Agent skill

Oauth2 Resource Server

by rrezartprebreza in rrezartprebreza/spring-boot-skills

A skill your agent uses when configuring Spring Boot as an OAuth2 resource server, validating JWTs from an external auth provider (Keycloak, Auth0, Okta, Cognito), extracting claims, or implementing…

MITAuto-check passedBackend & APIs

Install Oauth2 Resource Server

skills CLI
$ npx skills add rrezartprebreza/spring-boot-skills --skill oauth2-resource-server -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install rrezartprebreza/spring-boot-skills oauth2-resource-server --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/rrezartprebreza/spring-boot-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/spring-boot-3/oauth2-resource-server .claude/skills/oauth2-resource-server && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
oauth2-resource-server
GitHub stars
301
Token cost
~1.2k tokens
SKILL.md length
73 words
Files
6
Skills in repo
51
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when configuring Spring Boot as an OAuth2 resource server, validating JWTs from an external auth provider (Keycloak, Auth0, Okta, Cognito), extracting claims, or implementing…

  • Configuring Spring Boot as an OAuth2 resource server
  • SKILL.md covers Dependency, Security Configuration, application.yml — Common… and Custom Claim Extraction, plus 3 more sections
  • Runs Java scripts from its folder
  • Validating JWTs from an external auth provider (Keycloak

What it does

Oauth2 Resource Server is an agent skill from rrezartprebreza/spring-boot-skills. Use when configuring Spring Boot as an OAuth2 resource server, validating JWTs from an external auth provider (Keycloak, Auth0, Okta, Cognito), extracting claims, or implementing scope-based authorization.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files (for example `agents/openai.yaml`).

It sits in Backend & APIs, covering OAuth and OpenID Connect, Backend development and Authentication. It works with Spring Boot, Auth0 and Okta. The repository describes itself as: Production-grade Claude Code and Codex skills for Spring Boot developers. The licence is MIT.

When your agent uses it

  • Configuring Spring Boot as an OAuth2 resource server
  • Validating JWTs from an external auth provider (Keycloak
  • Extracting claims
  • Implementing scope-based authorization

Example prompts

  • “/oauth2-resource-server”

What it can do on your machine

Read from SKILL.md and the folder at commit f0c06a0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Java), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Oauth2 Resource Server loads about 1.2k tokens when it runs. Until then it costs about 57 tokens; SKILL.md has 73 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~57
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from rrezartprebreza/spring-boot-skills at commit f0c06a0, republished under its MIT licence (© rrezartprebreza). 73 words, ~1,164 tokens.

Download SKILL.mdSave it as .claude/skills/oauth2-resource-server/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
oauth2-resource-server
description
Use when configuring Spring Boot as an OAuth2 resource server, validating JWTs from an external auth provider (Keycloak, Auth0, Okta, Cognito), extracting claims, or implementing scope-based authorization.

OAuth2 Resource Server

Dependency

xml
<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-oauth2-resource-server</artifactId>
</dependency>

Security Configuration

java
@Configuration
@EnableWebSecurity
@EnableMethodSecurity
public class ResourceServerConfig {

    @Bean
    public SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
        return http
            .csrf(AbstractHttpConfigurer::disable)
            .sessionManagement(s -> s.sessionCreationPolicy(STATELESS))
            .authorizeHttpRequests(auth -> auth
                .requestMatchers("/actuator/health").permitAll()
                .requestMatchers("/api/v1/admin/**").hasAuthority("SCOPE_admin")
                .anyRequest().authenticated()
            )
            .oauth2ResourceServer(oauth2 -> oauth2
                .jwt(jwt -> jwt.jwtAuthenticationConverter(jwtAuthConverter()))
            )
            .build();
    }

    @Bean
    public JwtAuthenticationConverter jwtAuthConverter() {
        var converter = new JwtGrantedAuthoritiesConverter();
        converter.setAuthoritiesClaimName("roles"); // Keycloak uses "roles"
        converter.setAuthorityPrefix("ROLE_");

        var authConverter = new JwtAuthenticationConverter();
        authConverter.setJwtGrantedAuthoritiesConverter(converter);
        return authConverter;
    }
}

application.yml — Common Providers

yaml
# Keycloak
spring:
  security:
    oauth2:
      resourceserver:
        jwt:
          issuer-uri: https://keycloak.example.com/realms/my-realm
          jwk-set-uri: https://keycloak.example.com/realms/my-realm/protocol/openid-connect/certs

# Auth0
spring:
  security:
    oauth2:
      resourceserver:
        jwt:
          issuer-uri: https://your-domain.auth0.com/
          audiences: https://your-api.example.com  # custom claim validation

Custom Claim Extraction

java
@Component
public class JwtClaimExtractor {

    public UUID getUserId(JwtAuthenticationToken token) {
        return UUID.fromString(token.getToken().getClaimAsString("sub"));
    }

    public String getEmail(JwtAuthenticationToken token) {
        return token.getToken().getClaimAsString("email");
    }

    public List<String> getRoles(JwtAuthenticationToken token) {
        // Keycloak nests roles under realm_access.roles
        Map<String, Object> realmAccess = token.getToken().getClaimAsMap("realm_access");
        if (realmAccess == null) return List.of();
        return (List<String>) realmAccess.getOrDefault("roles", List.of());
    }
}

Controller — Accessing Current User

java
@RestController
@RequiredArgsConstructor
public class OrderController {

    @GetMapping("/api/v1/orders/my")
    public ApiResponse<List<OrderResponse>> myOrders(
        @AuthenticationPrincipal Jwt jwt  // inject JWT directly
    ) {
        UUID userId = UUID.fromString(jwt.getSubject());
        return ApiResponse.ok(orderService.findByUser(userId));
    }

    // Or with JwtAuthenticationToken for full principal
    @GetMapping("/api/v1/profile")
    public ApiResponse<ProfileResponse> profile(JwtAuthenticationToken token) {
        return ApiResponse.ok(userService.findByEmail(
            token.getToken().getClaimAsString("email")
        ));
    }
}

Method Security with Scopes

java
@PreAuthorize("hasAuthority('SCOPE_orders:read')")
public List<Order> findAll() { ... }

@PreAuthorize("hasRole('ADMIN') or @orderSecurity.isOwner(#orderId, authentication)")
public Order findById(UUID orderId) { ... }

// Custom security bean
@Component("orderSecurity")
public class OrderSecurityService {
    public boolean isOwner(UUID orderId, Authentication auth) {
        Jwt jwt = (Jwt) auth.getPrincipal();
        UUID userId = UUID.fromString(jwt.getSubject());
        return orderRepository.existsByIdAndCustomerId(orderId, userId);
    }
}

Gotchas

  • Agent uses hasRole("ADMIN") for scope check — scopes use hasAuthority("SCOPE_admin")
  • Agent forgets issuer-uri validation — always configure to prevent token forgery
  • Agent maps roles wrong for Keycloak — roles are nested under realm_access.roles
  • Agent uses getPrincipal() directly — cast to Jwt or use @AuthenticationPrincipal Jwt
  • Agent adds userDetailsService bean — not needed for resource servers (stateless JWT)

© rrezartprebreza, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files in skills/spring-boot-3/oauth2-resource-server of rrezartprebreza/spring-boot-skills.

  • SKILL.md
  • agents/openai.yaml
  • examples/bad-resource-server-config.java
  • examples/good-resource-server-config.java
  • templates/JwtClaimExtractor.java
  • templates/ResourceServerConfig.java

Open the folder on GitHubat commit f0c06a0

Compare with similar skills

Oauth2 Resource Server next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Oauth2 Resource Server compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Oauth2 Resource Server this skillrrezartprebreza/spring-boot-skills301—~1.2kAutomated safety check: PassMIT
Spring Boot Security JWTgiuseppe-trisciuoglio/developer-kit357—~3.9kAutomated safety check: NotesMIT
Java ArchitectJeffallan/claude-skills12k—~1.5kAutomated safety check: PassMIT
Iam Auditbriiirussell/cybersecurity-skills413—~3.1kAutomated safety check: NotesMIT
Cometchat Securitycometchat/cometchat-skills132—~1.9kAutomated safety check: PassMIT
Fortify Developmentcoollabsio/coolify63k4 repos~1.9kAutomated safety check: PassMIT

Similar skills

  • Spring Boot Security JWT

    giuseppe-trisciuoglio/developer-kit

    Provides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based…

    357 GitHub stars~3.9k tokensUpdated 1 mo ago
    Backend & APIsAuto-check: notes
  • Java Architect

    Jeffallan/claude-skills

    Builds Spring Boot 3.x services on Java 21 with domain-driven design, WebFlux, JPA tuning and Spring Security using OAuth2 and JWT, verified by Maven or Gradle builds.

    12k GitHub stars~1.5k tokensUpdated 7 days ago
    Backend & APIsAuto-check passed
  • Iam Audit

    briiirussell/cybersecurity-skills

    Audit, design, and migrate Identity and Access Management — cloud provider IAM (AWS, GCP, Azure), identity providers (Okta, Entra ID / Azure AD, Auth0, Google Workspace), application authorization…

    413 GitHub stars~3.1k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes
  • Cometchat Security

    cometchat/cometchat-skills

    Enterprise auth & access control for CometChat — SSO/OIDC/SAML via your own IdP, server-minted auth tokens, token revocation & session control, and role-based access (RBAC app-wide roles + group…

    132 GitHub stars~1.9k tokensUpdated 5 days ago
    Backend & APIsAuto-check passed
  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed
  • Socialite Development

    hexlet-volunteers/hexlet-sicp

    Manages OAuth social authentication with Laravel Socialite. An agent skill from hexlet-volunteers/hexlet-sicp.

    114 GitHub starsUsed in 5 repos~1.2k tokens
    Backend & APIsAuto-check passed

More from rrezartprebreza/spring-boot-skills

All 51 skills in this repo
  • AI Observability

    rrezartprebreza/spring-boot-skills

    A skill your agent uses when adding Spring AI-specific model observations, token usage, latency, externally configured cost attribution, advisor telemetry, or protected prompt and completion logging.

    301 GitHub stars~1.6k tokensUpdated 19 days ago
    Auto-check passed
  • API Versioning

    rrezartprebreza/spring-boot-skills

    A skill your agent uses when versioning Spring MVC or WebFlux APIs in Spring Boot 3 / Spring Framework 6.

    301 GitHub stars~516 tokensUpdated 19 days ago
    Auto-check passed
  • API Versioning

    rrezartprebreza/spring-boot-skills

    A skill your agent uses when versioning Spring MVC or WebFlux APIs in Spring Boot 4 / Spring Framework 7.

    301 GitHub stars~643 tokensUpdated 19 days ago
    Auto-check passed
  • Container Native Deployment

    rrezartprebreza/spring-boot-skills

    A skill your agent uses when packaging a Spring Boot 3 application as an OCI image or GraalVM native executable.

    301 GitHub stars~781 tokensUpdated 19 days ago
    Auto-check passed
  • Container Native Deployment

    rrezartprebreza/spring-boot-skills

    A skill your agent uses when packaging Spring Boot 4 as an OCI image, JVM container, AOT application, or GraalVM native executable.

    301 GitHub stars~706 tokensUpdated 19 days ago
    Auto-check passed
  • Domain Driven Design

    rrezartprebreza/spring-boot-skills

    A skill your agent uses when evolving aggregate invariants, value objects or domain events in an existing DDD-style Spring Boot 3 application, or when DDD is explicitly requested.

    301 GitHub stars~2.1k tokensUpdated 19 days ago
    Auto-check passed

Categories

Questions about Oauth2 Resource Server

What does Oauth2 Resource Server do?

A skill your agent uses when configuring Spring Boot as an OAuth2 resource server, validating JWTs from an external auth provider (Keycloak, Auth0, Okta, Cognito), extracting claims, or implementing…. Oauth2 Resource Server is an agent skill from rrezartprebreza/spring-boot-skills. Use when configuring Spring Boot as an OAuth2 resource server, validating JWTs from an external auth provider (Keycloak, Auth0, Okta, Cognito), extracting claims, or implementing scope-based authorization.

When should I use Oauth2 Resource Server?

Oauth2 Resource Server fits situations like: configuring Spring Boot as an OAuth2 resource server; validating JWTs from an external auth provider (Keycloak; extracting claims; implementing scope-based authorization.

How do I install Oauth2 Resource Server in Claude Code?

Run `npx skills add rrezartprebreza/spring-boot-skills --skill oauth2-resource-server -a claude-code`. Or copy the skill folder (skills/spring-boot-3/oauth2-resource-server in rrezartprebreza/spring-boot-skills) into .claude/skills/oauth2-resource-server in your project. Claude Code loads it when a task matches its description.

How do I install Oauth2 Resource Server in Codex?

Run `npx skills add rrezartprebreza/spring-boot-skills --skill oauth2-resource-server -a codex`. Or copy the skill folder (skills/spring-boot-3/oauth2-resource-server in rrezartprebreza/spring-boot-skills) into .agents/skills/oauth2-resource-server in your project. Codex loads it when a task matches its description.

Can I use Oauth2 Resource Server in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add rrezartprebreza/spring-boot-skills --skill oauth2-resource-server -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/oauth2-resource-server, .gemini/skills/oauth2-resource-server, .github/skills/oauth2-resource-server and .opencode/skills/oauth2-resource-server in your project.

What does Oauth2 Resource Server need to run?

Going by SKILL.md and its folder, Oauth2 Resource Server needs Java for the scripts in its folder.

Does Oauth2 Resource Server access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Oauth2 Resource Server safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Oauth2 Resource Server use?

Oauth2 Resource Server is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Oauth2 Resource Server use?

About 1.2k tokens (SKILL.md is roughly 4.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Oauth2 Resource Server?

Skills that share tags, products or a category with Oauth2 Resource Server: Spring Boot Security JWT (giuseppe-trisciuoglio/developer-kit, 357 stars), Java Architect (Jeffallan/claude-skills, 12k stars), Iam Audit (briiirussell/cybersecurity-skills, 413 stars) and Cometchat Security (cometchat/cometchat-skills, 132 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Oauth2 Resource Server?

rrezartprebreza (a GitHub user) maintains it in rrezartprebreza/spring-boot-skills, which has 301 GitHub stars. The repository holds 51 skills in this directory. The repository was last updated on September 21, 2026.

Source: rrezartprebreza/spring-boot-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.