Agent skill

Configuration Authentication Cross Device

by greenpau in greenpau/caddy-security

Configure and verify optional cross-device portal login, QR activation, explicit approval, browser binding, cancellation, and lifecycle through Caddy.

Apache-2.0Auto-check passedFrontend & Design

Install Configuration Authentication Cross Device

skills CLI
$ npx skills add greenpau/caddy-security --skill configuration-authentication-cross-device -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install greenpau/caddy-security configuration-authentication-cross-device --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/configuration-authentication-cross-device .claude/skills/configuration-authentication-cross-device && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
configuration-authentication-cross-device
GitHub stars
2.3k
Token cost
~2.3k tokens
SKILL.md length
1,030 words
Files
2
Skills in repo
29
Repo updated
First seen
Licence
Apache-2.0

At a glance

Configure and verify optional cross-device portal login, QR activation, explicit approval, browser binding, cancellation, and lifecycle through Caddy.

  • Tasks that involve Responsive design
  • SKILL.md covers Configuration and ownership, Routing and browser contract, Identity, cancellation and… and Acceptance and validation
  • Calls make
  • Tasks that involve Authentication

What it does

Configuration Authentication Cross Device is an agent skill from greenpau/caddy-security. Configure and verify optional cross-device portal login, QR activation, explicit approval, browser binding, cancellation, and lifecycle through Caddy. Native login and external provider configuration retain their own owners.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Frontend & Design, covering Responsive design and Authentication. The repository describes itself as: 🔐 Authentication, Authorization, and Accounting (AAA) App and Plugin for Caddy v2. 💎 Implements Form-Based, Basic, Local, LDAP, OpenID Connect, OAuth 2.0 (Github, Google…. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Responsive design
  • Tasks that involve Authentication

Example prompts

  • “/configuration-authentication-cross-device”

What it can do on your machine

Read from SKILL.md and the folder at commit a48553d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • make

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Configuration Authentication Cross Device loads about 2.3k tokens when it runs. Until then it costs about 67 tokens; SKILL.md has 1,030 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~67
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from greenpau/caddy-security at commit a48553d, republished under its Apache-2.0 licence (© greenpau). 1,030 words, ~2,250 tokens.

Download SKILL.mdSave it as .claude/skills/configuration-authentication-cross-device/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
configuration-authentication-cross-device
description
Configure and verify optional cross-device portal login, QR activation, explicit approval, browser binding, cancellation, and lifecycle through Caddy. Native login and external provider configuration retain their own owners.

Cross-device Portal Login

Configuration and ownership

The selected published go-authcrunch v1.3.11 supplies the parser, runtime and embedded UI. Check go.mod and the selected module directory when changing this integration; a sibling working tree is only a read-only reference. No local replacement or copied portal handler, QR generator, store or template is needed.

Inside an existing authentication portal:

caddyfile
authentication portal myportal {
    enable identity store localdb
    enable cross-device login
    cookie cross-device session id name __Secure-LOGIN_TRANSFER
}

Declare localdb separately and mount the portal through authenticate with myportal. Omit the cookie override to use AUTHP_CROSS_DEVICE_SESSION_ID. disable cross-device login explicitly disables the feature. Omission also disables it and preserves a nil field in adapted JSON. Enabling produces "cross_device_login":{"enabled":true} in the portal config; an explicit false/empty object is disabled on JSON load. Cookie naming alone never enables routes or a login action.

caddyfile_authn.go collects complete enable/disable statements before the ordinary miscellaneous/admin dispatch, encodes original token boundaries with cfgutil.EncodeArgs, and calls the public cross_device/parser.NewCrossDeviceLoginConfigFromDirectives once per portal. The shared parser owns grammar and duplicate/conflict checks, including imports. Reject empty/multiline tokens before encoding, nested blocks, joined quoted keywords, wrong arity and unsupported arguments without echoing their values. Individual quoted keywords preserve the same token boundaries and remain valid. Do not add per-line boolean mutation to caddyfile_authn_misc.go.

Routing and browser contract

Mount the entire namespace, without stripping its prefix:

caddyfile
auth.example.com {
    @portal path /auth /auth/*
    route @portal {
        authenticate with myportal
    }
}

All paths below are relative to that mount; root and nested mounts work. A name containing cross-device, such as /cross-device-team/auth, is not a transfer route by substring. /oauth2/cross-device and /saml/cross-device remain provider realms even when transfer is disabled. Unknown transfer children return 404; do not reserve the name globally or add permissive CORS.

PathMethodsBehavior
/cross-deviceGETRequest page, QR and copyable activation link
/cross-device/startPOSTNew request; 300-second lifetime, 2-second polling
/cross-device/activate?code=...GETMatching-code warning and approver binding
/cross-device/beginPOSTCSRF validation and fresh HTML login
/cross-device/confirmGET, POSTDisplay account/code; explicit approve or deny
/cross-device/pollPOSTPending/slow down or independent credential cookies
/cross-device/cancelPOSTCancel before redemption

Use HTTPS on both devices. POSTs require exactly one matching Origin, compatible Fetch Metadata and one URL-encoded Content-Type; parameters such as charset=UTF-8 are supported. The 4 KiB bound includes streamed bodies without Content-Length. Oversize is 413, unsupported media is 415, malformed/ambiguous forms or Content-Type is 400, and method errors advertise supported methods. Caddy owns trusted forwarded origin/source normalization. Preserve Referrer-Policy: strict-origin; no-referrer makes Chrome form Origin become null and correctly fail CSRF validation.

The link/QR contains only an activation code. A separate requester secret stays in page memory and POST bodies; the code cannot redeem approval. Poll responses issue HttpOnly cookies, never bearer tokens in JSON. Keep normal redirect trust allowlists, and never log form bodies or place the requester secret in URLs.

The approver binding cookie is Secure, HttpOnly, host-only, mount-scoped, SameSite=None and has a 300-second Max-Age. None permits signed cross-site SAML POST callbacks. Browser binding, strict transfer POST origins and explicit approval remain mandatory. Shared prefix/override/collision rules apply; __Host- names require a root mount. Ordinary cookie attributes do not relax this binding. A second tab's new binding must invalidate an older account's form; only the displayed account may reach its corresponding requester.

Show full SKILL.md (522 more words)Show less

Identity, cancellation and lifecycle

Scanning and logging in do not approve a request. Require fresh HTML login and all selected factors, or a freshly verified OAuth/SAML callback, then explicit approval of the displayed account and matching code. Existing JWTs, Basic, API-key and JSON login cannot complete approval. Local credential versions and current requester challenge policy are checked again at redemption. Provider transfers rerun requester transforms and never copy upstream identity tokens; they do not introduce upstream revocation introspection.

Each device receives independent access, refresh and OP sessions. Rotation of a live approver refresh family remains valid. Logout, replay, fresh account replacement and logout after the access cookie is gone invalidate unconsumed approval. Only committed local refresh issuance supplies its authoritative family reference; custom access/provider sid claims are not family IDs. Failed completion publishes no credentials and releases an undelivered family. These checks belong to AuthCrunch and need no Caddy logout or issuance hooks.

Pending records are volatile, origin/mount scoped, limited to 1024 per portal and eight per trusted source IP, and consumed atomically before issuance. Reload, restart and Close discard them even with persistent state. Persistent reload itself retains the existing host rejection policy: use complete stop/start. Multiple instances require affinity for a pending interaction. Lost redemption responses require a new request; cancellation cannot undo consumed approval.

Navigation ends the visible flow and clears its capability. Back may show a terminal document or a new request, never resume the old capability. Late clipboard/network callbacks must not replace cancellation. The embedded client uses original AbortController APIs, ten-second request/body deadlines and a separate five-second cancellation deadline; it does not require AbortSignal.any or AbortSignal.timeout. Chrome evidence does not certify physical TV/VR hardware. Custom login templates must retain the conditional cross-device action outside ordinary provider-link visibility conditions.

Acceptance and validation

  • Unit/adapt/resolution cases in caddyfile_authn_cross_device_test.go and testcase_authenticate_with_cross_device qualify omission, enabled/disabled JSON, encoded grammar, imports, redaction and cookie defaults/overrides. Existing cookie parser cases retain reserved modern keywords and collisions.
  • TestCaddyCrossDeviceE2E exercises actual Caddy TLS routes, independent credentials/resource access, mounts, strict HTTP boundaries, MFA/refresh/OP, non-HTML exclusion, revocation, race redemption, JSON reload, persistent restart, optional host-prefix scope and failed-issuance rollback. TestCaddyRuntimeStateE2E/cross_device_pending also crosses an actual built-Caddy process restart with durable state enabled.
  • TestCaddyCrossDeviceProvidersE2E uses real signed OAuth and SAML callbacks, including the provider realm cross-device, provider-only/mixed UI and a custom access-only sid.
  • TestCaddyCrossDeviceBrowserE2E runs independent Chrome contexts through the embedded UI with private fixture trust, QR/copy, explicit approval, navigation, cancellation, native aborts without static helpers, and the two-account stale-form regression. Keep TLS/Origin enforcement intact. Dispose completed scenario contexts before opening the next devices; assert their contexts and targets are gone. The stale-form scenario retains two isolated requesters and two approver tabs sharing one fresh context. TestBrowserContextCleanup checks awaited disposal, partial failure cleanup and ownership of contexts still requiring cleanup.
  • TestCaddyCrossDeviceExpirationE2E waits for the real five-minute deadline, checks source quota despite untrusted forwarded addresses and verifies expiry releases capacity. It deliberately adds five minutes to the full Go suite.

Use this command for focused evidence, then make ci-check for the full gate:

bash
make test TEST='TestPortalCrossDevice|TestPortalCookie|TestCaddyCrossDevice' TEST_DIR=.

Keep failures in separate coverage bundles. Sibling tests and official OP conformance do not substitute for these Caddy journeys.

© greenpau, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .codex/skills/configuration-authentication-cross-device of greenpau/caddy-security.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit a48553d

Compare with similar skills

Configuration Authentication Cross Device next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Configuration Authentication Cross Device compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Configuration Authentication Cross Device this skillgreenpau/caddy-security2.3k—~2.3kAutomated safety check: PassApache-2.0
Vue Component Developmentgdarko/laravel-vue-starter145—~1.1kAutomated safety check: PassMIT
Game UI UXukanwat/overtime3871 repos~2.2kAutomated safety check: PassApache-2.0
Cross App Shared Authooiyeefei/ccc494—~5.9kAutomated safety check: PassMIT
Figma To StaticLeoYeAI/openclaw-master-skills2.2k—~7.1kAutomated safety check: PassMIT
UI StylingOhh-889/skyroc79513 repos~2.5kAutomated safety check: PassMIT

Similar skills

  • Vue Component Development

    gdarko/laravel-vue-starter

    Activate when creating or modifying Vue 3 components, pages, layouts, stores, or services in the frontend.

    145 GitHub stars~1.1k tokensUpdated 6 mo ago
    Frontend & DesignAuto-check passed
  • Game UI UX

    ukanwat/overtime

    Design and build game UI/UX — HUDs, menus, and overlays — that survive every screen: anchor- based responsive layout, resolution/aspect scaling and safe areas, keyboard/gamepad focus navigation, a…

    387 GitHub starsUsed in 1 repo~2.2k tokens
    Frontend & DesignAuto-check passed
  • Blueprint for wiring many apps to one shared login plus a central accounts database, so a person has a single account across every app and access to each app accrues per app (opt-in, deny-by-default).

    494 GitHub stars~5.9k tokensUpdated 2 mo ago
    Frontend & DesignAuto-check passed
  • Figma To Static

    LeoYeAI/openclaw-master-skills

    Convert Figma design files to pixel-level mobile-first static HTML/CSS pages.

    2.2k GitHub stars~7.1k tokensUpdated 2 mo ago
    Frontend & DesignAuto-check passed
  • UI Styling

    Ohh-889/skyroc

    Create beautiful, accessible user interfaces with shadcn/ui components (built on Radix UI + Tailwind), Tailwind CSS utility-first styling, and canvas-based visual designs.

    795 GitHub starsUsed in 13 repos~2.5k tokens
    Frontend & DesignAuto-check passed
  • Material 3

    hamen/material-3-skill

    Implement Google's Material Design 3 (Material You) UI system.

    1.5k GitHub starsUsed in 2 repos~7.8k tokens
    Frontend & DesignAuto-check passed

More from greenpau/caddy-security

All 29 skills in this repo
  • Authentication Portal API

    greenpau/caddy-security

    Build or troubleshoot portal JSON/native login clients, refresh, profile and admin APIs, and public JWKS.

