
Oauth2 Provider Design
samber/developer-platform-skills/skills/oauth2-provider-designby samber594cf70d343eMIT3 starsListed Oct 8, 2026Updated Oct 8, 2026Repository updated 10 days ago
Design the OAuth2 authorization-server surface a B2B SaaS offers third-party apps - the OAuth 2.1 protocol baseline (PKCE for every client, no implicit or password grants, exact redirect matching), token TTL and refresh-rotation policy, scope taxonomy and granularity, consent-screen design with partial and incremental grants, client registration posture, and the tiered app-verification program. Use whenever the user mentions OAuth, "Sign in with X", access and refresh tokens, scopes, consent screens, PKCE, or third-party apps acting on a customer's behalf - even if they never say "OAuth provider". Issuer side only, not integrating against someone else's OAuth. Do NOT use for API-key design - use samber/developer-platform-skills@api-auth-key-management instead.
Add to a SourceWeft workspace
- Open the skill in your dashboard and add it to a workspace.
- Enable it for the chats that should use it.
This skill is instructions only: it ships no scripts to execute.
Add to SourceWeftYou will be asked to sign in first, then taken straight to this skill.
Ask your agent to install it
Paste this prompt into Claude Code, Codex, Cursor or another agent that can run commands — or into SourceWeft chat. The agent reads this skill's install guide, shows you its source, license and scripts, and installs it with the SourceWeft CLI once you agree.
Read https://sourceweft.com/skills/gh-samber-developer-platform-skills-oauth2-provider-design/install.md and install the skill it describes. Before installing, show me its source, license and whether it ships scripts, and wait for my OK. Ask me before changing anything else on my machine.Install it yourself from a terminal
For Claude Code, Codex, Cursor and other local agents. The SourceWeft CLI fetches the skill from its source repository at the commit scanned here, and verifies every file against the hashes recorded when the skill was scanned. If anything differs, nothing is written.
npx @sourceweft/cli skills install @samber/oauth2-provider-designAdd --agent claude-code, codex, cursor or universal to choose which agent gets it (Claude Code by default).
Upstream installer — not verified by SourceWeft
The open-source skills installer fetches the same pinned commit, but does not check the files against the hashes SourceWeft recorded.
npx skills add https://github.com/samber/developer-platform-skills/tree/594cf70d343e34339e8f83610e33b0b2c3945fd4/skills/oauth2-provider-designSource and attribution
Source:samber/developer-platform-skillsinskills/oauth2-provider-designat commit594cf70
License: MIT
Content belongs to its original authors. SourceWeft indexes it from a public repository.
More from samber/developer-platform-skills

Webhook Platform Design
samber
Designs a provider-side outbound webhook platform: event catalog, payload envelope, signing, retries, subscriptions and debugging.

Sql Jdbc Access Design
samber
Designs customer-facing SQL access to a SaaS product's data, covering architecture, isolation, schema contracts, governance and pricing.

Sdk Portfolio Strategy
samber
Guides platform teams in writing a public API SDK portfolio strategy: language order, build model, support tiers, versioning and EOL.

Public Graphql Api Design
samber
Designs public GraphQL API surfaces: schema conventions, Relay pagination, typed errors, guardrails and federation boundaries.

Public Api Design Review
samber
Checklist-driven design review of public REST API surfaces, bucketing findings as Must-change or Improvement against cited rules.

Partner App Onboarding
samber
Designs a B2B SaaS partner-developer onboarding journey from signup to first submitted app, with gates, provisioning, education, support and funnel metrics.
More in Software Development

Playground
anthropics
Builds self-contained interactive HTML playgrounds with controls, live preview, and copyable prompt output.

M5 Onboard
anthropics
Provisions M5Stack ESP32 boards by detecting them on USB, flashing UIFlow 2.0 firmware, and installing a MicroPython app bundle.

Cardputer Buddy
anthropics
Guides iterating on a Cardputer-Adv MicroPython app bundle: adding apps, pushing files over USB-serial, tailing logs, and running REPL commands.

Web Design Guidelines
vercel-labs
Reviews UI code against Web Interface Guidelines fetched from a remote source and reports findings as file:line entries.

Vercel React Native Skills
vercel-labs
React Native and Expo best-practice rules covering list performance, animation, navigation, UI patterns, state, and monorepo setup.

Vercel React Best Practices
vercel-labs
Vercel's React and Next.js performance guidelines, organized as 70 rules for writing, reviewing, and refactoring code.