# Detecting OAUTH Token Theft

> Detect OAuth access token theft and misuse by analyzing sign-in logs for impossible travel, new device patterns, token replay from unusual IPs, and anomalous scope requests via Microsoft Graph and Okta APIs.

- Skill: `autohandai-community-skills/detecting-oauth-token-theft` (Agent Skill, multi-file: 4 files)
- Install (CLI): `npx skillmds@latest add autohandai-community-skills/detecting-oauth-token-theft`
- Raw SKILL.md: https://api.skillmd.com/api/skills/autohandai-community-skills/detecting-oauth-token-theft/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Integrations & APIs
- License: Apache-2.0
- Author: autohandai (https://skillmd.com/u/autohandai-community-skills)
- Updated: 2026-09-21
- Page: https://skillmd.com/skills/autohandai-community-skills/detecting-oauth-token-theft

---


# Detecting OAuth Token Theft

Analyze OAuth sign-in telemetry for indicators of token theft including
impossible travel, device fingerprint changes, and token replay attacks.

