token-security
Safeguard articles tagged "token-security" — guides, analysis, and best practices for software supply chain and application security.
6 articles
A Link Is Fetched Before Anyone Clicks It
Paste a URL into a chat message and a server fetches it automatically to build a preview card, before anyone reads the message or clicks anything. That fetch consumes a single-use link or a time-limited token just as effectively as the intended recipient would have.
npm Classic Tokens Are Gone. The keyv Worm Shows Why That Mattered.
Every npm classic token has been permanently revoked — unrecoverable, unrecreatable. Teams treated it as a chore. Then a worm propagated across 444 packages on exactly that kind of credential.
OAuth and authentication patterns for Model Context Proto...
MCP OAuth authentication has been rewritten three times since March 2025. Here's how the spec, its token security model, and real CVEs like CVE-2025-49596 shape safe MCP deployments.
Session Persistence Security Risks
CircleCI, Okta, Sourcegraph, and Codecov were all breached the same way: a session token outlived the trust that created it. Here's how session persistence becomes a supply chain risk.
jose npm: A Security Review and Safe Usage Guide
The jose npm package is a well-regarded library for JWT, JWS, and JWE across JavaScript runtimes. It gives you the right primitives; using them securely still comes down to how you verify tokens.
Slack 2022-2023 Incidents: Operational Retrospective
Slack disclosed a stolen-token incident over the 2022 holidays and a related GitHub repository access event; the operational lessons apply broadly.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.