Safeguard
Tag

token-security

Safeguard articles tagged "token-security" — guides, analysis, and best practices for software supply chain and application security.

6 articles

Open Source Security

npm Classic Tokens Are Gone. The keyv Worm Shows Why That Mattered.

Every npm classic token has been permanently revoked — unrecoverable, unrecreatable. Teams treated it as a chore. Then a worm propagated across 444 packages on exactly that kind of credential.

Aug 7, 20266 min read
AI Security

OAuth and authentication patterns for Model Context Proto...

MCP OAuth authentication has been rewritten three times since March 2025. Here's how the spec, its token security model, and real CVEs like CVE-2025-49596 shape safe MCP deployments.

Aug 5, 20267 min read
Industry Analysis

Session Persistence Security Risks

CircleCI, Okta, Sourcegraph, and Codecov were all breached the same way: a session token outlived the trust that created it. Here's how session persistence becomes a supply chain risk.

Jul 7, 20268 min read
Open Source

jose npm: A Security Review and Safe Usage Guide

The jose npm package is a well-regarded library for JWT, JWS, and JWE across JavaScript runtimes. It gives you the right primitives; using them securely still comes down to how you verify tokens.

Jun 7, 20266 min read
Incident Analysis

Slack 2022-2023 Incidents: Operational Retrospective

Slack disclosed a stolen-token incident over the 2022 holidays and a related GitHub repository access event; the operational lessons apply broadly.

Mar 13, 20267 min read
Application Security

OAuth Token Security Throughout the Lifecycle

OAuth tokens grant access to APIs, services, and user data. Their security across creation, storage, use, and revocation determines your application risk posture.

Feb 7, 20264 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

token-security — Safeguard Blog