A developer built Seneschal, an OAuth broker that lets AI agents access Gmail, Calendar, and Drive with user approval while keeping tokens secure. Google's Restricted tier requires expensive security assessments and annual reviews, so Seneschal remains in Testing mode (100 users max) until demand justifies the compliance costs.
Quest is an open-source, self-hosted AI agent workbench that lets users connect services like email, Slack, and finance tools to Claude, Gemini, and other LLMs while prioritizing security for sensitive data. It enforces strict isolation between private data access and internet connectivity, requires human approval for any outbound actions, and provides a web UI for configuration and monitoring.
Instapaper launches API v2 with modern standards including OAuth 2, bearer tokens, and RESTful design, replacing the 2011 API v1. The company also releases open source SDKs for Python and TypeScript, along with an OpenAPI spec, enabling developers to build integrations for millions of users.
Anthropic's MCP Python SDK versions 1.9.1–2.1.1 contain an OAuth vulnerability allowing malicious MCP servers to steal login credentials and achieve full account takeover. The flaw exploits a fallback authentication discovery path that skips security validation checks, enabling attackers to intercept credentials intended for legitimate login providers across three OAuth implementations.