My soul dog died a few months ago. I taught myself how to make inlaid rings so I could make myself a memorial ring with a bit of his fur. Goodbye, Fawkes. I’ll see you over the rainbow bridge 😭😭💐
Kim Maida
@maida.kim
Founding GTM Engineer + Head of Developer Relations / Product / Identity & Access Management Doing agentic AI security stuff at Keycard / ex-FusionAuth, ex-Okta, ex-Auth0 DevRel & blog: https://maida.kim Art & miniatures: https://mihi-mini.studio
Transport, identity, policy, runtime: agent security isn't one question. This dev maps all four layers, what each covers, and which is most under-built right now. { author: @maida.kim } dev.to/kimmaida/the...
The Agent Security Stack: Transport, Identity, Policy, Runtime
Let's say you're building an agent. It reads Linear issues, pulls context from Gmail, opens GitHub...
dev.to
Congrats to our top 7 authors this week! 🎉 @maida.kim built an AI raffle agent and then tried to rig it. Living with MS pushed Stephen J Newhouse to give their AI agents persistent memory. Check out these and more below 👇 dev.to/devteam/top-...
Top 7 Featured DEV Posts of the Week
Welcome to this week's Top 7, where the DEV editorial team handpicks their favorite posts from the...
dev.to
Kim built a personal planning dashboard that reads Calendar, Linear, Gmail, Slack, GitHub, and Granola — with one Keycard login replacing 7 OAuth flows, ephemeral scoped tokens per tool call, and a full audit trail of every credential issued. { author: @maida.kim } dev.to/kimmaida/i-b...
I Built a Secure Planning Agent with MCP and Keycard
My workday is scattered across many disconnected tools: Google Calendar, Linear, Gmail, Google Docs,...
dev.to
I wrote a blog post about how I built a daily planning agent (called Todaygent, of course) that calls 7 different OAuth resources. I’m so confident in its access controls that I can tell it to delete all my emails or mark all my Linear tasks to Done without any fear that it’ll actually do it.
Congrats to our top authors this week! 🏆 Make sure to check out @maida.kim's analysis of how our concepts of security and trust are shifting as AI agents gain more authority. Plus: a CSS framework built entirely with emojis, teaching a robot to play a board game, and more! dev.to/devteam/top-...
Top 7 Featured DEV Posts of the Week
Welcome to this week's Top 7, where the DEV editorial team handpicks their favorite posts from the...
dev.to
I cleaned my battlestation. I forgot to take before photos, but it was a disaster zone. Took me about 5 hours to clean it
Sneak peek at another diorama: nature’s revenge. This is actually done, I just have to compile all the clips into one video and do the glamour shots 🙃
Am I the only person who thinks season 2 of Deadwood is really poorly written? So many characters are just randomly dropped in (most of them just to be removed right away having had no impact on anything). I hope season 3 is a bit more coherent because season 2 is all over the place.
Finished my Clair Obscur: Expedition 33 handmade figurine of Monoco! I’d been looking at figures online and then told myself I should stop being lazy and just make my own. I’m glad I did!
I’ve been working on a handmade figure of Monoco for the shelf behind me in my office. This is my progress so far. #expedition33
I’ve been working on a handmade figure of Monoco for the shelf behind me in my office. This is my progress so far. #expedition33
To me, the very best video games aren't flawless -- far from it. They're the ones that are just so good that I don't care about the flaws. All of my very favorite games are flawed in some way(s). Except maybe one.
FusionAuth’s @maida.kim joins @jazzsequence.com and shares her path through DevRel, why identity work matters, and how art helps her stay balanced.
Kim Maida on Identity, DevRel and Finding Balance
When you think of identity and authentication, “fun” might not be the first word that comes to mind. But for Kim Maida, Senior Director of Developer Relations at FusionAuth, it’s a calling. In this episode of Community + Code, Kim talks about her journey through Developer Relations and how she found herself coming back again […]
communitycode.dev
The Minicorda’s first field test! It was pretty easy to just carry on the plane, and it’s so quiet I have no concerns playing it in the hotel room.
ICYMI: you can get my modern OAuth stream on demand here: fusionauth.io/webinar/evol...
Evolving Auth Standards: Security Best Practices for App Developers - FusionAuth Webinar
Authorization and authentication open standards have been protecting users, apps, and resources for over a decade.
fusionauth.io
I’ve been teaching myself fingerstyle and classical guitar. I’ve found myself improving by learning the same song multiple times, but in progressively more challenging arrangements. The progression is really interesting to see when learning this way. It’s very rewarding each time I “level up.”
I just saw someone use the abbreviation “AI;DR” and I’ll be laughing for a while.
This is my most-anticipated movie this year. I can't wait to watch the entire finished product of this: www.youtube.com/@Flipbookoft...
Flipbook of the Rings
We are "re-animating" Lord of the Rings as the world's longest flipbook! It's the entire 3 hour movie, shot for shot–over 120,000 hand drawn pages, contributed by more than 1,000 artists. This channel...
youtube.com
Next week, I’ll be heading out to Maryland to speak at @jsconf.bsky.social and @ng-conf.bsky.social! It’s been over 2 years since I last spoke at an in-person event (spent that time doing docs, not DevRel). I’m very much looking forward to teaching, learning, and connecting with developers!
The ultimate blocker to weekend productivity. So glad I cleaned the bathroom before sitting down on the couch. Ambitions of kitchen cleaning and grocery store now delayed indefinitely.
Tomorrow I'll be streaming about evolving #oauth and modern best practices. Join me! The session is remote and free. fusionauth.link/evolving-auth
It looks like Dinosaur Field Station of NJ is closing and selling their Dino sculptures
CRIME and BREACH are actual vulnerability names. You have to hand it to security researchers for coming up with such epic acronyms. CRIME = Compression Ratio Info-leak Made Easy (CVE-2012-4929) BREACH = Browser Reconnaissance and Exfiltration via Adaptive Compression of Hypertext (CVE-2013-3587)
As much as I appreciate the efficiency and productivity #AI lends us in our daily lives, as an artist and creator, it makes me very sad that I feel the need to explicitly take credit for things I make using my own creativity, skills, experience, and insight.
The kitten saga! 1/4 This weekend I discovered these kittens stuck in a tree: