oauth-oidc-specialist
SubagentExpert in OAuth 2.0 and OpenID Connect protocol specifications, security best practices, and compliance. Specializes in flow selection, token security, protocol-level debugging, and standards compliance. Use for protocol design decisions, security reviews, and debugging token/auth flows at the HTTP
When Claude delegates to this
- Use for protocol design decisions, security reviews, and debugging token/auth flows at the HTTP level.
What it does
Expert in OAuth 2.0 and OpenID Connect protocol specifications, security best practices, and compliance. Specializes in flow selection, token security, protocol-level debugging, and standards compliance.
Model unspecified
No model pin — runs on your session's model.
Default effort
No reasoning budget declared.
Separate context
Runs in its own window, so it costs your main context almost nothing — unlike a skill.
Its system prompt
38 linesThe instructions this subagent runs under, verbatim — this is the persona it adopts once delegated to.
You are an OAuth 2.0 and OpenID Connect protocol specialist with deep expertise in identity protocols and security standards.
**Core Expertise Areas:**
**OAuth 2.0 Specification:**
- RFC 6749 (OAuth 2.0 Framework) and RFC 6750 (Bearer Tokens)
- RFC 7636 (PKCE) — mandatory for public clients
- RFC 7662 (Token Introspection) and RFC 7009 (Token Revocation)
- RFC 9449 (DPoP) — proof-of-possession tokens
- RFC 9126 (PAR — Pushed Authorization Requests)
- OAuth 2.1 draft consolidation
**OpenID Connect:**
- Core specification: ID tokens, UserInfo endpoint, claims
- Discovery (/.well-known/openid-configuration)
- Dynamic client registration
- Session management and logout (front-channel, back-channel)
- PKCE enforcement and nonce validation
**Security Analysis:**
- Authorization code interception attack prevention
- Token leakage via referrer headers or browser history
- CSRF protection in authorization flows
- Mix-up attack prevention
- Redirect URI validation best practices
**Protocol Debugging:**
- HTTP-level flow tracing (authorization, token, userinfo)
- JWT decoding and claims inspection
- Discovery document validation
- JWKS and key matching for signature verification
- Token lifetime and clock skew issues
**Compliance Guidance:**
- OAuth 2.0 Security Best Current Practice (BCP)
- FAPI (Financial-grade API) compliance
- CIBA (Client-Initiated Backchannel Authentication)
- Selecting appropriate flows for client typesShipped by 1 plugin
Installing any of these installs this subagent.
What this can do
Capabilities declared in this component's own frontmatter — not inferred.
Inherit all session tools
Declares no tool restrictions — inherits every session tool
~77 tokens of context used while enabled, before you invoke anything
Reviews
Log in to leave a review.
No reviews yet — be the first.
Explore related
Other things in this space — across every part of the ecosystem, not just subagents.
Subagentssimilar to this one
All subagents →ECC
The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.
235.3K stars
claude-security
The dedicated Claude Security orchestrator. Hand it an unattended job — "fully scan this repository and patch what you find; I understand it will use a lot of tokens" — and it runs the whole thing itself: capturing the revision, driving the multi-agent scan through the claude-security:scan workflow,
32.8K stars
scan-verifier
Restricted read-only verifier dispatched by the Claude Security scan workflow to vote on one candidate finding; not for direct invocation.
32.8K stars
Plugins
All plugins →claude-security
Deep vulnerability scanning of your own code, run entirely inside your Claude Code session at a chosen effort tier, with every finding challenged before it is reported and the verification tally computed in code. Turns surviving findings into targeted patches, each verified by a panel of agents, tha
32.9K stars
claude-md-management
Tools to maintain and improve CLAUDE.md files - audit quality, capture session learnings, and keep project memory current.
32.9K stars
math-olympiad
Solve competition math (IMO, Putnam, USAMO) with adversarial verification that catches what self-verification misses. Fresh-context verifiers attack proofs with specific failure patterns. Calibrated abstention over bluffing.
32.9K stars
MCP Servers
All mcp servers →codebase-memory-mcp
High-performance code intelligence MCP server. Indexes codebases into a persistent knowledge graph — average repo in milliseconds. 158 languages, sub-ms queries, 99% fewer tokens. Single static binary, zero dependencies.
36.7K stars
dbhub
Zero-dependency, token-efficient database MCP server for Postgres, MySQL, SQL Server, MariaDB, SQLite.
3.3K stars
ref-tools-ref-tools-mcp
Provide your AI coding tools with token-efficient access to up-to-date technical documentation for…
1.1K stars
Skills
All skills →ECC
The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.
235.3K stars
claude-mem
Persistent Context Across Sessions for Every Agent – Captures everything your agent does during sessions, compresses it with AI, and injects relevant context back into future sessions. Works with Claude Code, OpenClaw, Codex, Gemini, Hermes, Copilot, OpenCode + More
88.9K stars
session-report
Generate an explorable HTML report of Claude Code session usage (tokens, cache, subagents, skills, expensive prompts) from ~/.claude/projects transcripts.
32.8K stars
Commands
All commands →modernize-harden
Security vulnerability scan with a reviewable remediation patch — OWASP, CWE, CVE, secrets, injection
32.8K stars
modernize-status
Where am I in the modernization workflow — artifact inventory, staleness, secrets hygiene, next step
32.8K stars
audit-ssl
Audit ZIA SSL inspection rules -- list rules by action (INSPECT, DO_NOT_INSPECT, DO_NOT_DECRYPT, BLOCK), identify bypasses, and assess risk.