Emilio Cignetti

Senior Full-Stack Engineer

Italian and Argentine citizen

Work

Longer write-ups of things I have built. The complete history is on the CV.

Professional work

2025 to 2026

A production LLM pipeline that finds what slows engineers down

Development transcripts, scrubbed of secrets and personal data, read by Claude into typed findings. The confident ones arrive as pre-filled tickets.

A tool that reads engineers' transcripts has two ways to fail. It can send something it should never have sent, or it can produce findings nobody acts on. The second one kills it quietly.

  • Anthropic API
  • Claude
  • structured output
  • Go
  • Node.js
  • OAuth 2.0 device flow
  • Slack
  • Jira

2023 to 2025

An accessibility-first design system

Thirty-plus components published as an npm library and adopted as mandatory across an engineering organization of several teams.

A component library is not hard because components are hard. It is hard because every team wants a slightly different one, and every exception you grant is a bug you will ship in someone else's product.

  • Vue 2.7
  • TypeScript
  • SCSS
  • Storybook
  • design tokens
  • WAI-ARIA
  • axe

Personal projects

May 2025 to now

An OpenID Connect provider and a narrowing token exchange

An OpenID Connect server with an RFC 8693 token exchange, three resource servers, a client behind a backend-for-frontend, and an MCP server for agents.

A person consents once, broadly. Every token after that has to be narrowed by intersection before it touches an API, and no exchange may ever widen one.

  • NestJS
  • TypeScript
  • PostgreSQL
  • TypeORM
  • Drizzle
  • OAuth 2.1
  • OIDC
  • RFC 8693
  • Angular
  • Vue

August 2026 to now

Claude driving three microservices, on the user's own authority

An MCP server in front of id, inventory and social. The user asks in a chat box, and the server mints one token per audience and calls each API as them.

A chat box beats a user interface for anything you can say in one sentence — but only if the agent can reach several APIs on the user's own authority, without ever holding their credentials.

  • Model Context Protocol
  • OAuth 2.1
  • RFC 8693
  • RFC 9728
  • microservices
  • NestJS
  • TypeScript
  • Claude

June 2025 to now

A single-page client where the cookie path is the security boundary

An SPA behind a backend-for-frontend holding three separately-audienced tokens at once, isolated by cookie Path, degrading visibly when one cannot be got.

A client needing three APIs must hold three tokens with nothing in common. If any of them can be sent to the wrong proxy, the whole narrowing scheme upstream was decorative.

  • Angular
  • Vue 3
  • TypeScript
  • NestJS
  • Tailwind
  • Playwright