frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Google Cloud suspended my account for 2 years, only automated replies

140•andylizf•1d ago•80 comments

Task engine VM – for tasks with executable instructions (progress update)

3•tracyspacy•5h ago•3 comments

Ask HN: The Next Big OS Leap

2•rafaelmdec•1h ago•4 comments

Ask HN: Do you still use physical calculators?

30•speedylight•1d ago•81 comments

Ask HN: How do you handle auth when AI dev agents spin up short-lived apps?

2•NBenkovich•9h ago•1 comments

Ask HN: Any Successful Co-Ops of Software Engineers

8•rubyn00bie•22h ago•9 comments

A simple HTTPS, HTTP/3, SSL and security headers checker I built with AI

3•dragonman•11h ago•1 comments

Ask HN: Junior getting lost

48•TheRegularOne•3d ago•36 comments

Ask HN: Any real OpenClaw (Clawd Bot/Molt Bot) users? What's your experience?

101•cvhc•1d ago•148 comments

Ask HN: Do you also "hoard" notes/links but struggle to turn them into actions?

226•item007•2d ago•203 comments

AI has failed to replace a single software application or feature

18•cadabrabra•2d ago•20 comments

Ask HN: How do you reset an AppleID?

12•OhMeadhbh•2d ago•26 comments

Waypoint 1.1, a local-first world model for interactive simulation

13•lcastricato•2d ago•0 comments

Ask HN: What's your biggest LLM cost multiplier?

5•teilom•1d ago•5 comments

G Lang – A lightweight interpreter written in D (2.4MB)

2•pouyathe•2d ago•1 comments

Ask HN: How do you market a side project?

11•ruairidhwm•2d ago•11 comments

The preposterous notion of AI automating "repetitive" work

10•cadabrabra•2d ago•10 comments

Ask HN: What's the Point Anymore?

65•fnoef•5d ago•81 comments

Ask HN: How do you force yourself to take breaks while coding?

6•glidea•2d ago•24 comments

Ask HN: Should a software engineer have research exposure?

4•c_daeda•2d ago•1 comments

Ask HN: What recent UX changes make no sense to you?

34•superasn•5d ago•36 comments

Ask HN: How far has "vibe coding" come?

13•pigon1002•3d ago•27 comments

AI creates over-efficiency. Organizations must absorb it

7•eriam•2d ago•4 comments

Ask HN: Ergo wireless keyboard with mouse for coding?

5•MarcelOlsz•2d ago•5 comments

Ask HN: How did you get from learning to code to making your first dollar?

2•chistev•10h ago•2 comments

Ask HN: How are you managing secrets with AI agents?

2•m-hodges•2d ago•3 comments

Ask HN: Is free identity theft protection after a data breach worth the bother?

2•daoboy•2d ago•3 comments

Ask HN: Is archive.is currently broken for WSJ links?

8•bigwheels•3d ago•3 comments

How much recurring income do you generate in 2026 and from what?

12•djshah•4d ago•6 comments

Designing programming languages beyond AI comprehension

6•mr_bob_sacamano•4d ago•12 comments
Open in hackernews

Ask HN: How do you handle auth when AI dev agents spin up short-lived apps?

2•NBenkovich•9h ago
Hi HN,

I’m working on AI agents used for software development. These agents automatically spin up short-lived app instances – for example per pull request, per task, or per experiment – each with its own temporary URL.

Auth is handled in the standard way:

- OAuth2 / OIDC

- external identity provider

- redirect URLs must be registered in advance and be static

This clashes badly with short-lived apps:

- URLs are dynamic and unpredictable

- redirect URLs can’t realistically be pre-registered

- auth becomes the only non-ephemeral part of an otherwise fully automated workflow

What I see teams doing instead:

- disabling real auth in preview environments

- routing all callbacks through a single stable environment

- using wildcard redirects or proxy setups that feel like hacks

This gets especially awkward for AI dev agents, because they assume infrastructure is disposable and fully automated – no manual IdP config in the loop.

So I’m curious:

1. If you use short-lived preview apps, how do you handle real auth?

2. Are there clean OAuth/OIDC patterns that work with dynamic URLs?

3. Is the static redirect URL assumption still the right model here?

4. What actually works in production?

Looking for real setups and failure stories, not theory.

Comments

mattmanser•1h ago
There's actually loads of ways to solve this depending on what those apps are.

You haven't given us enough detail of what you are actually trying to do for anyone to give you concrete advice.

But the answer is probably a reverse proxy, checking the auth on the way. It's a standard solution for things like this, just ask your favourite AI for an example of how you'd do it.

That's what your teams are effectively already doing (redirecting through a single stable environment), they've just not realised they've setup one of their servers as an ad-hoc reverse-proxy.

Your teams could do with some senior engineers who know what they're doing.