    2.3k GitHub stars~2.9k tokensUpdated 4 days ago
    Auto-check passed
  • Coding Directives

    greenpau/caddy-security

    Implement or review caddy-security Go code, Caddy modules, parsers, lifecycle, and HTTP delegation.

    2.3k GitHub stars~4.1k tokensUpdated 4 days ago
    Auto-check passed
  • Configuration

    greenpau/caddy-security

    Build or review caddy-security Caddyfiles and select focused configuration skills.

    2.3k GitHub stars~2.6k tokensUpdated 4 days ago
    Auto-check passed
  • Configuration Crypto

    greenpau/caddy-security

    Configure portal/policy JWT keys, token names and lifetimes, key loading and generation, public-key discovery, and System API encryption keys.

    2.3k GitHub stars~3.5k tokensUpdated 4 days ago
    Auto-check passed
  • Configuration HTTP Integrations

    greenpau/caddy-security

    Mount authenticate and authorize handlers, separate portal and protected routes, align auth URLs, and preserve trusted proxy metadata.

    2.3k GitHub stars~3.2k tokensUpdated 4 days ago
    Auto-check passed
  • Configuration State

    greenpau/caddy-security

    Configure durable AuthCrunch runtime state, exclusive storage ownership, stop/start persistence, reload rejection, and recovery.

    2.3k GitHub stars~1.6k tokensUpdated 4 days ago
    Auto-check passed

Questions about Configuration Authentication Cross Device

What does Configuration Authentication Cross Device do?

Configure and verify optional cross-device portal login, QR activation, explicit approval, browser binding, cancellation, and lifecycle through Caddy. Configuration Authentication Cross Device is an agent skill from greenpau/caddy-security. Configure and verify optional cross-device portal login, QR activation, explicit approval, browser binding, cancellation, and lifecycle through Caddy.

When should I use Configuration Authentication Cross Device?

Configuration Authentication Cross Device fits situations like: tasks that involve Responsive design; tasks that involve Authentication.

How do I install Configuration Authentication Cross Device in Claude Code?

Run `npx skills add greenpau/caddy-security --skill configuration-authentication-cross-device -a claude-code`. Or copy the skill folder (.codex/skills/configuration-authentication-cross-device in greenpau/caddy-security) into .claude/skills/configuration-authentication-cross-device in your project. Claude Code loads it when a task matches its description.

How do I install Configuration Authentication Cross Device in Codex?

Run `npx skills add greenpau/caddy-security --skill configuration-authentication-cross-device -a codex`. Or copy the skill folder (.codex/skills/configuration-authentication-cross-device in greenpau/caddy-security) into .agents/skills/configuration-authentication-cross-device in your project. Codex loads it when a task matches its description.

Can I use Configuration Authentication Cross Device in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add greenpau/caddy-security --skill configuration-authentication-cross-device -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/configuration-authentication-cross-device, .gemini/skills/configuration-authentication-cross-device, .github/skills/configuration-authentication-cross-device and .opencode/skills/configuration-authentication-cross-device in your project.

What does Configuration Authentication Cross Device need to run?

Going by SKILL.md and its folder, Configuration Authentication Cross Device needs the command-line tools its instructions call (make).

Does Configuration Authentication Cross Device access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Configuration Authentication Cross Device safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Configuration Authentication Cross Device use?

Configuration Authentication Cross Device is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Configuration Authentication Cross Device use?

About 2.3k tokens (SKILL.md is roughly 9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Configuration Authentication Cross Device?

Skills that share tags, products or a category with Configuration Authentication Cross Device: Vue Component Development (gdarko/laravel-vue-starter, 145 stars), Game UI UX (ukanwat/overtime, 387 stars), Cross App Shared Auth (ooiyeefei/ccc, 494 stars) and Figma To Static (LeoYeAI/openclaw-master-skills, 2.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Configuration Authentication Cross Device?

greenpau (a GitHub user) maintains it in greenpau/caddy-security, which has 2,252 GitHub stars. The repository holds 29 skills in this directory. The repository was last updated on October 5, 2026.

Source: greenpau/caddy-security on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.