Authorize, don't authenticate

https://blog.marcua.net/2026/07/31/authorize-dont-authenticate.html

Comments

4 points · 2 comments · view on lemmy.world

2 Comments

tangeli@piefed.social · 2 pts · 36d

It's an interesting architecture but you still have to trust the app. Once you authorize access to your data, the app can retain a copy of it, disclose it, sell it to a third party, even modify or delete it, unless you authorized only read-only access, which would suffice for some apps but not all.

jbrains@sh.itjust.works · 1 pts · 36d

I like this idea and look forward to seeing how well it works in practice.