Atmos Auth
cloudposse/atmos
Authentication and identity management: providers (SSO/SAML/OIDC/GCP/Atmos Pro), identities, keyring, identity chaining, login/exec/shell/console, and github/sts for private GitHub access
Implement and debug OAuth 2.0 DPoP (RFC 9449) refresh token sender-constraining for WebCrypto, Node.js ES6, and browser runtimes integrating with Google's OAuth platform.
$ npx skills add google/skills --skill dpop-adoption -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install google/skills dpop-adoption --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/identity/dpop-adoption .claude/skills/dpop-adoption && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "dpop-adoption" agent skill from https://github.com/google/skills/tree/main/skills/identity/dpop-adoption into .claude/skills/dpop-adoption/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dpop-adoption", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/google/skills/tree/main/skills/identity/dpop-adoptionType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add google/skills --skill dpop-adoption -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install google/skills dpop-adoption --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/identity/dpop-adoption .agents/skills/dpop-adoption && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "dpop-adoption" agent skill from https://github.com/google/skills/tree/main/skills/identity/dpop-adoption into .agents/skills/dpop-adoption/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dpop-adoption", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add google/skills --skill dpop-adoption -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install google/skills dpop-adoption --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/identity/dpop-adoption .cursor/skills/dpop-adoption && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "dpop-adoption" agent skill from https://github.com/google/skills/tree/main/skills/identity/dpop-adoption into .cursor/skills/dpop-adoption/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dpop-adoption", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/google/skills.git --path skills/identity/dpop-adoption--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add google/skills --skill dpop-adoption -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install google/skills dpop-adoption --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/identity/dpop-adoption .gemini/skills/dpop-adoption && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "dpop-adoption" agent skill from https://github.com/google/skills/tree/main/skills/identity/dpop-adoption into .gemini/skills/dpop-adoption/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dpop-adoption", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install google/skills dpop-adoptionInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add google/skills --skill dpop-adoption -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/identity/dpop-adoption .github/skills/dpop-adoption && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "dpop-adoption" agent skill from https://github.com/google/skills/tree/main/skills/identity/dpop-adoption into .github/skills/dpop-adoption/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dpop-adoption", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add google/skills --skill dpop-adoption -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install google/skills dpop-adoption --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/identity/dpop-adoption .opencode/skills/dpop-adoption && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "dpop-adoption" agent skill from https://github.com/google/skills/tree/main/skills/identity/dpop-adoption into .opencode/skills/dpop-adoption/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dpop-adoption", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
dpop-adoptionImplement and debug OAuth 2.0 DPoP (RFC 9449) refresh token sender-constraining for WebCrypto, Node.js ES6, and browser runtimes integrating with Google's OAuth platform.
Dpop Adoption is an agent skill from google/skills, published by the product's own GitHub organization. Implement and debug OAuth 2.0 DPoP (RFC 9449) refresh token sender-constraining for WebCrypto, Node.js ES6, and browser runtimes integrating with Google's OAuth platform. Use when configuring non-extractable asymmetric key pairs (P-256), generating DPoP Proof JWTs for authorization code exchange and token refresh, or handling 400 usedpopnonce challenge retry loops at oauth2.googleapis.com/token. Don't use for unconstrained OAuth 2.0 flows (where refresh tokens are not bound to a client key pair), or for Google…
Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering OAuth and OpenID Connect and Authentication. It works with Google Cloud and Node.js. The repository describes itself as: Agent Skills for Google products and technologies. The licence is Apache-2.0.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 7d97937. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npxFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
oauth2.googleapis.comAlso links to:
developers.google.comdatatracker.ietf.orgFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Dpop Adoption loads about 2.8k tokens when it runs. Until then it costs about 144 tokens; SKILL.md has 1,002 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from google/skills at commit 7d97937, republished under its Apache-2.0 licence (© google). 1,002 words, ~2,815 tokens.
.claude/skills/dpop-adoption/SKILL.md (or your agent's skills folder).Demonstrating Proof-of-Possession (DPoP, RFC 9449) secures OAuth 2.0 refresh
tokens against interception and replay attacks by cryptographically binding them
to a private key held exclusively by the client. In Google's OAuth 2.0 platform,
DPoP binds the refresh token at the token endpoint, while access tokens issued
for Google APIs are standard Bearer tokens (token_type: "Bearer").
