fastapi-auth-and-security-review
Installation
SKILL.md
FastAPI Auth and Security Review
When to use
Invoke when adding login, token, or API-key handling to a FastAPI service that has the scaffold baseline, wiring an OAuth2/OIDC provider or JWT verification, defining the authorization model, hardening the HTTP surface (headers, CSRF, rate limiting), or running an OWASP-style review before release.
Do not use for: the service shell, settings, logging, or error tiers (use fastapi-service-scaffold), OpenTelemetry/metrics/SLO wiring (use fastapi-observability-readiness), task or event integration (use fastapi-async-and-task-integration), or performance and resilience gating (use fastapi-performance-and-resilience).
Inputs
Required:
- A service with the
fastapi-service-scaffoldbaseline (principalDependsseam, validated settings, error tiers present). - Approved
architecture/securitydecisions on auth provider, session vs token strategy, and secret handling — or explicit confirmation they are intentionally deferred.
Optional: