Why OAuth Breaks Differently for AI Agents: The Long-Lived Token Problem
Autonomous agents outlive the sessions OAuth assumes. How long-lived agent tokens create replay, scope creep and revocation gaps, and what to do about it.

Free, high-quality AI security education — courses, live events, and resources for the people defending AI systems.

A full AI-security curriculum, taught by passionate instructors.
Weekly live discussions and monthly summits with expert speakers.
Taught by the people innovating AI security for a living.



Autonomous agents outlive the sessions OAuth assumes. How long-lived agent tokens create replay, scope creep and revocation gaps, and what to do about it.

Abhijit Dey (Axis Bank) on what responsible AI actually means — cautious tokens, agents managed like employees, a separate AI gateway, and why AI should recommend, never decide, when the outcome affects a person.

BOLA has topped the OWASP API Security Top 10 since 2019. Darren Shelcusky on why seven years of detection hasn't fixed it — and why agentic AI turns a known engineering failure into an urgent one.
Your first stop in AI security — a tour of the technical and organizational forces shaping the field, from threat modeling to the frameworks now governing it.
An overview of MCP and its security implications, walking the OWASP MCP Top 10 through real-world incidents and the fixes that stop them.
As AI agents take on real work, they need managing like any employee — access, oversight, and accountability. A practical guide to doing it well.
Finish a course and get a shareable credential with its own public verification page.
Session recaps, new course drops, and the week's most important AI-security research — no noise.