The stats page on this site only ever showed the last 14 days, which meant every time I looked at it I was looking at noise. I rebuilt it to track lifetime totals properly, and the all-time numbers - covering the time since this site moved off WordPress - turned up a few things I didn't expect.
Toby Allen
Solutions Engineer at Okta. I write about identity, access management, and security. This site archives my published articles, talks, and presentations.
Series - Indepth Explainers
Latest
Six reviews caught the architecture and missed the data
A live-event monitoring dashboard went through six rounds of adversarial review before a line of code shipped - and every one of them was reviewing an argument, not the actual files, for four rounds running.
Auth0 Anonymous Sessions: The Cookieless Transfer Ticket Handoff
Auth0 has documented a second way to carry an anonymous session into login: a transfer ticket, exchanged for a short-lived anon_transfer_token and passed straight to /authorize as a query parameter, with no cookie involved at all.
Ten attempts, one diagram: what fixing an AI-generated image actually taught me
I asked Claude Code to generate a technical architecture diagram with gpt-image-1 for a blog post. Getting one five-box diagram fully correct took ten regenerations, and the version that shipped first was itself wrong - it got a clean render by quietly dropping the exact claim the whole post was about.
Integrating Intercom with Auth0 On-Behalf-Of Token Exchange for a Full Login Audit Trail
Third-party support tools like Intercom are usually bolted onto an application with a shared API key and a loosely-typed user ID. Auth0's On-Behalf-Of token exchange lets you do better: every message a customer sends carries a real, auditable delegation chain back to the login that started it, and a CIBA push puts a human back in the loop for the requests that need one.
@auth0/auth0-hono on Deno Deploy: A Logout That Doesn't Log You Out
@auth0/auth0-hono ships an idpLogout option that defaults to false, so calling /auth/logout only clears the local session cookie and never touches Auth0's own session at the identity provider. I found this deploying a third runtime for the same SDK, and it turned out to already be sitting unfixed in a demo I'd built weeks earlier.