Explore tweets tagged as #OAuth
๐ฉTA416 Targets Government and Diplomatic Organizations with PlugX and OAuth Phishing https://t.co/dbw8QbQ6R4 China-linked TA416 has resumed activity after a quiet period, targeting diplomatic and government organizations with updated PlugX campaigns. The group is abusing
1
10
29
Claude Bug Bounty Hunter - Claude Code skill for AI-assisted bug bounty hunting - recon, IDOR, XSS, SSRF, OAuth, GraphQL, LLM injection, and report generation https://t.co/cpAhSiQtPI
9
144
746
I don't get how this works. Claude OAuth + OpenClaw (OSS) = banned Claude OAuth + "personal software" using Agent SDK = OK So if I fork OpenClaw to use Agent SDK under the hood, this is OK? Or is it only OK for "personal use", and if I sell it, I am banned from allowing
@EricBuess Yep, working on improving clarity here to make it more explicit
51
12
422
This is huge : @X released an MCP server today.. How to Connect X to your ๐ฆ : **Step 1: Run the XMCP Server** git clone https://t.co/45vK6uCOKl cd xmcp cp env.example .env Edit the .env file with your X OAuth consumer key and secret. Set the callback URL to
78
213
2K
Claude Banned OpenClaw OAuth? We Bypassed It. Anthropic killed 3rd-party OAuth for subs today (April 4), shoving everyone onto the expensive API. OpenClaw doesn't care. We're moving downstream. Instead of fighting the OAuth ban, we're piping Claude CLI directly into OpenClaw.
Claude just banned OpenClaw and Hermes. Here's how to swap models and kill Claude MAX Oauth in under 2 mins Set this up NOW before you get locked out
126
81
865
HackerNotes TLDR for episode 169! https://t.co/w7HQ9TFNYo โบโ OAuth 2.1 mandates PKCE, so strip code_challenge from "2.1-compliant" servers to test for downgrade vulnerabilities โบโ MCP's new Client Identity Metadata Documents (CIMD) turn the authorization server into an SSRF
1
3
33
๐๏ธ Weekly recap (Mar 28-Apr 4) ๐ 5 releases ๐ ๏ธ 60 improvements 60 features & enhancements in this release Top features: โข BYOM Model picker correctly overrides the --model flag for the session โข Add device code flow (RFC 8628) for MCP OAuth in headless and CI environments โข
3
4
64
As a developer, you should be able to clearly explain at least 10 of these: - Load Balancer - API Gateway - Reverse Proxy - Throttling - Rate Limiting - Idempotency - Pagination - Cache Stampede - gRPC - GraphQL - Webhooks - OAuth - JWT - Cache Invalidation - Query Optimization
47
215
1K
Here's how to give your Hermes agent its own email inbox. @NousResearch No SMTP/IMAP, no Google Oauth, just plug in AgentMail using MCP. See how it works:
4
4
40
Hermes Agent Full Setup Guide (Does It Actually Beat OpenClaw?): 0:00 - What is Hermes Agent 1:07 - What Makes It Different? 1:49 - Install Hermes 6:11 - The Mistake I Made 7:02 - Anthropic OAuth 8:45 - Live Demo 10:34 - Honest Verdict vs OpenClaw 12:26 - Best Workflow
45
41
499
Hey @AnthropicAI you broke claude code logins with oauth too? Even though that's an option in the product? Just because I used that with openclaw before? What the hell man. Can I only API into claude code now??!
9
1
20
Race conditions in OAuth flows can still happen in custom implementations. Here's how to find it: During the token exchange, the server is supposed to treat an authorization code as single-use. If you race the token endpoint by sending parallel requests with the same code
7
38
258
Anthropic finally killed Open Claw Oauth use for Claude Max users ๐ญ hereโs what you can do about it ๐
4
1
24
@uttam_singhk We built Oauth for Agents @GetAgentID Captcha is essentially useless once there is Identity, trust, etc built into the agent infrastructure at a base level. The point of captcha is to remove bot access. Now we have to allow scoped bot access.
0
0
1
While you're handing your AI agent every password you own... The top 1% already moved to @Composio. No OAuth nightmares. No credential leaks. No 3am "who authorized this" panic. Their agents are locked down in minutes. Yours are one prompt injection away from disaster. Secure
Your AI agent is in bed with you. No protection. You just wanted it to work. Gmail. Allow. Calendar. Allow. Slack, Notion, GitHub. Allow. Allow. Allow. Every password, handed over. Your agent never needed a single one. They just needed @Composio Secure your agents in
33
49
576
Been testing Claude Managed Agents Here's my feedback: Vaults store OAuth tokens outside the sandbox, the agent never handles them directly The problem, vaults are workspace-scoped Anyone with workspace access, via API key or the Console, can reference your vaults and use
6
5
36
๐ก๏ธ Hackers Used EvilTokens, ClickFix Campaign to Attack Claude Code Users Source: https://t.co/auiLnXBqSb Two significant threat campaigns from March 2026, one abusing Microsoftโs OAuth authentication flow to silently hijack enterprise accounts, and another deploying the AMOS
1
20
50
์ ๊ฒฐ๊ตญ ์ดํ์ ์ธ AI ๊ตฌ๋
์ Claude Code ๋ณด๋ค Codex ๋ฅผ ํํ ๊ฒ ๊ฐ๋ค... ์์ด์ ํธ ์์ฒด๋ฅผ ๋ณ๋ ํ๋ก๊ทธ๋จ์ผ๋ก ์ง์ ๋ง๋ค ๋์ โAPIํคโ ๊ฐ ์๋๋ผ โOAUTH APIํคโ ๋ฅผ ์ธ ์ ์์ด์ผ.. ๋ด ๊ตฌ๋
์ ๊ทธ๋๋ก ์ธ ์ ์๋ค๋ฉด APIํค๋ณด๋ค 20๋ฐฐ๋ ์ ๋ ดํ๊ฒ ์ฒ๋ฆฌํ ์ ์๋๋ฐ ์ด๊ฑธ ๋ ๋น์ผ APIํค๋ก ๋ค์ ์ง๋๊ฑด ์ข..
2
0
11
Cleanest approach Iโve seen for agent auth: OAuth + per-action permissions! Composio really nailed this ๐๐๐
Your AI agent is in bed with you. No protection. You just wanted it to work. Gmail. Allow. Calendar. Allow. Slack, Notion, GitHub. Allow. Allow. Allow. Every password, handed over. Your agent never needed a single one. They just needed @Composio Secure your agents in
6
11
34