Agent skill

Configuration Sso App

by greenpau in greenpau/caddy-security

Configure portal-provided SAML SSO apps, AWS role names, metadata, certificates, and PKCS8 keys.

Apache-2.0Auto-check passedBackend & APIs

Install Configuration Sso App

skills CLI
$ npx skills add greenpau/caddy-security --skill configuration-sso-app -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install greenpau/caddy-security configuration-sso-app --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/configuration-sso-app .claude/skills/configuration-sso-app && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
configuration-sso-app
GitHub stars
2.3k
Token cost
~1.6k tokens
SKILL.md length
697 words
Files
2
Skills in repo
29
Repo updated
First seen
Licence
Apache-2.0

At a glance

Configure portal-provided SAML SSO apps, AWS role names, metadata, certificates, and PKCS8 keys.

  • Sso provider blocks and their runtime limits
  • SKILL.md covers Purpose, Shape, Supported Fields and Portal URLs And Roles, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • External SAML login providers are separate

What it does

Configuration Sso App is an agent skill from greenpau/caddy-security. Configure portal-provided SAML SSO apps, AWS role names, metadata, certificates, and PKCS8 keys. Use for sso provider blocks and their runtime limits; external SAML login providers are separate.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Backend & APIs, covering Authentication. It works with Amazon Web Services. The repository describes itself as: 🔐 Authentication, Authorization, and Accounting (AAA) App and Plugin for Caddy v2. 💎 Implements Form-Based, Basic, Local, LDAP, OpenID Connect, OAuth 2.0 (Github, Google…. The licence is Apache-2.0.

When your agent uses it

  • Sso provider blocks and their runtime limits
  • External SAML login providers are separate

Example prompts

  • “/configuration-sso-app”

What it can do on your machine

Read from SKILL.md and the folder at commit a48553d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are caddyfile).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Configuration Sso App loads about 1.6k tokens when it runs. Until then it costs about 54 tokens; SKILL.md has 697 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~54
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from greenpau/caddy-security at commit a48553d, republished under its Apache-2.0 licence (© greenpau). 697 words, ~1,578 tokens.

Download SKILL.mdSave it as .claude/skills/configuration-sso-app/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
configuration-sso-app
description
Configure portal-provided SAML SSO apps, AWS role names, metadata, certificates, and PKCS8 keys. Use for sso provider blocks and their runtime limits; external SAML login providers are separate.

Configuration SSO App

Purpose

Use this skill to configure the SSO app feature, expressed in Caddyfile as sso provider <name>. This is the Single Sign-On with SAML app path, not OAuth login provider setup.

External OAuth/OIDC login belongs to configuration-oauth-providers. External saml identity provider <name> login belongs to configuration-saml-providers. Those are separate configurations, not prerequisites for an SSO app change.

The Caddyfile syntax is authoritative in caddyfile_sso_provider.go; the provisioning behavior is authoritative in the selected go-authcrunch module, especially pkg/sso/config.go, pkg/sso/provider.go, pkg/sso/request.go, pkg/sso/metadata.go, and pkg/authn/handle_http_apps_sso.go.

Shape

caddyfile
{
	security {
		local identity store localdb {
			realm local
			path assets/config/users.json
		}

		sso provider aws {
			entity_id caddy-authp-idp
			driver aws
			cert assets/sso/authp_saml.crt
			private key assets/sso/authp_saml.key
			location https://example.com/auth/apps/sso/aws
		}

		authentication portal myportal {
			enable identity store localdb
			enable sso provider aws
		}
	}
}

The provider name must be unique and must match the portal's enable sso provider <name> value.

Supported Fields

The current Caddyfile parser supports only these lines:

  • disabled
  • entity_id <name> mapped to authcrunch entity_id
  • driver aws mapped to authcrunch driver
  • cert <path> mapped to authcrunch cert_path
  • private key <path> mapped to authcrunch private_key_path
  • location <url> appended to authcrunch locations

Although driver is syntactically optional in the Caddyfile parser, generate driver aws. go-authcrunch rejects an empty driver and currently supports only aws.

At least one location <url> is required by the Caddyfile parser, even for a disabled provider. Multiple locations are allowed and become SAML SingleSignOnService entries in generated metadata. Authcrunch embeds each configured location verbatim, so use the externally reachable SSO POST URL, including any portal base-path prefix such as /auth.

The certificate file must be PEM with block type CERTIFICATE. The private key file must be PEM with block type PRIVATE KEY and parse as a PKCS8 private key. Do not use RSA PRIVATE KEY examples unless the underlying authcrunch parser changes.

If a provider is marked disabled, it is not added to the authcrunch configuration. Do not enable a disabled provider from a portal; authcrunch validation expects enabled portal SSO provider names to have matching provider configuration.

