Edge Copy setup link
Skill evidence / oauth2-provider-design
Skill profile

oauth2-provider-design

Design the OAuth2 authorization-server surface a B2B SaaS offers third-party apps - the OAuth 2.1...

What this skill does for you

Design the OAuth2 authorization-server surface a B2B SaaS offers third-party apps - the OAuth 2.1 protocol baseline (PKCE for every client, no implicit or password grants, exact redirect matching), token TTL and refresh-rotation policy, scope taxonomy and granularity, consent-screen design with partial and incremental grants, client registration posture, and the tiered app-verification program. Use whenever the user mentions OAuth, "Sign in with X", access and refresh tokens, scopes, consent screens, PKCE, or third-party apps acting on a customer's behalf - even if they never say "OAuth provider". Issuer side only, not integrating against someone else's OAuth. Do NOT use for API-key design - use samber/developer-platform-skills@api-auth-key-management instead.

Quoted from the skill description in the pinned source

Who made it

Publishersamber
Installs373as of Sep 27, 2026

Use it with Edge

Set up Edge for me: read getedge.cc/SKILL.md and follow it. Then use Edge to load the oauth2-provider-design skill from samber/developer-platform-skills.

Paste it into Claude, ChatGPT, Codex or Cursor.

Or read the skill source first.

Security evidence

Security state at 2026-09-30: reviewed. State definitions. This records static evidence for this revision; live load eligibility is checked again.

3 static scans, 0 counted findings. The listed scanners recorded the results shown for this package revision.

ScannerDateResultFindings
Edge static checks2026-09-27Pass0
Cisco skill-scanner2026-09-27Pass0
Semgrep Edge rules2026-09-27Pass0

Static scans check the code, not how well the skill works.

Scanner scope, raw findings and mirrored provider records

Edge static checks (Edge-run): edge-static/1.0.1. Scope: Static patterns for remote execution, credentials with network sends, obfuscation, prompt overrides, hidden Unicode, binaries and persistence. Revision: 37219ca68b5b97789172a67d6241e7524577f949. Raw findings: . Counted findings: .

Cisco skill-scanner (Edge-run): cisco-skill-scanner/2.1.0. Scope: Local static, YARA, pipeline and behavioral analyzers; no LLM or AI Defense analysis. Revision: 37219ca68b5b97789172a67d6241e7524577f949. Raw findings: . Counted findings: .

Semgrep Edge rules (Edge-run): semgrep/1.178.0+edge-rules.c15016a36fd3+offline-v1. Scope: Six Edge-authored static rules with Semgrep CE; offline execution and metrics disabled. Semgrep-maintained rules excluded. Revision: 37219ca68b5b97789172a67d6241e7524577f949. Raw findings: . Counted findings: .

Source and licence

Repository
https://github.com/samber/developer-platform-skills
Pinned skill file
View source at revision
Revision
37219ca68b5b97789172a67d6241e7524577f949
Package hash
sha256:591b9955ec6358fdc159a582d4cb20111fa6261e1e39fccb75b3f21e17f5465a
Licence
MIT