Oauth2 Provider Design

samber/developer-platform-skills/skills/oauth2-provider-design

作者 samber594cf70d343eMIT3 个星标收录于 2026年10月8日更新于 2026年10月8日仓库10天前更新

Design the OAuth2 authorization-server surface a B2B SaaS offers third-party apps - the OAuth 2.1 protocol baseline (PKCE for every client, no implicit or password grants, exact redirect matching), token TTL and refresh-rotation policy, scope taxonomy and granularity, consent-screen design with partial and incremental grants, client registration posture, and the tiered app-verification program. Use whenever the user mentions OAuth, "Sign in with X", access and refresh tokens, scopes, consent screens, PKCE, or third-party apps acting on a customer's behalf - even if they never say "OAuth provider". Issuer side only, not integrating against someone else's OAuth. Do NOT use for API-key design - use samber/developer-platform-skills@api-auth-key-management instead.

  1. 594cf70d343e当前提交 594cf70发布于 2026年10月8日

来源与署名

来源:samber/developer-platform-skills位于skills/oauth2-provider-design提交594cf70

许可证: MIT

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架