Agent skill

Configuration Authentication

by greenpau in greenpau/caddy-security

Configure authentication portals, backend selection, redirect trust, refresh, and portal wiring.

Apache-2.0Auto-check passedBackend & APIs

Install Configuration Authentication

skills CLI
$ npx skills add greenpau/caddy-security --skill configuration-authentication -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install greenpau/caddy-security configuration-authentication --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/configuration-authentication .claude/skills/configuration-authentication && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
configuration-authentication
GitHub stars
2.3k
Token cost
~2.3k tokens
SKILL.md length
932 words
Files
3 (incl. references)
Skills in repo
29
Repo updated
First seen
Licence
Apache-2.0

At a glance

Configure authentication portals, backend selection, redirect trust, refresh, and portal wiring.

  • Tasks that involve Authentication
  • SKILL.md covers Purpose, Shape, Portal Wiring and Common Portal Options, plus 2 more sections
  • Needs JWT_SHARED_KEY
  • Tasks that involve OAuth and OpenID Connect

What it does

Configuration Authentication is an agent skill from greenpau/caddy-security. Configure authentication portals, backend selection, redirect trust, refresh, and portal wiring. Delegates cookies, UI, transforms, crypto, and OIDC provider details to focused skills.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `agents/openai.yaml` and `references/token-refresh.md`).

It sits in Backend & APIs, covering Authentication and OAuth and OpenID Connect. The repository describes itself as: 🔐 Authentication, Authorization, and Accounting (AAA) App and Plugin for Caddy v2. 💎 Implements Form-Based, Basic, Local, LDAP, OpenID Connect, OAuth 2.0 (Github, Google…. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Authentication
  • Tasks that involve OAuth and OpenID Connect

Example prompts

  • “/configuration-authentication”

Requirements

  • A credential in JWT_SHARED_KEY

What it can do on your machine

Read from SKILL.md and the folder at commit a48553d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are caddyfile).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • JWT_SHARED_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Configuration Authentication loads about 2.3k tokens when it runs, and up to ~6.4k if it reads all its reference files. Until then it costs about 53 tokens; SKILL.md has 932 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~53
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from greenpau/caddy-security at commit a48553d, republished under its Apache-2.0 licence (© greenpau). 932 words, ~2,311 tokens.

Download SKILL.mdSave it as .claude/skills/configuration-authentication/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
configuration-authentication
description
Configure authentication portals, backend selection, redirect trust, refresh, and portal wiring. Delegates cookies, UI, transforms, crypto, and OIDC provider details to focused skills.

Configuration Authentication

Purpose

Use this skill to configure authentication portal <name> blocks and the route-level authenticate with <portal> handler.

Use configuration-http-integrations to place portal routes, select matchers, wire same-host or split-host portals, separate portal/protected routes, and check directive ordering.

Read these files when details matter:

  • caddyfile_authn.go for the portal block.
  • caddyfile_authn_token_refresh.go and token refresh for readable portal refresh configuration, explicit local realms, transports, bounded lifetimes and stores, cookies, placeholders and TLS validation.
  • caddyfile_authn_crypto.go for crypto key directives.
  • caddyfile_authn_misc.go for enable, validate, and trust.
  • caddyfile_authn_admin_api.go and selected upstream pkg/authn/admin_api/parser for the independent admin/API key-export switches.
  • plugin_authn.go for route-level authenticate syntax.
  • ../go-authcrunch/config.go for portal validation, default backend attachment, and user registration wiring.
  • ../go-authcrunch/pkg/authn/config.go and ../go-authcrunch/pkg/authn/portal.go for portal defaults and runtime behavior.

Use focused repo-local skills for specialized portal sub-blocks:

  • Use configuration-authentication-cross-device to enable QR/link login, explicit approval, browser binding, cancellation and volatile request lifecycle through the existing portal route.
  • Use configuration-oauth-applications to configure portal oidc provider blocks, named client selection, private registrations, and dedicated provider signing keys. Its provider reference covers explicit realm participation and separate issuers/cookie scopes across portals; attaching a store for portal login does not enable its realm for OIDC.
  • Use configuration-crypto to configure portal crypto defaults, JWT signing keys, auto-generated keys, token names and lifetimes, secret-backed key material, and System API system keys.
  • Use configuration-authentication-cookies to configure cookie directives and token-cookie naming.
  • Use configuration-authentication-ui to configure ui blocks, templates, static assets, custom CSS/JS/HTML, themes, languages, logos, and private links.
  • Use configuration-authentication-user-transforms to configure transform user blocks, ACL matchers, typed claims, conditional challenge selection, additive legacy requirements, claim replacements, and transform UI links. Persisted local-user challenge rules belong to configuration-users.
  • Use configuration-saml-providers to configure saml identity provider <name> login providers enabled by the portal.
  • Use authentication-portal-api to build or troubleshoot JSON login, /whoami, /beacon, refresh token, and admin/server API interactions.

Shape

caddyfile
{
	security {
		local identity store localdb {
			realm local
			path assets/config/users.json
		}

		authentication portal myportal {
			crypto default token lifetime 3600
			crypto key sign-verify {env.JWT_SHARED_KEY}
			enable identity store localdb
		}
	}
}

example.com {
	@portal path /auth /auth/*
	route @portal {
		authenticate with myportal
	}
}

The portal name must match the authenticate with <portal> reference. Route-level syntax also allows a matcher: authenticate @matcher with <portal>.

Use myportal or a descriptive name such as employee_portal in examples, fixtures, and tests. Avoid naming a portal portal: the repeated words in authentication portal portal are confusing. Keep references consistent, for example authentication portal myportal and authenticate with myportal.

Portal Wiring

Add only the backends the portal should use:

caddyfile
enable identity store localdb
enable identity provider github azure
enable sso provider aws

Define those stores, identity providers, or SSO app providers with the matching domain skills before enabling them. enable identity provider <name> references oauth identity provider <name> or saml identity provider <name> blocks; enable sso provider <name> references sso provider <name> SSO app blocks. Identity stores and identity providers can take multiple names on one line.

If a portal has no explicit identity stores and no explicit identity providers, authcrunch currently attaches all configured identity stores and identity providers during Config.Validate(). Prefer explicit enable lines in new examples. After defaults and disabled-backend filtering, a portal must have at least one identity store or identity provider; SSO providers are additional app providers and do not satisfy the login-backend requirement by themselves.

User registration is global authcrunch config. A user registration <name> block names its target identity store; authcrunch validates that store, marks it registration-enabled, and attaches the registry to any portal that has that identity store enabled. Do not generate an enable user registration <name> portal line: the current enable parser does not accept it.

Show full SKILL.md (387 more words)Show less

Common Portal Options

Use crypto keys for token signing and verification:

caddyfile
crypto default token lifetime 3600
crypto key sign-verify {env.JWT_SHARED_KEY}

Use both enable source ip tracking and validate source address when issued tokens should carry and verify the source address. The first sets authcrunch token grantor source-address tracking; the second makes the token validator enforce the source-address claim.

Trusted redirect URI checks support login and logout redirect targets:

caddyfile
trust login redirect uri domain exact example.com path prefix /app
trust logout redirect uri domain example.com path /

The match type is optional and defaults to exact; supported match types are exact, partial, prefix, suffix, and regex. Both domain and path need values. Keep login/logout, redirect, and uri as separate header tokens. Quoted domain/path values remain data even when they contain those words; they cannot change which redirect trust list receives the rule.

Enable admin/server API endpoints only when they are needed and protected by an authenticated admin session:

caddyfile
enable admin api

Both enable and disable are supported for admin api and admin api private key export. Each setting occurs at most once in the portal; both default to disabled. Key export does not implicitly enable the API and requires both flags plus authenticated admin authorization at runtime.

See authentication-portal-api for /api/server/metadata, /api/server/realms, /api/server/info, JSON login, /beacon, and /whoami behavior. Admin API troubleshooting should check the directive, the active portal session, and whether the user has an admin role before changing route layout.

Portal access uses built-in role tiers. authp/admin grants administrative portal capabilities, authp/user grants normal user settings/profile capabilities, and authp/guest is the fallback portal-only role when neither admin nor user roles are assigned. When debugging portal UI access, search debug logs for configured portal access-list rules and inspect transforms that add or drop authp/* roles.

Fixtures

Use these fixtures as examples:

  • testdata/caddyfile_adapt/testcase_security_authentication_portal.Caddyfile
  • testdata/caddyfile_adapt/testcase_authenticate_with_registration.Caddyfile

TestParseCaddyfileRedirectTrustMalformed and TestParseCaddyfileRedirectTrustValues cover incomplete selectors and quoted values. testcase_authenticate_with_redirect_trust_malformed must fail adaptation with a parser error, not a panic. The redirect-trust subtest in TestCaddyOAuthE2E verifies separate login/logout behavior over TLS and confirms that rejected reconfiguration leaves the running portal usable.

Acceptance criteria

  • A portal with explicitly selected, enabled backends serves login at its exact mount; a disabled or unknown backend is rejected rather than silently replaced.
  • Trusted redirect rules retain their intended login/logout scope and matcher semantics after adaptation and runtime replacement.
  • Refresh/OIDC participation is explicit per local realm. A portal-only syntax fixture does not qualify renewal, provider exchanges, or durable restart; those outcomes use the linked feature's Caddy unit and E2E evidence.

© greenpau, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in .codex/skills/configuration-authentication of greenpau/caddy-security.

  • SKILL.md
  • agents/openai.yaml
  • references/token-refresh.md

Open the folder on GitHubat commit a48553d

Compare with similar skills

Configuration Authentication next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Configuration Authentication compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Configuration Authentication this skillgreenpau/caddy-security2.3k—~2.3kAutomated safety check: PassApache-2.0
Fortify Developmentcoollabsio/coolify63k4 repos~1.9kAutomated safety check: PassMIT
Security Reviewdoorkeeper-gem/doorkeeper5.5k—~1.4kAutomated safety check: PassMIT
Cognitoitsmostafa/aws-agent-skills1.2k1 repos~2.3kAutomated safety check: PassMIT
OAuth Account Setupspinabot/brigade11k—~878Automated safety check: PassMIT
Auth Implementation Patternsynulihao/AgentSkillOS61710 repos~4.4kAutomated safety check: PassNone

Similar skills

  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed
  • Security Review

    doorkeeper-gem/doorkeeper

    Verify that code changes do not introduce OAuth security vulnerabilities.

    5.5k GitHub stars~1.4k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Cognito

    itsmostafa/aws-agent-skills

    AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.3k tokens
    Backend & APIsAuto-check passed
  • OAuth Account Setup

    spinabot/brigade

    Connects an OAuth 2.0 account such as Gmail with the built-in oauth_authorize tool: an authorization link, automatic code capture and sealed token storage.

    11k GitHub stars~878 tokensUpdated 5 days ago
    Backend & APIsAuto-check passed
  • Auth Implementation Patterns

    ynulihao/AgentSkillOS

    Master authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable access control systems.

    617 GitHub starsUsed in 10 repos~4.4k tokens
    Backend & APIsAuto-check passed
  • Socialite Development

    hexlet-volunteers/hexlet-sicp

    Manages OAuth social authentication with Laravel Socialite. An agent skill from hexlet-volunteers/hexlet-sicp.

    114 GitHub starsUsed in 5 repos~1.2k tokens
    Backend & APIsAuto-check passed

More from greenpau/caddy-security

All 29 skills in this repo
  • Authentication Portal API

    greenpau/caddy-security

    Build or troubleshoot portal JSON/native login clients, refresh, profile and admin APIs, and public JWKS.

