<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://blog.christianposta.com/</id><title>Christian Posta</title><subtitle>Christian Posta's blog on Istio, Envoy, API gateways, MCP, and the infrastructure that runs production AI agents.</subtitle> <updated>2026-07-15T22:59:41+00:00</updated> <author> <name>Christian Posta</name> <uri>https://blog.christianposta.com/</uri> </author><link rel="self" type="application/atom+xml" href="https://blog.christianposta.com/feed.xml"/><link rel="alternate" type="text/html" hreflang="en" href="https://blog.christianposta.com/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2026 Christian Posta </rights> <icon>/assets/img/favicons/favicon.ico</icon> <logo>/assets/img/favicons/favicon-96x96.png</logo> <entry><title>Okta SAML and Keycloak for ID-JAG Cross App Access</title><link href="https://blog.christianposta.com/okta-saml-and-keycloak-for-id-jag-cross-app-access/" rel="alternate" type="text/html" title="Okta SAML and Keycloak for ID-JAG Cross App Access" /><published>2026-07-13T01:05:21+00:00</published> <updated>2026-07-15T22:59:25+00:00</updated> <id>https://blog.christianposta.com/okta-saml-and-keycloak-for-id-jag-cross-app-access/</id> <content type="text/html" src="https://blog.christianposta.com/okta-saml-and-keycloak-for-id-jag-cross-app-access/" /> <author> <name>Christian Posta</name> </author> <category term="AI Agents" /> <category term="Identity" /> <summary>A working Okta SAML/SSO → ID-JAG → Keycloak access-token path for Cross-App Access</summary> </entry> <entry><title>What 'is' Agent Identity? Human? Workload? A new Layer?</title><link href="https://blog.christianposta.com/what-is-agent-identity/" rel="alternate" type="text/html" title="What &amp;apos;is&amp;apos; Agent Identity? Human? Workload? A new Layer?" /><published>2026-06-16T02:35:18+00:00</published> <updated>2026-06-23T01:10:02+00:00</updated> <id>https://blog.christianposta.com/what-is-agent-identity/</id> <content type="text/html" src="https://blog.christianposta.com/what-is-agent-identity/" /> <author> <name>Christian Posta</name> </author> <summary>In previous posts, I’ve covered the reasons why an AI agent needs an identity. I recommend reading that first. In this post I want to nail down “what is agent identity” because I’ve seen a lot of different interpretations from smart people such as “use OAuth” to “it’s just workload identity”, and new protocols cropping up, etc. But what “is” an agent identity in concrete terms? An AI agent is ...</summary> </entry> <entry><title>The Differences Between Microservices and AI Agents</title><link href="https://blog.christianposta.com/difference-between-microservices-and-ai-agents/" rel="alternate" type="text/html" title="The Differences Between Microservices and AI Agents" /><published>2026-06-15T22:40:22+00:00</published> <updated>2026-06-15T23:23:46+00:00</updated> <id>https://blog.christianposta.com/difference-between-microservices-and-ai-agents/</id> <content type="text/html" src="https://blog.christianposta.com/difference-between-microservices-and-ai-agents/" /> <author> <name>Christian Posta</name> </author> <summary>Microservices and AI agents are not the same thing. And just because you introduce an LLM doesn’t make a microservice an AI agent. Not realizing this will lead to catastrophic security and infrastructure mistakes. We have become accustomed to building service style architectures over the past 15+ years. Actually, probably much longer. This diagram probably resonates quite strongly with modern a...</summary> </entry> <entry><title>Avoiding MCP Confused Deputy With AAuth</title><link href="https://blog.christianposta.com/avoiding-mcp-confused-deputy-with-aauth/" rel="alternate" type="text/html" title="Avoiding MCP Confused Deputy With AAuth" /><published>2026-05-04T18:38:15+00:00</published> <updated>2026-05-04T18:38:15+00:00</updated> <id>https://blog.christianposta.com/avoiding-mcp-confused-deputy-with-aauth/</id> <content type="text/html" src="https://blog.christianposta.com/avoiding-mcp-confused-deputy-with-aauth/" /> <author> <name>Christian Posta</name> </author> <category term="AI Agents" /> <summary>MCP’s Authorization Spec builds heavily around OAuth 2.1 authorization code grant, but the more dynamic AI agent and MCP systems get, the more we need something that is built to live in this new world. Agent Auth (AAuth) is a protocol built for the needs of modern AI agentic applications: agent identity across services / trust domains dynamic agent registration agent discover permission...</summary> </entry> <entry><title>Inbound Auth for Agentcore With Agentgateway</title><link href="https://blog.christianposta.com/inbound-auth-for-agentcore-with-agentgateway/" rel="alternate" type="text/html" title="Inbound Auth for Agentcore With Agentgateway" /><published>2026-03-04T01:48:35+00:00</published> <updated>2026-03-04T01:48:35+00:00</updated> <id>https://blog.christianposta.com/inbound-auth-for-agentcore-with-agentgateway/</id> <content type="text/html" src="https://blog.christianposta.com/inbound-auth-for-agentcore-with-agentgateway/" /> <author> <name>Christian Posta</name> </author> <category term="AI Agents" /> <summary>The best thing about being on the frontline of large enterprises adopting AI agents and MCP tools at scale is we get to see real, practical challenges. AWS Agentcore is a popular platform for deploying custom-built AI agents, but one question crops up frequently: how do callers authenticate to my agent, and how does the agent know who is calling? Getting both right ie, strong caller authenticat...</summary> </entry> </feed>
