GitHub OAuth Nango Integration
AgentWorkforce/relay
A skill your agent uses when implementing GitHub OAuth + GitHub App authentication with Nango - provides two-connection pattern for user login and repo access with webhook handling
A skill your agent uses when a val's HTTP endpoints should not be open to the whole internet — limiting an app to a team, understanding why an endpoint redirects to a login page, letting a webhook…
$ npx skills add hashgraph-online/awesome-codex-plugins --skill restricted-access -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install hashgraph-online/awesome-codex-plugins restricted-access --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/hashgraph-online/awesome-codex-plugins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/val-town/plugins/skills/restricted-access .claude/skills/restricted-access && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "restricted-access" agent skill from https://github.com/hashgraph-online/awesome-codex-plugins/tree/main/plugins/val-town/plugins/skills/restricted-access into .claude/skills/restricted-access/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "restricted-access", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/hashgraph-online/awesome-codex-plugins/tree/main/plugins/val-town/plugins/skills/restricted-accessType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add hashgraph-online/awesome-codex-plugins --skill restricted-access -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install hashgraph-online/awesome-codex-plugins restricted-access --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hashgraph-online/awesome-codex-plugins.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/val-town/plugins/skills/restricted-access .agents/skills/restricted-access && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "restricted-access" agent skill from https://github.com/hashgraph-online/awesome-codex-plugins/tree/main/plugins/val-town/plugins/skills/restricted-access into .agents/skills/restricted-access/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "restricted-access", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add hashgraph-online/awesome-codex-plugins --skill restricted-access -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install hashgraph-online/awesome-codex-plugins restricted-access --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hashgraph-online/awesome-codex-plugins.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/val-town/plugins/skills/restricted-access .cursor/skills/restricted-access && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "restricted-access" agent skill from https://github.com/hashgraph-online/awesome-codex-plugins/tree/main/plugins/val-town/plugins/skills/restricted-access into .cursor/skills/restricted-access/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "restricted-access", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/hashgraph-online/awesome-codex-plugins.git --path plugins/val-town/plugins/skills/restricted-access--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add hashgraph-online/awesome-codex-plugins --skill restricted-access -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install hashgraph-online/awesome-codex-plugins restricted-access --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hashgraph-online/awesome-codex-plugins.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/val-town/plugins/skills/restricted-access .gemini/skills/restricted-access && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "restricted-access" agent skill from https://github.com/hashgraph-online/awesome-codex-plugins/tree/main/plugins/val-town/plugins/skills/restricted-access into .gemini/skills/restricted-access/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "restricted-access", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install hashgraph-online/awesome-codex-plugins restricted-accessInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add hashgraph-online/awesome-codex-plugins --skill restricted-access -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/hashgraph-online/awesome-codex-plugins.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/val-town/plugins/skills/restricted-access .github/skills/restricted-access && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "restricted-access" agent skill from https://github.com/hashgraph-online/awesome-codex-plugins/tree/main/plugins/val-town/plugins/skills/restricted-access into .github/skills/restricted-access/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "restricted-access", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add hashgraph-online/awesome-codex-plugins --skill restricted-access -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install hashgraph-online/awesome-codex-plugins restricted-access --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hashgraph-online/awesome-codex-plugins.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/val-town/plugins/skills/restricted-access .opencode/skills/restricted-access && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "restricted-access" agent skill from https://github.com/hashgraph-online/awesome-codex-plugins/tree/main/plugins/val-town/plugins/skills/restricted-access into .opencode/skills/restricted-access/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "restricted-access", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
restricted-accessA skill your agent uses when a val's HTTP endpoints should not be open to the whole internet — limiting an app to a team, understanding why an endpoint redirects to a login page, letting a webhook…
Restricted Access is an agent skill from hashgraph-online/awesome-codex-plugins. Use when a val's HTTP endpoints should not be open to the whole internet — limiting an app to a team, understanding why an endpoint redirects to a login page, letting a webhook through, or identifying which Val Town user is viewing an app. Covers app access (httpPrivacy), org grants, bypass tokens for automation, and the X-Val-Town-User identity header. For building your own login flow inside a val, see the oauth skill instead.
Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering Webhooks, Authentication and OAuth and OpenID Connect. The repository describes itself as: A curated list of awesome OpenAI Codex / ChatGPT plugins, skills, and resources. The 1 Codex Marketplace. See live plugins at: https://hol.org/plugins/best-codex-plugins. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit 78497e5. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript).
From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
api.val.townFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Restricted Access loads about 1.8k tokens when it runs. Until then it costs about 114 tokens; SKILL.md has 829 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from hashgraph-online/awesome-codex-plugins at commit 78497e5, republished under its Apache-2.0 licence (© hashgraph-online). 829 words, ~1,754 tokens.
.claude/skills/restricted-access/SKILL.md (or your agent's skills folder).A val has two independent access settings. Changing one does not change the other:
privacy: public / unlisted / private) — who can read the source on val.town.httpPrivacy: public / restricted) — who can call the val's HTTP endpoints.A val can have private code and a wide-open endpoint, or public code and a locked-down endpoint. update_val's privacy field only moves the first one; app access is changed with set_http_privacy.
Restricted app access is available to organizations that have the feature enabled. Vals created in such an org may default to restricted — always read httpPrivacy off a get_val_detail, list_vals, create_val, or remix_val response rather than assuming a new val's URL is open.
Two different things both sound like "make my app require a login":
std/oauth (see the oauth skill) runs inside your val: you wrap your handler, and anyone with a Val Town account can log in. You control the session and can build per-user features.Pick restricted access for an internal tool that only your team should reach. Pick std/oauth when any Val Town user may sign in and the app needs its own notion of a logged-in user.
Don't stack them by accident. Adding oauthMiddleware to an already-restricted val means the visitor authenticates twice — once at the gate, once in your code. If a restricted val needs to know who is viewing, use the identity header below instead of adding OAuth.
Access is granted to organizations, not individual people. A viewer gets in when the val has a grant to an org and that viewer is a member of it. Removing either one revokes access on the very next request — nothing is cached for the length of a session.
Grants come from:
add_allowed_user grants an org, list_allowed_users shows current grants, remove_allowed_user revokes one.list_allowed_users alongside direct grants.An unauthenticated request does not reach the val. The platform answers with a 302 redirect to a Val Town login or authorization page. This is the single most common source of confusion when debugging a restricted val:
fetch_val_endpoint reports a redirect it won't follow.curl shows a 302 to val.town instead of your response.403 explaining they need access to their organization.None of these mean the val's code is broken. Check httpPrivacy first — if it's restricted, the gate is doing its job. Make the val public with set_http_privacy, grant the caller's org, or use a bypass token.
Machines can't complete a login redirect, so a restricted val that receives webhooks (Stripe, GitHub, a cron job in another val) needs a bypass token — a secret scoped to that one val.
Create it with create_bypass_token; the secret is shown once and cannot be retrieved again. Manage tokens with list_bypass_tokens and revoke_bypass_token.
Present it either way:
// Header (preferred — keeps the secret out of logs and referrers)
await fetch(url, { headers: { "X-Val-Town-Access": Deno.env.get("MY_BYPASS_TOKEN")! } });
// Query param (for services that only accept a URL, e.g. some webhook configs)
await fetch(`${url}?val_town_access=${Deno.env.get("MY_BYPASS_TOKEN")}`);The platform strips the header and the query param before your handler runs, so your code never sees them. A bypass-token request carries no viewer identity — it is an anonymous machine caller.
For a human viewer who came in through the gate, the platform forwards a short-lived signed X-Val-Town-User header. It is not the identity itself — exchange it for the viewer's profile using the val's own API token, which Val Town injects as the valtown environment variable:
const IDENTITY_HEADER = "X-Val-Town-User";
/** Returns the viewer's public profile, or null when there isn't one. */
async function getViewer(req: Request) {
const signed = req.headers.get(IDENTITY_HEADER);
if (!signed) return null;
const res = await fetch("https://api.val.town/v3/val/viewer", {
headers: {
Authorization: `Bearer ${Deno.env.get("valtown")}`,
[IDENTITY_HEADER]: signed,
},
});
if (!res.ok) return null;
// { id, username, type, bio, profileImageUrl, url, links }
return await res.json();
}Rules that matter:
!-assert it or index into a null result.The transport above (X-Val-Town-User plus the /v3/val/viewer exchange) is how this works today and may change; the three rules hold regardless.
| Task | Tool |
|---|---|
| Check the current setting | get_val_detail (httpPrivacy field) |
| Make an endpoint public or restricted | set_http_privacy |
| See who has access | list_allowed_users |
| Grant / revoke an org | add_allowed_user / remove_allowed_user |
| Create / list / revoke automation secrets | create_bypass_token / list_bypass_tokens / revoke_bypass_token |
Restricted vals can only be iframed by val.town, so an embed of one on an external site will be blocked by the browser regardless of who's logged in.
© hashgraph-online, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in plugins/val-town/plugins/skills/restricted-access of hashgraph-online/awesome-codex-plugins.
Open the folder on GitHubat commit 78497e5
Restricted Access next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Restricted Access this skillhashgraph-online/awesome-codex-plugins | 1.2k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | |
| GitHub OAuth Nango IntegrationAgentWorkforce/relay | 866 | 1 repos | ~3.4k | Automated safety check: Pass | Apache-2.0 | |
| Frappe Core APIImpertio-Studio/Frappe_Claude_Skill_Package | 187 | 1 repos | ~3.2k | Automated safety check: Pass | MIT | |
| Frappe Errors APIImpertio-Studio/Frappe_Claude_Skill_Package | 187 | 1 repos | ~4k | Automated safety check: Pass | MIT | |
| Web Ssrfs0ld13rr/pentestcode | 827 | — | ~660 | Automated safety check: Warn | MIT | |
| Shopify APIMicrock/ordinary-claude-skills | 403 | 1 repos | ~4.3k | Automated safety check: Pass | Custom licence |
AgentWorkforce/relay
A skill your agent uses when implementing GitHub OAuth + GitHub App authentication with Nango - provides two-connection pattern for user login and repo access with webhook handling
Impertio-Studio/Frappe_Claude_Skill_Package
A skill your agent uses when building ERPNext/Frappe API integrations (v14/v15/v16) including REST API, RPC API, authentication, webhooks, and rate limiting.
Impertio-Studio/Frappe_Claude_Skill_Package
A skill your agent uses when debugging or handling API errors in Frappe/ERPNext v14/v15/v16.
s0ld13rr/pentestcode
Server-Side Request Forgery detection→internal-access→proof for web apps.
Microck/ordinary-claude-skills
Complete API integration guide for Shopify including GraphQL Admin API, REST Admin API, Storefront API, Ajax API, OAuth authentication, rate limiting, and webhooks.
aiskillstore/marketplace
Expert patterns for HubSpot CRM integration including OAuth authentication, CRM objects, associations, batch operations, webhooks, and custom objects.
hashgraph-online/awesome-codex-plugins
Create original anime-style reaction stickers as looping GIFs and MP4 previews, using generated character pose sheets and timed key poses.
hashgraph-online/awesome-codex-plugins
Manage and query Calibre libraries with the calibredb CLI (local paths or Calibre Content server URLs).
hashgraph-online/awesome-codex-plugins
A skill your agent uses when adding, changing, testing, or debugging Rust HTTP APIs and services, especially when Codex needs black-box integration tests, random-port app startup, real database test…
hashgraph-online/awesome-codex-plugins
Make a studio's game look like something at build time — a cover from a real frame of the game (free), painted covers, backdrops, textures and character plates from image models through the…
hashgraph-online/awesome-codex-plugins
Balance game difficulty, resources, rewards, probability, progression, economies, and dominant strategies.
hashgraph-online/awesome-codex-plugins
Analyze nonfiction manuscripts for reader engagement signals, including heading-level word counts, slow starts, long slogs, weak takeaway titles, value pacing, beta-reader comment dropoff, and…
Categories
A skill your agent uses when a val's HTTP endpoints should not be open to the whole internet — limiting an app to a team, understanding why an endpoint redirects to a login page, letting a webhook…. Restricted Access is an agent skill from hashgraph-online/awesome-codex-plugins. Use when a val's HTTP endpoints should not be open to the whole internet — limiting an app to a team, understanding why an endpoint redirects to a login page, letting a webhook through, or identifying which Val Town user is viewing an app.
Restricted Access fits situations like: A vals HTTP endpoints should not be open to the whole internet — limiting an app to a team; understanding why an endpoint redirects to a login page; letting a webhook through; identifying which Val Town user is viewing an app.
Run `npx skills add hashgraph-online/awesome-codex-plugins --skill restricted-access -a claude-code`. Or copy the skill folder (plugins/val-town/plugins/skills/restricted-access in hashgraph-online/awesome-codex-plugins) into .claude/skills/restricted-access in your project. Claude Code loads it when a task matches its description.
Run `npx skills add hashgraph-online/awesome-codex-plugins --skill restricted-access -a codex`. Or copy the skill folder (plugins/val-town/plugins/skills/restricted-access in hashgraph-online/awesome-codex-plugins) into .agents/skills/restricted-access in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hashgraph-online/awesome-codex-plugins --skill restricted-access -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/restricted-access, .gemini/skills/restricted-access, .github/skills/restricted-access and .opencode/skills/restricted-access in your project.
SKILL.md names no scripts, command-line tools or credentials: Restricted Access is instructions for the agent only. Our summary lists: A credential in MY_BYPASS_TOKEN.
SKILL.md names 1 domain. In commands or code: api.val.town; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Restricted Access is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.8k tokens (SKILL.md is roughly 7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Restricted Access: GitHub OAuth Nango Integration (AgentWorkforce/relay, 866 stars), Frappe Core API (Impertio-Studio/Frappe_Claude_Skill_Package, 187 stars), Frappe Errors API (Impertio-Studio/Frappe_Claude_Skill_Package, 187 stars) and Web Ssrf (s0ld13rr/pentestcode, 827 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
hashgraph-online (a GitHub organization) maintains it in hashgraph-online/awesome-codex-plugins, which has 1,242 GitHub stars. The repository holds 686 skills in this directory. The repository was last updated on October 8, 2026.
Source: hashgraph-online/awesome-codex-plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.