Jwx Guide V4
lestrrat-go/jwx
Guide for developing Go applications with github.com/lestrrat-go/jwx v4 — parse/sign JWTs, work with JWS/JWE/JWK, pick algorithms, and avoid the common footguns.
Configure portal user transforms: matchers, typed claims, role actions, conditional challenges, MFA, and deny rules.
$ npx skills add greenpau/caddy-security --skill configuration-authentication-user-transforms -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install greenpau/caddy-security configuration-authentication-user-transforms --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/configuration-authentication-user-transforms .claude/skills/configuration-authentication-user-transforms && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "configuration-authentication-user-transforms" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-authentication-user-transforms into .claude/skills/configuration-authentication-user-transforms/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuration-authentication-user-transforms", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-authentication-user-transformsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add greenpau/caddy-security --skill configuration-authentication-user-transforms -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install greenpau/caddy-security configuration-authentication-user-transforms --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.codex/skills/configuration-authentication-user-transforms .agents/skills/configuration-authentication-user-transforms && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "configuration-authentication-user-transforms" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-authentication-user-transforms into .agents/skills/configuration-authentication-user-transforms/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuration-authentication-user-transforms", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add greenpau/caddy-security --skill configuration-authentication-user-transforms -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install greenpau/caddy-security configuration-authentication-user-transforms --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.codex/skills/configuration-authentication-user-transforms .cursor/skills/configuration-authentication-user-transforms && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "configuration-authentication-user-transforms" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-authentication-user-transforms into .cursor/skills/configuration-authentication-user-transforms/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuration-authentication-user-transforms", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/greenpau/caddy-security.git --path .codex/skills/configuration-authentication-user-transforms--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add greenpau/caddy-security --skill configuration-authentication-user-transforms -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install greenpau/caddy-security configuration-authentication-user-transforms --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.codex/skills/configuration-authentication-user-transforms .gemini/skills/configuration-authentication-user-transforms && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "configuration-authentication-user-transforms" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-authentication-user-transforms into .gemini/skills/configuration-authentication-user-transforms/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuration-authentication-user-transforms", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install greenpau/caddy-security configuration-authentication-user-transformsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add greenpau/caddy-security --skill configuration-authentication-user-transforms -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .github/skills && cp -r skills-src/.codex/skills/configuration-authentication-user-transforms .github/skills/configuration-authentication-user-transforms && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "configuration-authentication-user-transforms" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-authentication-user-transforms into .github/skills/configuration-authentication-user-transforms/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuration-authentication-user-transforms", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add greenpau/caddy-security --skill configuration-authentication-user-transforms -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install greenpau/caddy-security configuration-authentication-user-transforms --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.codex/skills/configuration-authentication-user-transforms .opencode/skills/configuration-authentication-user-transforms && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "configuration-authentication-user-transforms" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-authentication-user-transforms into .opencode/skills/configuration-authentication-user-transforms/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuration-authentication-user-transforms", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
configuration-authentication-user-transformsConfigure portal user transforms: matchers, typed claims, role actions, conditional challenges, MFA, and deny rules.
Configuration Authentication User Transforms is an agent skill from greenpau/caddy-security. Configure portal user transforms: matchers, typed claims, role actions, conditional challenges, MFA, and deny rules. Use for authentication-time policy; stored account rules belong to configuration-users.
Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).
It sits in Backend & APIs, covering Authentication. It works with GitHub. The repository describes itself as: 🔐 Authentication, Authorization, and Accounting (AAA) App and Plugin for Caddy v2. 💎 Implements Form-Based, Basic, Local, LDAP, OpenID Connect, OAuth 2.0 (Github, Google…. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit a48553d. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
goFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
docs.github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Configuration Authentication User Transforms loads about 3k tokens when it runs. Until then it costs about 62 tokens; SKILL.md has 1,279 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from greenpau/caddy-security at commit a48553d, republished under its Apache-2.0 licence (© greenpau). 1,279 words, ~2,982 tokens.
.claude/skills/configuration-authentication-user-transforms/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Use for transform user or transform users inside an authentication portal.
caddyfile_authn_transform.go forwards the complete block to the selected
module's pkg/authn/transformer/parser; provisioning resolves individual
arguments and compiles the result again. Inspect go list -m -json github.com/greenpau/go-authcrunch before relying on sibling source. The
published v1.3.8 supports the grammar below.
The surrounding portal configuration owns wiring; static users own stored challenge rules. The authentication flow contract owns login and profile API behavior. Load those details only when changing the corresponding boundary, rather than reloading the portal router for a transform.
Every block needs at least one matcher and one action. Conditions combine as
match-all. Ordinary bare match retains the historical exact match spelling
in adapted JSON; match any stays unconditional and match github retains its
provider-specific spelling, including malformed statements for shared validation.
Classification uses the shared parser, so a claim value containing the word match remains an action.
These are alternative statements inside a transform, not a complete config:
match any
match realm local
field email exists
field picture not exists
partial match email @example.com
no regex match any role ^authp/(admin|user)$
action add role authp/user
action overwrite roles authp/user
action drop matched role
action delete org
require mfa
deny
ui link "User Profile" /auth/profile/ icon "las la-cog" target_blankACL strategies are exact, partial, prefix, suffix, and regex, with
optional no and any according to pkg/acl/condition.go. Field aliases come
from pkg/acl/acl.go: for example role/group/groups → roles, mail →
email, and subject → sub. amr is a list of verified methods.
action is optional before add, overwrite, delete and drop; it does
not prefix require. block and deny are synonyms. Actions and matching
transforms retain declaration order. overwrite accepts known claim fields; delete also removes custom fields.
Custom claims use add with an explicit type:
add matrix_id "@{claims.sub}:matrix.example.com" as string
add teams "operations team" support as string list
add nested metadata label with "literal value" as string
add nested empty as mapA custom scalar needs exactly one value. List aliases are list, string_list
and the two keywords string list. Nested paths need at least one key; values
follow with, and an empty map uses as map. Nested values are literal;
ordinary string/list actions expand claim placeholders. Follow
pkg/authn/transformer/parser/custom_fields.go and its runtime consumer rather
than inferring grammar from JSON.
{env.*} and whole-value secrets:<id>:<key> resolve during Caddy provisioning.
{claims.*} templates survive that pass only in transform arguments and expand
at authentication time in action values. ACL matcher values remain literal.
Quotes, spaces and secrets remain a single argument;
empty resolved tokens and unknown Caddy placeholders in configured arguments
fail provisioning. Encoded native JSON actions and matchers must each contain
one line; reject CR/LF before decoding so a later CSV record cannot disappear.
Resolved multiline transform values also fail shared validation. Caddy does not
recursively expand inserted replacement data. See
runtime resolution.
Inside a portal, require both a stable account ID and organization membership:
transform user {
match github id exact 12345678
match github org exact acme
action add role authp/admin
}For alternatives, use separate blocks. An organization-only block can use regex:
transform user {
match github org regex ^(acme|acme-labs)$
action add role authp/user
}The four forms are match github id exact <id>,
match github id regex <pattern>, match github org exact <login> and
match github org regex <pattern>. Each accepts exactly one operand. Quote
patterns containing spaces or Caddy delimiters. Exact IDs are canonical positive
uint64 decimals: zero, signs, leading zeros, fractions, exponent notation and
overflow are rejected. Organization operands are login names, not display names
or numeric organization IDs. Matching is case-sensitive; regex uses Go regexp
search semantics. Anchor whole-value matches; request case folding with (?i).
Distinct conditions in one block are ANDed. One organization condition succeeds
if any eligible organization matches. Missing claims never satisfy these positive
matchers, even regex .*. Duplicate conditions for the same field, invalid
regex and malformed arguments fail shared validation without exposing operands.
Organization matching requires the existing provider-body setting:
user_org_filters .*Use narrower filters for eligible organizations. With no filter, lookup is
disabled and organization conditions cannot match. The lookup reads one page of
public membership from GitHub's organizations_url; it adds neither pagination
nor private membership discovery. Adding read:org alone does not change that
endpoint. See GitHub's list-user-organizations API
and the provider claim contract.
github_id is a lossless string derived from /user's numeric ID; metadata.id
remains numeric and sub remains github.com/<login>. Renaming an account leaves
ID matching stable. An absent ID does not match; a supplied malformed ID rejects
login. github_orgs contains filtered organization logins; existing
github.com/<org>/members groups remain available. The portal establishes trust
from the selected backend's driver, not realm names, origin, roles or groups.
Both claims are read-only to transform actions, including nested writes.
The shared compiler owns lowering and validation for Caddyfile and persisted
JSON configurations. Never implement a second GitHub parser in Caddy or rewrite
serialized matchers. Lower-level exact match github_id ... and
regex match github_orgs ... remain supported. A direct transformer factory
caller must supply trusted provider claims; arbitrary caller-created maps do
not establish authenticated GitHub identity.
match any applies without requiring token timestamps in selected AuthCrunch
v1.3.11. It is supported with portal refresh, OIDC and System API keys as well
as ordinary access-only login. The earlier Caddy compatibility restriction is
removed. Use realm matchers when policy should apply only to selected backends;
do not fabricate exp or rewrite matchers to make unconditional rules run.
TestPortalTransformMatchAnyIdentityContext and
TestPortalTransformMatchAnyEncoding check timed and untimed claims through
Caddy resolution, including quoted and runtime-resolved native JSON matchers.
The testcase_authenticate_with_match_any_refresh and
testcase_authenticate_with_match_any_system fixtures adapt and resolve.
The challenge TLS journey checks unconditional factor selection and claims in
login and refresh, successful OIDC identity revalidation, and Basic rejection
without the required proof. System API E2E checks unconditional transformed
claims and rejects password-only assertions when the policy requires TOTP.
Malformed multiline transforms still reject replacement without disturbing the
serving app. See the dependency qualification.
Inside a portal, this policy prefers an enrolled security key, then an enrolled TOTP token, then the account password:
transform user {
match realm local
require auth challenges u2f
require auth challenges totp if u2f not available
require auth challenges password if u2f and totp not available
}Rule bodies are parsed by pkg/authchal/parser:
<method> [<method>...] [if <method> [and <method>...] not available]
<method> [or <method>...] [if <method> [and <method>...] not available]Methods are password, totp, u2f, and mfa. Adjacent methods require all;
or selects the first available alternative. mfa represents an available
second factor. Conditions require the named credentials to be unavailable.
Do not mix an or choice with adjacent-method requirements. Duplicate rules,
unknown methods and email methods/conditions are rejected: the portal has no
email checkpoint. Method keywords are literal configuration, not placeholders.
The first eligible rule across matching transforms replaces backend/user
challenge selection. Credential availability comes from server-owned inventory,
never roles, amr, or transformed claims. If a matched conditional policy has
no eligible rule, authentication fails; it does not fall back to a password.
Without a matching conditional policy, stored user rules/defaults apply.
Legacy require password|mfa|totp|u2f remains additive after selection; it can
force MFA enrollment when appropriate. Replacing the backend policy can remove
the password checkpoint: a TOTP-only or U2F-only rule is a deliberate policy
choice. Use adjacent password totp when both proofs are required.
Successful tokens receive authoritative AMR evidence: password → pwd, TOTP →
otp, WebAuthn/U2F → hwk. Transform actions cannot fabricate completed
methods. Direct Basic and API-key login, portal refresh, OP sessions and OIDC
refresh reevaluate current policy and cannot bypass unmet requirements.
Request-context matchers (such as issuer/address) evaluate current request
context, including backchannel requests; use stable realm/identity selectors
unless that context dependence is intentional.
caddyfile_authn_transform_test.go covers shared parsing, custom claims,
canonical JSON, conditional selection, errors and runtime replacement.
testcase_authenticate_with_challenges supplies adapt/resolution fixtures.
TestCaddyAuthenticationChallengesE2E exercises actual verified Caddy TLS:
root/nested mounts, HTML/JSON and native clients, TOTP/U2F-only selection,
password fallback, AMR authorization, refresh/OIDC, Basic/API-key rejection, no eligible
rule, stored policies and profile edits. WebAuthn uses signed assertions and
rejects wrong origin and signature. Keep these boundaries when extending syntax.
TestPortalTransformGithubMatchers and TestPortalTransformGithubRejects
check provider syntax, quote boundaries, persisted matchers, ordinary ACL
compatibility, shared errors and reserved claims. The
testcase_authenticate_with_github_transforms adaptation fixture contains all
four forms. TestCaddyGithubTransformsE2E adapts and provisions Caddy, follows
OAuth code exchange over verified local TLS, independently verifies
the signed portal token and checks a protected route. It covers exact/regex
matches and misses, AND semantics, renamed and large IDs, missing/malformed
claims, filtered/empty/denied organization lookup and a different driver using
a realm named github. Fixed provider URLs terminate at a bounded loopback
CONNECT proxy in an isolated subprocess; no production endpoint or trust
overrides are added.
© greenpau, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in .codex/skills/configuration-authentication-user-transforms of greenpau/caddy-security.
Open the folder on GitHubat commit a48553d
Configuration Authentication User Transforms next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Configuration Authentication User Transforms this skillgreenpau/caddy-security | 2.3k | — | ~3k | Automated safety check: Pass | Apache-2.0 | |
| Jwx Guide V4lestrrat-go/jwx | 2.4k | — | ~5.3k | Automated safety check: Pass | MIT | |
| GitHub OAuth Nango IntegrationAgentWorkforce/relay | 866 | 1 repos | ~3.4k | Automated safety check: Pass | Apache-2.0 | |
| JWTkataras/jwt | 212 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Auth Setupbutterbase-ai/butterbase-skills | 534 | — | ~2.2k | Automated safety check: Pass | MIT | |
| Apikerhodgef/apiker | 127 | — | ~1.4k | Automated safety check: Pass | MIT |
lestrrat-go/jwx
Guide for developing Go applications with github.com/lestrrat-go/jwx v4 — parse/sign JWTs, work with JWS/JWE/JWK, pick algorithms, and avoid the common footguns.
AgentWorkforce/relay
A skill your agent uses when implementing GitHub OAuth + GitHub App authentication with Nango - provides two-connection pattern for user login and repo access with webhook handling
kataras/jwt
Development guide for the jwt JSON Web Token library for Go (github.com/kataras/jwt).
butterbase-ai/butterbase-skills
A skill your agent uses when configuring OAuth providers (Google/GitHub/Apple/X/etc.), setting up post-login auth hooks, tuning JWT lifetimes, or generating service API keys
hodgef/apiker
Develop, review, and extend the Apiker library — a framework for building serverless REST APIs on Cloudflare Workers + Durable Objects.
microsoft/apm
Activate when code touches token management, credential resolution, git auth flows, GITHUBAPMPAT, ADOAPMPAT, AuthResolver, HostInfo, AuthContext, or any remote host authentication -- even if 'auth'…
greenpau/caddy-security
Build or troubleshoot portal JSON/native login clients, refresh, profile and admin APIs, and public JWKS.
greenpau/caddy-security
Implement or review caddy-security Go code, Caddy modules, parsers, lifecycle, and HTTP delegation.
greenpau/caddy-security
Build or review caddy-security Caddyfiles and select focused configuration skills.
greenpau/caddy-security
Configure portal/policy JWT keys, token names and lifetimes, key loading and generation, public-key discovery, and System API encryption keys.
greenpau/caddy-security
Mount authenticate and authorize handlers, separate portal and protected routes, align auth URLs, and preserve trusted proxy metadata.
greenpau/caddy-security
Configure durable AuthCrunch runtime state, exclusive storage ownership, stop/start persistence, reload rejection, and recovery.
Works with
Categories
Configure portal user transforms: matchers, typed claims, role actions, conditional challenges, MFA, and deny rules. Configuration Authentication User Transforms is an agent skill from greenpau/caddy-security. Configure portal user transforms: matchers, typed claims, role actions, conditional challenges, MFA, and deny rules.
Configuration Authentication User Transforms fits situations like: authentication-time policy; stored account rules belong to configuration-users.
Run `npx skills add greenpau/caddy-security --skill configuration-authentication-user-transforms -a claude-code`. Or copy the skill folder (.codex/skills/configuration-authentication-user-transforms in greenpau/caddy-security) into .claude/skills/configuration-authentication-user-transforms in your project. Claude Code loads it when a task matches its description.
Run `npx skills add greenpau/caddy-security --skill configuration-authentication-user-transforms -a codex`. Or copy the skill folder (.codex/skills/configuration-authentication-user-transforms in greenpau/caddy-security) into .agents/skills/configuration-authentication-user-transforms in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add greenpau/caddy-security --skill configuration-authentication-user-transforms -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/configuration-authentication-user-transforms, .gemini/skills/configuration-authentication-user-transforms, .github/skills/configuration-authentication-user-transforms and .opencode/skills/configuration-authentication-user-transforms in your project.
Going by SKILL.md and its folder, Configuration Authentication User Transforms needs the command-line tools its instructions call (go).
SKILL.md names 1 domain. As links in the text: docs.github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Configuration Authentication User Transforms is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Configuration Authentication User Transforms: Jwx Guide V4 (lestrrat-go/jwx, 2.4k stars), GitHub OAuth Nango Integration (AgentWorkforce/relay, 866 stars), JWT (kataras/jwt, 212 stars) and Auth Setup (butterbase-ai/butterbase-skills, 534 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
greenpau (a GitHub user) maintains it in greenpau/caddy-security, which has 2,251 GitHub stars. The repository holds 29 skills in this directory. The repository was last updated on October 5, 2026.
Source: greenpau/caddy-security on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.