Secure OAUTH Oidc

Design, implement, audit, test, troubleshoot, or migrate secure OAuth 2.0 and OpenID Connect (OIDC) systems using RFC 9700 / BCP 240. Use for authorization servers and OpenID Providers, OAuth clients and OIDC relying parties, resource servers, native apps, browser-based apps, multi-issuer login, redirect URIs, authorization code and PKCE flows, state and nonce handling, ID Token validation, token storage and replay, refresh-token rotation, sender-constrained tokens (DPoP or mTLS), mix-up and injection attacks, discovery and metadata, reverse proxies, or migration away from implicit and resource-owner-password grants.

citypaul Updated

File contents

citypaul/.dotfiles/tree/main/claude/.claude/skills/secure-oauth-oidc commit b2d9beb8e4

Frequently asked questions

npx skillmds@latest add citypaul/secure-oauth-oidc