HN user

grinich

6,261 karma

Michael Grinich

WorkOS founder

mg@workos.com

https://twitter.com/grinich

Posts173
Comments1,302
View on HN
workos.com 2mo ago

Auth.md: an open protocol for agent registration

grinich
7pts0
workos.com 2mo ago

Handwritten SDKs Are Dead

grinich
5pts1
www.getadb.com 3mo ago

getadb.com - instant database for agents

grinich
1pts0
workos.com 4mo ago

WorkOS raises $100M Series C, hits $2B valuation

grinich
4pts0
twitter.com 10mo ago

Did Atlassian copy our logo?

grinich
1pts0
workos.com 11mo ago

SAMLStorm: Critical Authentication Bypass in XML-crypto and Node.js libraries

grinich
2pts0
twitter.com 1y ago

Account Takeover Attack on X via OAuth Impersonation

grinich
2pts1
workos.com 1y ago

SAMLStorm: Critical Authentication Bypass in XML-crypto and Node.js libraries

grinich
10pts0
workos.com 1y ago

How to run DeepSeek R1 locally

grinich
84pts32
workos.com 1y ago

WorkOS Radar

grinich
1pts0
www.enterprise-ready.com 1y ago

Enterprise Ready Conf

grinich
1pts0
workos.com 2y ago

Auth in Middleware, or How I Learned to Stop Worrying and Love the Edge

grinich
1pts0
workos.com 2y ago

Migrating to Next.js App Router with zero downtime

grinich
2pts0
workos.com 2y ago

WorkOS acquires Warrant (YC S21)

grinich
9pts0
californiaforever.com 2y ago

California Forever

grinich
143pts165
www.stripe.press 3y ago

Poor Charlie’s Almanack

grinich
6pts1
workos.com 3y ago

Crossing the Enterprise Chasm with Claire Hughes Johnson (Former Stripe COO)

grinich
1pts0
workos.com 3y ago

WorkOS 404 page (Mac OS System 7 clone)

grinich
2pts0
workos.com 3y ago

WorkOS Audit Logs

grinich
1pts0
workos.com 4y ago

WorkOS raises $80m in Series B financing, acquires Modulz

grinich
6pts4
cofounder.quest 4y ago

Cofounder Quest

grinich
2pts0
workos.com 4y ago

Lessons We Learned Adding Dark Mode to WorkOS

grinich
7pts0
medium.com 5y ago

WorkOS raises $15M to build “Stripe for enterprise-ready features”

grinich
84pts10
workos.com 5y ago

Building Webhooks into Your Application: Guidelines and Best Practices (2020)

grinich
115pts26
news.ycombinator.com 5y ago

HN homepage on the day it launched (Oct 9, 2006)

grinich
3pts0
news.ycombinator.com 5y ago

HN homepage on the day it launched (Oct 9, 2006)

grinich
24pts8
githubuniverse.com 5y ago

GitHub Universe Keynote (Live Stream)

grinich
2pts0
workos.com 5y ago

Building Webhooks into Your Application: Guidelines and Best Practices

grinich
3pts0
workos.com 5y ago

The Developer's Guide to SoC 2 Compliance

grinich
4pts0
workos.com 5y ago

Fun with SAML SSO Vulnerabilities and Footguns

grinich
5pts0

Hi I'm the founder of WorkOS.

We're working on multi-app support. The large majority of our customers only have 1 app (ChatGPT, Claude, Cursor, etc.) but this isn't the case for developers building lots of side projects.

Also working on shipping an agent-friendly Dashboard. Stay tuned :)

Would love to hear any more feedback: mg@workos.com

WorkOS powers auth for OpenAI, Anthropic, Cursor, Vercel, Perplexity, Clay, Webflow, Granola, and a bunch of others. Free up to 1m users, you pay for enterprise features.

I'm the founder and happy to help. We've differentiated by focusing on "b2b auth" via SAML/SCIM, but today we do everything else. We also have products for feature flags, encryption, bot blocking, MCP auth, etc.

Fun fact, we actually launched on HN in 2020 :) https://news.ycombinator.com/item?id=22607402

If you’re looking for b2b identity, I’m the founder of WorkOS and we power this for a bunch of apps. Feel free to email me, mg@workos.com

(self plug since you asked!)

WorkOS does exactly this. It's "Stripe for enterprise features."

https://workos.com

Our customers include OpenAI, Anthropic, xAI, Cursor, Perplexity, Vercel, Replit, Webflow, Clay, Hex, Carta, Plaid, Drata, Vanta, and many others. If you've used these products, you've used WorkOS!

