The stats page on this site only ever showed the last 14 days, which meant every time I looked at it I was looking at noise. I rebuilt it to track lifetime totals properly, and the all-time numbers - covering the time since this site moved off WordPress - turned up a few things I didn't expect.
Toby Allen
Solutions Engineer at Okta. I write about identity, access management, and security. This site archives my published articles, talks, and presentations.
Series - Indepth Explainers
Latest
Ten attempts, one diagram: what fixing an AI-generated image actually taught me
I asked Claude Code to generate a technical architecture diagram with gpt-image-1 for a blog post. Getting one five-box diagram fully correct took ten regenerations, and the version that shipped first was itself wrong - it got a clean render by quietly dropping the exact claim the whole post was about.
Integrating Intercom with Auth0 On-Behalf-Of Token Exchange for a Full Login Audit Trail
Third-party support tools like Intercom are usually bolted onto an application with a shared API key and a loosely-typed user ID. Auth0's On-Behalf-Of token exchange lets you do better: every message a customer sends carries a real, auditable delegation chain back to the login that started it, and a CIBA push puts a human back in the loop for the requests that need one.
@auth0/auth0-hono on Deno Deploy: A Logout That Doesn't Log You Out
@auth0/auth0-hono ships an idpLogout option that defaults to false, so calling /auth/logout only clears the local session cookie and never touches Auth0's own session at the identity provider. I found this deploying a third runtime for the same SDK, and it turned out to already be sitting unfixed in a demo I'd built weeks earlier.
Auth0 Token Vault with Organizations: Per-Org Isolation and Three Setup Gotchas
Auth0's Token Vault partitions a user's Connected Accounts by Organization, so the same Google or GitHub connection in one org is invisible from another. The isolation itself just works. Getting a demo application to the point where it worked took three separately-gated setup steps, each with a misleading error.
The feature was built and the model never heard about it
Two new capabilities shipped in the same session, wired into the backend correctly and invisible to the chat model anyway - because registering a tool and telling the model it exists turned out to be two separate, separately-forgettable steps.