Tweet by tweetsbycolin
May 22, 2026
I went looking for your auth.md last night to double check you hadn’t shipped a 2fa/sso bypass 🙃 But yea, this is where the rubber meets the road for introducing federated ID-JAG minters. It’s a similar challenge to offering Sign in with Google alongside 2fa and sso. There are lots of extra requirements for production-grade security, but they’re not actually written into the oauth standard. But in the context of ID-JAG for agents, we suddenly benefit meaningfully from these extra requirements being codified in a spec. In theory, we can push all these failure scenarios through ID-JAGs insufficient_user_authentication error, but I haven’t seen much definition of how to do that (particularly “this user requires an ID-JAG from a different IdP”, and “this user needs to 2fa with me-the-service, not their idp”)
- Author
- tweetsbycolin
- Date
- May 22, 2026
- Canonical URL
- /tweets/tweetsbycolin-2057938967090053300-05452a