Portal URLs And Roles

The auth portal recognizes SSO app endpoints by the /apps/sso/<provider> path inside the portal route. With the common /auth portal base path used by this repo's configs and fixtures, external URLs are usually under /auth/apps/sso/<provider>:

text
/auth/apps/sso/aws
/auth/apps/sso/aws/metadata.xml
/auth/apps/sso/aws/assume/<account_id>/<role_name>

If the authenticate route is mounted at a different base path, keep that prefix in the external URL. go-authcrunch/pkg/sso/request.go parses the first /apps/sso/ segment in the request path, so /custom/apps/sso/aws and /auth/apps/sso/aws both map to provider aws.

Use <base-path>/apps/sso/<provider>/metadata.xml when a SAML service needs generated IdP metadata. The configured location values are embedded in that metadata as HTTP-POST SSO service locations.

Current authcrunch handling requires an authenticated portal session before serving the SSO menu, metadata, or assume-role endpoint. Despite the metadata handler comment, no admin role check is implemented for metadata in handle_http_apps_sso.go.

For AWS role selection, user roles must use this shape:

text
aws/<account_id>/<role_name>

For example, a local user might have:

caddyfile
roles authp/user aws/123456789012/Administrator

The selected authcrunch assume-role handler returns a placeholder response for <base-path>/apps/sso/<provider>/assume/.... Do not promise complete AWS federation behavior from configuration alone unless the handler implementation changes.

Show full SKILL.md (229 more words)Show less

Review Checklist

Check generated SSO app entries against these code-backed constraints:

  • Use sso provider <name>, not oauth identity provider <name>.
  • Keep SSO provider names unique; authcrunch server provisioning rejects duplicates.
  • Include entity_id, driver aws, cert, private key, and at least one location.
  • cert points to a PEM certificate file.
  • private key points to a PKCS8 PEM private key file.
  • The location URL is the service endpoint that should appear in SAML metadata, including the portal base path, usually /auth/apps/sso/<provider> on the auth portal host.
  • The portal enables the same provider name with enable sso provider <name>.
  • The portal has at least one identity store or login identity provider; SSO app providers do not count as authentication backends.
  • Any AWS roles assigned to users use aws/<account_id>/<role_name>.
  • No unsupported provider fields are generated.

Fixtures

Use these examples:

  • caddyfile_sso_provider.go for accepted Caddyfile subdirectives.
  • caddyfile_sso_provider_test.go for parser examples and expected adapted JSON.
  • go-authcrunch/pkg/sso/config_test.go for authcrunch validation behavior.
  • go-authcrunch/pkg/sso/request_test.go for SSO URL parsing behavior.

The Caddy parser tests establish field mapping, not certificate loading or an AWS federation journey. This checkout has no app-side SAML SSO E2E. A local runtime check should verify that readable certificate/PKCS8 inputs produce the configured metadata URLs, unauthenticated requests redirect to login, and an authenticated session can obtain metadata. Report the assume-role placeholder as unavailable federation behavior; a successful HTTP 200 containing ASSUME ROLE is not an AWS login.

© greenpau, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .codex/skills/configuration-sso-app of greenpau/caddy-security.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit a48553d

Compare with similar skills

Configuration Sso App next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Configuration Sso App compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Configuration Sso App this skillgreenpau/caddy-security2.3k—~1.6kAutomated safety check: PassApache-2.0
Cognitoitsmostafa/aws-agent-skills1.2k1 repos~2.3kAutomated safety check: PassMIT
Interactive Loginyc-software/qm15k—~635Automated safety check: PassMIT
Atmos Authcloudposse/atmos1.4k—~4.2kAutomated safety check: PassApache-2.0
Managing Cloud Identity With Oktamukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: PassApache-2.0
Iam Auditbriiirussell/cybersecurity-skills413—~3.1kAutomated safety check: NotesMIT

Similar skills

  • Cognito

    itsmostafa/aws-agent-skills

    AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.3k tokens
    Backend & APIsAuto-check passed
  • Interactive Login

    yc-software/qm

    Log a CLI in with a browser/device-code flow (aws sso, gh, glab, gcloud, …) and save the result to the keychain so later commands can request it through execute.credentials.

    15k GitHub stars~635 tokensUpdated today
    Backend & APIsAuto-check passed
  • Atmos Auth

    cloudposse/atmos

    Authentication and identity management: providers (SSO/SAML/OIDC/GCP/Atmos Pro), identities, keyring, identity chaining, login/exec/shell/console, and github/sts for private GitHub access

    1.4k GitHub stars~4.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • Managing Cloud Identity With Okta

    mukul975/Anthropic-Cybersecurity-Skills

    Implement Okta as a centralized cloud identity provider: configure SSO with AWS, Azure, and GCP, deploy phishing-resistant MFA with Okta FastPass, automate user provisioning/deprovisioning, and…

    34k GitHub stars~3.1k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Iam Audit

    briiirussell/cybersecurity-skills

    Audit, design, and migrate Identity and Access Management — cloud provider IAM (AWS, GCP, Azure), identity providers (Okta, Entra ID / Azure AD, Auth0, Google Workspace), application authorization…

    413 GitHub stars~3.1k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes
  • AWS Auth

    aws/agent-toolkit-for-aws

    Official

    Adds user authentication to web and mobile apps with Amazon Cognito (user pools and identity pools) and the AWS Amplify client auth libraries.

    2.8k GitHub stars~3.4k tokensUpdated yesterday
    Backend & APIsAuto-check passed

More from greenpau/caddy-security

All 29 skills in this repo
  • Authentication Portal API

    greenpau/caddy-security

    Build or troubleshoot portal JSON/native login clients, refresh, profile and admin APIs, and public JWKS.

    2.3k GitHub stars~2.9k tokensUpdated 5 days ago
    Auto-check passed
  • Coding Directives

    greenpau/caddy-security

    Implement or review caddy-security Go code, Caddy modules, parsers, lifecycle, and HTTP delegation.

    2.3k GitHub stars~4.1k tokensUpdated 5 days ago
    Auto-check passed
  • Configuration

    greenpau/caddy-security

    Build or review caddy-security Caddyfiles and select focused configuration skills.

    2.3k GitHub stars~2.6k tokensUpdated 5 days ago
    Auto-check passed
  • Configuration Crypto

    greenpau/caddy-security

    Configure portal/policy JWT keys, token names and lifetimes, key loading and generation, public-key discovery, and System API encryption keys.

    2.3k GitHub stars~3.5k tokensUpdated 5 days ago
    Auto-check passed
  • Configuration HTTP Integrations

    greenpau/caddy-security

    Mount authenticate and authorize handlers, separate portal and protected routes, align auth URLs, and preserve trusted proxy metadata.

    2.3k GitHub stars~3.2k tokensUpdated 5 days ago
    Auto-check passed
  • Configuration State

    greenpau/caddy-security

    Configure durable AuthCrunch runtime state, exclusive storage ownership, stop/start persistence, reload rejection, and recovery.

    2.3k GitHub stars~1.6k tokensUpdated 5 days ago
    Auto-check passed

Categories

Questions about Configuration Sso App

What does Configuration Sso App do?

Configure portal-provided SAML SSO apps, AWS role names, metadata, certificates, and PKCS8 keys. Configuration Sso App is an agent skill from greenpau/caddy-security. Configure portal-provided SAML SSO apps, AWS role names, metadata, certificates, and PKCS8 keys.

When should I use Configuration Sso App?

Configuration Sso App fits situations like: sso provider blocks and their runtime limits; external SAML login providers are separate.

How do I install Configuration Sso App in Claude Code?

Run `npx skills add greenpau/caddy-security --skill configuration-sso-app -a claude-code`. Or copy the skill folder (.codex/skills/configuration-sso-app in greenpau/caddy-security) into .claude/skills/configuration-sso-app in your project. Claude Code loads it when a task matches its description.

How do I install Configuration Sso App in Codex?

Run `npx skills add greenpau/caddy-security --skill configuration-sso-app -a codex`. Or copy the skill folder (.codex/skills/configuration-sso-app in greenpau/caddy-security) into .agents/skills/configuration-sso-app in your project. Codex loads it when a task matches its description.

Can I use Configuration Sso App in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add greenpau/caddy-security --skill configuration-sso-app -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/configuration-sso-app, .gemini/skills/configuration-sso-app, .github/skills/configuration-sso-app and .opencode/skills/configuration-sso-app in your project.

What does Configuration Sso App need to run?

SKILL.md names no scripts, command-line tools or credentials: Configuration Sso App is instructions for the agent only.

Does Configuration Sso App access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Configuration Sso App safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Configuration Sso App use?

Configuration Sso App is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Configuration Sso App use?

About 1.6k tokens (SKILL.md is roughly 6.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Configuration Sso App?

Skills that share tags, products or a category with Configuration Sso App: Cognito (itsmostafa/aws-agent-skills, 1.2k stars), Interactive Login (yc-software/qm, 15k stars), Atmos Auth (cloudposse/atmos, 1.4k stars) and Managing Cloud Identity With Okta (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Configuration Sso App?

greenpau (a GitHub user) maintains it in greenpau/caddy-security, which has 2,252 GitHub stars. The repository holds 29 skills in this directory. The repository was last updated on October 5, 2026.

Source: greenpau/caddy-security on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.