Agent skill

Secure OAuth Oidc

by citypaul in citypaul/.dotfiles

Design, implement, audit, test, troubleshoot, or migrate secure OAuth 2.0 and OpenID Connect (OIDC) systems using RFC 9700 / BCP 240.

Custom licenceAuto-check passedBackend & APIs

Install Secure OAuth Oidc

skills CLI
$ npx skills add citypaul/.dotfiles --skill secure-oauth-oidc -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install citypaul/.dotfiles secure-oauth-oidc --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/citypaul/.dotfiles.git skills-src && mkdir -p .claude/skills && cp -r skills-src/claude/.claude/skills/secure-oauth-oidc .claude/skills/secure-oauth-oidc && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
secure-oauth-oidc
GitHub stars
740
Token cost
~3.8k tokens
SKILL.md length
1,978 words
Files
7 (incl. references)
Skills in repo
44
Repo updated
First seen
Licence
Custom licence

At a glance

Design, implement, audit, test, troubleshoot, or migrate secure OAuth 2.0 and OpenID Connect (OIDC) systems using RFC 9700 / BCP 240.

  • Works in 7 steps: Goal — delegated API access, user… → Parties — authorization server / OpenID… → Client type and execution context —… → …
  • Authorization servers and OpenID Providers
  • SKILL.md covers Bring the flow you touch up to…, Load the right references, Establish the security profile… and Build a transaction ledger, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Secure OAuth Oidc is an agent skill from citypaul/.dotfiles. Design, implement, audit, test, troubleshoot, or migrate secure OAuth 2.0 and OpenID Connect (OIDC) systems using RFC 9700 / BCP 240. Use for authorization servers and OpenID Providers, OAuth clients and OIDC relying parties, resource servers, native apps, browser-based apps, multi-issuer login, redirect URIs, authorization code and PKCE flows, state and nonce handling, ID Token validation, token storage and replay, refresh-token rotation, sender-constrained tokens (DPoP or mTLS), mix-up and injection attacks…

Its SKILL.md is about 3.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including reference files (for example `agents/openai.yaml`, `references/attack-and-test-catalog.md` and `references/oidc-validation.md`).

It sits in Backend & APIs, covering OAuth and OpenID Connect.

When your agent uses it

  • Authorization servers and OpenID Providers
  • OAuth clients and OIDC relying parties
  • Resource servers
  • Browser-based apps

Example prompts

  • “/secure-oauth-oidc”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Goal — delegated API access, user authentication, both, machine-to-machine access, device authorization, or token exchange.
  2. Parties — authorization server / OpenID Provider, client / relying party, resource server, resource owner / end-user, browser or system…
  3. Client type and execution context — confidential or public; server-side web app, browser app, native app, service, CLI, or device…
  4. Flows and response modes — enumerate every grant, response type, response mode, callback, token exchange, refresh path, logout path, and…
  5. Trust topology — single issuer or multiple; static or dynamic discovery/registration; one or many resource servers; same-party or…
  6. Applicable profile — RFC 9700 baseline plus OIDC Core, native-app BCP, DPoP, mTLS, PAR/JAR/JARM, FAPI, or another deployment profile. A…
  7. Evidence — exact code, config, metadata, library and version, tests, and runtime behavior. Mark anything not inspected as unknown.

What it can do on your machine

Read from SKILL.md and the folder at commit cd4028d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Secure OAuth Oidc loads about 3.8k tokens when it runs, and up to ~22k if it reads all its reference files. Until then it costs about 161 tokens; SKILL.md has 1,978 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~161
When it runs · the whole SKILL.md, loaded when a task matches
~3.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~22k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 1,978 words (~3,789 tokens).

“Treat OAuth security as a set of end-to-end protocol invariants, not a checklist of parameters. Use RFC 9700 / BCP 240 as the baseline, then add the requirements of the selected OAuth extension, OpenID Connect, platform profile, and deployment.”

— opening of SKILL.md by citypaul, Custom licence
name
secure-oauth-oidc

Read the full SKILL.md on GitHub

Files

SKILL.md and 6 other files (references) in claude/.claude/skills/secure-oauth-oidc of citypaul/.dotfiles.

  • SKILL.md
  • agents/openai.yaml
  • references/attack-and-test-catalog.md
  • references/oidc-validation.md
  • references/review-and-delivery.md
  • references/rfc9700-control-catalog.md
  • references/standards-map.md

Open the folder on GitHubat commit cd4028d

Compare with similar skills

Secure OAuth Oidc next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Secure OAuth Oidc compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Secure OAuth Oidc this skillcitypaul/.dotfiles740—~3.8kAutomated safety check: PassCustom licence
Fortify Developmentcoollabsio/coolify63k4 repos~1.9kAutomated safety check: PassMIT
OmniRoute Provider Managementdiegosouzapw/OmniRoute75k—~2.4kAutomated safety check: PassMIT
Antipattern Preventiondoorkeeper-gem/doorkeeper5.5k—~1.1kAutomated safety check: PassMIT
Cognitoitsmostafa/aws-agent-skills1.2k1 repos~2.3kAutomated safety check: PassMIT
Notion Worker Third-Party Auth Guidemakenotion/workers-template4391 repos~3.5kAutomated safety check: NotesMIT

Similar skills

  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed
  • OmniRoute Provider Management

    diegosouzapw/OmniRoute

    Manages AI provider connections, API keys, OAuth flows and connection tests through OmniRoute's REST API across its 327-provider catalog.

    75k GitHub stars~2.4k tokensUpdated today
    Backend & APIsAuto-check passed
  • Antipattern Prevention

    doorkeeper-gem/doorkeeper

    Avoid common Ruby and Rails antipatterns that degrade maintainability and performance.

    5.5k GitHub stars~1.1k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Cognito

    itsmostafa/aws-agent-skills

    AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.3k tokens
    Backend & APIsAuto-check passed
  • Notion Worker Third-Party Auth Guide

    makenotion/workers-template

    Official

    Decides whether a Notion Worker should use a brokered credential, a plaintext environment secret, or OAuth to authenticate against a non-Notion service.

    439 GitHub starsUsed in 1 repo~3.5k tokens
    Backend & APIsAuto-check: notes
  • Stripe Best Practices

    kanchengw/cnllm

    Guides Stripe integration decisions — API selection (Checkout Sessions vs PaymentIntents), Connect platform setup (Accounts v2, controller properties), billing/subscriptions, Treasury financial…

    173 GitHub starsUsed in 2 repos~925 tokens
    Backend & APIsAuto-check passed

More from citypaul/.dotfiles

All 44 skills in this repo
  • Find Skills

    citypaul/.dotfiles

    Discover and, with authorization, install agent skills from the open skills ecosystem.

    740 GitHub stars~2.5k tokensUpdated 2 days ago
    Auto-check passed
  • Render Code Shape

    citypaul/.dotfiles

    Render the shape of code — module boundaries, the types that cross them, signatures, and a cited call graph — for code that already exists or a change about to be built.

    740 GitHub stars~2.5k tokensUpdated 2 days ago
    Auto-check passed
  • Structure Codebase

    citypaul/.dotfiles

    Design, audit, and evolve physical source and package structures that expose real architectural boundaries while keeping related behavior together.

    740 GitHub stars~4.4k tokensUpdated 2 days ago
    Auto-check passed
  • Test Design Reviewer

    citypaul/.dotfiles

    Review test quality using Dave Farley's eight properties of good tests.

    740 GitHub stars~1k tokensUpdated 2 days ago
    Auto-check passed
  • Characterisation Tests

    citypaul/.dotfiles

    A skill your agent uses when modifying existing code that lacks tests and you need to document its actual current behavior before making changes -- the legacy code dilemma where you need tests to…

    740 GitHub stars~3.6k tokensUpdated 2 days ago
    Auto-check passed
  • CI Debugging

    citypaul/.dotfiles

    Systematic CI/CD failure diagnosis using hypothesis-first investigation, local reproduction, and environment delta analysis.

    740 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check: notes

Categories

Questions about Secure OAuth Oidc

What does Secure OAuth Oidc do?

Design, implement, audit, test, troubleshoot, or migrate secure OAuth 2.0 and OpenID Connect (OIDC) systems using RFC 9700 / BCP 240. dotfiles.0 and OpenID Connect (OIDC) systems using RFC 9700 / BCP 240.

When should I use Secure OAuth Oidc?

Secure OAuth Oidc fits situations like: authorization servers and OpenID Providers; OAuth clients and OIDC relying parties; resource servers; browser-based apps.

How do I install Secure OAuth Oidc in Claude Code?

Run `npx skills add citypaul/.dotfiles --skill secure-oauth-oidc -a claude-code`. Or copy the skill folder (claude/.claude/skills/secure-oauth-oidc in citypaul/.dotfiles) into .claude/skills/secure-oauth-oidc in your project. Claude Code loads it when a task matches its description.

How do I install Secure OAuth Oidc in Codex?

Run `npx skills add citypaul/.dotfiles --skill secure-oauth-oidc -a codex`. Or copy the skill folder (claude/.claude/skills/secure-oauth-oidc in citypaul/.dotfiles) into .agents/skills/secure-oauth-oidc in your project. Codex loads it when a task matches its description.

Can I use Secure OAuth Oidc in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add citypaul/.dotfiles --skill secure-oauth-oidc -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/secure-oauth-oidc, .gemini/skills/secure-oauth-oidc, .github/skills/secure-oauth-oidc and .opencode/skills/secure-oauth-oidc in your project.

What does Secure OAuth Oidc need to run?

SKILL.md names no scripts, command-line tools or credentials: Secure OAuth Oidc is instructions for the agent only.

Does Secure OAuth Oidc access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Secure OAuth Oidc safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Secure OAuth Oidc use?

Secure OAuth Oidc has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Secure OAuth Oidc use?

About 3.8k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 19k tokens, read only when the agent opens those files.

What are the alternatives to Secure OAuth Oidc?

Skills that share tags, products or a category with Secure OAuth Oidc: Fortify Development (coollabsio/coolify, 63k stars), OmniRoute Provider Management (diegosouzapw/OmniRoute, 75k stars), Antipattern Prevention (doorkeeper-gem/doorkeeper, 5.5k stars) and Cognito (itsmostafa/aws-agent-skills, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Secure OAuth Oidc?

citypaul (a GitHub user) maintains it in citypaul/.dotfiles, which has 740 GitHub stars. The repository holds 44 skills in this directory. The repository was last updated on October 9, 2026.

Source: citypaul/.dotfiles on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.