Fortify Development
coollabsio/coolify
ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.
Build or troubleshoot portal JSON/native login clients, refresh, profile and admin APIs, and public JWKS.
$ npx skills add greenpau/caddy-security --skill authentication-portal-api -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install greenpau/caddy-security authentication-portal-api --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/authentication-portal-api .claude/skills/authentication-portal-api && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "authentication-portal-api" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/authentication-portal-api into .claude/skills/authentication-portal-api/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "authentication-portal-api", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/greenpau/caddy-security/tree/main/.codex/skills/authentication-portal-apiType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add greenpau/caddy-security --skill authentication-portal-api -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install greenpau/caddy-security authentication-portal-api --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.codex/skills/authentication-portal-api .agents/skills/authentication-portal-api && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "authentication-portal-api" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/authentication-portal-api into .agents/skills/authentication-portal-api/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "authentication-portal-api", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add greenpau/caddy-security --skill authentication-portal-api -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install greenpau/caddy-security authentication-portal-api --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.codex/skills/authentication-portal-api .cursor/skills/authentication-portal-api && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "authentication-portal-api" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/authentication-portal-api into .cursor/skills/authentication-portal-api/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "authentication-portal-api", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/greenpau/caddy-security.git --path .codex/skills/authentication-portal-api--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add greenpau/caddy-security --skill authentication-portal-api -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install greenpau/caddy-security authentication-portal-api --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.codex/skills/authentication-portal-api .gemini/skills/authentication-portal-api && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "authentication-portal-api" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/authentication-portal-api into .gemini/skills/authentication-portal-api/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "authentication-portal-api", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install greenpau/caddy-security authentication-portal-apiInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add greenpau/caddy-security --skill authentication-portal-api -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .github/skills && cp -r skills-src/.codex/skills/authentication-portal-api .github/skills/authentication-portal-api && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "authentication-portal-api" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/authentication-portal-api into .github/skills/authentication-portal-api/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "authentication-portal-api", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add greenpau/caddy-security --skill authentication-portal-api -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install greenpau/caddy-security authentication-portal-api --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.codex/skills/authentication-portal-api .opencode/skills/authentication-portal-api && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "authentication-portal-api" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/authentication-portal-api into .opencode/skills/authentication-portal-api/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "authentication-portal-api", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
authentication-portal-apiBuild or troubleshoot portal JSON/native login clients, refresh, profile and admin APIs, and public JWKS.
Authentication Portal API is an agent skill from greenpau/caddy-security. Build or troubleshoot portal JSON/native login clients, refresh, profile and admin APIs, and public JWKS. Use for HTTP contracts; portal Caddyfile wiring belongs to configuration-authentication.
Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including reference files (for example `agents/openai.yaml`, `references/admin-api.md` and `references/authentication-flows.md`).
It sits in Backend & APIs, covering Authentication. The repository describes itself as: 🔐 Authentication, Authorization, and Accounting (AAA) App and Plugin for Caddy v2. 💎 Implements Form-Based, Basic, Local, LDAP, OpenID Connect, OAuth 2.0 (Github, Google…. The licence is Apache-2.0.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit a48553d. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Authentication Portal API loads about 2.9k tokens when it runs, and up to ~12k if it reads all its reference files. Until then it costs about 55 tokens; SKILL.md has 1,371 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from greenpau/caddy-security at commit a48553d, republished under its Apache-2.0 licence (© greenpau). 1,371 words, ~2,921 tokens.
.claude/skills/authentication-portal-api/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.Use this skill for HTTP/JSON interactions with a configured authentication portal. Surrounding Caddyfile declarations belong to configuration-authentication; route mounting belongs to configuration-http-integrations. These are configuration boundaries, not prerequisites for an HTTP client task.
For user-owned profile keys, legacy PGP/RSA metadata, ownership isolation, and canonical profile identity and transformed-claim isolation, read profile public keys. For conditional login selection, authoritative AMR and profile policy preview/ replacement, read authentication flows. For password/MFA mutations and refresh/OIDC invalidation, read local identity compatibility.
For the standalone caddy-authenticator CLI, profile configuration, terminal
input and private storage, use the
command maintenance reference.
Keep fresh login delegated to the public authclient package; the command owns
cached-token scheduling and its explicit native refresh request.
Read these files when details matter:
../go-authcrunch/pkg/authn/handle_json_*.go
for JSON handlers and response shapes.../go-authcrunch/pkg/authn/handle_http_*.go
for browser versus JSON behavior.caddyfile_authn.go and caddyfile_authn_admin_api.go for admin directives.../go-authcrunch/pkg/authn/admin_api/parser/parser.go,
admin_api_config.go, respond_api.go, and handle_api_private_keys.go
for the admin configuration and authorization boundary (the latter three
files are directly under pkg/authn).Upstream handler paths are read-only references under the repository scope. Keep client changes and integration tests here. If an API fix belongs to go-authcrunch, describe the separate upstream work instead of editing or testing that checkout.
Portal endpoints return JSON when the request includes either:
Accept: application/json
format=jsonWithout one of those signals, many endpoints follow browser-oriented behavior such as rendering HTML or redirecting.
Assume endpoint paths are relative to the portal base path. If the portal is
served at /auth, then /login means /auth/login, /whoami means
/auth/whoami, and admin endpoints are under /auth/api/server/....
For the public Go client, native transport, API-key login and private credential
files, use JSON/native interoperability.
Authenticate performs fresh login; renewal is a separate explicit operation.
Programmatic login is challenge-based:
POST <base>/login with username and realm.sandbox_id, sandbox_secret, and next_challenge.sandbox_id, current
sandbox_secret, challenge_kind, and challenge_response.sandbox_secret and return another challenge.authenticated: true, access_token_name, and access_token. An enabled,
participating local refresh login instead uses the transport contract below:
browser tokens arrive in cookies; opted-in native clients receive JSON tokens.Common challenge kinds are password, totp, and mfa. The public Go authclient
supports password/TOTP, including combined MFA selection. It does not implement
WebAuthn/U2F assertions and returns ErrUnsupportedChallenge for an assertion
challenge. A separate client that supports assertions first answers
challenge_kind: mfa with challenge_response: webauthn; the next challenge
contains a base64-encoded WebAuthn payload. The final response must contain the
signed WebAuthn result.
Do not reuse an old sandbox_secret; use the latest value returned by the
portal. Sandbox sessions are temporary and separate from the final JWT session.
Use the token refresh configuration
for explicit participating local realms, origin, mount, cookie naming and limits.
The selected go-authcrunch implements real rotation; /api/refresh_token
is no longer a timestamp probe. No enabled block means access-only behavior and
404 at the refresh/session API routes.
Browser login uses the default cookie transport. Tokens arrive in HttpOnly
cookies and JSON contains session/expiry metadata without bearer credentials.
After login, POST {} as JSON to <base>/api/refresh_token, <base>/api/logout,
or <base>/api/refresh_session with the cookie jar, exact configured HTTPS
Origin, and X-Authcrunch-Refresh: 1. Disallowed fetch metadata, origins or
mixed transports fail closed. Responses preserve Cache-Control: no-store.
A valid refresh cookie can rotate despite an expired or malformed access token.
The browser coordinator also sends the optional rotation precondition
X-Authcrunch-Refresh-Session; forward it unchanged. Session lookup is
browser-only and must never recover an uncertain rotation. See
browser refresh through Caddy for continuation,
coordination, strict request parsing, fresh-login recovery and real Chrome tests.
Native clients require body transport enabled and send
refresh_transport: body at every login checkpoint. Send no Cookie, Origin or
Sec-Fetch headers. Login and rotation return access_token, refresh_token,
names, session ID, and expiry metadata in JSON without cookies. Subsequent POSTs
use {"refresh_token":"<credential>"}. Omitting explicit native opt-in selects
browser transport; enabling the feature alone does not opt clients in.
Successful rotation changes the refresh credential and access-token jti,
retains the session binding and absolute deadline, and reloads current local
identity attributes. Replaying an old refresh token revokes the family. Serialize
rotations and avoid automatic retries when delivery is ambiguous. Invalid/revoked
credentials return 401, origin/transport violations 403, admission exhaustion
503. A family's rotation-limit exhaustion revokes it and reclaims capacity.
With a refresh cookie, GET <base>/logout displays confirmation; the session API
POST completes revocation and cookie deletion, including an associated OP
session. Portal refresh grants are unrelated to OIDC refresh or upstream provider
refresh. API-key and other unsupported login kinds remain access-only.
TestCaddyTokenRefreshE2E covers these transports through verified Caddy TLS.
Use /beacon for a light authentication probe. A valid token returns 200 OK
with a plain OK body; an invalid or expired token returns an access-denied
JSON response when JSON was requested.
Use /whoami for the current user claims. Useful query parameters include:
probe=true: include authenticated and expires_in.format=json: force JSON when no JSON Accept header is present.id_token=true: include the upstream identity provider ID token when an
OAuth provider was configured with enable id token cookie.Send access tokens using the portal-supported Authorization header or cookies
that match the portal's token validator configuration. If custom access-token
cookie names are used, keep portal and authorization policy names aligned with
configuration-authentication-cookies and configuration-crypto.
GET <mount>/.well-known/jwks.json returns the public keys used for portal
access-token signing. HEAD returns the same headers and Content-Length with
no body. No enable directive, session, admin API, or private-export setting is
required. Requests with invalid credentials, JSON headers, or format=json
still reach discovery before authentication and content negotiation.
The first eligible non-system signer determines availability: an asymmetric
signer enables discovery, while HMAC first returns 404 even when asymmetric
signers follow. Verification-only keys never enable discovery. When available,
the endpoint publishes RSA, EC, and Ed25519 signing public keys in signing
order, excluding HMAC, verification-only, and System API keys. Success is an
object with a keys array, including for one key, using
application/jwk-set+json. All methods use Cache-Control: no-store and
nosniff, without cookies or login redirects. Unsupported methods return 405
with Allow: GET, HEAD.
Ed25519 keys use kty: OKP, crv: Ed25519, and a 32-byte unpadded base64url
x; no private d or EC y appears. Match the exact alg and kid to the
signed JWT. Generated keys can advertise EdDSA or Ed25519; imported keys
default to EdDSA. Default key ID 0 is omitted in both JWT and JWK. See
crypto settings for key sources and labels.
The embedding Caddy routes define the mount boundary. Use the complete path
beneath that mount; trailing slashes, filename suffixes, and query-only matches
are not discovery. See public JWKS routing
to keep it ahead of a protected catch-all. This endpoint is distinct from
/oidc/jwks and the OP's dedicated RS256 ID-token signing keys.
TestCaddyJWKSE2E verifies the HTTP contract over trusted TLS, reconstructs
public keys from discovery to verify real login tokens independently, and
checks gatekeeper rejection of wrong keys and tampered tokens. Its first request
is HEAD, and negative-route checks inspect both headers and bodies.
TestCaddyJWKSPersistenceE2E checks persisted rollover across fresh processes:
retained verification keys continue accepting old tokens
without publishing them; removing those keys on reload rejects cached old
tokens. Discovery publishes current signing configuration and does not retain
removed keys automatically.
Admin endpoints require the configured admin API and an authorized portal session. Private signing-key export is independently disabled by default and requires both flags plus administrator authorization. Public JWKS is separate and needs neither flag. Read admin/server API contracts for endpoint shapes, exact status/method behavior, key formats, and Caddy tests.
Accept: application/json or format=json.sandbox_id, latest sandbox_secret, and expected challenge_kind.require mfa transforms, and
auth challenge rules stored in the local user database./whoami omits upstream ID token: verify the OAuth provider uses
enable id token cookie ... and the browser/client sends the ID-token cookie./api/refresh_token failures: check explicit realm participation, configured
origin/mount, the required browser header, native opt-in, and replay/capacity
limits using the transport contract above.enable admin api, active portal
session, and authp/admin or equivalent portal admin role.© greenpau, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 6 other files (references) in .codex/skills/authentication-portal-api of greenpau/caddy-security.
