Agent skill

Rfc Compliance

by doorkeeper-gem in doorkeeper-gem/doorkeeper

Verify OAuth protocol implementations stay aligned with relevant RFCs.

MITAuto-check passedBackend & APIs

Install Rfc Compliance

skills CLI
$ npx skills add doorkeeper-gem/doorkeeper --skill rfc-compliance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install doorkeeper-gem/doorkeeper rfc-compliance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/doorkeeper-gem/doorkeeper.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/rfc-compliance .claude/skills/rfc-compliance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
rfc-compliance
GitHub stars
5.5k
Token cost
~1.7k tokens
SKILL.md length
677 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
MIT

At a glance

Verify OAuth protocol implementations stay aligned with relevant RFCs.

  • Works in 2 steps: Authorization request → PreAuthorization… → Token request → AuthorizationCodeRequest…
  • Modifying grant flows
  • SKILL.md covers Core RFCs, Error Response Format (RFC…, Token Response Format (RFC… and Authorization Code Flow (RFC…, plus 8 more sections
  • Calls bundle

What it does

Rfc Compliance is an agent skill from doorkeeper-gem/doorkeeper. Verify OAuth protocol implementations stay aligned with relevant RFCs. Use when adding or modifying grant flows, token responses, error formats, redirect behavior, introspection, revocation, PKCE, or metadata endpoints in Doorkeeper.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering OAuth and OpenID Connect. The repository describes itself as: Doorkeeper is an OAuth 2 provider for Ruby on Rails / Grape. The licence is MIT.

When your agent uses it

  • Modifying grant flows
  • Token responses
  • Redirect behavior
  • Metadata endpoints in Doorkeeper

Example prompts

  • “/rfc-compliance”

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. Authorization request → PreAuthorization validates, Code issues grant
  2. Token request → AuthorizationCodeRequest validates grant + issues token

What it can do on your machine

Read from SKILL.md and the folder at commit 80f4eba. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bundle

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Rfc Compliance loads about 1.7k tokens when it runs. Until then it costs about 62 tokens; SKILL.md has 677 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~62
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from doorkeeper-gem/doorkeeper at commit 80f4eba, republished under its MIT licence (© doorkeeper-gem). 677 words, ~1,721 tokens.

Download SKILL.mdSave it as .claude/skills/rfc-compliance/SKILL.md (or your agent's skills folder).
name
rfc-compliance
description
Verify OAuth protocol implementations stay aligned with relevant RFCs. Use when adding or modifying grant flows, token responses, error formats, redirect behavior, introspection, revocation, PKCE, or metadata endpoints in Doorkeeper.

RFC Compliance

When implementing or modifying OAuth protocol behavior in Doorkeeper, use this skill to verify the implementation stays aligned with the relevant RFCs.

Core RFCs

RFCTopicKey Files
6749OAuth 2.0 Frameworklib/doorkeeper/oauth/, app/controllers/doorkeeper/
6750Bearer Token Usagelib/doorkeeper/oauth/token.rb, lib/doorkeeper/rails/helpers.rb
7009Token Revocationapp/controllers/doorkeeper/tokens_controller.rb (revoke action)
7636PKCElib/doorkeeper/oauth/pre_authorization.rb, lib/doorkeeper/oauth/authorization_code_request.rb
7662Token Introspectionlib/doorkeeper/oauth/token_introspection.rb
8252OAuth for Native Appslib/doorkeeper/oauth/helpers/uri_checker.rb (loopback)
9207Authorization Server Issuer Identificationlib/doorkeeper/oauth/code_response.rb (iss param)
8707Resource Indicatorslib/doorkeeper/oauth/resource_indicator_validator.rb

Error Response Format (RFC 6749 §5.2)

Token endpoint errors MUST include:

  • error — single ASCII error code (required)
  • error_description — human-readable description (optional)
  • HTTP status codes: 400 for most errors, 401 for invalid client auth

Valid error codes for the token endpoint: invalid_request, invalid_client, invalid_grant, unauthorized_client, unsupported_grant_type, invalid_scope

Reference: lib/doorkeeper/oauth/error_response.rb

Authorization endpoint errors that are redirectable include error, error_description, and state in the redirect. Non-redirectable errors (invalid redirect_uri, invalid client_id) MUST NOT redirect — render an error page instead.

Reference: lib/doorkeeper/oauth/pre_authorization.rb — redirectable? logic

Token Response Format (RFC 6749 §5.1)

Successful token responses MUST include:

  • access_token — the token value
  • token_type — "Bearer" (case-insensitive per RFC 6750)
  • expires_in — lifetime in seconds (recommended)

MAY include:

  • refresh_token
  • scope — if different from requested

MUST NOT include:

  • refresh_token in implicit grant responses

Reference: lib/doorkeeper/oauth/token_response.rb

Authorization Code Flow (RFC 6749 §4.1)

  1. Authorization request → PreAuthorization validates, Code issues grant
  2. Token request → AuthorizationCodeRequest validates grant + issues token

Key constraints:

  • Code is single-use (§4.1.2) — revoke tokens on replay
  • Code must be bound to client_id and redirect_uri
  • Code SHOULD expire in max 10 minutes (configurable via authorization_code_expires_in)
  • redirect_uri in token request must match the one used in authorization request

PKCE (RFC 7636)

  • code_challenge_method defaults to "plain" when omitted (§4.2) — but Doorkeeper intentionally requires it when code_challenge is present (secure-by-default deviation)
  • S256: BASE64URL(SHA256(code_verifier)) must equal code_challenge
  • plain: code_verifier must equal code_challenge
  • code_verifier is 43-128 characters from [A-Z] / [a-z] / [0-9] / "-" / "." / "_" / "~"

Token Introspection (RFC 7662)

  • MUST require authentication of the requesting party
  • Response for inactive/invalid tokens: {"active": false} — no other fields
  • Response for active tokens includes: active, scope, client_id, token_type, exp, iat, sub, aud, iss
  • Doorkeeper omits token_type and exp for refresh tokens in introspection responses (these fields are OPTIONAL per §2.2, not prohibited — but they are semantically inapplicable to refresh tokens)

Reference: lib/doorkeeper/oauth/token_introspection.rb

Token Revocation (RFC 7009)

  • Return 200 OK even for invalid/unknown tokens (§2.1) — prevents token enumeration
  • Client authentication is required
  • The token_type_hint parameter is optional; server must still check both types
  • Revoking an access token SHOULD revoke associated refresh token (and vice versa)

Current known deviation: Doorkeeper returns 403 when the token belongs to a different client, rather than 200.

Show full SKILL.md (255 more words)Show less

Bearer Token Errors (RFC 6750 §3)

  • 401 responses MUST include WWW-Authenticate: Bearer header
  • Error codes in WWW-Authenticate: invalid_request, invalid_token, insufficient_scope
  • 403 for insufficient_scope, 401 for invalid_token, 400 for invalid_request

Reference: lib/doorkeeper/oauth/error_response.rb — authenticate_info method

Resource Indicators (RFC 8707)

  • Resource URIs must be absolute and must not contain a fragment
  • Multiple resources use repeated resource parameters (Rack limitation: use resource[] syntax)
  • Tokens are audience-restricted to the declared resources
  • Refresh requests enforce subset restriction against original grant

Reference: lib/doorkeeper/oauth/resource_indicator_validator.rb

Authorization Server Metadata (RFC 8414)

Served at /.well-known/oauth-authorization-server. Must include:

  • issuer — MUST be identical to the iss in authorization responses
  • authorization_endpoint, token_endpoint
  • response_types_supported, grant_types_supported
  • token_endpoint_auth_methods_supported
  • scopes_supported (recommended)

Reference: lib/doorkeeper/oauth/metadata_response.rb

Implementation Patterns

Adding a new grant type
  1. Create a strategy class in lib/doorkeeper/request/ extending Doorkeeper::Request::Strategy
  2. Create a request class in lib/doorkeeper/oauth/ extending Doorkeeper::OAuth::BaseRequest
  3. Register with Doorkeeper::GrantFlow.register in lib/doorkeeper/grant_flow.rb
  4. Add to default grant_flows if it's a standard flow
  5. Add specs in spec/requests/flows/ and spec/lib/oauth/
Adding a new error code
  1. Add to lib/doorkeeper/errors.rb as a new class inheriting BaseResponseError
  2. Add I18n key in config/locales/en.yml
  3. Map to correct HTTP status in the error class's #type method
Adding a new configuration option
  1. Add via option DSL in lib/doorkeeper/config.rb
  2. Add validation in lib/doorkeeper/config/validations.rb if needed
  3. Document in the initializer template: lib/generators/doorkeeper/templates/initializer.rb
  4. Add specs in spec/lib/config_spec.rb

Verification

After implementing protocol changes:

  1. Run flow specs: bundle exec rspec spec/requests/flows/
  2. Run endpoint specs: bundle exec rspec spec/requests/endpoints/
  3. Run OAuth unit specs: bundle exec rspec spec/lib/oauth/
  4. Verify metadata response: bundle exec rspec spec/requests/endpoints/metadata_spec.rb

© doorkeeper-gem, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/rfc-compliance of doorkeeper-gem/doorkeeper.

Open the folder on GitHubat commit 80f4eba

Compare with similar skills

Rfc Compliance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Rfc Compliance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Rfc Compliance this skilldoorkeeper-gem/doorkeeper5.5k—~1.7kAutomated safety check: PassMIT
Fortify Developmentcoollabsio/coolify63k4 repos~1.9kAutomated safety check: PassMIT
OmniRoute Provider Managementdiegosouzapw/OmniRoute75k—~2.4kAutomated safety check: PassMIT
Cognitoitsmostafa/aws-agent-skills1.2k1 repos~2.3kAutomated safety check: PassMIT
Notion Worker Third-Party Auth Guidemakenotion/workers-template4391 repos~3.5kAutomated safety check: NotesMIT
Stripe Best Practiceskanchengw/cnllm1732 repos~925Automated safety check: PassApache-2.0

Similar skills

  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed
  • OmniRoute Provider Management

    diegosouzapw/OmniRoute

    Manages AI provider connections, API keys, OAuth flows and connection tests through OmniRoute's REST API across its 327-provider catalog.

    75k GitHub stars~2.4k tokensUpdated today
    Backend & APIsAuto-check passed
  • Cognito

    itsmostafa/aws-agent-skills

    AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.3k tokens
    Backend & APIsAuto-check passed
  • Notion Worker Third-Party Auth Guide

    makenotion/workers-template

    Official

    Decides whether a Notion Worker should use a brokered credential, a plaintext environment secret, or OAuth to authenticate against a non-Notion service.

    439 GitHub starsUsed in 1 repo~3.5k tokens
    Backend & APIsAuto-check: notes
  • Stripe Best Practices

    kanchengw/cnllm

    Guides Stripe integration decisions — API selection (Checkout Sessions vs PaymentIntents), Connect platform setup (Accounts v2, controller properties), billing/subscriptions, Treasury financial…

    173 GitHub starsUsed in 2 repos~925 tokens
    Backend & APIsAuto-check passed
  • Tmeet Skill

    Pinvou/pinvou-agent

    何时用:用户明确要通过命令行操作腾讯会议(tmeet),或 Agent 遇到工具缺失/调用失败/能力不足想反馈平台时。OAuth 登录/登出/状态、会议管理(创建/更新/取消/查询/搜索/受邀者)、录制管理(列表/播放地址/智能纪要/转写/权限申请)、元宝纪要(按关键词/时间搜索、稳态/瞬态详情)、会议报告(参会人/等候室/导出明细/异步任务)、通讯录(仅限会议邀请/呼叫入会前置解析,严禁单独查…

    2.4k GitHub stars~4.8k tokensUpdated yesterday
    Backend & APIsAuto-check passed

More from doorkeeper-gem/doorkeeper

  • Antipattern Prevention

    doorkeeper-gem/doorkeeper

    Avoid common Ruby and Rails antipatterns that degrade maintainability and performance.

    5.5k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Code Quality

    doorkeeper-gem/doorkeeper

    Maintain code health and architecture standards when implementing features or refactoring Doorkeeper.

    5.5k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Dependency Safety

    doorkeeper-gem/doorkeeper

    Ensure gems are safe, necessary, and properly constrained when adding, updating, or reviewing dependencies in Doorkeeper.

    5.5k GitHub stars~931 tokensUpdated yesterday
    Auto-check passed
  • Security Review

    doorkeeper-gem/doorkeeper

    Verify that code changes do not introduce OAuth security vulnerabilities.

    5.5k GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • Testing

    doorkeeper-gem/doorkeeper

    Write correct and complete RSpec tests for Doorkeeper. An agent skill from doorkeeper-gem/doorkeeper.

    5.5k GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Rfc Compliance

What does Rfc Compliance do?

Verify OAuth protocol implementations stay aligned with relevant RFCs. Rfc Compliance is an agent skill from doorkeeper-gem/doorkeeper. Verify OAuth protocol implementations stay aligned with relevant RFCs.

When should I use Rfc Compliance?

Rfc Compliance fits situations like: modifying grant flows; token responses; redirect behavior; metadata endpoints in Doorkeeper.

How do I install Rfc Compliance in Claude Code?

Run `npx skills add doorkeeper-gem/doorkeeper --skill rfc-compliance -a claude-code`. Or copy the skill folder (.agents/skills/rfc-compliance in doorkeeper-gem/doorkeeper) into .claude/skills/rfc-compliance in your project. Claude Code loads it when a task matches its description.

How do I install Rfc Compliance in Codex?

Run `npx skills add doorkeeper-gem/doorkeeper --skill rfc-compliance -a codex`. Or copy the skill folder (.agents/skills/rfc-compliance in doorkeeper-gem/doorkeeper) into .agents/skills/rfc-compliance in your project. Codex loads it when a task matches its description.

Can I use Rfc Compliance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add doorkeeper-gem/doorkeeper --skill rfc-compliance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/rfc-compliance, .gemini/skills/rfc-compliance, .github/skills/rfc-compliance and .opencode/skills/rfc-compliance in your project.

What does Rfc Compliance need to run?

Going by SKILL.md and its folder, Rfc Compliance needs the command-line tools its instructions call (bundle).

Does Rfc Compliance access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Rfc Compliance safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Rfc Compliance use?

Rfc Compliance is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Rfc Compliance use?

About 1.7k tokens (SKILL.md is roughly 6.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Rfc Compliance?

Skills that share tags, products or a category with Rfc Compliance: Fortify Development (coollabsio/coolify, 63k stars), OmniRoute Provider Management (diegosouzapw/OmniRoute, 75k stars), Cognito (itsmostafa/aws-agent-skills, 1.2k stars) and Notion Worker Third-Party Auth Guide (makenotion/workers-template, 439 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Rfc Compliance?

doorkeeper-gem (a GitHub organization) maintains it in doorkeeper-gem/doorkeeper, which has 5,523 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 9, 2026.

Source: doorkeeper-gem/doorkeeper on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.