
Oauth2 Provider Design
samber/developer-platform-skills/skills/oauth2-provider-designby samber594cf70d343eMIT3 starsListed Oct 8, 2026Updated Oct 8, 2026Repository updated 10 days ago
Design the OAuth2 authorization-server surface a B2B SaaS offers third-party apps - the OAuth 2.1 protocol baseline (PKCE for every client, no implicit or password grants, exact redirect matching), token TTL and refresh-rotation policy, scope taxonomy and granularity, consent-screen design with partial and incremental grants, client registration posture, and the tiered app-verification program. Use whenever the user mentions OAuth, "Sign in with X", access and refresh tokens, scopes, consent screens, PKCE, or third-party apps acting on a customer's behalf - even if they never say "OAuth provider". Issuer side only, not integrating against someone else's OAuth. Do NOT use for API-key design - use samber/developer-platform-skills@api-auth-key-management instead.
Only the file list is public. File contents are available once the skill is installed in a workspace.
| Path | Size | Type |
|---|---|---|
| evals/evals.json | 35.2 KB | application/json |
| references/app-verification-program.md | 8.1 KB | text/markdown |
| references/consent-screen-design.md | 4.5 KB | text/markdown |
| references/protocol-baseline.md | 6.2 KB | text/markdown |
| references/scope-taxonomy-archetypes.md | 6 KB | text/markdown |
| SKILL.md | 22.1 KB | text/markdown |
Source and attribution
Source:samber/developer-platform-skillsinskills/oauth2-provider-designat commit594cf70
License: MIT
Content belongs to its original authors. SourceWeft indexes it from a public repository.
More from samber/developer-platform-skills

Webhook Platform Design
samber
Designs a provider-side outbound webhook platform: event catalog, payload envelope, signing, retries, subscriptions and debugging.

Sql Jdbc Access Design
samber
Designs customer-facing SQL access to a SaaS product's data, covering architecture, isolation, schema contracts, governance and pricing.

Sdk Portfolio Strategy
samber
Guides platform teams in writing a public API SDK portfolio strategy: language order, build model, support tiers, versioning and EOL.

Public Graphql Api Design
samber
Designs public GraphQL API surfaces: schema conventions, Relay pagination, typed errors, guardrails and federation boundaries.

Public Api Design Review
samber
Checklist-driven design review of public REST API surfaces, bucketing findings as Must-change or Improvement against cited rules.

Partner App Onboarding
samber
Designs a B2B SaaS partner-developer onboarding journey from signup to first submitted app, with gates, provisioning, education, support and funnel metrics.
More in Software Development

Playground
anthropics
Builds self-contained interactive HTML playgrounds with controls, live preview, and copyable prompt output.

M5 Onboard
anthropics
Provisions M5Stack ESP32 boards by detecting them on USB, flashing UIFlow 2.0 firmware, and installing a MicroPython app bundle.

Cardputer Buddy
anthropics
Guides iterating on a Cardputer-Adv MicroPython app bundle: adding apps, pushing files over USB-serial, tailing logs, and running REPL commands.

Web Design Guidelines
vercel-labs
Reviews UI code against Web Interface Guidelines fetched from a remote source and reports findings as file:line entries.

Vercel React Native Skills
vercel-labs
React Native and Expo best-practice rules covering list performance, animation, navigation, UI patterns, state, and monorepo setup.

Vercel React Best Practices
vercel-labs
Vercel's React and Next.js performance guidelines, organized as 70 rules for writing, reviewing, and refactoring code.