Agent skill

Validate OAuth Integration

by rome-os in rome-os/rome

Validate a Rome-managed OAuth integration end-to-end — prove a user can click Connect and Rome ends up holding a delegated token it can use to call the provider's API.

MITAuto-check: notesBackend & APIs

Install Validate OAuth Integration

skills CLI
$ npx skills add rome-os/rome --skill validate-oauth-integration -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install rome-os/rome validate-oauth-integration --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/rome-os/rome.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/validate-oauth-integration .claude/skills/validate-oauth-integration && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
validate-oauth-integration
GitHub stars
725
Token cost
~2k tokens
SKILL.md length
908 words
Files
1
Skills in repo
18
Repo updated
First seen
Licence
MIT

At a glance

Validate a Rome-managed OAuth integration end-to-end — prove a user can click Connect and Rome ends up holding a delegated token it can use to call the provider's API.

  • Works in 5 steps: Put the provider creds in the Pantheon… → Open an https tunnel to this stack's… → Register the tunnel callback in the… → …
  • Call the providers API
  • SKILL.md covers Layer 0 — Static + unit (host,…, Layer 1 — Token usage, no…, Layer 2 — The real delegation… and Cleanup
  • Calls pnpm, docker and cloudflared

What it does

Validate OAuth Integration is an agent skill from rome-os/rome. Validate a Rome-managed OAuth integration end-to-end — prove a user can click Connect and Rome ends up holding a delegated token it can use to call the provider's API. Use when asked to "validate / test the <service OAuth connector", "check that a user can connect <service", or "verify the OAuth round-trip". This is the validation half of the GitHub/Slack model (brokered by Pantheon, NOT Composio). For building a new integration, run the add-oauth-integration skill first; this skill assumes the code already…

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering OAuth and OpenID Connect, App automation through connectors and Webhooks. It works with Composio, Slack, GitHub and pnpm. The repository describes itself as: A compounding agent OS for recursive agents. Also an open source alternative to Grok Bot and Meta's Muse. The licence is MIT.

When your agent uses it

  • Call the providers API
  • Asked to validate / test the <service OAuth connector
  • Check that a user can connect <service
  • Verify the OAuth round-trip

Example prompts

  • “s API. Use when asked to”
  • “check that a user can connect <service”
  • “verify the OAuth round-trip”
  • “/validate-oauth-integration”

Requirements

  • Docker

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Put the provider creds in the Pantheon env — packages/pantheon/.env
  2. Open an https tunnel to this stack's Pantheon. Find your slug (docker ps --format '{{.Names}}' | grep pantheon → -pantheon-web-1), then…
  3. Register the tunnel callback in the provider app's redirect URLs: https:///oauth//callback. Providers allow several — keep the prod one…
  4. Boot the stack pointed at the tunnel
  5. Connect. Open the dashboard (http://.rome.localhost:3000) → Settings → Connections → Connect (or ask the agent). Approve on the consent…

What it can do on your machine

Read from SKILL.md and the folder at commit ed26d88. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm
    • docker
    • cloudflared

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm and docker, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Validate OAuth Integration loads about 2k tokens when it runs. Until then it costs about 155 tokens; SKILL.md has 908 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~155
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:53
    the Pantheon env** — `packages/pantheon/.env`:

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from rome-os/rome at commit ed26d88, republished under its MIT licence (© rome-os). 908 words, ~1,985 tokens.

Download SKILL.mdSave it as .claude/skills/validate-oauth-integration/SKILL.md (or your agent's skills folder).
name
validate-oauth-integration
description
Validate a Rome-managed OAuth integration end-to-end — prove a user can click Connect and Rome ends up holding a delegated token it can use to call the provider's API. Use when asked to "validate / test the <service> OAuth connector", "check that a user can connect <service>", or "verify the OAuth round-trip". This is the validation half of the GitHub/Slack model (brokered by Pantheon, NOT Composio). For *building* a new integration, run the add-oauth-integration skill first; this skill assumes the code already exists. NOT for Composio-managed toolkits and NOT for inbound webhook events.

Validate an OAuth integration

Goal end-state proven: a user opens Settings → Connections, clicks Connect <Service>, approves on the provider's consent screen, and Rome holds a delegated token it can call the provider's API with. The recipe is provider-agnostic — only the creds and the registered redirect URL change per provider. Slack (PR #1225) is the worked example throughout.

Validate in three escalating layers. Run them in order; each is cheaper to debug than the next. Report honestly which layers actually ran — Layer 2 needs a registered app, creds, and a human at the consent screen, so it is often where the human takes over.

The cross-service round-trip Layer 2 exercises:

dashboard ──▶ core /api/oauth/<provider>/start ──▶ Pantheon /start
  ──▶ provider authorize (real consent) ──▶ Pantheon /oauth/<provider>/callback
  ──▶ exchangeCode + fetchProfile (verified-email gate) ──▶ broker handoff
  ──▶ dashboard /callback ──▶ core /oauth/redeem ──▶ token persisted + token file

Layer 0 — Static + unit (host, fast)

  • pnpm typecheck (all workspaces).
  • Touched suites: the Pantheon adapter (pnpm --filter rome-pantheon exec vitest run src/lib/oauth), the core provider lists (pnpm --filter @rome/core exec vitest run src/lib/oauth-providers.test.ts), and the connector (pnpm --filter @rome/app-connector exec vitest run) if the token-consumer half exists.
  • Update the drift guards the new provider trips: the enabled-provider lists in packages/core/src/lib/oauth-providers.test.ts and the Rome-managed lists in rome_apps/connector/src/web/lib/connections.test.ts. Any test that used the service as a stand-in Composio toolkit must switch to a still-Composio one (e.g. notion).

Layer 1 — Token usage, no OAuth dance (fast confidence in the consumer code)

Mint a token out-of-band and prove Rome can use it, decoupled from the consent flow:

  • In the provider's developer console, "Install to Workspace" (or equivalent) to mint a token without the redirect flow.
  • Write it into the rome container by hand at /run/rome/<provider>-oauth-token (single string, or JSON for multi-token services like Slack's {botToken,userToken,teamId}).
  • Ask the agent to run connector_proxy against a read endpoint (an auth.test-equivalent) and a write endpoint.

This isolates the proxy/token-selection code from the broker, so a failure here is unambiguously in the consumer half.

Layer 2 — The real delegation round-trip (proves Rome can obtain a token)

The one hard constraint: https redirect

Most providers (Slack among them) only accept https redirect URLs — no http, not even localhost. The dev stack's local Pantheon is served over http://pantheon.<slug>.rome.localhost:3000, which the provider rejects. Front it with an https tunnel for the test. (GitHub is the exception — it allows http redirects, so its leg works in plain dev:all.)

Prerequisites
  • The provider app registered, with client id/secret and a redirect URL you can point at the tunnel.
  • A tunnel that yields an https URL: cloudflared (free quick tunnels, no account) or ngrok.
  • Docker + the dev:all stack (see root CLAUDE.md dev-loop).
Steps
  1. Put the provider creds in the Pantheon env — packages/pantheon/.env:

    <PROVIDER>_OAUTH_CLIENT_ID=...
    <PROVIDER>_OAUTH_CLIENT_SECRET=...

    pantheon-web reads this file at (re)start. The env_file is baked at container create — a restart won't pick up edits; re-run dev:all to recreate.

  2. Open an https tunnel to this stack's Pantheon. Find your slug (docker ps --format '{{.Names}}' | grep pantheon → <slug>-pantheon-web-1), then forward to Traefik with the Pantheon host header so routing still resolves:

    bash
    cloudflared tunnel --url http://localhost:3000 \
      --http-host-header pantheon.<slug>.rome.localhost

    Note the printed https://<random>.trycloudflare.com — that's <tunnel-host>. (A named tunnel / reserved domain gives a stable host so you don't re-edit the redirect URL every session.)

  3. Register the tunnel callback in the provider app's redirect URLs: https://<tunnel-host>/oauth/<provider>/callback. Providers allow several — keep the prod one too. Remove the trycloudflare entry when you're done.

  4. Boot the stack pointed at the tunnel:

    bash
    ROME_DEV_PANTHEON_PUBLIC_ORIGIN=https://<tunnel-host> pnpm dev:all

    Wait for the rome container to log Rome started. This keeps the per-stack local Pantheon (and its in-cluster redeem) but advertises the tunnel as the browser-facing origin, so the redirect_uri Pantheon emits is the https URL the provider accepts.

  5. Connect. Open the dashboard (http://<slug>.rome.localhost:3000) → Settings → Connections → Connect <Service> (or ask the agent). Approve on the consent screen.

Show full SKILL.md (332 more words)Show less
Two local-only blockers the happy path hides
  • /start needs a Pantheon session. Local Pantheon has no Google login, and the seeded-dev-owner fallback covers only enrollment (/instance/authorize), NOT the OAuth broker /start. Enable the password form (PANTHEON_LEGACY_LOGIN_CODE env → /login?legacy=<code>) and sign in as the seeded dev owner at the tunnel origin (the session cookie is per-origin) before clicking Connect — otherwise /start bounces you to /login and the dance never begins.
  • The token write fails after the email gate passes if /run/rome is read-only. The daemon runs uid 501; the /run/rome tmpfs must be world-writable (mode=1777 in compose.dev.yml) or redeem throws EACCES once it reaches the file write — a confusing "everything worked then died at the very end" symptom. Runtime unblock without recreate: docker exec -u 0 <rome> chmod 1777 /run/rome.
Verifying success
  • UI / API: the Connect card flips to "<Service> connected"; GET /api/integrations lists the provider with connected: true and the connected account's email is the human who consented — not a bot/service identity. (If it shows an empty or service email, fetchProfile is resolving the wrong identity — see the add-oauth-integration skill's installer-identity trap.)
  • Token persisted to the instance (the file the connector reads):
    bash
    ROME=$(docker ps --format '{{.Names}}' | grep rome-1)
    docker exec "$ROME" cat /run/rome/<provider>-oauth-token
  • Round-trip works: in chat, have the agent call connector_proxy against a read endpoint (e.g. Slack path: "/api/auth.test", method: "POST") → expect the provider's success signal (ok: true). For multi-token services, also exercise an endpoint that needs the secondary token (Slack: search.messages needs the user token, not the bot token).
  • Scopes actually granted: the auth.test-equivalent (or the token-introspection endpoint) shows the scopes the token really carries. This is the only proof that a scope you added to the adapter was also offered by the registered app and granted at consent — code-side scope lists are not self-proving.

Cleanup

Leave no test residue: remove the tunnel redirect URL from the provider app, bring the stack down, kill the tunnel, and delete any temporary browser profile copy used to drive the consent screen.

© rome-os, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/validate-oauth-integration of rome-os/rome.

Open the folder on GitHubat commit ed26d88

Compare with similar skills

Validate OAuth Integration next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Validate OAuth Integration compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Validate OAuth Integration this skillrome-os/rome725—~2kAutomated safety check: NotesMIT
Openloomi Connectorsmelandlabs/openloomi1k—~3.3kAutomated safety check: PassApache-2.0
Connect Appsyc-software/qm15k—~746Automated safety check: PassMIT
Emulate Seedyonatangross/orchestkit289—~4.5kAutomated safety check: PassMIT
ComposioComposioHQ/composio30k1 repos~1.7kAutomated safety check: PassMIT
Connect Apps with ComposioComposioHQ/awesome-claude-skills77k3 repos~557Automated safety check: PassNone

Similar skills

  • Openloomi Connectors

    melandlabs/openloomi

    openloomi Connectors tools - manage the native 7 messaging integrations and pair with the composio skill for the 1000+ apps OAuth layer (Slack, Discord, X, Gmail, Outlook, Google…

    1k GitHub stars~3.3k tokensUpdated 14 days ago
    Productivity & AutomationAuto-check passed
  • Connect Apps

    yc-software/qm

    Connect an administrator-enabled SaaS app for a user with a one-time OAuth consent link.

    15k GitHub stars~746 tokensUpdated today
    Backend & APIsAuto-check passed
  • Emulate Seed

    yonatangross/orchestkit

    Generate emulate seed configs for stateful API emulation. An agent skill from yonatangross/orchestkit.

    289 GitHub stars~4.5k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Composio

    ComposioHQ/composio

    Route and complete Composio work across Composio For You and Composio Platform.

    30k GitHub starsUsed in 1 repo~1.7k tokens
    Productivity & AutomationAuto-check passed
  • Connect Apps with Composio

    ComposioHQ/awesome-claude-skills

    Connects an agent to 1000+ external apps through the Composio Tool Router plugin, so it can actually send emails, create issues and post messages instead of only drafting them.