WorkOS makes it easy to "cross the enterprise chasm." Here's a bit more of the backstory: https://x.com/grinich/status/1841569664465568248

We also launched on HN 5 years ago :) https://news.ycombinator.com/item?id=22607402

I started a startup to fix this exact problem integrating and configuring SSO/SAML.[0]

We launched here on HN 5 years ago[1] and today power SSO for OpenAI, Cursor, Vercel, and a thousand other apps. We also found the initial configuration step to be painful for users, so we built a self-serve wizard that enables enterprise admins to fix issues.[2]

It's still crazy how much complexity there is with enterprise identity systems and managing the user lifecycle for big orgs. It's like the whole thing is made of weird edge cases and even moreso when you add SCIM, RBAC, MFA, etc etc.

(If anyone reading this also loves suffering at the intersection of IAM and developer tools, we are hiring! Email in my profile :))

[0] https://workos.com

[1] https://news.ycombinator.com/item?id=22607402

[2] https://workos.com/admin-portal

Hey - I'm the founder of WorkOS. Happy to chat about the playbook we see with OSS projects spinning-off a commercial offering. It's pretty common and we work with a lot of these businesses, enabling them to continue investment in the ecosystem too. mg@workos.com

Hi - I'm the founder of WorkOS. Would love any feedback you can share here or via email (mg@workos.com)

Betterauth and WorkOS are pretty different. For example, WorkOS isn't designed exclusively for TypeScript (we support SDKs for a bunch of languages/platforms) and WorkOS runs as a cloud service. The developer experience will always be different because of this.

We also design the platform to be modular, which enables you to just use WorkOS for SSO or SCIM alongside an existing auth stack. We call these the standalone APIs and lots of customers use it this way.

WorkOS is focused on enterprise features for b2b apps and solving problems that come with growing upmarket. Today we power auth for OpenAI, Anthropic, Perplexity, Cursor, Vercel, Plaid, and hundreds more.

We love getting feedback so please feel free to post here, email, or twitter DMs are open. Thanks!

(I also love open source and am glad to see more innovation happening here in the ecosystem!)

I'm the founder of WorkOS and we solve this problem for developers, primarily focusing on the challenges around enterprise SAML, SCIM, complex RBAC, fine-grained authorization, and more.

We build the Admin Portal for IdP configuration: https://workos.com/admin-portal

WorkOS actually launched on HN about 5 years ago[0] and today it's used by OpenAI, Cursor, Perplexity, and hundreds of other companies.

Feel free to email me if I can help: mg@workos.com

[0] https://news.ycombinator.com/item?id=22607402

There are several open source options out there (several linked above) that could be a good fit for your business economics. I know lots of folks talk about Supabase and Auth.js on X.

If you have the time and patience, you can also certainly build it yourself. There's no miracles here, just complex engineering and solving a thousand edge cases.

If you decide to use open source, make sure you quickly update dependencies so you're always running latest. Ruby-SAML had a major vulnerability disclosed last month and thousands of apps were affected: https://workos.com/blog/ruby-saml-cve-2024-45409

I work at WorkOS / AuthKit.

We took the Heroku approach. All apps get a free *.authkit.app domain for the hosted login page.

AuthKit never has any WorkOS branding. Clerk puts "Powered by Clerk" on your login page unless you pay. This feels gross. Imagine if Heroku/Vercel were injecting ads into your app?!

AuthKit has free MFA. I believe everyone should get secure auth. Clerk charges to enable MFA. They also charge for passkeys and features like impersonation. Why?

Custom domains cost us $ to run (we pay Cloudflare) so we charge for this. It's also designed for commercial apps. The authkit.app is great for any hobby app.

Hey thanks for the shout-out. I work at WorkOS / AuthKit.

tl;dr - we know this feature is missing and we are working on it

Changing email address is of those simple sounding features that has a ton of complex edge-cases that are critically important to get right. The crux of it is how organization membership/invites and resource sharing typically works with unconfirmed email addresses in apps. What happens with the old email address? Can a different user claim it? Are you allowed to change your email address if your account comes from SAML/SCIM? If you get this behavior wrong, it will lead to inconsistencies that can even cause security vulnerabilities.

Solving this for thousands of different types of apps of course makes the problem significantly more complex. It turns out different developers actually want slightly different behavior, so we need AuthKit to be customizable to accommodate this. More than anything, want to avoid changing these APIs after launching them (even in beta) so there isn't developer thrash. We are working to make sure the solution is as complete as possible and that's taking longer than I would hope.

In the meantime we have some workarounds. e.g. popular apps like Cursor are built on AuthKit and work great.

Anyone can send me an email if you want to chat about this. We're also hiring if you want to work on it. :) mg@workos.com