Authenticate production Podium integrations and survive the auth-side failures — OAuth2 access-token expiry storms, refresh-token decay after 90 days of non-use, scope drift on re-grant, secret…

MITAuto-check: notesBackend & APIs

Install Podium Auth

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill podium-auth -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace podium-auth --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/podium-auth .claude/skills/podium-auth && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
podium-auth
GitHub stars
2.8k
Token cost
~3.7k tokens
SKILL.md length
1,032 words
Files
11 (incl. scripts, references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Authenticate production Podium integrations and survive the auth-side failures — OAuth2 access-token expiry storms, refresh-token decay after 90 days of non-use, scope drift on re-grant, secret…

  • Works in 6 steps: Token-cache pattern (neutralizes expiry… → Refresh-token rotation persistence… → 90-day decay monitor (neutralizes… → …
  • Hardening token caching
  • SKILL.md covers Overview, Prerequisites, Instructions and Error Handling, plus 3 more sections
  • Runs Python scripts from its folder; calls git, curl and jq; reaches accounts.podium.com and api.podium.com; needs PODIUM_CLIENT_SECRET

What it does

Podium Auth is an agent skill from jeremylongshore/tons-of-skills-marketplace. Authenticate production Podium integrations and survive the auth-side failures — OAuth2 access-token expiry storms, refresh-token decay after 90 days of non-use, scope drift on re-grant, secret rotation without downtime, multi-tenant token routing, leakage in commits. Use when hardening token caching, building a refresh-token decay monitor, rotating Podium client credentials, or recovering from 401/403 auth cascades. Trigger with "podium auth", "podium oauth", "podium token refresh", "podium scope drift", "podium…

Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 13 other files, including scripts and reference files (for example `ARD.md`, `PRD.md` and `config/settings.yaml`). Compatibility notes: Designed for Claude Code

It sits in Backend & APIs, covering OAuth and OpenID Connect, Multi-tenancy and Secrets management. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Hardening token caching
  • Building a refresh-token decay monitor
  • Rotating Podium client credentials
  • Recovering from 401/403 auth cascades

Example prompts

  • “podium auth”
  • “podium oauth”
  • “podium token refresh”
  • “/podium-auth”

Requirements

  • Python 3
  • Node.js
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Bash(curl:*), Bash(jq:*), Bash(python3:*), Bash(openssl:*), Grep

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Token-cache pattern (neutralizes expiry storms)
  2. Refresh-token rotation persistence (neutralizes silent rotation drift)
  3. 90-day decay monitor (neutralizes refresh-token expiry)
  4. Scope validation on every refresh (neutralizes scope drift)
  5. Secret leakage prevention (neutralizes commit leakage)
  6. Dual-credential rotation runbook (neutralizes downtime on rotation)

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Bash(curl:*)
    • Bash(jq:*)
    • Bash(python3:*)
    • Bash(openssl:*)
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 4 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • git
    • curl
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • accounts.podium.com
    • api.podium.com

    Also links to:

    • docs.podium.com
    • podium.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • PODIUM_CLIENT_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Podium Auth loads about 3.7k tokens when it runs, and up to ~9.1k if it reads all its reference files. Until then it costs about 146 tokens; SKILL.md has 1,032 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~146
When it runs · the whole SKILL.md, loaded when a task matches
~3.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~9.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:35
    xposes the entire integration. Standard `.env` hygiene is non-optional.
  • NoteMentions a .env fileSKILL.md:204
    .env
  • NoteMentions a .env fileSKILL.md:205
    .env.local
  • NoteMentions a .env fileSKILL.md:206
    .env.*.local
  • NoteMentions a .env fileSKILL.md:211
    it log --all --full-history --oneline -- .env

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 1,032 words, ~3,721 tokens.

Download SKILL.mdSave it as .claude/skills/podium-auth/SKILL.md (or your agent's skills folder). This skill also uses 10 other files; get the full folder from GitHub.
name
podium-auth
description
Authenticate production Podium integrations and survive the auth-side failures — OAuth2 access-token expiry storms, refresh-token decay after 90 days of non-use, scope drift on re-grant, secret rotation without downtime, multi-tenant token routing, leakage in commits. Use when hardening token caching, building a refresh-token decay monitor, rotating Podium client credentials, or recovering from 401/403 auth cascades. Trigger with "podium auth", "podium oauth", "podium token refresh", "podium scope drift", "podium credential rotation", "podium multi-location auth".
allowed-tools
Read, Write, Edit, Bash(curl:*), Bash(jq:*), Bash(python3:*), Bash(openssl:*), Grep
compatibility
Designed for Claude Code
version
2.12.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
podium, oauth2, authentication, token-management, secret-rotation, multi-tenant

Podium Auth

Overview

Authenticate a service to the Podium API and operate the auth layer in production. This is not a setup walkthrough — it is the auth code your integration runs at 3am when a refresh token expires after the long weekend, when a Podium admin removes a scope on re-grant, when an agency credential router sends a request to the wrong location, and when on-call needs to rotate a leaked client secret without dropping in-flight call-transcript webhooks.

The six production failures this skill prevents:

  1. Access-token expiry storms — OAuth2 access tokens expire on the order of an hour. Every concurrent request notices expiry simultaneously, races to refresh, the token endpoint rate-limits, and the integration cascades to red. Reactive refresh on 401 is wrong.
  2. Refresh-token decay (90-day non-use clock) — Podium refresh tokens expire after 90 days without use. Integrations with seasonal usage patterns (a campervan retailer's off-season) silently lose access on day 91 and require a full user reconnection.
  3. Scope drift on re-grant — When a Podium organization admin re-grants the OAuth app, the new token's scope set may differ from the old one. Cached tokens start returning 403 on previously-working endpoints. Retrying does not help.
  4. Secret leakage in commits — Podium client secrets are wide-scope and not auto-expiring. A single leaked commit exposes the entire integration. Standard .env hygiene is non-optional.
  5. Multi-tenant credential routing — Agencies managing 50+ Podium organizations cannot use a single env var. Requests sent to the wrong organization silently operate on the wrong location's contacts and webchats with no error.
  6. Rotation without downtime — Rotating a leaked client secret naively drops every in-flight webhook handler. Production rotation needs dual-credential overlap, drained refresh, and a verified health check before the old secret is revoked.

Prerequisites

  • Python 3.10+ (examples) or Node.js 18+
  • Podium account with an OAuth app: Settings → Developer → Apps → Create app
  • client_id, client_secret, redirect_uri from the app's OAuth tab
  • A user-completed authorization flow producing the initial refresh_token
  • A secret store the runtime can read at startup and on rotation signal (env var for dev, AWS Secrets Manager / GCP Secret Manager / SOPS for prod)

Instructions

Build in this order. Each section neutralizes one production failure mode.

1. Token-cache pattern (neutralizes expiry storms)

Cache the access token in-process keyed by organization, and refresh proactively at 80% of TTL behind a single-flight lock so concurrent callers serialize on one refresh.

python
import asyncio
import time
from dataclasses import dataclass
from typing import Optional
import httpx

@dataclass
class CachedToken:
    value: str
    expires_at: float  # unix seconds

class PodiumAuth:
    TOKEN_URL = "https://accounts.podium.com/oauth/token"

    def __init__(self, client_id: str, client_secret: str, refresh_token: str):
        self.client_id = client_id
        self.client_secret = client_secret
        self.refresh_token = refresh_token
        self._cached: Optional[CachedToken] = None
        self._lock = asyncio.Lock()

    async def get_token(self) -> str:
        # Refresh at 80% of TTL — token endpoint can throttle if every call refreshes
        if self._cached and time.time() < self._cached.expires_at - 600:
            return self._cached.value

        async with self._lock:
            # Re-check inside the lock — another coroutine may have refreshed
            if self._cached and time.time() < self._cached.expires_at - 600:
                return self._cached.value
            await self._refresh()
            return self._cached.value

    async def _refresh(self) -> None:
        async with httpx.AsyncClient(timeout=10) as c:
            r = await c.post(
                self.TOKEN_URL,
                data={
                    "grant_type": "refresh_token",
                    "refresh_token": self.refresh_token,
                    "client_id": self.client_id,
                    "client_secret": self.client_secret,
                },
            )
        if r.status_code != 200:
            raise PodiumAuthError(r.status_code, r.text)
        body = r.json()
        self._cached = CachedToken(
            value=body["access_token"],
            expires_at=time.time() + body["expires_in"],
        )
        # Podium rotates the refresh token on every refresh — persist the new one
        if "refresh_token" in body:
            self.refresh_token = body["refresh_token"]
            await self._persist_refresh_token(body["refresh_token"])

class PodiumAuthError(Exception):
    def __init__(self, status: int, body: str):
        super().__init__(f"Podium auth failed {status}: {body}")
        self.status = status
        self.body = body

The single-flight lock is non-negotiable. Under burst load (a Shopify webhook fans out 200 review requests at midnight when the access token has just expired), every request races to the token endpoint, Podium throttles, and the burst fails atomically.

2. Refresh-token rotation persistence (neutralizes silent rotation drift)

Podium rotates the refresh token on every successful refresh. The old refresh token is invalidated immediately. If your process refreshes successfully but crashes before persisting the new refresh token, the next process startup has a dead credential.

Persist the new refresh token to your secret store inside the refresh call, before returning the new access token to the caller:

python
async def _persist_refresh_token(self, new_refresh: str) -> None:
    # Replace with your secret store: AWS Secrets Manager, GCP Secret Manager, SOPS, etc.
    # Atomic write — temp file + rename, never a partial write.
    import os, tempfile, json
    path = os.environ["PODIUM_REFRESH_TOKEN_FILE"]
    fd, tmp = tempfile.mkstemp(dir=os.path.dirname(path), prefix=".podium_refresh.")
    try:
        with os.fdopen(fd, "w") as f:
            json.dump({"refresh_token": new_refresh, "rotated_at": time.time()}, f)
        os.replace(tmp, path)
    except Exception:
        os.unlink(tmp)
        raise
3. 90-day decay monitor (neutralizes refresh-token expiry)

Podium refresh tokens die after 90 days of non-use. Track last_used_at alongside the token; warn at day 60, page at day 75, hard-fail at day 85 with instructions for re-authorization.

python
DECAY_WARN_DAYS = 60
DECAY_PAGE_DAYS = 75
DECAY_HARD_FAIL_DAYS = 85

def check_decay(last_used_at: float) -> None:
    age_days = (time.time() - last_used_at) / 86400
    if age_days >= DECAY_HARD_FAIL_DAYS:
        raise PodiumAuthError(
            0,
            f"Refresh token unused for {age_days:.0f}d (>{DECAY_HARD_FAIL_DAYS}d) — "
            "user must re-authorize the Podium OAuth app before requests resume.",
        )
    if age_days >= DECAY_PAGE_DAYS:
        page_oncall(
            f"Podium refresh token nearing expiry: {age_days:.0f}d / 90d",
            severity="high",
        )
    elif age_days >= DECAY_WARN_DAYS:
        log_warn(f"Podium refresh token age: {age_days:.0f}d / 90d")

This protects the seasonal-business case explicitly: a campervan retailer's off-season is exactly the failure mode where naive integrations break silently and ship operators discover it when they reopen for summer.

4. Scope validation on every refresh (neutralizes scope drift)

When a Podium admin re-grants your app, the new access token's scope set is whatever the admin selected — which may be a subset of what you previously had. Validate scopes immediately after each refresh; fail loudly rather than discover the drift on a 403 in production:

python
REQUIRED_SCOPES = {
    "conversations.read",
    "conversations.write",
    "contacts.read",
    "contacts.write",
    "reviews.read",
    "reviews.write",
}

def validate_scopes(token_body: dict) -> None:
    granted = set(token_body.get("scope", "").split(" "))
    missing = REQUIRED_SCOPES - granted
    if missing:
        raise PodiumAuthError(
            0,
            f"Scope drift detected — missing: {sorted(missing)}. "
            "A Podium org admin must re-grant these scopes in the OAuth app settings.",
        )

Wire validate_scopes(body) into _refresh() immediately after the JSON parse, before assigning to self._cached.

Show full SKILL.md (398 more words)Show less
5. Secret leakage prevention (neutralizes commit leakage)

Podium client secrets are long-lived and grant access to every endpoint the OAuth app is scoped for. Never put them in source code, log output, or git history.

bash
# .gitignore — verify these are present
.env
.env.local
.env.*.local
podium-credentials.json
podium-refresh-token.json

# Audit the repo for accidentally-committed credentials before this becomes prod
git log --all --full-history --oneline -- .env
grep -rnE "podium.*(client_secret|refresh_token)\s*=\s*['\"]" --include="*.py" --include="*.ts" --include="*.json" .

For prod, encrypt credentials at rest with SOPS + age (Intent Solutions standard) and decrypt in-process — never write the plaintext to disk.

6. Dual-credential rotation runbook (neutralizes downtime on rotation)

When rotating a leaked or aging client secret:

  1. Create the new credential first — in the Podium developer console, generate a new client_secret for the same OAuth app. Both old and new are valid simultaneously for a short window.
  2. Deploy the new secret to your secret store under a versioned key (podium/client_secret_v2).
  3. Signal the running process to reload (SIGHUP, env var change trigger, or rolling restart). The token cache picks up the new secret on the next refresh.
  4. Verify with a health-check call — fetch the OAuth token info endpoint and confirm the response carries the expected client_id.
  5. Revoke the old secret in the Podium console only after the health check passes and queue depth has drained.
python
async def verify_credential(token: str) -> bool:
    async with httpx.AsyncClient(timeout=5) as c:
        r = await c.get(
            "https://api.podium.com/v4/me",
            headers={"Authorization": f"Bearer {token}"},
        )
    return r.status_code in (200, 204)

Error Handling

HTTP StatusPodium ErrorRoot CauseAction
401 Unauthorizedinvalid_tokenAccess token expired or malformedRefresh; if refresh also 401, re-authorize
401 Unauthorizedinvalid_grantRefresh token expired (90d) or revokedUser must re-authorize the OAuth app
403 Forbiddeninsufficient_scopeScope removed on re-grantAdmin re-grants required scopes
400 Bad Requestinvalid_clientWrong client_id/secret combinationVerify against Podium dev console
429 Too Many Requestsrate_limitedToken endpoint throttled (auth burst)Back off with Retry-After header
500/502/503server_errorPodium-side transientExponential backoff with jitter, max 4 attempts

Examples

Minimal access-token request
bash
curl -s -X POST https://accounts.podium.com/oauth/token \
  -d grant_type=refresh_token \
  -d refresh_token="{your-refresh-token}" \
  -d client_id="{your-client-id}" \
  -d client_secret="{your-client-secret}" | jq '{access_token, expires_in, scope}'
Wire the cache into an HTTP client
python
auth = PodiumAuth(
    client_id=os.environ["PODIUM_CLIENT_ID"],
    client_secret=os.environ["PODIUM_CLIENT_SECRET"],
    refresh_token=load_refresh_token(),
)

async def podium_get(path: str) -> httpx.Response:
    token = await auth.get_token()
    async with httpx.AsyncClient() as c:
        return await c.get(
            f"https://api.podium.com{path}",
            headers={"Authorization": f"Bearer {token}"},
        )
Multi-tenant router (agency case)
python
class PodiumOrgRouter:
    def __init__(self, credentials: dict[str, dict]):
        # credentials = {"acme-rv": {client_id, client_secret, refresh_token}, ...}
        self._auths: dict[str, PodiumAuth] = {
            org: PodiumAuth(**creds) for org, creds in credentials.items()
        }

    async def get_token(self, org_slug: str) -> str:
        auth = self._auths.get(org_slug)
        if not auth:
            raise KeyError(f"No Podium credentials for org: {org_slug}")
        return await auth.get_token()

Output

  • Token-cache module with single-flight refresh at 80% TTL
  • Refresh-token rotation persistence (atomic write to secret store)
  • 90-day decay monitor with warn / page / hard-fail thresholds
  • Scope validation invoked on every refresh
  • .gitignore audited for credential leakage patterns
  • Dual-credential rotation runbook documented in the repo

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 10 other files (scripts, references) in skills/.curated/podium-auth of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • ARD.md
  • PRD.md
  • config/settings.yaml
  • references/errors.md
  • references/examples.md
  • references/implementation.md
  • scripts/rotate_secret.py
  • scripts/scope_audit.py
  • scripts/token_refresh.py
  • scripts/verify_creds.py

Open the folder on GitHubat commit cfae287

Compare with similar skills

Podium Auth next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Podium Auth compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Podium Auth this skilljeremylongshore/tons-of-skills-marketplace2.8k—~3.7kAutomated safety check: NotesMIT
Notion Worker Third-Party Auth Guidemakenotion/workers-template4391 repos~3.5kAutomated safety check: NotesMIT
Supercheck Security Authsupercheck-io/supercheck215—~1.2kAutomated safety check: PassAGPL-3.0
OneCLI Gatewaynanocoai/nanoclaw31k—~856Automated safety check: PassMIT
Frontmcp Configagentfront/frontmcp146—~7kAutomated safety check: PassApache-2.0
API Authcyanheads/pubmed-mcp-server158—~2.9kAutomated safety check: PassApache-2.0

Similar skills

  • Notion Worker Third-Party Auth Guide

    makenotion/workers-template

    Official

    Decides whether a Notion Worker should use a brokered credential, a plaintext environment secret, or OAuth to authenticate against a non-Notion service.

    439 GitHub starsUsed in 1 repo~3.5k tokens
    Backend & APIsAuto-check: notes
  • Supercheck Security Auth

    supercheck-io/supercheck

    Work on Supercheck authentication, RBAC, tenant isolation, sessions, API and trigger keys, invitations, project membership, project variables, OAuth, super-admin behavior, SSRF, or…

    215 GitHub stars~1.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • OneCLI Gateway

    nanocoai/nanoclaw

    Explains how to call external APIs through the OneCLI proxy, which injects stored credentials into outgoing HTTPS requests so the agent never handles keys.

    31k GitHub stars~856 tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Frontmcp Config

    agentfront/frontmcp

    A skill your agent uses when configuring a FrontMCP server through frontmcp.config or the @FrontMcp options.

    146 GitHub stars~7k tokensUpdated today
    Backend & APIsAuto-check passed
  • API Auth

    cyanheads/pubmed-mcp-server

    Authentication, authorization, and multi-tenancy patterns for @cyanheads/mcp-ts-core.

    158 GitHub stars~2.9k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Quarkus Security

    affaan-m/ECC

    Quarkus security implementation patterns: JWT and OIDC authentication, @RolesAllowed RBAC and SecurityIdentity checks, Bean Validation and custom validators, parameterized Panache queries, BCrypt…

    277k GitHub starsUsed in 1 repo~3.1k tokens
    Backend & APIsAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Categories

Questions about Podium Auth

What does Podium Auth do?

Authenticate production Podium integrations and survive the auth-side failures — OAuth2 access-token expiry storms, refresh-token decay after 90 days of non-use, scope drift on re-grant, secret…. Podium Auth is an agent skill from jeremylongshore/tons-of-skills-marketplace. Authenticate production Podium integrations and survive the auth-side failures — OAuth2 access-token expiry storms, refresh-token decay after 90 days of non-use, scope drift on re-grant, secret rotation without downtime, multi-tenant token routing, leakage in commits.

When should I use Podium Auth?

Podium Auth fits situations like: hardening token caching; building a refresh-token decay monitor; rotating Podium client credentials; recovering from 401/403 auth cascades.

How do I install Podium Auth in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill podium-auth -a claude-code`. Or copy the skill folder (skills/.curated/podium-auth in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/podium-auth in your project. Claude Code loads it when a task matches its description.

How do I install Podium Auth in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill podium-auth -a codex`. Or copy the skill folder (skills/.curated/podium-auth in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/podium-auth in your project. Codex loads it when a task matches its description.

Can I use Podium Auth in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill podium-auth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/podium-auth, .gemini/skills/podium-auth, .github/skills/podium-auth and .opencode/skills/podium-auth in your project.

What does Podium Auth need to run?

Going by SKILL.md and its folder, Podium Auth needs Python for the scripts in its folder, the command-line tools its instructions call (git, curl and jq) and credentials named PODIUM_CLIENT_SECRET. Our summary lists: Python 3; Node.js. Its frontmatter pre-approves these tools: Read, Write, Edit, Bash(curl:*), Bash(jq:*), Bash(python3:*), Bash(openssl:*), Grep. Compatibility (from SKILL.md): Designed for Claude Code.

Does Podium Auth access the network?

SKILL.md names 4 domains. In commands or code: accounts.podium.com and api.podium.com; the agent is likely to contact these when it follows the instructions. As links in the text: docs.podium.com and podium.com. This is read from the text; nothing was executed.

Is Podium Auth safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Podium Auth use?

Podium Auth is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Podium Auth use?

About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.3k tokens, read only when the agent opens those files.

What are the alternatives to Podium Auth?

Skills that share tags, products or a category with Podium Auth: Notion Worker Third-Party Auth Guide (makenotion/workers-template, 439 stars), Supercheck Security Auth (supercheck-io/supercheck, 215 stars), OneCLI Gateway (nanocoai/nanoclaw, 31k stars) and Frontmcp Config (agentfront/frontmcp, 146 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Podium Auth?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.