Uploaded November 2025 | Updated September 2026, 23 minutes ago
WorkOS engineer Nick Holden recaps ERC announcements (AuthKit for platforms, Pipes, Studio) and dives into the new API Keys: secure, org‑scoped keys with a drop‑in widget and SDKs. He explains why API keys matter for humans and AI agents, how they relate to Vault, and small UX details that make keys safer to manage.
CHAPTERS:
0:04 - Intro: AuthKit team and conference highlights
0:44 - AuthKit for platforms (Convex demo, other platforms)
1:33 - Stripe Billing, Pipes, ChatGPT apps, Studio
2:17 - New: API Keys product
2:22 - Why API keys matter (humans and AI agents)
2:46 - DIY challenges: secure creation/management
3:18 - Drop‑in API Keys widget + SDKs for validation
4:00 - Org‑scoped keys today; user‑scoped future
5:36 - AI access: MCP Auth vs API keys
6:40 - Vault vs API Keys; permissions/roles on keys
8:46 - Safety detail: “last used at” timestamps for revocation
WorkOS engineer Nick Holden recaps ERC announcements (AuthKit for platforms, Pipes, Studio) and dives into the new API Keys: secure, org‑scoped keys with a drop‑in widget and SDKs. He explains why API keys matter for humans and AI agents, how they relate to Vault, and small UX details that make keys safer to manage.
CHAPTERS:
0:04 - Intro: AuthKit team and conference highlights
0:44 - AuthKit for platforms (Convex demo, other platforms)
1:33 - Stripe Billing, Pipes, ChatGPT apps, Studio
2:17 - New: API Keys product
2:22 - Why API keys matter (humans and AI agents)
2:46 - DIY challenges: secure creation/management
3:18 - Drop‑in API Keys widget + SDKs for validation
4:00 - Org‑scoped keys today; user‑scoped future
5:36 - AI access: MCP Auth vs API keys
6:40 - Vault vs API Keys; permissions/roles on keys
8:46 - Safety detail: “last used at” timestamps for revocation