Open the folder on GitHubat commit a48553d
Authentication Portal API next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Authentication Portal API this skillgreenpau/caddy-security | 2.3k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| Fortify Developmentcoollabsio/coolify | 63k | 4 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Supabase Development and Debuggingsupabase/agent-skills | 2.7k | 3 repos | ~3.6k | Automated safety check: Pass | MIT | |
| Better Auth Best Practiceslatitude-dev/latitude-llm | 4.7k | 7 repos | ~1.6k | Automated safety check: Pass | MIT | |
| Gitnexus Exploringaws-samples/sample-kolya-br-proxy | 106 | 12 repos | ~749 | Automated safety check: Pass | MIT-0 | |
| Supabasecurvenote/curvenote | 170 | 5 repos | ~2.2k | Automated safety check: Pass | Custom licence |
coollabsio/coolify
ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.
supabase/agent-skills
General Supabase skill for database, auth, Edge Functions, Realtime and storage work, plus client libraries, migrations, security audits, debugging and reading logs.
latitude-dev/latitude-llm
Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables.
aws-samples/sample-kolya-br-proxy
A skill your agent uses when the user asks how code works, wants to understand architecture, trace execution flows, or explore unfamiliar parts of the codebase.
curvenote/curvenote
A skill your agent uses when doing ANY task involving Supabase.
google-gemini/gemini-skills
A skill your agent uses when building real-time, bidirectional streaming applications with the Gemini Live API, or migrating legacy Live models (2.0/2.5/3.1) to Gemini 3.8 Live.
greenpau/caddy-security
Implement or review caddy-security Go code, Caddy modules, parsers, lifecycle, and HTTP delegation.
greenpau/caddy-security
Build or review caddy-security Caddyfiles and select focused configuration skills.
greenpau/caddy-security
Configure portal/policy JWT keys, token names and lifetimes, key loading and generation, public-key discovery, and System API encryption keys.
greenpau/caddy-security
Mount authenticate and authorize handlers, separate portal and protected routes, align auth URLs, and preserve trusted proxy metadata.
greenpau/caddy-security
Configure durable AuthCrunch runtime state, exclusive storage ownership, stop/start persistence, reload rejection, and recovery.
greenpau/caddy-security
Configure static local accounts, required identity fields, trusted password imports, bcrypt API keys, roles, and stored challenge rules.
Categories
Build or troubleshoot portal JSON/native login clients, refresh, profile and admin APIs, and public JWKS. Authentication Portal API is an agent skill from greenpau/caddy-security. Build or troubleshoot portal JSON/native login clients, refresh, profile and admin APIs, and public JWKS.
Authentication Portal API fits situations like: portal Caddyfile wiring belongs to configuration-authentication; tasks that involve Authentication.
Run `npx skills add greenpau/caddy-security --skill authentication-portal-api -a claude-code`. Or copy the skill folder (.codex/skills/authentication-portal-api in greenpau/caddy-security) into .claude/skills/authentication-portal-api in your project. Claude Code loads it when a task matches its description.
Run `npx skills add greenpau/caddy-security --skill authentication-portal-api -a codex`. Or copy the skill folder (.codex/skills/authentication-portal-api in greenpau/caddy-security) into .agents/skills/authentication-portal-api in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add greenpau/caddy-security --skill authentication-portal-api -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/authentication-portal-api, .gemini/skills/authentication-portal-api, .github/skills/authentication-portal-api and .opencode/skills/authentication-portal-api in your project.
SKILL.md names no scripts, command-line tools or credentials: Authentication Portal API is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Authentication Portal API is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 9.5k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Authentication Portal API: Fortify Development (coollabsio/coolify, 63k stars), Supabase Development and Debugging (supabase/agent-skills, 2.7k stars), Better Auth Best Practices (latitude-dev/latitude-llm, 4.7k stars) and Gitnexus Exploring (aws-samples/sample-kolya-br-proxy, 106 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
greenpau (a GitHub user) maintains it in greenpau/caddy-security, which has 2,252 GitHub stars. The repository holds 29 skills in this directory. The repository was last updated on October 5, 2026.
Source: greenpau/caddy-security on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.