Oauth2 Provider Design

samber/developer-platform-skills/skills/oauth2-provider-design

by samber594cf70d343eMIT3 starsListed Oct 8, 2026Updated Oct 8, 2026Repository updated 10 days ago

Design the OAuth2 authorization-server surface a B2B SaaS offers third-party apps - the OAuth 2.1 protocol baseline (PKCE for every client, no implicit or password grants, exact redirect matching), token TTL and refresh-rotation policy, scope taxonomy and granularity, consent-screen design with partial and incremental grants, client registration posture, and the tiered app-verification program. Use whenever the user mentions OAuth, "Sign in with X", access and refresh tokens, scopes, consent screens, PKCE, or third-party apps acting on a customer's behalf - even if they never say "OAuth provider". Issuer side only, not integrating against someone else's OAuth. Do NOT use for API-key design - use samber/developer-platform-skills@api-auth-key-management instead.

Only the file list is public. File contents are available once the skill is installed in a workspace.

PathSizeType
evals/evals.json35.2 KBapplication/json
references/app-verification-program.md8.1 KBtext/markdown
references/consent-screen-design.md4.5 KBtext/markdown
references/protocol-baseline.md6.2 KBtext/markdown
references/scope-taxonomy-archetypes.md6 KBtext/markdown
SKILL.md22.1 KBtext/markdown

Source and attribution

Source:samber/developer-platform-skillsinskills/oauth2-provider-designat commit594cf70

License: MIT

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal