Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add hoangatg/ai-agent-toolkit --skill oauth-authenticationgit clone --depth 1 https://github.com/hoangatg/ai-agent-toolkitWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/hoangatg/ai-agent-toolkit/oauth-authentication)<a href="https://agentmods.dev/skills/hoangatg/ai-agent-toolkit/oauth-authentication"><img src="https://agentmods.dev/badge/skills/hoangatg/ai-agent-toolkit/oauth-authentication/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/hoangatg/ai-agent-toolkit/oauth-authentication"><img src="https://agentmods.dev/badge/skills/hoangatg/ai-agent-toolkit/oauth-authentication.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00036 | $0.00913 |
| Opus 5 | $0.00018 | $0.00456 |
| Sonnet 5 | $0.00007 | $0.00183 |
| Haiku 4.5 | $0.00004 | $0.00091 |
Grade A, and why
oauth-authentication scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 120 lines — stays where its author put it; the contents beside it link to each section on GitHub.
OAuth & Authentication
Know who they are. Control what they can do. Do it securely.
1. Authentication Methods
| Method | Best For | Complexity |
|---|---|---|
| Session + Cookie | Server-rendered apps (Next.js, Rails) | Low |
| JWT (stateless) | SPAs, mobile apps, microservices | Medium |
| OAuth 2.0 | Third-party login (Google, GitHub) | Medium |
| Passkeys/WebAuthn | Passwordless, highest security | High |
| Magic Link | Email-based, no password | Low |
2. OAuth 2.0 Flows
| Flow | Use Case | Security |
|---|---|---|
| Authorization Code + PKCE | Web apps, mobile apps | ✅ Most secure |
| Client Credentials | Machine-to-machine | ✅ Server only |
| Device Code | TVs, CLI tools | ✅ |
| ❌ Deprecated | ❌ Don't use | |
| ❌ Deprecated | ❌ Don't use |
Rule: Always use Authorization Code + PKCE for user-facing apps.
3. JWT Best Practices
Token Design
| Aspect | Recommendation |
|---|---|
| Access token | Short-lived (15 min) |
| Refresh token | Long-lived (7-30 days), rotated |
| Algorithm | RS256 (asymmetric) for distributed |
| Claims | Minimal: sub, iat, exp, roles |
| Storage | HttpOnly cookie (web), secure storage (mobile) |
Token Security
| ❌ Don't | ✅ Do |
|---|---|
| Store in localStorage | HttpOnly, Secure, SameSite cookies |
| Long-lived access tokens | Short access + refresh rotation |
| Send in URL params | Send in Authorization header |
| Encode sensitive data | Minimal claims, lookup DB for details |
4. Authorization Patterns
| Pattern | Best For |
|---|---|
| RBAC (Role-Based) | Simple: admin, editor, viewer |
| ABAC (Attribute-Based) | Complex: department + level + resource |
| ReBAC (Relationship-Based) | Social: "friends of friends" (Zanzibar) |
| ACL | File/resource-level permissions |
5. Auth Providers
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 120 lines · 36 tokens per session scan A f50b1e567f7a
oauth-authentication is a skill published in the GitHub repository hoangatg/ai-agent-toolkit (1 stars, last pushed 5mo ago), licensed MIT. It adds 36 tokens to every session and 913 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
springboot-patterns
Spring Boot architecture patterns, REST API design, layered services, data access, caching, async processing, and logging. Use for Java Spring Boot backend work.
django-patterns
Django architecture patterns, REST API design with DRF, ORM best practices, caching, signals, middleware, and production-grade Django apps.
api-design
REST API design patterns including resource naming, status codes, pagination, filtering, error responses, versioning, and rate limiting for production APIs.
backend-patterns
Backend architecture patterns, API design, database optimization, and server-side best practices for Node.js, Express, and Next.js API routes.
sdd-apply
Skill "sdd-apply" from Gentleman-Programming/gentle-ai, covering execution role, language domain contract, purpose, what you receive and execution and persistence contract.
api-design
You are the API Design Specialist, responsible for designing RESTful, GraphQL, or other API interfaces. You ensure APIs are well-designed, documented, versioned, and follow best practices.