Notion Worker Third-Party Auth Guide
makenotion/workers-template
Decides whether a Notion Worker should use a brokered credential, a plaintext environment secret, or OAuth to authenticate against a non-Notion service.
Authenticate production Podium integrations and survive the auth-side failures — OAuth2 access-token expiry storms, refresh-token decay after 90 days of non-use, scope drift on re-grant, secret…
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill podium-auth -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace podium-auth --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/podium-auth .claude/skills/podium-auth && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "podium-auth" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/podium-auth into .claude/skills/podium-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "podium-auth", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/podium-authType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill podium-auth -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace podium-auth --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/.curated/podium-auth .agents/skills/podium-auth && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "podium-auth" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/podium-auth into .agents/skills/podium-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "podium-auth", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill podium-auth -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace podium-auth --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/.curated/podium-auth .cursor/skills/podium-auth && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "podium-auth" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/podium-auth into .cursor/skills/podium-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "podium-auth", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/jeremylongshore/tons-of-skills-marketplace.git --path skills/.curated/podium-auth--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill podium-auth -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace podium-auth --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/.curated/podium-auth .gemini/skills/podium-auth && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "podium-auth" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/podium-auth into .gemini/skills/podium-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "podium-auth", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install jeremylongshore/tons-of-skills-marketplace podium-authInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill podium-auth -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/.curated/podium-auth .github/skills/podium-auth && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "podium-auth" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/podium-auth into .github/skills/podium-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "podium-auth", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill podium-auth -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace podium-auth --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/.curated/podium-auth .opencode/skills/podium-auth && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "podium-auth" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/podium-auth into .opencode/skills/podium-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "podium-auth", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
podium-authAuthenticate production Podium integrations and survive the auth-side failures — OAuth2 access-token expiry storms, refresh-token decay after 90 days of non-use, scope drift on re-grant, secret…
Podium Auth is an agent skill from jeremylongshore/tons-of-skills-marketplace. Authenticate production Podium integrations and survive the auth-side failures — OAuth2 access-token expiry storms, refresh-token decay after 90 days of non-use, scope drift on re-grant, secret rotation without downtime, multi-tenant token routing, leakage in commits. Use when hardening token caching, building a refresh-token decay monitor, rotating Podium client credentials, or recovering from 401/403 auth cascades. Trigger with "podium auth", "podium oauth", "podium token refresh", "podium scope drift", "podium…
Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 13 other files, including scripts and reference files (for example `ARD.md`, `PRD.md` and `config/settings.yaml`). Compatibility notes: Designed for Claude Code
It sits in Backend & APIs, covering OAuth and OpenID Connect, Multi-tenancy and Secrets management. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadWriteEditBash(curl:*)Bash(jq:*)Bash(python3:*)Bash(openssl:*)GrepFrom allowed-tools in the SKILL.md frontmatter.
Ships 4 files in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
gitcurljqFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
accounts.podium.comapi.podium.comAlso links to:
docs.podium.compodium.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
PODIUM_CLIENT_SECRETFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Designed for Claude Code
From compatibility in the SKILL.md frontmatter.
Podium Auth loads about 3.7k tokens when it runs, and up to ~9.1k if it reads all its reference files. Until then it costs about 146 tokens; SKILL.md has 1,032 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
xposes the entire integration. Standard `.env` hygiene is non-optional..env.env.local.env.*.localit log --all --full-history --oneline -- .envAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 1,032 words, ~3,721 tokens.
.claude/skills/podium-auth/SKILL.md (or your agent's skills folder). This skill also uses 10 other files; get the full folder from GitHub.Authenticate a service to the Podium API and operate the auth layer in production. This is not a setup walkthrough — it is the auth code your integration runs at 3am when a refresh token expires after the long weekend, when a Podium admin removes a scope on re-grant, when an agency credential router sends a request to the wrong location, and when on-call needs to rotate a leaked client secret without dropping in-flight call-transcript webhooks.
The six production failures this skill prevents:
401 is wrong.403 on previously-working endpoints. Retrying does not help..env hygiene is non-optional.client_id, client_secret, redirect_uri from the app's OAuth tabrefresh_tokenBuild in this order. Each section neutralizes one production failure mode.
Cache the access token in-process keyed by organization, and refresh proactively at 80% of TTL behind a single-flight lock so concurrent callers serialize on one refresh.
import asyncio
import time
from dataclasses import dataclass
from typing import Optional
import httpx
@dataclass
class CachedToken:
value: str
expires_at: float # unix seconds
class PodiumAuth:
TOKEN_URL = "https://accounts.podium.com/oauth/token"
def __init__(self, client_id: str, client_secret: str, refresh_token: str):
self.client_id = client_id
self.client_secret = client_secret
self.refresh_token = refresh_token
self._cached: Optional[CachedToken] = None
self._lock = asyncio.Lock()
async def get_token(self) -> str:
# Refresh at 80% of TTL — token endpoint can throttle if every call refreshes
if self._cached and time.time() < self._cached.expires_at - 600:
return self._cached.value
async with self._lock:
# Re-check inside the lock — another coroutine may have refreshed
if self._cached and time.time() < self._cached.expires_at - 600:
return self._cached.value
await self._refresh()
return self._cached.value
async def _refresh(self) -> None:
async with httpx.AsyncClient(timeout=10) as c:
r = await c.post(
self.TOKEN_URL,
data={
"grant_type": "refresh_token",
"refresh_token": self.refresh_token,
"client_id": self.client_id,
"client_secret": self.client_secret,
},
)
if r.status_code != 200:
raise PodiumAuthError(r.status_code, r.text)
body = r.json()
self._cached = CachedToken(
value=body["access_token"],
expires_at=time.time() + body["expires_in"],
)
# Podium rotates the refresh token on every refresh — persist the new one
if "refresh_token" in body:
self.refresh_token = body["refresh_token"]
await self._persist_refresh_token(body["refresh_token"])
class PodiumAuthError(Exception):
def __init__(self, status: int, body: str):
super().__init__(f"Podium auth failed {status}: {body}")
self.status = status
self.body = bodyThe single-flight lock is non-negotiable. Under burst load (a Shopify webhook fans out 200 review requests at midnight when the access token has just expired), every request races to the token endpoint, Podium throttles, and the burst fails atomically.
Podium rotates the refresh token on every successful refresh. The old refresh token is invalidated immediately. If your process refreshes successfully but crashes before persisting the new refresh token, the next process startup has a dead credential.
Persist the new refresh token to your secret store inside the refresh call, before returning the new access token to the caller:
async def _persist_refresh_token(self, new_refresh: str) -> None:
# Replace with your secret store: AWS Secrets Manager, GCP Secret Manager, SOPS, etc.
# Atomic write — temp file + rename, never a partial write.
import os, tempfile, json
path = os.environ["PODIUM_REFRESH_TOKEN_FILE"]
fd, tmp = tempfile.mkstemp(dir=os.path.dirname(path), prefix=".podium_refresh.")
try:
with os.fdopen(fd, "w") as f:
json.dump({"refresh_token": new_refresh, "rotated_at": time.time()}, f)
os.replace(tmp, path)
except Exception:
os.unlink(tmp)
raisePodium refresh tokens die after 90 days of non-use. Track last_used_at alongside the token; warn at day 60, page at day 75, hard-fail at day 85 with instructions for re-authorization.
DECAY_WARN_DAYS = 60
DECAY_PAGE_DAYS = 75
DECAY_HARD_FAIL_DAYS = 85
def check_decay(last_used_at: float) -> None:
age_days = (time.time() - last_used_at) / 86400
if age_days >= DECAY_HARD_FAIL_DAYS:
raise PodiumAuthError(
0,
f"Refresh token unused for {age_days:.0f}d (>{DECAY_HARD_FAIL_DAYS}d) — "
"user must re-authorize the Podium OAuth app before requests resume.",
)
if age_days >= DECAY_PAGE_DAYS:
page_oncall(
f"Podium refresh token nearing expiry: {age_days:.0f}d / 90d",
severity="high",
)
elif age_days >= DECAY_WARN_DAYS:
log_warn(f"Podium refresh token age: {age_days:.0f}d / 90d")This protects the seasonal-business case explicitly: a campervan retailer's off-season is exactly the failure mode where naive integrations break silently and ship operators discover it when they reopen for summer.
When a Podium admin re-grants your app, the new access token's scope set is whatever the admin selected — which may be a subset of what you previously had. Validate scopes immediately after each refresh; fail loudly rather than discover the drift on a 403 in production:
REQUIRED_SCOPES = {
"conversations.read",
"conversations.write",
"contacts.read",
"contacts.write",
"reviews.read",
"reviews.write",
}
def validate_scopes(token_body: dict) -> None:
granted = set(token_body.get("scope", "").split(" "))
missing = REQUIRED_SCOPES - granted
if missing:
raise PodiumAuthError(
0,
f"Scope drift detected — missing: {sorted(missing)}. "
"A Podium org admin must re-grant these scopes in the OAuth app settings.",
)Wire validate_scopes(body) into _refresh() immediately after the JSON parse, before assigning to self._cached.
Podium client secrets are long-lived and grant access to every endpoint the OAuth app is scoped for. Never put them in source code, log output, or git history.
# .gitignore — verify these are present
.env
.env.local
.env.*.local
podium-credentials.json
podium-refresh-token.json
# Audit the repo for accidentally-committed credentials before this becomes prod
git log --all --full-history --oneline -- .env
grep -rnE "podium.*(client_secret|refresh_token)\s*=\s*['\"]" --include="*.py" --include="*.ts" --include="*.json" .For prod, encrypt credentials at rest with SOPS + age (Intent Solutions standard) and decrypt in-process — never write the plaintext to disk.
When rotating a leaked or aging client secret:
podium/client_secret_v2).client_id.async def verify_credential(token: str) -> bool:
async with httpx.AsyncClient(timeout=5) as c:
r = await c.get(
"https://api.podium.com/v4/me",
headers={"Authorization": f"Bearer {token}"},
)
return r.status_code in (200, 204)| HTTP Status | Podium Error | Root Cause | Action |
|---|---|---|---|
401 Unauthorized | invalid_token | Access token expired or malformed | Refresh; if refresh also 401, re-authorize |
401 Unauthorized | invalid_grant | Refresh token expired (90d) or revoked | User must re-authorize the OAuth app |
403 Forbidden | insufficient_scope | Scope removed on re-grant | Admin re-grants required scopes |
400 Bad Request | invalid_client | Wrong client_id/secret combination | Verify against Podium dev console |
429 Too Many Requests | rate_limited | Token endpoint throttled (auth burst) | Back off with Retry-After header |
500/502/503 | server_error | Podium-side transient | Exponential backoff with jitter, max 4 attempts |
curl -s -X POST https://accounts.podium.com/oauth/token \
-d grant_type=refresh_token \
-d refresh_token="{your-refresh-token}" \
-d client_id="{your-client-id}" \
-d client_secret="{your-client-secret}" | jq '{access_token, expires_in, scope}'auth = PodiumAuth(
client_id=os.environ["PODIUM_CLIENT_ID"],
client_secret=os.environ["PODIUM_CLIENT_SECRET"],
refresh_token=load_refresh_token(),
)
async def podium_get(path: str) -> httpx.Response:
token = await auth.get_token()
async with httpx.AsyncClient() as c:
return await c.get(
f"https://api.podium.com{path}",
headers={"Authorization": f"Bearer {token}"},
)class PodiumOrgRouter:
def __init__(self, credentials: dict[str, dict]):
# credentials = {"acme-rv": {client_id, client_secret, refresh_token}, ...}
self._auths: dict[str, PodiumAuth] = {
org: PodiumAuth(**creds) for org, creds in credentials.items()
}
async def get_token(self, org_slug: str) -> str:
auth = self._auths.get(org_slug)
if not auth:
raise KeyError(f"No Podium credentials for org: {org_slug}")
return await auth.get_token().gitignore audited for credential leakage patterns© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 10 other files (scripts, references) in skills/.curated/podium-auth of jeremylongshore/tons-of-skills-marketplace.
Open the folder on GitHubat commit cfae287
Podium Auth next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Podium Auth this skilljeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~3.7k | Automated safety check: Notes | MIT | |
| Notion Worker Third-Party Auth Guidemakenotion/workers-template | 439 | 1 repos | ~3.5k | Automated safety check: Notes | MIT | |
| Supercheck Security Authsupercheck-io/supercheck | 215 | — | ~1.2k | Automated safety check: Pass | AGPL-3.0 | |
| OneCLI Gatewaynanocoai/nanoclaw | 31k | — | ~856 | Automated safety check: Pass | MIT | |
| Frontmcp Configagentfront/frontmcp | 146 | — | ~7k | Automated safety check: Pass | Apache-2.0 | |
| API Authcyanheads/pubmed-mcp-server | 158 | — | ~2.9k | Automated safety check: Pass | Apache-2.0 |
makenotion/workers-template
Decides whether a Notion Worker should use a brokered credential, a plaintext environment secret, or OAuth to authenticate against a non-Notion service.
supercheck-io/supercheck
Work on Supercheck authentication, RBAC, tenant isolation, sessions, API and trigger keys, invitations, project membership, project variables, OAuth, super-admin behavior, SSRF, or…
nanocoai/nanoclaw
Explains how to call external APIs through the OneCLI proxy, which injects stored credentials into outgoing HTTPS requests so the agent never handles keys.
agentfront/frontmcp
A skill your agent uses when configuring a FrontMCP server through frontmcp.config or the @FrontMcp options.
cyanheads/pubmed-mcp-server
Authentication, authorization, and multi-tenancy patterns for @cyanheads/mcp-ts-core.
affaan-m/ECC
Quarkus security implementation patterns: JWT and OIDC authentication, @RolesAllowed RBAC and SecurityIdentity checks, Bean Validation and custom validators, parameterized Panache queries, BCrypt…
jeremylongshore/tons-of-skills-marketplace
Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.
jeremylongshore/tons-of-skills-marketplace
Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.
jeremylongshore/tons-of-skills-marketplace
Execute proactive auto-loading: automatically detects and loads agents.md files.
jeremylongshore/tons-of-skills-marketplace
Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.
jeremylongshore/tons-of-skills-marketplace
Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.
jeremylongshore/tons-of-skills-marketplace
Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.
Categories
Authenticate production Podium integrations and survive the auth-side failures — OAuth2 access-token expiry storms, refresh-token decay after 90 days of non-use, scope drift on re-grant, secret…. Podium Auth is an agent skill from jeremylongshore/tons-of-skills-marketplace. Authenticate production Podium integrations and survive the auth-side failures — OAuth2 access-token expiry storms, refresh-token decay after 90 days of non-use, scope drift on re-grant, secret rotation without downtime, multi-tenant token routing, leakage in commits.
Podium Auth fits situations like: hardening token caching; building a refresh-token decay monitor; rotating Podium client credentials; recovering from 401/403 auth cascades.
Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill podium-auth -a claude-code`. Or copy the skill folder (skills/.curated/podium-auth in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/podium-auth in your project. Claude Code loads it when a task matches its description.
Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill podium-auth -a codex`. Or copy the skill folder (skills/.curated/podium-auth in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/podium-auth in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill podium-auth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/podium-auth, .gemini/skills/podium-auth, .github/skills/podium-auth and .opencode/skills/podium-auth in your project.
Going by SKILL.md and its folder, Podium Auth needs Python for the scripts in its folder, the command-line tools its instructions call (git, curl and jq) and credentials named PODIUM_CLIENT_SECRET. Our summary lists: Python 3; Node.js. Its frontmatter pre-approves these tools: Read, Write, Edit, Bash(curl:*), Bash(jq:*), Bash(python3:*), Bash(openssl:*), Grep. Compatibility (from SKILL.md): Designed for Claude Code.
SKILL.md names 4 domains. In commands or code: accounts.podium.com and api.podium.com; the agent is likely to contact these when it follows the instructions. As links in the text: docs.podium.com and podium.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Podium Auth is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.3k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Podium Auth: Notion Worker Third-Party Auth Guide (makenotion/workers-template, 439 stars), Supercheck Security Auth (supercheck-io/supercheck, 215 stars), OneCLI Gateway (nanocoai/nanoclaw, 31k stars) and Frontmcp Config (agentfront/frontmcp, 146 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.
Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.