    77k GitHub starsUsed in 3 repos~557 tokens
    Productivity & AutomationAuto-check passed
  • Setting Up Relayfile

    AgentWorkforce/relay

    A skill your agent uses when an agent or human needs to set up relayfile end-to-end so agents can read and write provider files through a local mount.

    866 GitHub starsUsed in 1 repo~3.3k tokens
    Productivity & AutomationAuto-check passed

More from rome-os/rome

All 18 skills in this repo
  • Color Audit

    rome-os/rome

    Audit a design system's color palette against measurable color-science disciplines — WCAG/APCA contrast of declared token pairs, perceptual (OKLCH) ramp uniformity, color-blindness safety of…

    725 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Audit the subordinate copy in a UI — section descriptions, field helper text, hints, card subtitles, empty-state body copy, tooltip bodies — against the secondary-text ruleset, and emit a per-string…

    725 GitHub stars~2.8k tokensUpdated today
    Auto-check passed
  • UX Semantics Audit

    rome-os/rome

    Audit an existing UI/UX design (React/JSX/TSX components, HTML, or generated app code) against a tiered ruleset of verifiable UX principles, and produce structured, evidence-cited findings that a…

    725 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Add a new Rome-managed OAuth integration for a third-party service so a user can delegate access by clicking Connect, and Rome can act on the service with the delegated token (the GitHub/Slack model…

    725 GitHub stars~3.6k tokensUpdated today
    Auto-check passed
  • Composio CLI

    rome-os/rome

    Help users operate the published Composio CLI to find the right tool, connect accounts, inspect schemas, execute tools, subscribe to trigger events with composio listen, script workflows with…

    725 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • File Issue

    rome-os/rome

    File one GitHub issue from a description the user gives — classify it as a bug report, feature request, or task spec, gather what the body needs from the tracker and the code, ask the user only for…

    725 GitHub stars~1.7k tokensUpdated today
    Auto-check passed

Questions about Validate OAuth Integration

What does Validate OAuth Integration do?

Validate a Rome-managed OAuth integration end-to-end — prove a user can click Connect and Rome ends up holding a delegated token it can use to call the provider's API. Validate OAuth Integration is an agent skill from rome-os/rome. Validate a Rome-managed OAuth integration end-to-end — prove a user can click Connect and Rome ends up holding a delegated token it can use to call the provider's API.

When should I use Validate OAuth Integration?

Validate OAuth Integration fits situations like: call the providers API; asked to validate / test the <service OAuth connector; check that a user can connect <service; verify the OAuth round-trip.

How do I install Validate OAuth Integration in Claude Code?

Run `npx skills add rome-os/rome --skill validate-oauth-integration -a claude-code`. Or copy the skill folder (.claude/skills/validate-oauth-integration in rome-os/rome) into .claude/skills/validate-oauth-integration in your project. Claude Code loads it when a task matches its description.

How do I install Validate OAuth Integration in Codex?

Run `npx skills add rome-os/rome --skill validate-oauth-integration -a codex`. Or copy the skill folder (.claude/skills/validate-oauth-integration in rome-os/rome) into .agents/skills/validate-oauth-integration in your project. Codex loads it when a task matches its description.

Can I use Validate OAuth Integration in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add rome-os/rome --skill validate-oauth-integration -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/validate-oauth-integration, .gemini/skills/validate-oauth-integration, .github/skills/validate-oauth-integration and .opencode/skills/validate-oauth-integration in your project.

What does Validate OAuth Integration need to run?

Going by SKILL.md and its folder, Validate OAuth Integration needs the command-line tools its instructions call (pnpm, docker and cloudflared). Our summary lists: Docker.

Does Validate OAuth Integration access the network?

SKILL.md contains no URLs. Its commands use docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Validate OAuth Integration safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Validate OAuth Integration use?

Validate OAuth Integration is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Validate OAuth Integration use?

About 2k tokens (SKILL.md is roughly 7.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Validate OAuth Integration?

Skills that share tags, products or a category with Validate OAuth Integration: Openloomi Connectors (melandlabs/openloomi, 1k stars), Connect Apps (yc-software/qm, 15k stars), Emulate Seed (yonatangross/orchestkit, 289 stars) and Composio (ComposioHQ/composio, 30k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Validate OAuth Integration?

rome-os (a GitHub organization) maintains it in rome-os/rome, which has 725 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on October 8, 2026.

Source: rome-os/rome on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.