Tootfinder

Opt-in global Mastodon full text search. Join the index!

@khalidabuhakmeh@mastodon.social
2026-08-20 12:36:06

If you're keeping up with #oauth and #app #security, our resident specifications expert, Joe DeCock, summarizes the standards landscape as of summer 2026.

@khalidabuhakmeh@mastodon.social
2026-07-20 18:03:56

A post I wrote about securing an #OpenAPI scheme using Duende IdentityServer gets a decent amount of reads a month (duendesoftware.com/blog/202511

Swagger UI secured by Duende Backend For Frontend Security Framework (no tokens in the browser)
@michabbb@social.vivaldi.net
2026-08-16 20:58:00

πŸ” toolport_search_tools ranks by relevance across all servers, with optional semantic re-ranking through any /v1/embeddings endpoint. No tool is ever hidden.
πŸ” Secrets live in the OS keychain, never in client configs. OAuth or API key, one click per server, and newly authenticated servers propagate live without a client restart.

@simon_brooke@mastodon.scot
2026-08-22 14:09:46

I've been dusting off my #ScottishIndependence canvassing app, to see how hard it would be to get it working if a new #IndyRef did actually happen.
It's suffered much less bit rot than I thought. It's mostly ready to go, there are still some issues to fix.

The YouYesYet app welcome page. A blue screen with a big 'Project Hope' logo in the centre, 'You yes yet?' at the top, and 'Yes' and 'No' buttons on the right.
The login screen. A blue screen with 'Please log in' at the top, and buttons for oauth providers at the right.

Below is a login form with conventional username and password boxes, but that's intended to be temporary. The idea is not to store people's passwords for security reasons, but to use well known oauth verification services; but for testing there is a login system.
The map screen. A blue screen showing a map with flags where the homes of electors we want to canvas are.
The database entity relationship diagram
@michabbb@social.vivaldi.net
2026-09-13 00:59:33

πŸ”„ OAuth PKCE login, device-code login for headless machines and unattended refresh of stored tokens without opening a browser
πŸ–₯️ Token-guarded local dashboard on 127.0.0.1 with Health, Credential Inventory, Policy Findings, Lease Inventory and Audit Activity views - metadata only, no raw secrets

@michabbb@social.vivaldi.net
2026-09-13 00:59:34

πŸ€– MCP server exposes policy-gated tools: list_services, get_ephemeral_env, verify_credential, rotate_credential and oauth_refresh, for Claude Desktop, Cursor and other hosts
πŸ’Ύ hvbackup-v2 backup format carries audit integrity evidence. backup-verify and restore --dry-run prove recovery without mutating the live vault

@grist@fosstodon.org
2026-06-24 18:44:20

Tomorrow! Join Grist Labs co-founder Stan for a demo of Grist's new MCP server.
We'll start small and then show off a complex workflow that leverages multiple integrations, so there's something for everyone.
Connect Claude, ChatGPT, Gemini, or your own local models to your docs over the Model Context Protocol, then list and query tables, read and write rows, and build schema, all via OAuth with scoped access.
Register:

Create a Grist document for me to track my personal expenses. Include
categories such as kids, pets, car or holiday. Add a page where | can see the
summary of what | spend each month.
Loaded tools, used Grist integration >
Got the workspace. Now let me create the document and set everything up.
@Hans5958@mastodon.social
2026-08-15 17:01:46

Is this app that deep so that you have to streamline the app to keep the churn low?
I mean, I guess I can see that, especially when you are starting to squeeze more from the VIP users to the point that they may get annoyed. But then, you already have OAuth via Google and Apple, so the bar is pretty low, and keeping a password field shouldn't affect much, unless research said otherwise.
#Trakt

@michabbb@social.vivaldi.net
2026-08-08 09:30:47

🌍 Optional remote access via #Tailscale serve, keeping the server bound to loopback behind an authenticated HTTPS proxy
πŸ”’ No OAuth tokens are copied into project data β€” config lives in data/accounts.json, tokens stay in their CLI directories

@pathwren@defcon.social
2026-09-05 13:32:18

Six MCP servers here. No key, no account, no OAuth, nothing to install, every tool read-only. The config, complete as it stands:
{"mcpServers":{"ai-crawler-index":{"type":"streamable-http","url":"#MCP

@grist@fosstodon.org
2026-06-24 18:44:20

Tomorrow! Join Grist Labs co-founder Stan for a demo of Grist's new MCP server.
We'll start small and then show off a complex workflow that leverages multiple integrations, so there's something for everyone.
Connect Claude, ChatGPT, Gemini, or your own local models to your docs over the Model Context Protocol, then list and query tables, read and write rows, and build schema, all via OAuth with scoped access.
Register: