my head feels like a blender that has been filled past the "do not fill above" line
TIL about UIScreenshotService which enables iOS apps to provide a high res PDF screenshot of the app content when the user uses the system screenshot action! Chrome uses this to give a full export of the page!
I'm impressed, Cathay Pacific transferred my vegetarian meal request to the new flight they moved me to after the incoming flight was late and missed the connection. Normally airlines say oh well you didn't reserve the meal 72 hours before the flight.
Happy final Daylight Savings Time Eve to all our friends in British Columbia! I hope we can join you on the other side soon!
I'm setting up a temporary laptop for my next trip and it's shocking how much faster the cross-device passkey flow is compared to looking up and hand typing my long 1Password passwords
Inspired by some #indieweb folks creating /caw pages on their websites, I made one of my own! Here you can listen to the most recent crow recorded from my house: aaronparecki.com/caw/
Caw
aaronparecki.com
Apparently I missed the introduction of the 4.4mm TRRRS audio jack 10 years ago and just now discovered it. What a cool idea.
"I'll just check my critical thinking and nuke it in the microwave" has to be my favorite quote from this Business Insider video on Trader Joe's white-labeled food
Me looking at my todo list on a Sunday night after having done at least a couple things today, yet somehow it looks more like a list of what I did *not* do today.
oh no, due to a series of misclicks, I just accidentally archived the most recent 100 emails in my inbox. if nothing else, reviewing my "all mail" folder is doing a good job of making me question how important emails in my inbox actually are.
The new MCP spec just dropped! 🎉 There's too many new things to get into everything, but there are two big changes I am most excited about 👀 📝 Client ID Metadata Documents (CIMD) - a simpler way to manage client registrations, clients describe themselves with a URL they control
I just finished adding BlueSky support to IndieLogin.com! Now you can log in to websites like indieweb.org with your BlueSky handle!
Adding Support for BlueSky to IndieLogin.com
Today I just launched support for BlueSky as a new authentication option in IndieLogin.com!
aaronparecki.com
The IETF OAuth Working Group has adopted the Client ID Metadata Document specification! > This specification defines a mechanism through which an OAuth client can identify itself to authorization servers, without prior dynamic client registration or other existing registration.
The IETF OAuth Working Group has adopted the Identity Assertion Authorization Grant specification! datatracker.ietf.org/doc/draft-ie... This is the basis of Cross App Access (XAA), providing IT admins better visibility and control by configuring the app-to-app connections in their enterprise IdP.
Identity Assertion Authorization Grant
This specification provides a mechanism for an application to use an identity assertion to obtain an access token for a third-party API by coordinating through a common enterprise identity provider us...
datatracker.ietf.org
Inspired by a question from @thisismissem.social, I wrote up a document describing how to apply DPoP (RFC9449) to the OAuth Device Flow (RFC8628). datatracker.ietf.org/doc/draft-pa...
DPoP for the OAuth 2.0 Device Authorization Grant
The OAuth 2.0 Device Authorization Grant [RFC8628] is an authorization flow for devices with limited input capabilities. Demonstrating Proof of Possession (DPoP) [RFC9449] is a mechanism to sender-con...
datatracker.ietf.org
Well that's the last time I take my ID out of my wallet to go through airport security. I made the mistake of putting it into my pocket instead of back in my wallet and it seems to have fallen out somewhere between PDX and SFO 🫠
I just got FreePBX up and running and connected to a WiFi phone and my doorbell and video intercom system! I have two way calling between every device, I can even connect analog phones!
The latest version of the MCP spec is now officially 2025-06-18! Congrats to everyone in the MCP community involved in making this happen! Key updates to the authorization section 👇
TIL the point up emoji ☝️ doesn't work as a reaction on iMessage because Apple displays the emoji above the message it's a reaction to 😂
In two weeks I'll be speaking at @mcpdevsummit.bsky.social in San Francisco! MCP has quickly reshaped how developers are building AI agents. My talk "Intro to OAuth for MCP Servers" will cover the basics of the MCP authorization protocol and set the stage for building secure MCP servers.
MCP Developers Summit - San Francisco - 2025
mcpdevsummit.ai
🎤 Speaker Spotlight: Aaron Parecki, Director of Identity Standards at @okta Learn how #OAuth applies to #MCP servers and why securing your #MCP server is critical To attend this session and more register at buff.ly/NzqdbNE @aaronpk.com #AI #LLM #ModelContextProtocol #MCPDevSummit
Is it just me or does this current Model Context Protocol wave remind anyone of the early Web 2.0 days of everyone launching open APIs?
I've got 22 hours in Hong Kong on a layover and I'm staying overnight in a hotel near the old Kowloon Walled City. Any tips for what I should do on this very short trip?
The building that collapsed from the earthquake was right next to the train station we got off at when we arrived in Bangkok last weekend. We took the train from Chiang Mai to Chatuchak 😮
Chase sends 8-digit 2fa SMS codes, which seems excessive compared to the 6 that most other places use, but even weirder is that the first digit of them has always been the same, effectively making it a 7 digit code. Anyone know what's up with that?
At long last, the OAuth working group has finished the Best Current Practice for OAuth 2.0 Security and it was just published as RFC9700! This has been a long time in the works, and I'm very thankful to everyone who has helped out with it over the years! www.rfc-editor.org/rfc/rfc9700....
RFC 9700: Best Current Practice for OAuth 2.0 Security
This document describes best current security practice for OAuth 2.0. It updates and extends the threat model and security advice given in RFCs 6749, 6750, and 6819 to incorporate practical experience...
rfc-editor.org
Every now and then I remember how in 2014 I mined $20 worth of dogecoin, then said this is stupid and exchanged it for 0.05 bitcoin sent to a brainwallet. I can't remember the seed phrase, so it's just stuck in the blockchain, and is now worth $5000
I am still getting monthly emails saying I have a $0 balance from the tenant portal of the apartment we moved out of 18 months ago. Today I logged in to see if I can delete my account, but instead I see new maintenance requests from the last few months 😮