ClaudeSuperPower

identityserver-token-security

Skill

Advanced token security features in Duende IdentityServer including DPoP, mTLS certificate binding, Pushed Authorization Requests (PAR), JWT Secured Authorization Requests (JAR), and FAPI 2.0 compliance configuration.

Install

git clone https://github.com/DuendeSoftware/duende-skills.git ~/.claude/skills/identityserver-token-security

What is identityserver-token-security?

Advanced token security features in Duende IdentityServer including DPoP, mTLS certificate binding, Pushed Authorization Requests (PAR), JWT Secured Authorization Requests (JAR), and FAPI 2.0 compliance configuration.

What this can do

Capabilities declared in this component's own frontmatter — not inferred.

Inherit all session tools

Declares no tool restrictions — inherits every session tool

~54 tokens of context used while enabled, before you invoke anything

Documentation

README · ~11 min read

Advanced Token Security (DPoP, mTLS, PAR, JAR, FAPI)

When to Use This Skill

  • Implementing Proof-of-Possession (PoP) tokens with DPoP or mTLS
  • Configuring Pushed Authorization Requests (PAR) for front-channel parameter security
  • Setting up JWT Secured Authorization Requests (JAR) for tamperproof authorize requests
  • Building FAPI 2.0 compliant authorization servers
  • Choosing between DPoP and mTLS for sender-constrained tokens
  • Configuring APIs to validate proof-of-possession tokens
  • Meeting regulatory or industry security requirements (open banking, e-health, e-government)

Docs: https://docs.duendesoftware.com/identityserver/tokens/security

Reviews

Log in to leave a review.

No reviews yet — be the first.

Explore related

Other things in this space — across every part of the ecosystem, not just skills.