🔐 Identity comes first
Users, services, and AI agents all need strong, verifiable identities. No auth = no trust
🎯 Use scopes (and use them well)
Over-permissioned APIs are a liability.
👀 Visibility beats assumptions
You can’t secure what you can’t see.