<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Security on Ken Kitts</title><link>https://kenkitts.com/tags/security/</link><description>Recent content in Security on Ken Kitts</description><generator>Hugo</generator><language>en</language><lastBuildDate>Mon, 03 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://kenkitts.com/tags/security/index.xml" rel="self" type="application/rss+xml"/><item><title>I Gave Claude Code a Static API Key. Then I Took It Back.</title><link>https://kenkitts.com/posts/claude-code-okta-pkce-helper/</link><pubDate>Mon, 03 Aug 2026 00:00:00 +0000</pubDate><guid>https://kenkitts.com/posts/claude-code-okta-pkce-helper/</guid><description>Claude Code&amp;#39;s apiKeyHelper contract is one line: print a token to stdout. The easy way is a static key sitting in plaintext forever. Here&amp;#39;s the harder way — Okta, PKCE, and a script that logs in so you don&amp;#39;t have to leave a credential lying around.</description></item></channel></rss>