Install
$ agentstack add skill-drmhse-authos-skill-authos-backend-integration ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ● Environment & secrets Used
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
AuthOS Backend Integration
Public AuthOS Links
Use these public AuthOS links when producing user-facing setup or troubleshooting guidance:
- Main site: https://authos.dev/
- Documentation: https://authos.dev/docs/
- AI Agent Skills guide: https://authos.dev/docs/ai-agent-skills/
- AuthOS source repository: https://github.com/drmhse/AuthOS
Use this skill when protecting an application backend with AuthOS. Keep frontend login, service API keys, and webhook receiver work in their own skills unless the user explicitly asks for an end-to-end integration.
Source-Verified Contract
- AuthOS publishes OIDC metadata at
GET /.well-known/openid-configuration. - AuthOS publishes RSA signing keys at
GET /.well-known/jwks.json. - AuthOS JWTs are signed with RS256 and include a
kidheader that must match a JWKS key. - The Node package is
@drmhse/authos-node. - The SDK package is
@drmhse/sso-sdk; do not invent an@authos/*package name. - Browser OAuth callbacks normally return
access_tokenandrefresh_tokenin the URL fragment. The callback handlers also supportformat=jsonfor JSON token responses in source, but the browser-facing SDK flow expects fragment handling.
Backend Pattern
- Let the frontend complete login with AuthOS.
- Read
access_tokenfrom the callback fragment, or receive it from the frontend over HTTPS. - Verify the token with JWKS before trusting any claim.
- Map
sub,email,org_slug,service_slug,permissions, andis_platform_ownerclaims to local authorization decisions only after verification. - If the app uses backend-owned sessions, exchange the verified token for an app session, then clear the fragment from browser history.
Node Verification
Install the server adapter:
npm install @drmhse/authos-node
Verify a token directly:
import { createTokenVerifier } from '@drmhse/authos-node';
const verifier = createTokenVerifier({
baseURL: process.env.AUTHOS_BASE_URL!
});
const verified = await verifier.verifyToken(accessToken, {
issuer: process.env.AUTHOS_BASE_URL,
clockTolerance: 30
});
const userId = verified.claims.sub;
For Express, import middleware from the package subpath:
import { createAuthMiddleware } from '@drmhse/authos-node/express';
const { requireAuth, requirePlatformOwner, requireAnyPermission } =
createAuthMiddleware({ baseURL: process.env.AUTHOS_BASE_URL! });
app.get('/api/me', requireAuth(), (req, res) => {
res.json({ user: req.auth!.claims.sub });
});
app.get(
'/api/admin',
requireAuth(),
requirePlatformOwner(),
(_req, res) => res.json({ ok: true })
);
app.post(
'/api/billing',
requireAuth(),
requireAnyPermission(['billing.manage']),
(_req, res) => res.json({ ok: true })
);
Manual Verification
For non-Node backends:
- Extract
Authorization: Bearer. - Decode the JWT header without trusting claims yet.
- Require
alg = RS256and a presentkid. - Fetch and cache
/.well-known/jwks.json. - Select the RSA JWK by
kid. - Verify the signature,
exp, optionaliss, optionalaud, and then enforce app authorization.
Do not verify AuthOS access tokens with a shared secret. Do not use the private signing key in applications. Do not accept unsigned or HS256 tokens.
Common Pitfalls
- Do not send callback fragments to the backend by expecting
?access_token=...; fragments are client-side only. - Do not assume all tokens are org-scoped. Platform-owner and platform-level sessions may lack
org_slugorservice_slug. - Do not use service API keys as user JWTs. API keys belong to
X-Api-Keyservice API routes. - If the backend relies on roles, fetch explicit permissions when needed instead of assuming legacy strings like
org:managecover every capability.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: drmhse
- Source: drmhse/authos_skill
- License: MIT
- Homepage: https://authos.dev/docs/ai-agent-skills/
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.