="image"/>
      <content:encoded>https://aaronparecki.com/2020/07/22/9/</content:encoded>
      <pubDate>Wed, 22 Jul 2020 00:00:00 -0400</pubDate>
      <link>https://speakerdeck.com/aaronpk/oauth-2-dot-1-oauth-security-workshop</link>
      <guid>https://speakerdeck.com/aaronpk/oauth-2-dot-1-oauth-security-workshop</guid>
    </item>
    <item>
      <title>Protecting Single-Page Apps using OAuth</title>
      <description>https://aaronparecki.com/2020/07/22/7/</description>
      <media:content url="https://files.speakerdeck.com/presentations/573b141fd39e47288710d85c707df678/preview_slide_0.jpg?15892698" type="image/jpeg" medium="image"/>
      <content:encoded>https://aaronparecki.com/2020/07/22/7/</content:encoded>
      <pubDate>Wed, 22 Jul 2020 00:00:00 -0400</pubDate>
      <link>https://speakerdeck.com/aaronpk/protecting-single-page-apps-using-oauth</link>
      <guid>https://speakerdeck.com/aaronpk/protecting-single-page-apps-using-oauth</guid>
    </item>
    <item>
      <title>The State of OAuth</title>
      <description>Presented at Interface by API Days</description>
      <media:content url="https://files.speakerdeck.com/presentations/142a8e5e51ab49159dc75ba78bee4137/preview_slide_0.jpg?15778222" type="image/jpeg" medium="image"/>
      <content:encoded>Presented at Interface by API Days</content:encoded>
      <pubDate>Tue, 30 Jun 2020 00:00:00 -0400</pubDate>
      <link>https://speakerdeck.com/aaronpk/the-state-of-oauth</link>
      <guid>https://speakerdeck.com/aaronpk/the-state-of-oauth</guid>
    </item>
    <item>
      <title>OAuth 2.0 Client Intermediary Metadata - IETF 107</title>
      <description>Presented at IETF 107 virtual interim meeting.

https://events.oauth.net/2020/05/oauth-virtual-interim-meeting-client-intermediary-and-reciprocal-oauth-BmTavIx802Ez</description>
      <media:content url="https://files.speakerdeck.com/presentations/c542325470284c8fa7ba56dabb4f342b/preview_slide_0.jpg?15438225" type="image/jpeg" medium="image"/>
      <content:encoded>Presented at IETF 107 virtual interim meeting.

https://events.oauth.net/2020/05/oauth-virtual-interim-meeting-client-intermediary-and-reciprocal-oauth-BmTavIx802Ez</content:encoded>
      <pubDate>Fri, 08 May 2020 00:00:00 -0400</pubDate>
      <link>https://speakerdeck.com/aaronpk/oauth-2-dot-0-client-intermediary-metadata-ietf-107</link>
      <guid>https://speakerdeck.com/aaronpk/oauth-2-dot-0-client-intermediary-metadata-ietf-107</guid>
    </item>
    <item>
      <title>How to Hack OAuth - Goto Chicago 2020</title>
      <description>https://aaronparecki.com/2020/04/28/12/</description>
      <media:content url="https://files.speakerdeck.com/presentations/8c090ba4cfa441c898ee7be83fb4345e/preview_slide_0.jpg?15372265" type="image/jpeg" medium="image"/>
      <content:encoded>https://aaronparecki.com/2020/04/28/12/</content:encoded>
      <pubDate>Tue, 28 Apr 2020 00:00:00 -0400</pubDate>
      <link>https://speakerdeck.com/aaronpk/how-to-hack-oauth-goto-chicago-2020</link>
      <guid>https://speakerdeck.com/aaronpk/how-to-hack-oauth-goto-chicago-2020</guid>
    </item>
    <item>
      <title>What's New with OAuth and OpenID Connect?</title>
      <description>In this talk you'll learn about the latest developments with the OAuth and OIDC specs directly from the standards group. The latest additions to the specs enable richer experiences and better security for applications using OAuth.

https://www.oktane20.com/agenda#573</description>
      <media:content url="https://files.speakerdeck.com/presentations/90d89faa0d36423c8e65b2dc9004203d/preview_slide_0.jpg?15225299" type="image/jpeg" medium="image"/>
      <content:encoded>In this talk you'll learn about the latest developments with the OAuth and OIDC specs directly from the standards group. The latest additions to the specs enable richer experiences and better security for applications using OAuth.

https://www.oktane20.com/agenda#573</content:encoded>
      <pubDate>Tue, 31 Mar 2020 00:00:00 -0400</pubDate>
      <link>https://speakerdeck.com/aaronpk/whats-new-with-oauth-and-openid-connect</link>
      <guid>https://speakerdeck.com/aaronpk/whats-new-with-oauth-and-openid-connect</guid>
    </item>
  </channel>
</rss>
