skills/oauth-oidc-implementer/SKILL.md
--- license: Apache-2.0 name: oauth-oidc-implementer version: 1.0.0 category: Security tags: - oauth - oidc - authentication - authorization - jwt - security --- # OAuth/OIDC Implementer Expert in implementing OAuth 2.0 and OpenID Connect (OIDC) authentication flows. Specializes in secure token handling, social login integration, API authorization, and identity provider configuration. ## Decision Points ### Flow Selection Matrix **For Web Applications (with backend):** - If fron
npx skillsauth add curiositech/windags-skills oauth-oidc-implementerInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Expert in implementing OAuth 2.0 and OpenID Connect (OIDC) authentication flows. Specializes in secure token handling, social login integration, API authorization, and identity provider configuration.
For Web Applications (with backend):
For API Access:
For Enterprise SSO:
Access Tokens:
Refresh Tokens:
Detection: Error response contains "error": "invalid_grant"
Root Cause: Authorization code expired (>10min) or PKCE verifier mismatch
Fix: Implement proper code exchange timing and verify PKCE generation/storage
Detection: API returns 401 with expired token, no automatic retry Root Cause: Missing token refresh logic or refresh token rotation failure Fix: Implement automatic refresh with race condition handling and fallback to login
Detection: OAuth callback validation fails with state parameter errors Root Cause: State not properly stored/validated or CSRF attack in progress Fix: Verify state generation uses cryptographically secure randomness and server-side validation
Detection: Requesting excessive scopes (scope=* or kitchen-sink permissions)
Root Cause: Over-requesting permissions instead of minimal viable scopes
Fix: Request only needed scopes initially, use incremental authorization for additional permissions
Detection: Infinite redirects between app and identity provider Root Cause: Session state mismatch or malformed logout implementation Fix: Implement proper session cleanup and logout flow with back-channel notification
Scenario: React app implementing "Login with Google" using Authorization Code + PKCE
Step 1: Initialize Flow
// Expert catches: PKCE generation must be cryptographically secure
const codeVerifier = base64URLEncode(crypto.getRandomValues(new Uint8Array(32)));
const codeChallenge = base64URLEncode(await crypto.subtle.digest('SHA-256', new TextEncoder().encode(codeVerifier)));
// Novice misses: State must be stored server-side to prevent tampering
const state = crypto.randomUUID();
sessionStorage.setItem('oauth_state', state);
sessionStorage.setItem('pkce_verifier', codeVerifier);
Step 2: Decision Point Navigation
openid profile email onlyStep 3: Handle Callback
// Expert validates: State MUST match exactly
if (urlState !== sessionStorage.getItem('oauth_state')) {
throw new Error('CSRF protection failed');
}
// Novice misses: Code verifier must be included in token exchange
const tokenRequest = {
grant_type: 'authorization_code',
code: authCode,
code_verifier: sessionStorage.getItem('pkce_verifier'),
client_id: CLIENT_ID,
redirect_uri: REDIRECT_URI
};
Step 4: Token Handling
Implementation checklist for production readiness:
Do NOT use this skill for:
api-security-specialist for static API keysauthentication-specialist for credential handlingenterprise-sso-architect for SAML-specific flowsjwt-specialist for application-specific token generationDelegate to other skills:
tls-certificate-managerdatabase-architectapi-rate-limitersecurity-monitoring-specialistdata-ai
license: Apache-2.0 NOT for unrelated tasks outside this domain.
development
Use when designing caching strategies (cache-aside, write-through, write-behind), implementing distributed locks, building rate limiters, leaderboards, real-time streams (XADD/consumer groups), pub/sub, or tuning eviction policies. Triggers: thundering-herd on cache miss, dogpile on key expiry, Redlock vs SET-NX-PX choice, sliding-window rate limiter, hot-key on a single cluster slot, big-key blowup, MULTI/EXEC across slots, KEYS in production. NOT for Redis Cluster operations/admin (different domain), embedded KV (SQLite, leveldb), in-process LRU caches, or Memcached.
tools
Drawing the `'use client'` boundary correctly in React Server Components apps (Next.js App Router, RSC frameworks) — leaf-pushing, slot composition, serialization rules, and environment poisoning prevention. Grounded in react.dev and Next.js 16 docs.
development
Use when designing rate limiting for an API, choosing between token bucket / sliding window / leaky bucket / fixed window, implementing it in Redis, deciding edge (Cloudflare/Upstash) vs origin enforcement, sizing per-user vs per-IP vs per-endpoint quotas, returning the right 429 response with Retry-After, or fixing the boundary-burst bug in fixed-window limiters. Triggers: 429 too many requests, INCR + EXPIRE, ZADD + ZREMRANGEBYSCORE + ZCARD, X-RateLimit-Remaining header, Cloudflare WAF rate limiting rules, Upstash @upstash/ratelimit, leaky bucket shaping vs policing, distributed rate limiter consistency. NOT for DDoS mitigation specifically (different scale), CAPTCHA / bot management, full WAF design, or per-user quota billing.