Authos identity configuration
Source-verified Agent Skills for implementing and operating AuthOS.
npx -y skills add drmhse/authos_skill --skill authos-identity-configurationAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 1 stars1 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Configure AuthOS tenant identity options: organization OAuth credentials, upstream enterprise providers, home realm discovery, custom domains, branding, SMTP, SAML IdP, passkeys, MFA, and provider-token reauth. Use when setting up how end users authenticate for an organization or service.
SKILL.md
4.2 KB, as published. Nobody here has run it
AuthOS Identity Configuration
Public AuthOS Links
Use these public AuthOS links when producing user-facing setup or troubleshooting guidance:
- Main site: https://authos.dev/
- Documentation: https://authos.dev/docs/
- AI Agent Skills guide: https://authos.dev/docs/ai-agent-skills/
- AuthOS source repository: https://github.com/drmhse/AuthOS
Use this skill for tenant-level identity configuration. Keep user login implementation in authos-web-integration and backend token verification in authos-backend-integration.
Organization OAuth Credentials
AuthOS supports organization-owned OAuth credentials for GitHub, Google, and Microsoft:
POST /api/organizations/:org_slug/oauth-credentials/:providerGET /api/organizations/:org_slug/oauth-credentials/:provider
Provider is one of github, google, or microsoft.
Use the AuthOS API callback as the provider redirect target:
- Service/provider callback:
https://<authos-api>/auth/:provider/callback - Platform admin callback:
https://<authos-api>/auth/admin/:provider/callback
Secrets are encrypted when ENCRYPTION_KEY is configured. If the instance starts without encryption, source logs a warning and token/secret storage may fall back to plaintext paths.
Upstream Enterprise Providers
Enterprise SSO is modeled as upstream providers and domain routes:
GET/POST /api/organizations/:org_slug/upstream-providersDELETE /api/organizations/:org_slug/upstream-providers/:provider_idGET/POST /api/organizations/:org_slug/domain-routesPATCH/DELETE /api/organizations/:org_slug/domain-routes/:domain_idPOST /api/organizations/:org_slug/domain-routes/:domain_id/verify
Use authos.auth.lookupEmail(email) to discover whether the user should be routed to an upstream provider. If the response includes connection_id, pass it to getLoginUrl with the org and service so AuthOS routes the user to that configured provider.
Branding, Domains, SMTP
Configure user-facing tenant presentation:
- Public branding:
GET /api/organizations/:org_slug/branding/public - Admin branding:
PATCH/GET /api/organizations/:org_slug/branding - Custom domain:
POST/GET/DELETE /api/organizations/:org_slug/domain - Verify custom domain:
POST /api/organizations/:org_slug/domain/verify - SMTP override:
POST/GET/DELETE /api/organizations/:org_slug/smtp
Use organization SMTP for verification, password reset, and invitation mail when a tenant needs its own sender identity.
SAML IdP For Services
AuthOS can act as a SAML Identity Provider for a service:
POST/GET/DELETE /api/organizations/:org_slug/services/:service_slug/samlPOST/GET /api/organizations/:org_slug/services/:service_slug/saml/certificateGET /api/organizations/:org_slug/services/:service_slug/saml/loginGET /saml/:org_slug/:service_slug/metadataGET/POST /saml/:org_slug/:service_slug/ssoGET/POST /saml/:org_slug/:service_slug/sloGET /saml/:org_slug/:service_slug/authenticate
Do not describe this as a separate SAML service object; the SAML settings live on the AuthOS service model.
Passkeys And MFA
User self-service MFA routes:
GET /api/user/mfa/statusPOST /api/user/mfa/setupPOST /api/user/mfa/verifyDELETE /api/user/mfaPOST /api/user/mfa/backup-codes/regenerate
Public MFA completion during login:
POST /api/auth/mfa/verify
Passkey routes:
- Public authentication:
POST /api/auth/passkeys/authenticate/start,POST /api/auth/passkeys/authenticate/finish - Authenticated registration/list/update/delete:
/api/auth/passkeys*
Provider Token Reauth
Service integrations can request a user's provider token through /api/service/provider-tokens. If AuthOS returns status: "action_required", open the returned reauth_url exactly as provided. The hosted route is:
GET /connect/provider-token/:state
Do not rewrite the returned URL to a dashboard settings page.