Home / Companies / SSOJet / Blog / October 2026

October 2026 Summaries

1 posts from SSOJet

Filter
Month: Year:
Post Summaries Back to Blog
Client credentials OAuth is presented as the appropriate authentication method for CI pipelines and other machine-to-machine workloads because personal access tokens produce inaccurate audit trails, excessive permissions, and offboarding risks. Under RFC 6749, this grant is limited to confidential clients such as servers or CI runners, uses the application rather than a human as the identity, and generally should not issue refresh tokens because the machine can reauthenticate with its own credentials. In multi-tenant systems, each machine credential should be bound to exactly one tenant when created, with tenant context taken from token claims rather than request parameters to prevent cross-tenant access. JWT access tokens should distinguish machine subjects from user subjects through namespacing and explicit identity-type claims, prevent client-controlled identifiers that could cause subject collisions, and validate the token audience. The guidance also recommends narrowly scoped, workload-specific credentials, short-lived cached access tokens, dual-secret rotation to avoid downtime, expirations and revocation tied to workload retirement, customer visibility into credentials and their last use, and unified audit logging that records the machine identity, tenant, authorizing scope, and relevant human-trigger correlation.
Oct 01, 2026 3,282 words in the original blog post.