Cognito
itsmostafa/aws-agent-skills
AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.
Configure portal-provided SAML SSO apps, AWS role names, metadata, certificates, and PKCS8 keys.
$ npx skills add greenpau/caddy-security --skill configuration-sso-app -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install greenpau/caddy-security configuration-sso-app --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/configuration-sso-app .claude/skills/configuration-sso-app && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "configuration-sso-app" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-sso-app into .claude/skills/configuration-sso-app/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuration-sso-app", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-sso-appType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add greenpau/caddy-security --skill configuration-sso-app -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install greenpau/caddy-security configuration-sso-app --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.codex/skills/configuration-sso-app .agents/skills/configuration-sso-app && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "configuration-sso-app" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-sso-app into .agents/skills/configuration-sso-app/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuration-sso-app", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add greenpau/caddy-security --skill configuration-sso-app -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install greenpau/caddy-security configuration-sso-app --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.codex/skills/configuration-sso-app .cursor/skills/configuration-sso-app && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "configuration-sso-app" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-sso-app into .cursor/skills/configuration-sso-app/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuration-sso-app", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/greenpau/caddy-security.git --path .codex/skills/configuration-sso-app--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add greenpau/caddy-security --skill configuration-sso-app -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install greenpau/caddy-security configuration-sso-app --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.codex/skills/configuration-sso-app .gemini/skills/configuration-sso-app && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "configuration-sso-app" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-sso-app into .gemini/skills/configuration-sso-app/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuration-sso-app", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install greenpau/caddy-security configuration-sso-appInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add greenpau/caddy-security --skill configuration-sso-app -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .github/skills && cp -r skills-src/.codex/skills/configuration-sso-app .github/skills/configuration-sso-app && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "configuration-sso-app" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-sso-app into .github/skills/configuration-sso-app/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuration-sso-app", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add greenpau/caddy-security --skill configuration-sso-app -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install greenpau/caddy-security configuration-sso-app --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.codex/skills/configuration-sso-app .opencode/skills/configuration-sso-app && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "configuration-sso-app" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-sso-app into .opencode/skills/configuration-sso-app/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuration-sso-app", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
configuration-sso-appConfigure portal-provided SAML SSO apps, AWS role names, metadata, certificates, and PKCS8 keys.
Configuration Sso App is an agent skill from greenpau/caddy-security. Configure portal-provided SAML SSO apps, AWS role names, metadata, certificates, and PKCS8 keys. Use for sso provider blocks and their runtime limits; external SAML login providers are separate.
Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).
It sits in Backend & APIs, covering Authentication. It works with Amazon Web Services. The repository describes itself as: 🔐 Authentication, Authorization, and Accounting (AAA) App and Plugin for Caddy v2. 💎 Implements Form-Based, Basic, Local, LDAP, OpenID Connect, OAuth 2.0 (Github, Google…. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit a48553d. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are caddyfile).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Configuration Sso App loads about 1.6k tokens when it runs. Until then it costs about 54 tokens; SKILL.md has 697 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from greenpau/caddy-security at commit a48553d, republished under its Apache-2.0 licence (© greenpau). 697 words, ~1,578 tokens.
.claude/skills/configuration-sso-app/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Use this skill to configure the SSO app feature, expressed in Caddyfile as
sso provider <name>. This is the Single Sign-On with SAML app path, not OAuth
login provider setup.
External OAuth/OIDC login belongs to
configuration-oauth-providers.
External saml identity provider <name> login belongs to
configuration-saml-providers.
Those are separate configurations, not prerequisites for an SSO app change.
The Caddyfile syntax is authoritative in caddyfile_sso_provider.go; the
provisioning behavior is authoritative in the selected go-authcrunch module,
especially pkg/sso/config.go, pkg/sso/provider.go, pkg/sso/request.go,
pkg/sso/metadata.go, and pkg/authn/handle_http_apps_sso.go.
{
security {
local identity store localdb {
realm local
path assets/config/users.json
}
sso provider aws {
entity_id caddy-authp-idp
driver aws
cert assets/sso/authp_saml.crt
private key assets/sso/authp_saml.key
location https://example.com/auth/apps/sso/aws
}
authentication portal myportal {
enable identity store localdb
enable sso provider aws
}
}
}The provider name must be unique and must match the portal's
enable sso provider <name> value.
The current Caddyfile parser supports only these lines:
disabledentity_id <name> mapped to authcrunch entity_iddriver aws mapped to authcrunch drivercert <path> mapped to authcrunch cert_pathprivate key <path> mapped to authcrunch private_key_pathlocation <url> appended to authcrunch locationsAlthough driver is syntactically optional in the Caddyfile parser, generate
driver aws. go-authcrunch rejects an empty driver and currently supports
only aws.
At least one location <url> is required by the Caddyfile parser, even for a
disabled provider. Multiple locations are allowed and become SAML
SingleSignOnService entries in generated metadata. Authcrunch embeds each
configured location verbatim, so use the externally reachable SSO POST URL,
including any portal base-path prefix such as /auth.
The certificate file must be PEM with block type CERTIFICATE. The private key
file must be PEM with block type PRIVATE KEY and parse as a PKCS8 private key.
Do not use RSA PRIVATE KEY examples unless the underlying authcrunch parser
changes.
If a provider is marked disabled, it is not added to the authcrunch
configuration. Do not enable a disabled provider from a portal; authcrunch
validation expects enabled portal SSO provider names to have matching provider
configuration.
The auth portal recognizes SSO app endpoints by the /apps/sso/<provider> path
inside the portal route. With the common /auth portal base path used by this
repo's configs and fixtures, external URLs are usually under
/auth/apps/sso/<provider>:
/auth/apps/sso/aws
/auth/apps/sso/aws/metadata.xml
/auth/apps/sso/aws/assume/<account_id>/<role_name>If the authenticate route is mounted at a different base path, keep that prefix
in the external URL. go-authcrunch/pkg/sso/request.go parses the first
/apps/sso/ segment in the request path, so /custom/apps/sso/aws and
/auth/apps/sso/aws both map to provider aws.
Use <base-path>/apps/sso/<provider>/metadata.xml when a SAML service needs
generated IdP metadata. The configured location values are embedded in that
metadata as HTTP-POST SSO service locations.
Current authcrunch handling requires an authenticated portal session before
serving the SSO menu, metadata, or assume-role endpoint. Despite the metadata
handler comment, no admin role check is implemented for metadata in
handle_http_apps_sso.go.
For AWS role selection, user roles must use this shape:
aws/<account_id>/<role_name>For example, a local user might have:
roles authp/user aws/123456789012/AdministratorThe selected authcrunch assume-role handler returns a placeholder response
for <base-path>/apps/sso/<provider>/assume/.... Do not promise complete AWS
federation behavior from configuration alone unless the handler implementation
changes.
Check generated SSO app entries against these code-backed constraints:
sso provider <name>, not oauth identity provider <name>.entity_id, driver aws, cert, private key, and at least one
location.cert points to a PEM certificate file.private key points to a PKCS8 PEM private key file.location URL is the service endpoint that should appear in SAML
metadata, including the portal base path, usually
/auth/apps/sso/<provider> on the auth portal host.enable sso provider <name>.aws/<account_id>/<role_name>.Use these examples:
caddyfile_sso_provider.go for accepted Caddyfile subdirectives.caddyfile_sso_provider_test.go for parser examples and expected adapted
JSON.go-authcrunch/pkg/sso/config_test.go for authcrunch validation behavior.go-authcrunch/pkg/sso/request_test.go for SSO URL parsing behavior.The Caddy parser tests establish field mapping, not certificate loading or an
AWS federation journey. This checkout has no app-side SAML SSO E2E. A local
runtime check should verify that readable certificate/PKCS8 inputs produce the
configured metadata URLs, unauthenticated requests redirect to login, and an
authenticated session can obtain metadata. Report the assume-role placeholder
as unavailable federation behavior; a successful HTTP 200 containing
ASSUME ROLE is not an AWS login.
© greenpau, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in .codex/skills/configuration-sso-app of greenpau/caddy-security.
Open the folder on GitHubat commit a48553d
Configuration Sso App next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Configuration Sso App this skillgreenpau/caddy-security | 2.3k | — | ~1.6k | Automated safety check: Pass | Apache-2.0 | |
| Cognitoitsmostafa/aws-agent-skills | 1.2k | 1 repos | ~2.3k | Automated safety check: Pass | MIT | |
| Interactive Loginyc-software/qm | 15k | — | ~635 | Automated safety check: Pass | MIT | |
| Atmos Authcloudposse/atmos | 1.4k | — | ~4.2k | Automated safety check: Pass | Apache-2.0 | |
| Managing Cloud Identity With Oktamukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | |
| Iam Auditbriiirussell/cybersecurity-skills | 413 | — | ~3.1k | Automated safety check: Notes | MIT |
itsmostafa/aws-agent-skills
AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.
yc-software/qm
Log a CLI in with a browser/device-code flow (aws sso, gh, glab, gcloud, …) and save the result to the keychain so later commands can request it through execute.credentials.
cloudposse/atmos
Authentication and identity management: providers (SSO/SAML/OIDC/GCP/Atmos Pro), identities, keyring, identity chaining, login/exec/shell/console, and github/sts for private GitHub access
mukul975/Anthropic-Cybersecurity-Skills
Implement Okta as a centralized cloud identity provider: configure SSO with AWS, Azure, and GCP, deploy phishing-resistant MFA with Okta FastPass, automate user provisioning/deprovisioning, and…
briiirussell/cybersecurity-skills
Audit, design, and migrate Identity and Access Management — cloud provider IAM (AWS, GCP, Azure), identity providers (Okta, Entra ID / Azure AD, Auth0, Google Workspace), application authorization…
aws/agent-toolkit-for-aws
Adds user authentication to web and mobile apps with Amazon Cognito (user pools and identity pools) and the AWS Amplify client auth libraries.
greenpau/caddy-security
Build or troubleshoot portal JSON/native login clients, refresh, profile and admin APIs, and public JWKS.
greenpau/caddy-security
Implement or review caddy-security Go code, Caddy modules, parsers, lifecycle, and HTTP delegation.
greenpau/caddy-security
Build or review caddy-security Caddyfiles and select focused configuration skills.
greenpau/caddy-security
Configure portal/policy JWT keys, token names and lifetimes, key loading and generation, public-key discovery, and System API encryption keys.
greenpau/caddy-security
Mount authenticate and authorize handlers, separate portal and protected routes, align auth URLs, and preserve trusted proxy metadata.
greenpau/caddy-security
Configure durable AuthCrunch runtime state, exclusive storage ownership, stop/start persistence, reload rejection, and recovery.
Works with
Categories
Configure portal-provided SAML SSO apps, AWS role names, metadata, certificates, and PKCS8 keys. Configuration Sso App is an agent skill from greenpau/caddy-security. Configure portal-provided SAML SSO apps, AWS role names, metadata, certificates, and PKCS8 keys.
Configuration Sso App fits situations like: sso provider blocks and their runtime limits; external SAML login providers are separate.
Run `npx skills add greenpau/caddy-security --skill configuration-sso-app -a claude-code`. Or copy the skill folder (.codex/skills/configuration-sso-app in greenpau/caddy-security) into .claude/skills/configuration-sso-app in your project. Claude Code loads it when a task matches its description.
Run `npx skills add greenpau/caddy-security --skill configuration-sso-app -a codex`. Or copy the skill folder (.codex/skills/configuration-sso-app in greenpau/caddy-security) into .agents/skills/configuration-sso-app in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add greenpau/caddy-security --skill configuration-sso-app -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/configuration-sso-app, .gemini/skills/configuration-sso-app, .github/skills/configuration-sso-app and .opencode/skills/configuration-sso-app in your project.
SKILL.md names no scripts, command-line tools or credentials: Configuration Sso App is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Configuration Sso App is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.6k tokens (SKILL.md is roughly 6.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Configuration Sso App: Cognito (itsmostafa/aws-agent-skills, 1.2k stars), Interactive Login (yc-software/qm, 15k stars), Atmos Auth (cloudposse/atmos, 1.4k stars) and Managing Cloud Identity With Okta (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
greenpau (a GitHub user) maintains it in greenpau/caddy-security, which has 2,252 GitHub stars. The repository holds 29 skills in this directory. The repository was last updated on October 5, 2026.
Source: greenpau/caddy-security on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.