When implementing DPoP helpers or upgrading HTTP clients, you MUST adhere to the following strict security invariants:
"type": "module" for Node 18+ and browsers),
ALWAYS access globalThis.crypto directly after verifying the environment
context.require('node:crypto') or
reference browser-scoped window.crypto, as these cause module
initialization crashes across hybrid runtimes.P-256) curve: { name: 'ECDSA', namedCurve: 'P-256' }.extractable: false). This guarantees the private key
can never leave the hardware cryptographic boundary (Secure Enclave, Android
KeyStore, or JS sandbox memory), thwarting XSS and dependency token theft
attacks.extractable: true) to allow
emitting JSON Web Keys (JWKs)."kty": "EC""crv": "P-256""x": Base64URL-encoded x-coordinate without trailing equal sign
padding (=)."y": Base64URL-encoded y-coordinate without trailing equal sign
padding (=)."d") or superfluous metadata.crypto.subtle.sign),
ECDSA signatures are ALREADY emitted natively in raw IEEE P1363 format
(concatenated 32-byte r and s buffers, 64 bytes total). DO NOT
attempt DER-to-Raw conversion on crypto.subtle.sign outputs, as parsing a
64-byte raw buffer as ASN.1 DER causes an immediate runtime exception
(Invalid DER sequence). Directly base64url-encode the raw ArrayBuffer.java.security.Signature) or Node CommonJS (crypto.createSign), convert
ASN.1 DER output to raw 64-byte IEEE P1363 format before base64url encoding.client_secret requirements on server endpoints and browser CORS
limitations on the DPoP-Nonce response header.access_type=offline, binds refresh tokens server-side using
DPoP, and maintains secure session cookies with the frontend.When creating new modules, your module MUST explicitly export all functions below to integrate cleanly with CI/CD verification harnesses and automated probers. When inspecting or refactoring existing codebases, ensure equivalent cryptographic and RFC 9449 logic is present. Obey strict claim derivation logic in all cases:
createDPoPProof)When generating the DPoP Proof JWT in createDPoPProof:
1. JOSE Header (typ, alg, jwk):
// Header
{
"typ": "dpop+jwt",
"alg": "ES256",
"jwk": await exportPublicJWK(publicKey)
}2. Payload Claims:
"htm": Uppercase HTTP Method ("POST" for token requests)."htu": Target URI stripped of query parameters and hash fragments using
sanitizeHTU(htu). For token requests, this is
https://oauth2.googleapis.com/token."iat": Current integer epoch timestamp in seconds
(Math.floor(Date.now() / 1000))."jti" (Critical Invariant):jti argument is provided to createDPoPProof, use that
exact string over all others.authCode argument is provided (during initial code
exchange), set jti = await calculateAuthCodeJti(authCode) where
calculateAuthCodeJti computes base64url(sha256(authCode)) to ensure
the DPoP proof is cryptographically bound to the authorization code.jti nor authCode is provided, generate a fresh
cryptographic random string via generateRandomString() (such as
crypto.getRandomValues(new Uint8Array(24)) base64url encoded)."ath" (Optional): If an accessToken argument is provided for RFC 9449
resource requests, compute base64url(sha256(accessToken)) via
calculateATH(accessToken) and inject it (RFC 9449 Section 6.1)."nonce" (Optional): If a nonce argument is provided, inject it directly
into the payload.// 1. Key generation & JWK export
export async function generateDPoPKeyPair() // -> { publicKey, privateKey } (private key extractable=false)
export async function exportPublicJWK(publicKey) // -> { kty: 'EC', crv: 'P-256', x, y }
// 2. Proof generation & validation
export async function createDPoPProof({ privateKey, publicKey, htm, htu, nonce, accessToken, authCode, jti }) // -> signed JWT string
export async function verifyDPoPProof(dpopProofJwt) // -> { isValid: boolean, header, payload, error }
export function sanitizeHTU(htu) // -> URL stripped of query and hash: const u = new URL(htu); return `${u.origin}${u.pathname}`;
// 3. Cryptographic & encoding utilities
export function base64UrlEncode(buffer) // -> Uint8Array/ArrayBuffer to base64url string without '=' padding
export function base64UrlDecode(str) // -> base64url string to Uint8Array/Buffer
export function stringToBase64Url(str) // -> UTF-8 string to base64url
export function base64UrlToString(str) // -> base64url to UTF-8 string
export function generateRandomString(byteLength = 32) // -> cryptographic random base64url string
export async function calculateATH(accessToken) // -> base64url(sha256(accessToken)) per RFC 9449 Sec 6.1
export async function calculateAuthCodeJti(code) // -> base64url(sha256(code))
export async function generatePKCE() // -> { codeVerifier (>=43 chars), codeChallenge, codeChallengeMethod: 'S256' }When integrating with Google's OAuth 2.0 platform:
oauth2.googleapis.com/token):DPoP HTTP header:
`DPoP: ${proofJwt}` when making POST requests for code exchange
(grant_type=authorization_code) and token refresh
(grant_type=refresh_token)."token_type": "Bearer". Downstream
requests to Google APIs (e.g. Calendar, Drive, Gmail) use standard
`Authorization: Bearer ${accessToken}` headers without DPoP
headers.400 Bad Request with
error: "use_dpop_nonce" and a "DPoP-Nonce" response header:400 use_dpop_nonce challenge to
establish a fresh nonce namespace. This is standard RFC-compliant
protocol behavior, not a server failure.this.dpopNonce).nonce claim and a fresh jti.When prompted to synthesize or output code deliverables under this skill, prioritize returning clean, directly importable code blocks without redundant conversational preambles or repetitive filler. For conceptual or architectural inquiries, provide standard direct answers.
MCP) can query real-time
Google Developer documentation using the
Google Developer Knowledge MCP Server
(npx -y @google/mcp-developer-knowledge-server) via
developer_knowledge:search_documents and
developer_knowledge:get_documents.© google, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/identity/dpop-adoption of google/skills.
