Hacker Newsnew | past | comments | ask | show | jobs | submit | grinich's commentslogin

Custom roles per-org is supported natively with WorkOS. (I'm the founder.)

I think we have the most advanced RBAC system. You can even map roles from custom IdP groups via SCIM.

More info here: https://workos.com/guides/user-provisioning-scim


Hi I'm the founder of WorkOS.

We're working on multi-app support. The large majority of our customers only have 1 app (ChatGPT, Claude, Cursor, etc.) but this isn't the case for developers building lots of side projects.

Also working on shipping an agent-friendly Dashboard. Stay tuned :)

Would love to hear any more feedback: mg@workos.com


WorkOS has a built-in workflow for all the complex SAML/SCIM attribute mapping.

https://workos.com/docs/directory-sync/attributes

Also certificate renewal flows:

https://workos.com/changelog/certificate-renewal-flow

(I'm the founder.)


WorkOS powers auth for OpenAI, Anthropic, Cursor, Vercel, Perplexity, Clay, Webflow, Granola, and a bunch of others. Free up to 1m users, you pay for enterprise features.

I'm the founder and happy to help. We've differentiated by focusing on "b2b auth" via SAML/SCIM, but today we do everything else. We also have products for feature flags, encryption, bot blocking, MCP auth, etc.

Fun fact, we actually launched on HN in 2020 :) https://news.ycombinator.com/item?id=22607402


This is awesome - I had heard the name floating around but didn't realize how permissive your free tier was. I'm using Clerk for my new project https://thoughtprint.space/ but might switch it over to WorkOS.


Docs to migrate from Clerk to WorkOS: http://workos.com/docs/migrate/clerk

Claude Code can often one-shot it. Feel free to reach out if I can help!


Recently I moved to WorkOS for modulus.so. love your product.

MCP auth and feature flags are two feature that got me in. I also like that it's flexible enough for me to write custom logic in auth flow - which a lot of providers tries to abstract.


What do you use for RBAC today? Do you have AI rewrite it every time?


The author of the initial comment mentioned that customers of contract work prefer code which is 100% theirs, purpose-written, not a dependency, even vendored.


If you’re looking for b2b identity, I’m the founder of WorkOS and we power this for a bunch of apps. Feel free to email me, mg@workos.com


We use WorkOS to support some of our offerings but not for our own corporate identity/authentication. I’m not close to the project so I don’t have experience using WorkOS but definitely curious about replacing Okta.



I lost track what they use … Auth0, Ory, WorkOS… sounds like they should go ahead and finally acquire something #scnr


It's so bad

Here is a major vulnerability we disclosed earlier this year:

https://workos.com/blog/samlstorm


I got hit with the same kind of phishing attack a couple months ago

It's pretty incredible the level of UI engineering that went into it.

Some screenshots I took: https://x.com/grinich/status/1963744947053703309


Hmm, since Chromium is working on adding browser-local AI features, I wonder if this one day could be a security check (for links opened from the outside of the browser). E.g. the browser detected that you clicked on a new-tab link, and the page looks like a commonly known site, then the AI detects that the URL isn't "x.com" and gives a heads-up warning. At least for the top 1000 most common sites, this could prevent a lot of phishing attacks.


I'm sorry but the imagecontent-x.com url should throw red flags for anyone.


This is exactly how not to defend against phishing. The meaningful defense is to foreclose on it entirely, not to just get super good at spotting fakes.


> The meaningful defense is to foreclose on it entirely

Sounds easy enough in theory. How do you do that in practice?


Use passkeys. Bully services that don’t offer them or lock them behind enterprise plans into implementing them.

That’s it. The single working Defense against credential theft.


So, in that case the browser (correctly) did not autofill? Is that a common occurrence for legit traffic from X? And no complaint about the website's identity from the browser -- the expected "lock" icon left of the URL?


As long as people are used to companies just buying new domains for the hell of it, yes. Just look at the amount of domains Microsoft uses for signing in! My password manager currently holds 8 of them. Eight! Who can be blamed for thinking it’s the password managers fault?


They migrated SSO/SAML to WorkOS, and consumer auth to forked open source.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: