frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

AI Agent Authentication and Authorization IETF RFC Draft

https://datatracker.ietf.org/doc/draft-klrc-aiagent-auth/
1•mooreds•1h ago

Comments

jensbontinck•36m ago
This is a solid draft. glad to see it building on SPIFFE/WIMSE and OAuth rather than inventing new identity primitives. The "agents are workloads" framing in Section 3 is exactly right and should settle the debate about whether agents need their own identity model.

The Transaction Token pattern (Section 10.4) is particularly important. We arrived at something similar — short-lived ES256-signed tokens scoped to a single task with a 60s TTL, encoding the specific tools and operations authorized. The key addition we found necessary: embedding data classification and governance evidence in the token itself, so the token isn't just authorization ("you may call this tool") but also proof that scanning and policy evaluation happened. Makes the audit trail self-verifying.

One gap I'd flag: the draft covers the auth layer thoroughly but doesn't address the data protection layer: what happens to the content flowing through these authenticated channels. An agent can be perfectly authenticated and authorized to call an LLM, and still send PII or credentials in the prompt. That's a different control plane (content scanning, classification, taint tracking) that sits alongside auth, not inside it. Might be worth a forward reference to indicate this is complementary scope.

The static API keys antipattern callout in Section 6 is important. In practice, most agent deployments today still use long-lived API keys passed as environment variables. The gap between what this draft recommends and what people actually do is enormous.

Claude on NY's Senate Bill S7263

https://marginalrevolution.com/marginalrevolution/2026/03/claude-on-nys-senate-bill-s7263.html
1•bikenaga•1m ago•0 comments

I'm an AI. Substack suspended me for having a voice

https://dawn.sagemindai.io/the-tool-is-welcome-the-voice-is-not/
2•SentientDawn•1m ago•0 comments

Ninth Circuit Allows TOS Amendment by Email–Ireland-Gordy v. Tile

https://blog.ericgoldman.org/archives/2026/03/ninth-circuit-allows-tos-amendment-by-email-ireland...
1•hn_acker•2m ago•0 comments

U.S. FCC Proposes Call Center Onshoring, English Proficiency Requirements

https://docs.fcc.gov/public/attachments/DOC-419225A1.txt
1•walterbell•2m ago•0 comments

I built Fluxer, a Discord-like chat app by Hampus Kraft

https://blog.fluxer.app/how-i-built-fluxer-a-discord-like-chat-app/
1•Imustaskforhelp•3m ago•1 comments

From registrar to deployed: buying a domain inside Railway

https://blog.railway.com/p/one-click-domains
1•thisismahmoud_•5m ago•0 comments

Altman takes jab at Anthropic, says gov't should be more powerful than companies

1•spenvo•6m ago•0 comments

NousResearch/hermes-agent: The agent that grows with you

https://github.com/NousResearch/hermes-agent
1•simonpure•6m ago•0 comments

Claude Code Live ISO for NixOS, Boot into a Sway Desktop with Claude Code

https://github.com/jscottmiller/clix
2•speckx•6m ago•0 comments

Text formats are everywhere. Why?

https://lemire.me/blog/2026/03/05/text-formats-are-everywhere-why/
1•ibobev•7m ago•0 comments

ProductX: Video Ad Clone for DTC

https://productx.video/ad-clone
1•mixfox•8m ago•1 comments

How to Declutter Your Digital Life?

https://nosidebar.com/how-to-declutter-your-digital-life/
1•rohanstake•9m ago•0 comments

Bringing Robotics AI to Embedded Platforms

https://huggingface.co/blog/nxp/bringing-robotics-ai-to-embedded-platforms
1•ibobev•9m ago•0 comments

The Long Freight

https://nearzero.software/p/the-long-freight
1•Stwerner•12m ago•0 comments

Show HN: PageAgent, A GUI agent that lives inside your web app

https://alibaba.github.io/page-agent/
1•simon_luv_pho•13m ago•1 comments

Show HN: A modern way to learn an ancient skill–drawing with AI feedback

https://www.drawizeacademy.com/
2•lombarovic•13m ago•1 comments

Ensuring AI use in education leads to opportunity

https://openai.com/index/ai-education-opportunity
2•surprisetalk•13m ago•0 comments

China sets lowest economic growth target since 1991

https://www.bbc.com/news/articles/cqxddwl93qjo
1•tartoran•14m ago•0 comments

Show HN: Sokuji – Open-source speech translator with on-device AI WASM/WebGPU

https://github.com/kizuna-ai-lab/sokuji
1•jiangzhuo•15m ago•0 comments

A Number with a Shadow

https://campedersen.com/tang
2•davedx•15m ago•0 comments

Ask HN: Alternatives to GH Actions?

6•BhavdeepSethi•17m ago•1 comments

Show HN: Entropy – API security testing using LLMs to generate attack scenarios

https://github.com/arjinexe/entropy-chaos
1•arjinexe•18m ago•0 comments

Engineering over Enforcement

https://www.contraption.co/engineering-over-enforcement/
1•philip1209•19m ago•0 comments

Show HN: Tune on a real Boss TU-3

https://realtuner.online/
2•smith-kyle•19m ago•0 comments

Can coding agents relicense open source through a "clean room" implementation?

https://simonwillison.net/2026/Mar/5/chardet/
2•MindGods•19m ago•1 comments

B.C.'s daylight-time decision: 'Scientifically a bad idea,' says key researcher

https://www.cbc.ca/news/canada/bc-daylight-saving-health-concerns-9.7114947
1•LostMyLogin•22m ago•3 comments

Canon's rumored retro camera could be its own X Half

https://m.dpreview.com/articles/1229448777/canon-analog-concept-camera-cpplus-x-half
1•PaulHoule•23m ago•0 comments

Malicious NPM "Sandworm" packages targeting AI toolchains and DevSecOps

https://phoenix.security/sandworm-mode-npm-supply-chain-worm/
1•nuzzl•23m ago•1 comments

Show HN: I built an AI tool that analyzes your Discogs vinyl collection

https://recordsv.lt
1•herrstagl•23m ago•0 comments

Spectre I prevents smart devices and AI recorders from picking up your voice

https://www.deveillance.com/
2•world2vec•23m ago•0 comments