
Oauth2 Provider Design
samber/developer-platform-skills/skills/oauth2-provider-design作者 samber594cf70d343eMIT3 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫10 天前更新
Design the OAuth2 authorization-server surface a B2B SaaS offers third-party apps - the OAuth 2.1 protocol baseline (PKCE for every client, no implicit or password grants, exact redirect matching), token TTL and refresh-rotation policy, scope taxonomy and granularity, consent-screen design with partial and incremental grants, client registration posture, and the tiered app-verification program. Use whenever the user mentions OAuth, "Sign in with X", access and refresh tokens, scopes, consent screens, PKCE, or third-party apps acting on a customer's behalf - even if they never say "OAuth provider". Issuer side only, not integrating against someone else's OAuth. Do NOT use for API-key design - use samber/developer-platform-skills@api-auth-key-management instead.
新增到 SourceWeft 工作區
- 在儀表板中開啟該技能,並將它新增到工作區。
- 為需要使用它的對話啟用該技能。
該技能僅含說明:不附帶任何可執行的腳本。
新增到 SourceWeft系統會先要求你登入,然後直接帶你回到這個技能。
讓你的代理程式來安裝
把這段提示詞貼上到 Claude Code、Codex、Cursor 或其他能執行命令的代理程式中,也可以貼上到 SourceWeft 對話裡。代理程式會閱讀這個技能的安裝說明,向你展示它的來源、授權條款和腳本情況,在你同意後用 SourceWeft CLI 安裝。
閱讀 https://sourceweft.com/skills/gh-samber-developer-platform-skills-oauth2-provider-design/install.md 中的說明,按說明安裝這個技能。安裝前先告訴我它的來源、授權條款以及是否附帶腳本,等我確認。修改我電腦上的其他任何內容之前也要先問我。用命令列自行安裝
適用於 Claude Code、Codex、Cursor 及其他本機代理程式。SourceWeft CLI 會從原始碼儲存庫中取得此處掃描過的那次提交,並根據掃描時記錄的雜湊值逐一驗證每個檔案。只要有任何不一致,就不會寫入任何內容。
npx @sourceweft/cli skills install @samber/oauth2-provider-design新增 --agent claude-code、codex、cursor 或 universal 來選擇安裝給哪個代理程式(預設為 Claude Code)。
上游安裝器——未經 SourceWeft 驗證
開源的 skills 安裝器會取得同一個固定的提交,但不會根據 SourceWeft 記錄的雜湊值驗證檔案。
npx skills add https://github.com/samber/developer-platform-skills/tree/594cf70d343e34339e8f83610e33b0b2c3945fd4/skills/oauth2-provider-design來源與署名
來源:samber/developer-platform-skills位於skills/oauth2-provider-design提交594cf70
授權條款: MIT
內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。
更多來自 samber/developer-platform-skills 的技能

Webhook Platform Design
samber
設計供應方出站 Webhook 平台:事件目錄、酬載封裝、簽章、重試、訂閱與除錯介面。

Sql Jdbc Access Design
samber
設計面向客戶的 SQL 資料存取方案,涵蓋架構、隔離、結構描述契約、治理與定價。

Sdk Portfolio Strategy
samber
指導平台團隊撰寫公開 API 的 SDK 組合策略:語言順序、建置模式、支援層級、版本管理與退役。

Public Graphql Api Design
samber
設計供第三方使用的公開 GraphQL API:結構定義慣例、Relay 分頁、具型別錯誤、防護上限與聯邦邊界。

Public Api Design Review
samber
以檢核清單驅動的公開 REST API 設計審查,將發現項目依引用規則歸為必須修改或改進。

Partner App Onboarding
samber
為 B2B SaaS 平台設計合作夥伴開發者入駐歷程,從註冊到首次提交應用程式,涵蓋准入、環境開通、教育、支援與漏斗指標。
更多Software Development技能

Playground
anthropics
建立自成一體的互動式 HTML 遊樂場,包含控制項、即時預覽與可複製的提示詞輸出。

M5 Onboard
anthropics
透過 USB 偵測 M5Stack ESP32 開發板,燒錄 UIFlow 2.0 韌體並安裝 MicroPython 應用程式套件。

Cardputer Buddy
anthropics
指導迭代 Cardputer-Adv 的 MicroPython 應用程式套件:新增應用程式、透過 USB 序列埠推送檔案、查看日誌並執行 REPL 指令。

Web Design Guidelines
vercel-labs
依據從遠端來源取得的 Web Interface Guidelines 審查 UI 程式碼,並以 file:line 形式回報問題。

Vercel React Native Skills
vercel-labs
React Native 與 Expo 最佳實務規則,涵蓋清單效能、動畫、導覽、UI 模式、狀態與 monorepo 設定。

Vercel React Best Practices
vercel-labs
Vercel 的 React 與 Next.js 效能指南,以 70 條規則的形式用於撰寫、審查與重構程式碼。