Making Software

Auth0

Making Software is a podcast where engineers from across the tech world, backend, frontend, security, open source, and more share how real software gets built. Each episode features an informal conversation full of lessons, stories, and technical insight from people who design and ship the systems we all rely on. The show goes beyond tools and frameworks to explore the thinking, trade-offs, and creativity behind great engineering, offering listeners an authentic look into the craft of building better software.

Episodes

  1. 6d ago

    Episode 9: Inside the Protocol Securing AI Agents at Work

    Every time you tell an AI agent to do something and it pops open a browser asking for your permission, you're probably clicking yes without reading it. Miguel Pedregosa is a Senior Software Engineer on the Protocols team at Auth0 (Okta). His team owns the implementation of identity standards inside Auth0 like OAuth, OIDC, SAML, WS-Federation. The infrastructure every developer integrating with Auth0 relies on without thinking about it. Before Auth0, Miguel worked on malvertising detection, tracing malware hidden inside ad traffic. The through line in his career: security-intensive environments where getting it wrong has real consequences. In this episode we talk about what it's like to build infrastructure that millions of developers depend on without knowing it, how Cross-App Access and Enterprise-Managed Auth for MCP came to exist, and what it takes to implement an IETF standard that's still being drafted while industry adoption is already happening. We also get into the difference between what enterprises and startups actually need from identity — and why Miguel thinks basic threat modeling matters even if you never want to touch an RFC. What You'll Learn: Why AI agent auth popups are a security flaw, not just a UX annoyance How Cross-App Access uses an existing enterprise identity provider to let agents authenticate without opening a browserWhat the IDJAG (Identity JWT Assertion Grant) is and why it's the central artifact of the protocolWhat it's like to implement an IETF standard while it's still being drafted — and how Auth0's team fed back into the specThe difference between what enterprises and startups need from identity: legacy system integration at scale- Why basic threat modeling is the minimum for anyone shipping AI agents, and the three questions to start withResources: Miguel on LinkedIn: https://www.linkedin.com/in/miguel-pedregosa/Cross-App Access blog post: https://auth0.com/blog/setting-up-testing-cross-app-access-auth0/Cross-App Access protocol: https://oauth.net/cross-app-access/IDJAG (Identity JWT Assertion Grant) spec: https://datatracker.ietf.org/doc/html/draft-ietf-oauth-identity-assertion-authz-grantIdentity and Authorization Chaining Across Domains: https://datatracker.ietf.org/doc/draft-ietf-oauth-identity-chaining/

  2. Jul 29

    Episode 7: Developers vs Builders: How AI Is Changing Who We Build For

    Who are we actually building for anymore, and does the answer change everything about how we teach, learn, and ship software? James Quick is a Developer Educator at Cloudflare with 13 years in developer relations, starting as a technical evangelist at Microsoft before most people knew that was a job. He hasn't written a line of code in 8 months. In that time he has built more than ever: a Frame.io clone for his team, a QuickBooks replacement, a Descript alternative, and Dropcast, a tool that generates custom podcasts from links so he can keep learning while commuting. In this episode we talk about how the line between developer and builder is dissolving, what that means for the people creating educational content, how AI completely flipped James's take on build vs buy, and how companies like Cloudflare are thinking about being part of the conversation in a world where LLMs make the recommendations. If you are a developer, a builder, or someone creating content for either, this one is for you. What You'll Learn: Why the audience for developer content has shifted from developers to builders, and what that forces educators to changeHow James builds more than ever without writing a line of code, and why he does not miss itWhy his opinion on build vs buy completely flipped, with real tools he built to prove itWhat AEO (Answer Engine Optimization) is and why it matters more than SEO for developer tools right nowHow Cloudflare thinks about being recommended by AI agents when builders never ask which platform to useWhy every app James builds now needs an MCP server, and how that changes the build decision- The one piece of advice James has given for 13 years that has not changed even with AI

  3. Jun 24

    Episode 6: Building Rails Infrastructure: The Story Behind Solid Queue | Open Source & Community

    Is Redis still mandatory for scaling background workflows, or can modern database disks handle millions of jobs per day? In this episode of Making Software, Rosa Gutierrez (Principal Programmer at 37 Signals) breaks down the creation of Solid Queue: the default background job adapter shipping with Rails 8. We dive deep into the technical decisions behind moving away from memory stores, the reality of maintaining infrastructure used by millions, and how AI agents are changing the culture of open-source contributions. What You'll Learn- The Death of Redis Multi-Gem Noise: Why Solid Queue was built to streamline a complex seven-gem setup in production. - Database vs. In-Memory: The architectural trade-offs, performance calculations, and transactional integrity advantages of database-backed queues. - The Human Tax of Open Source: The realities of maintaining critical framework code, handling community burnout, and guarding against repository noise. - The Rise of AI Agents on GitHub: Why LLMs are writing a massive wave of modern issues and PRs, and why they make surprisingly polite contributors. Solid-queue Repo: https://github.com/rails/solid_queueChapter Markers:00:00 - Introduction to Rosa Gutierrez & Making Software01:56 - Meet Rosa: 9+ Years at 37 Signals02:58 - The Ruby Bubble and Its Modern Comeback04:35 - Why AI Agents Love Ruby on Rails05:44 - The European Ruby Triathlon Infrastructure08:03 - The Origin Story of Solid Queue & Solid Cache10:48 - Moving Away From Memory Stores to Fast Relational Disks13:06 - Replacing 7 Gems and Testing Internally at HEY14:28 - Database Scalability Hardships & Transactional Integrity16:58 - Simplifying API Descriptors & Documentation for Rails 820:07 - Intentional Code Readability vs Legacy Gem Complexities22:09 - The Reality Shift of Mainstream Open Source Maintenance26:10 - GitHub Entitlement vs Polite AI Agents28:15 - Being a Founding member at the Rails Foundation30:37 - Organizing Rails World & Programming Committee Selection39:45 - Meticulous Advice for First-Time Open Source Contributors42:17 - Wrap-up

About

Making Software is a podcast where engineers from across the tech world, backend, frontend, security, open source, and more share how real software gets built. Each episode features an informal conversation full of lessons, stories, and technical insight from people who design and ship the systems we all rely on. The show goes beyond tools and frameworks to explore the thinking, trade-offs, and creativity behind great engineering, offering listeners an authentic look into the craft of building better software.