agentsclimarketplace

Oauth

Skill G1Joshi/Agent-Skills/skills/security/oauth

A comprehensive skill catalog for AI agents

Install
npx -y skills add G1Joshi/Agent-Skills --skill oauth

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 10 stars10 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

OAuth 2.0 authorization framework. Use for authorization.

SKILL.md

2.8 KB, as published. Nobody here has run it

OAuth 2.1

OAuth 2.1 is the consolidation of OAuth 2.0 and its best practices into a single standard. It allows third-party applications to grant limited access to an HTTP service through an authorization server.

When to Use

  • Social Login: "Log in with Google/Facebook".
  • Third-Party Access: Giving a budgeting app access to your bank APIs.
  • Microservices: Service A accessing Service B on behalf of a user.

Quick Start (Authorization Code Flow with PKCE)

// Client (Frontend) - redirect to Auth Server
const authUrl = `https://auth.example.com/authorize?
  response_type=code&
  client_id=${CLIENT_ID}&
  redirect_uri=${REDIRECT_URI}&
  scope=read:profile&
  code_challenge=${pkceChallenge}&
  code_challenge_method=S256`;

window.location.href = authUrl;

// Callback (Handling the redirect)
const code = new URLSearchParams(window.location.search).get("code");
const tokenResponse = await fetch("https://auth.example.com/token", {
  method: "POST",
  body: JSON.stringify({
    grant_type: "authorization_code",
    code,
    client_id: CLIENT_ID,
    redirect_uri: REDIRECT_URI,
    code_verifier: pkceVerifier, // Proof Key
  }),
});

Core Concepts

Roles

  • Resource Owner: The User.
  • Client: The App (Web, Mobile, Server).
  • Authorization Server: The Identity Provider (Auth0, Okta, Google).
  • Resource Server: The API holding the data.

PKCE (Proof Key for Code Exchange)

Now Mandatory in OAuth 2.1 for all clients (public and confidential). Prevents authorization code interception attacks.

Grants (Flows)

  • Authorization Code: The standard flow (Web/Mobile).
  • Client Credentials: Machine-to-Machine (No user).
  • Device Code: TV/Input-constrained devices.
  • Implicit Grant: REMOVED (Insecure). Do not use.
  • Password Grant: REMOVED (Insecure). Do not use.

Best Practices (2025)

Do:

  • Use Authorization Code Flow with PKCE for everything.
  • Validate Exact Redirect URIs (No wildcards).
  • Use Sender-Constrained Tokens (DPoP or mTLS) to prevent token replay/theft.

Don't:

  • Don't use the Implicit Grant (access token in URL fragment).
  • Don't store Access Tokens in localStorage (XSS risk). Use HttpOnly cookies or memory.

Troubleshooting

ErrorCauseSolution
invalid_grantCode expired or reused.Get a new authorization code.
redirect_uri_mismatchURI doesn't match allowlist.Check dashboard settings exactly.

References

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.