    2.3k GitHub stars~2.9k tokensUpdated 3 days ago
    Auto-check passed
  • Coding Directives

    greenpau/caddy-security

    Implement or review caddy-security Go code, Caddy modules, parsers, lifecycle, and HTTP delegation.

    2.3k GitHub stars~4.1k tokensUpdated 3 days ago
    Auto-check passed
  • Configuration

    greenpau/caddy-security

    Build or review caddy-security Caddyfiles and select focused configuration skills.

    2.3k GitHub stars~2.6k tokensUpdated 3 days ago
    Auto-check passed
  • Configuration Crypto

    greenpau/caddy-security

    Configure portal/policy JWT keys, token names and lifetimes, key loading and generation, public-key discovery, and System API encryption keys.

    2.3k GitHub stars~3.5k tokensUpdated 3 days ago
    Auto-check passed
  • Configuration HTTP Integrations

    greenpau/caddy-security

    Mount authenticate and authorize handlers, separate portal and protected routes, align auth URLs, and preserve trusted proxy metadata.

    2.3k GitHub stars~3.2k tokensUpdated 3 days ago
    Auto-check passed
  • Configuration State

    greenpau/caddy-security

    Configure durable AuthCrunch runtime state, exclusive storage ownership, stop/start persistence, reload rejection, and recovery.

    2.3k GitHub stars~1.6k tokensUpdated 3 days ago
    Auto-check passed

Categories

Questions about Configuration Authentication

What does Configuration Authentication do?

Configure authentication portals, backend selection, redirect trust, refresh, and portal wiring. Configuration Authentication is an agent skill from greenpau/caddy-security. Configure authentication portals, backend selection, redirect trust, refresh, and portal wiring.

When should I use Configuration Authentication?

Configuration Authentication fits situations like: tasks that involve Authentication; tasks that involve OAuth and OpenID Connect.

How do I install Configuration Authentication in Claude Code?

Run `npx skills add greenpau/caddy-security --skill configuration-authentication -a claude-code`. Or copy the skill folder (.codex/skills/configuration-authentication in greenpau/caddy-security) into .claude/skills/configuration-authentication in your project. Claude Code loads it when a task matches its description.

How do I install Configuration Authentication in Codex?

Run `npx skills add greenpau/caddy-security --skill configuration-authentication -a codex`. Or copy the skill folder (.codex/skills/configuration-authentication in greenpau/caddy-security) into .agents/skills/configuration-authentication in your project. Codex loads it when a task matches its description.

Can I use Configuration Authentication in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add greenpau/caddy-security --skill configuration-authentication -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/configuration-authentication, .gemini/skills/configuration-authentication, .github/skills/configuration-authentication and .opencode/skills/configuration-authentication in your project.

What does Configuration Authentication need to run?

Going by SKILL.md and its folder, Configuration Authentication needs credentials named JWT_SHARED_KEY. Our summary lists: A credential in JWT_SHARED_KEY.

Does Configuration Authentication access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Configuration Authentication safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Configuration Authentication use?

Configuration Authentication is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Configuration Authentication use?

About 2.3k tokens (SKILL.md is roughly 9.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.1k tokens, read only when the agent opens those files.

What are the alternatives to Configuration Authentication?

Skills that share tags, products or a category with Configuration Authentication: Fortify Development (coollabsio/coolify, 63k stars), Security Review (doorkeeper-gem/doorkeeper, 5.5k stars), Cognito (itsmostafa/aws-agent-skills, 1.2k stars) and OAuth Account Setup (spinabot/brigade, 11k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Configuration Authentication?

greenpau (a GitHub user) maintains it in greenpau/caddy-security, which has 2,251 GitHub stars. The repository holds 29 skills in this directory. The repository was last updated on October 5, 2026.

Source: greenpau/caddy-security on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.