Keycard Labs | Founding Principal Engineer & Founding Systems Engineer | Full-time | Remote (North or South America)
Keycard is on a mission to redefine machine identity for the AI Era — empowering developers to seamlessly connect people, agents, and services across networks, clouds, and applications. As generative AI and agent-based workflows grow more sophisticated, they demand real-time, adaptable access patterns. Keycard unlocks dynamic, identity-based credentials, ensuring every agent and service operates with precise, contextual permissions—creating a robust foundation for trusted AI systems.
We envision a global identity network, underpinned by open protocols, allowing distributed systems to adapt dynamically, scaling to handle complex AI workloads, and maintain cryptographically verifiable trust relationships. By rethinking secret management and machine identity from first principles, our goal is to delight developers, meet the performance demands of platform engineers, and establish new security primitives for cloud-native architectures — all in an inclusive, collaborative environment focused on consistent, high-quality execution and crafting products that developers love so much they bring them everywhere they go.
Keycard Labs | Founding Principal Engineer | Full-time | Remote
Keycard Labs is fundamentally rethinking infrastructure security, by moving from a world of static secrets and API keys to dynamically-issued, short-lived tokens. In that process, we are delivering an experience developers love, while making it easy to collaborate with teams that operate and secure applications.
This is your chance to build foundational technology that sits at the heart of developer and security workflow. We've all experienced the pain of managing secrets in traditional service-to-service authentication. That pain is only increasing as AI agents integrate with more APIs in dynamic, non-deterministic
ways. We are building the next generation of software to solve those problems.
We are a newly-funded company, co-founded by ex-Snyk and ex-Auth0 engineers with multiple prior startup exits. If you're excited about identity and security, and the opportunity to help shape the future of both the company and the technology, we'd love to hear from you!
Attestation is an option in the FIDO ecosystem, and it is up to each website whether or not attestation is needed. Attestation is often required in enterprise settings. While consumer adoption of WebAuthn is incredibly low, the introduction of passkeys and multi-device credentials looks poised to change that.
For consumer scenarios, attestation is often not a requirement. In that case, FIDO offers the "none" and "self" attestation modes. None conveys no attestation. Self attestation involves a per-website key pair. Either of these modes are privacy and DIY friendly.
Can I ask why you chose everyauth over Passport? (I'm the developer of Passport.)
By all accounts, Passport is by far the more popular authentication package (95,000 downloads from npm in the last month vs. 2,100 for everyauth). Furthermore, maintenance of everyauth seems to have come to a halt, leaving outstanding bugs and issues unaddressed. In contrast, Passport has 100% test coverage, and has an API that's been proven stable over ~2 years.
I lol'd at the title. Just having a Gruntfile is the first smell I notice when looking at a project. Seriously, why take two simple tools and layer a unnecessary "task runner" on top of them?
It seems like just about everyone's written a static site generator. Mine is Kerouac (https://github.com/jaredhanson/kerouac), another Node.js-based generator.
I specifically wanted to apply the middleware concept to generating pages, which turned out to be a decent fit. It ends up being a very similar API to Express, so its instantly familiar to Node.js developers. Check it out.
I like this trend of making ever-more simple static site generators. To promote my own project, check out Kerouac [1] if you prefer your tooling to be in Node.js.
This looks really great! One thing really bothers me however: a dependency on all of Backbone. Pulling in a bunch a view-related code for an ORM has a certain code smell.
Is there any effort to modularize Backbone itself, so that Bookshelf can only depend on the model and collection pieces?
This is fantastic! I'm really excited to see Mozilla improving the login experience for users across the web. It is a problem that is sorely in need of better solutions.
For the Node.js developers in the crowd, I'm happy to see Mozilla is using Passport.js (http://passportjs.org/) (which I'm the developer of) to power the OpenID/OAuth dances when doing identity bridging. You can see it in action at the BigTent repo: https://github.com/mozilla/browserid-bigtent
Passport.js can be used in your own applications to easily perform the server-side part of Persona/BrowserID as well as integrate with or transition from an existing login system.
I've long been fascinated with XMPP, because it is so flexible. Rather than focusing solely on a specific purpose (like IM), Junction exposes a middleware framework similar to Express so that you can develop applications on top of XMPP.
I've been happy with the approach, and I'd be curious to get feedback from other developers who've had similar thoughts regarding XMPP.
Agreed. It'd be great for interoperability to get a set of quality, conformant open source provider implementations in various languages. I've implemented OAuth 1.0 and OAuth 2.0 as middleware in Node.js, available here:
Passport (http://passportjs.org/) is worth investigating as an alternative to everyauth. Its primary advantage is a modular architecture focused solely on authentication, which is fully decoupled from routing and template engines. Many people find this approach more flexible and easier to integrate.
I'd say the experience is quite easy, especially when using browserid.org/verify for verification.
My biggest criticism is the lack of a concretely defined spec for how the Verified Email Protocol works, if one wanted to implement it directly, rather than relying on browserid.org.
Based on the code in the repository, the protocol seems relatively straightforward. But, as it currently stands, it'd be difficult to implement it based on the paper spec alone.
Anyway, nice work on BrowserID. I'm excited to see where its headed.
Keycard is on a mission to redefine machine identity for the AI Era — empowering developers to seamlessly connect people, agents, and services across networks, clouds, and applications. As generative AI and agent-based workflows grow more sophisticated, they demand real-time, adaptable access patterns. Keycard unlocks dynamic, identity-based credentials, ensuring every agent and service operates with precise, contextual permissions—creating a robust foundation for trusted AI systems.
We envision a global identity network, underpinned by open protocols, allowing distributed systems to adapt dynamically, scaling to handle complex AI workloads, and maintain cryptographically verifiable trust relationships. By rethinking secret management and machine identity from first principles, our goal is to delight developers, meet the performance demands of platform engineers, and establish new security primitives for cloud-native architectures — all in an inclusive, collaborative environment focused on consistent, high-quality execution and crafting products that developers love so much they bring them everywhere they go.
Founding Principal Engineer: https://www.keycard.sh/careers/founding-principal-engineer Founding Systems Engineer: https://www.keycard.sh/careers/founding-systems-engineer