Open the folder on GitHubat commit 7d97937
Dpop Adoption next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Dpop Adoption this skillgoogle/skills | 21k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | |
| Atmos Authcloudposse/atmos | 1.4k | — | ~4.2k | Automated safety check: Pass | Apache-2.0 | |
| Managing Cloud Identity With Oktamukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | |
| Iam Auditbriiirussell/cybersecurity-skills | 413 | — | ~3.1k | Automated safety check: Notes | MIT | |
| Google Cloud AuthVKirill/claude-lane-stack | 122 | — | ~3.1k | Automated safety check: Notes | MIT | |
| Lokalise Install Authjeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~1.4k | Automated safety check: Notes | MIT |
cloudposse/atmos
Authentication and identity management: providers (SSO/SAML/OIDC/GCP/Atmos Pro), identities, keyring, identity chaining, login/exec/shell/console, and github/sts for private GitHub access
mukul975/Anthropic-Cybersecurity-Skills
Implement Okta as a centralized cloud identity provider: configure SSO with AWS, Azure, and GCP, deploy phishing-resistant MFA with Okta FastPass, automate user provisioning/deprovisioning, and…
briiirussell/cybersecurity-skills
Audit, design, and migrate Identity and Access Management — cloud provider IAM (AWS, GCP, Azure), identity providers (Okta, Entra ID / Azure AD, Auth0, Google Workspace), application authorization…
VKirill/claude-lane-stack
[RU: oauth google, авторизация гугл, service account, sa key, refresh token, invalidgrant, adc, google cloud auth] Google auth for all Google APIs — OAuth 2.0, Service Account JWT, ADC.
jeremylongshore/tons-of-skills-marketplace
Install and configure Lokalise SDK/CLI authentication. An agent skill from jeremylongshore/tons-of-skills-marketplace.
aiskillstore/marketplace
Expert patterns for HubSpot CRM integration including OAuth authentication, CRM objects, associations, batch operations, webhooks, and custom objects.
google/skills
Query Cloud Trace spans, filter by latency thresholds or error status, correlate distributed traces with Cloud Logging, and diagnose latency bottlenecks across Google Cloud services.
google/skills
Manages Google Cloud Privileged Access Manager entitlements and grants: create and edit entitlements, request temporary access, and approve or deny pending grants.
google/skills
Writes Terraform alerting policies for AI agents that emit OpenTelemetry metrics, covering reliability, cost, safety, security and quality signals on Google Cloud.
google/skills
Deploys open models or custom weights from Model Garden to Agent Platform endpoints, checks deployment status and cleans up endpoints, confirming before any change.
google/skills
Searches, manages and scaffolds skills in the Gemini Enterprise Agent Platform Skill Registry using bundled Python scripts and Google Cloud credentials.
google/skills
Designs GCP infrastructure as local Terraform, validates and scans it against best practices, then imports it to Application Design Center for deployment and troubleshooting.
Works with
Categories
Implement and debug OAuth 2.0 DPoP (RFC 9449) refresh token sender-constraining for WebCrypto, Node.js ES6, and browser runtimes integrating with Google's OAuth platform. Dpop Adoption is an agent skill from google/skills, published by the product's own GitHub organization.js ES6, and browser runtimes integrating with Google's OAuth platform.
Dpop Adoption fits situations like: configuring non-extractable asymmetric key pairs (P-256); generating DPoP Proof JWTs for authorization code exchange and token refresh; handling 400 usedpopnonce challenge retry loops at oauth2.googleapis.com/token; unconstrained OAuth 2.0 flows (where refresh tokens are not bound to a client key pair).
Run `npx skills add google/skills --skill dpop-adoption -a claude-code`. Or copy the skill folder (skills/identity/dpop-adoption in google/skills) into .claude/skills/dpop-adoption in your project. Claude Code loads it when a task matches its description.
Run `npx skills add google/skills --skill dpop-adoption -a codex`. Or copy the skill folder (skills/identity/dpop-adoption in google/skills) into .agents/skills/dpop-adoption in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add google/skills --skill dpop-adoption -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dpop-adoption, .gemini/skills/dpop-adoption, .github/skills/dpop-adoption and .opencode/skills/dpop-adoption in your project.
Going by SKILL.md and its folder, Dpop Adoption needs the command-line tools its instructions call (npx). Our summary lists: Node.js.
SKILL.md names 3 domains. In commands or code: oauth2.googleapis.com; the agent is likely to contact it when it follows the instructions. As links in the text: developers.google.com and datatracker.ietf.org. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Dpop Adoption is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Dpop Adoption: Atmos Auth (cloudposse/atmos, 1.4k stars), Managing Cloud Identity With Okta (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Iam Audit (briiirussell/cybersecurity-skills, 413 stars) and Google Cloud Auth (VKirill/claude-lane-stack, 122 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
google (a GitHub organization, an official publisher) maintains it in google/skills, which has 21,032 GitHub stars. The repository holds 147 skills in this directory. The repository was last updated on October 8, 2026.
Source: google/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.