Agent skill

Configuration Saml Providers

by greenpau in greenpau/caddy-security

Configure external SAML login providers, ACS/IdP URLs, metadata, signing certificates, realms, and claims.

Apache-2.0Auto-check passedBackend & APIs

Install Configuration Saml Providers

skills CLI
$ npx skills add greenpau/caddy-security --skill configuration-saml-providers -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install greenpau/caddy-security configuration-saml-providers --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/configuration-saml-providers .claude/skills/configuration-saml-providers && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
configuration-saml-providers
GitHub stars
2.3k
Token cost
~1.6k tokens
SKILL.md length
724 words
Files
2
Skills in repo
29
Repo updated
First seen
Licence
Apache-2.0

At a glance

Configure external SAML login providers, ACS/IdP URLs, metadata, signing certificates, realms, and claims.

  • Portal SAML SSO app providers belong to configuration-sso-app
  • SKILL.md covers Purpose, Shape, Provider Notes and Review Checklist, plus 1 more section
  • Calls go
  • Tasks that involve Authentication

What it does

Configuration Saml Providers is an agent skill from greenpau/caddy-security. Configure external SAML login providers, ACS/IdP URLs, metadata, signing certificates, realms, and claims. Use for Azure or generic IdPs; portal SAML SSO app providers belong to configuration-sso-app.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Backend & APIs, covering Authentication and OAuth and OpenID Connect. It works with Microsoft Azure. The repository describes itself as: 🔐 Authentication, Authorization, and Accounting (AAA) App and Plugin for Caddy v2. 💎 Implements Form-Based, Basic, Local, LDAP, OpenID Connect, OAuth 2.0 (Github, Google…. The licence is Apache-2.0.

When your agent uses it

  • Portal SAML SSO app providers belong to configuration-sso-app
  • Tasks that involve Authentication
  • Tasks that involve OAuth and OpenID Connect

Example prompts

  • “/configuration-saml-providers”

What it can do on your machine

Read from SKILL.md and the folder at commit a48553d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • go

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Configuration Saml Providers loads about 1.6k tokens when it runs. Until then it costs about 57 tokens; SKILL.md has 724 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~57
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from greenpau/caddy-security at commit a48553d, republished under its Apache-2.0 licence (© greenpau). 724 words, ~1,640 tokens.

Download SKILL.mdSave it as .claude/skills/configuration-saml-providers/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
configuration-saml-providers
description
Configure external SAML login providers, ACS/IdP URLs, metadata, signing certificates, realms, and claims. Use for Azure or generic IdPs; portal SAML SSO app providers belong to configuration-sso-app.

Configuration SAML Providers

Purpose

Use this skill for saml identity provider <name> blocks that let users log in to an authentication portal through a SAML IdP. This is distinct from sso provider <name> blocks, which configure the portal as an IdP for SSO apps and belong in configuration-sso-app.

Read these files when details matter:

  • caddyfile_identity.go and caddyfile_identity_provider.go for parser dispatch and accepted provider fields.
  • The selected go-authcrunch module's pkg/idp/saml/ for validation, metadata handling, assertion validation, and driver behavior. Resolve its directory with go list -m -json github.com/greenpau/go-authcrunch; a sibling checkout may differ from the selected version.

Shape

caddyfile
{
	security {
		saml identity provider azure {
			realm azure
			driver azure
			idp_metadata_location /etc/caddy/saml/azure_metadata.xml
			idp_sign_cert_location /etc/caddy/saml/azure_signing_cert.pem
			tenant_id {env.AZURE_TENANT_ID}
			application_id {env.AZURE_APP_ID}
			application_name "Example Portal"
			entity_id "urn:caddy:example-portal"
			acs_url https://auth.example.com/auth/saml/azure
		}

		authentication portal myportal {
			enable identity provider azure
		}
	}
}

The provider name must match the portal's enable identity provider <name>. The realm becomes the login realm and is commonly matched in transforms:

caddyfile
transform user {
	match realm azure
	action add role authp/user
}

Provider Notes

The selected library binds the SAML response to its initiating browser using the portal's SAML session cookie. Configure its name inside the portal with cookie saml session id name <name> or the shared cookie prefix; see cookie names and attributes. Keep this cookie distinct from access, OIDC and refresh cookies. Login must start at the portal: unsolicited IdP-initiated responses are disabled. The response must return the issued RelayState and matching request ID to the same browser and ACS URL. Expired, missing, replayed or foreign-browser state fails; start a new portal login rather than replaying the assertion.

idp_metadata_location accepts a filesystem path or HTTP(S) URL. In v1.3.4, idp_sign_cert_location is a local PEM certificate path, read with pkg/util/file.ReadCertFile; it does not fetch certificate URLs. The separately configured certificate pins the signing trust anchor, so metadata cannot add another trusted signing key. Provisioning reads these files and may fetch remote metadata; adaptation alone does not check that they are usable.

Keep the portal base path in SAML URLs. If the portal is mounted at /auth and the SAML realm is azure, the ACS endpoint is usually https://auth.example.com/auth/saml/azure. For JumpCloud and other custom apps, configure the IdP ACS URL to the externally reachable portal URL, not the upstream app URL.

SAML assertion validation is time-sensitive. When SAML login fails with timestamp or assertion validity errors, check clock synchronization on the Caddy host before changing IdP metadata or certificates.

For driver azure, validation requires tenant_id, application_id and application_name. It derives the login URL from them and defaults an omitted metadata location to the tenant federation-metadata URL. Both drivers require realm, a signing certificate path and at least one acs_url; set a stable entity_id matching the IdP's SP configuration.

Current go-authcrunch SAML validation supports driver azure and driver generic. There is no first-class driver jumpcloud; for JumpCloud, use driver generic, configure a custom SAML app with SP entity ID, IdP entity ID, ACS URL and RSA-SHA256 signing. Generic configuration also requires an explicit idp_login_url; the login URL is not inferred from metadata. For example, inside security:

caddyfile
saml identity provider directory {
	realm directory
	driver generic
	entity_id urn:caddy:example-portal
	idp_login_url https://idp.example.com/saml/login
	idp_metadata_location /etc/caddy/saml/idp-metadata.xml
	idp_sign_cert_location /etc/caddy/saml/idp-signing.pem
	acs_url https://auth.example.com/auth/saml/directory
}

The assertion must supply attributes whose names end in identity/claims/emailaddress and identity/claims/displayname; these populate the required email and name claims. NameID alone, or attributes named only email and displayName, do not satisfy the current consumer. Roles are read from attribute names ending in Attributes/Role. Inspect pkg/idp/saml/authenticate.go before assuming another IdP claim name maps to a portal claim.

Show full SKILL.md (205 more words)Show less

Review Checklist

  • Use saml identity provider <name>, not sso provider <name>.
  • Include a stable realm and driver; selected go-authcrunch supports azure and generic.
  • Configure readable metadata and a local PEM signing certificate; provide idp_login_url for generic providers and the required Azure fields otherwise.
  • Include every externally reachable ACS URL with acs_url, especially when the portal is available on multiple hostnames or ports.
  • Keep the portal route and ACS URL aligned with authenticate mount path.
  • Enable the same provider name from the authentication portal.
  • Map IdP role or group claims with transform user rules when portal tokens need authp/user, authp/admin, or application roles.
  • Check host clock synchronization before diagnosing signed assertion failures.

Fixtures

Use these references:

  • caddyfile_identity_provider.go for current accepted Caddyfile fields.
  • go-authcrunch/pkg/idp/saml for runtime validation and assertion behavior.

caddyfile_authn_test.go contains an Azure parser example, but it does not read metadata or perform a signed SAML exchange. This checkout has no complete SAML login E2E. Before claiming a provider integration works, verify a portal-started login through actual Caddy with synthetic signed assertions, the expected email/name/roles, and protected-route access. Include missing generic login URL, unreadable certificate, wrong signature, wrong ACS, replay and missing or foreign browser cookie failures. Upstream SAML tests are implementation evidence, not Caddy qualification.

© greenpau, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .codex/skills/configuration-saml-providers of greenpau/caddy-security.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit a48553d

Compare with similar skills

Configuration Saml Providers next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Configuration Saml Providers compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Configuration Saml Providers this skillgreenpau/caddy-security2.3k—~1.6kAutomated safety check: PassApache-2.0
Entra App Registrationmicrosoft/GitHub-Copilot-for-Azure2552 repos~2.1kAutomated safety check: PassMIT
Managing Cloud Identity With Oktamukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: PassApache-2.0
Iam Auditbriiirussell/cybersecurity-skills413—~3.1kAutomated safety check: NotesMIT
Apex Entra App Registrationjonathan-vella/apex217—~1.3kAutomated safety check: PassMIT
Azure AuthLeoYeAI/openclaw-master-skills2.2k—~4.9kAutomated safety check: NotesMIT

Similar skills

  • Entra App Registration

    microsoft/GitHub-Copilot-for-Azure

    Official

    Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration.

    255 GitHub starsUsed in 2 repos~2.1k tokens
    Backend & APIsAuto-check passed
  • Managing Cloud Identity With Okta

    mukul975/Anthropic-Cybersecurity-Skills

    Implement Okta as a centralized cloud identity provider: configure SSO with AWS, Azure, and GCP, deploy phishing-resistant MFA with Okta FastPass, automate user provisioning/deprovisioning, and…

    34k GitHub stars~3.1k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Iam Audit

    briiirussell/cybersecurity-skills

    Audit, design, and migrate Identity and Access Management — cloud provider IAM (AWS, GCP, Azure), identity providers (Okta, Entra ID / Azure AD, Auth0, Google Workspace), application authorization…

    413 GitHub stars~3.1k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes
  • Apex Entra App Registration

    jonathan-vella/apex

    WORKFLOW SKILL — Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration.

    217 GitHub stars~1.3k tokensUpdated today
    Backend & APIsAuto-check passed
  • Azure Auth

    LeoYeAI/openclaw-master-skills

    Microsoft Entra ID (Azure AD) authentication for React SPAs with MSAL.js and Cloudflare Workers JWT validation using jose library.

    2.2k GitHub stars~4.9k tokensUpdated 2 mo ago
    Backend & APIsAuto-check: notes
  • Entra Id

    vinayaklatthe/microsoft-security-skills

    Guidance for Microsoft Entra ID (formerly Azure AD) — cloud identity and access management and the control plane for Zero Trust.

    175 GitHub stars~2.3k tokensUpdated 3 mo ago
    Backend & APIsAuto-check passed

More from greenpau/caddy-security

All 29 skills in this repo
  • Authentication Portal API

    greenpau/caddy-security

    Build or troubleshoot portal JSON/native login clients, refresh, profile and admin APIs, and public JWKS.

    2.3k GitHub stars~2.9k tokensUpdated 5 days ago
    Auto-check passed
  • Coding Directives

    greenpau/caddy-security

    Implement or review caddy-security Go code, Caddy modules, parsers, lifecycle, and HTTP delegation.

    2.3k GitHub stars~4.1k tokensUpdated 5 days ago
    Auto-check passed
  • Configuration

    greenpau/caddy-security

    Build or review caddy-security Caddyfiles and select focused configuration skills.

    2.3k GitHub stars~2.6k tokensUpdated 5 days ago
    Auto-check passed
  • Configuration Crypto

    greenpau/caddy-security

    Configure portal/policy JWT keys, token names and lifetimes, key loading and generation, public-key discovery, and System API encryption keys.

    2.3k GitHub stars~3.5k tokensUpdated 5 days ago
    Auto-check passed
  • Configuration HTTP Integrations

    greenpau/caddy-security

    Mount authenticate and authorize handlers, separate portal and protected routes, align auth URLs, and preserve trusted proxy metadata.

    2.3k GitHub stars~3.2k tokensUpdated 5 days ago
    Auto-check passed
  • Configuration State

    greenpau/caddy-security

    Configure durable AuthCrunch runtime state, exclusive storage ownership, stop/start persistence, reload rejection, and recovery.

    2.3k GitHub stars~1.6k tokensUpdated 5 days ago
    Auto-check passed

Works with

Categories

Questions about Configuration Saml Providers

What does Configuration Saml Providers do?

Configure external SAML login providers, ACS/IdP URLs, metadata, signing certificates, realms, and claims. Configuration Saml Providers is an agent skill from greenpau/caddy-security. Configure external SAML login providers, ACS/IdP URLs, metadata, signing certificates, realms, and claims.

When should I use Configuration Saml Providers?

Configuration Saml Providers fits situations like: portal SAML SSO app providers belong to configuration-sso-app; tasks that involve Authentication; tasks that involve OAuth and OpenID Connect.

How do I install Configuration Saml Providers in Claude Code?

Run `npx skills add greenpau/caddy-security --skill configuration-saml-providers -a claude-code`. Or copy the skill folder (.codex/skills/configuration-saml-providers in greenpau/caddy-security) into .claude/skills/configuration-saml-providers in your project. Claude Code loads it when a task matches its description.

How do I install Configuration Saml Providers in Codex?

Run `npx skills add greenpau/caddy-security --skill configuration-saml-providers -a codex`. Or copy the skill folder (.codex/skills/configuration-saml-providers in greenpau/caddy-security) into .agents/skills/configuration-saml-providers in your project. Codex loads it when a task matches its description.

Can I use Configuration Saml Providers in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add greenpau/caddy-security --skill configuration-saml-providers -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/configuration-saml-providers, .gemini/skills/configuration-saml-providers, .github/skills/configuration-saml-providers and .opencode/skills/configuration-saml-providers in your project.

What does Configuration Saml Providers need to run?

Going by SKILL.md and its folder, Configuration Saml Providers needs the command-line tools its instructions call (go).

Does Configuration Saml Providers access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Configuration Saml Providers safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Configuration Saml Providers use?

Configuration Saml Providers is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Configuration Saml Providers use?

About 1.6k tokens (SKILL.md is roughly 6.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Configuration Saml Providers?

Skills that share tags, products or a category with Configuration Saml Providers: Entra App Registration (microsoft/GitHub-Copilot-for-Azure, 255 stars), Managing Cloud Identity With Okta (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Iam Audit (briiirussell/cybersecurity-skills, 413 stars) and Apex Entra App Registration (jonathan-vella/apex, 217 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Configuration Saml Providers?

greenpau (a GitHub user) maintains it in greenpau/caddy-security, which has 2,252 GitHub stars. The repository holds 29 skills in this directory. The repository was last updated on October 5, 2026.

Source: greenpau/caddy-security on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.