identity-providers

Installation
SKILL.md

Identity Providers — cross-vendor authentication mechanics

This skill encodes how modern authentication protocols actually work at the level needed to detect abuse. It is vendor-neutral — specific platform telemetry lives in entra-id, okta-identity, and active-directory.


1. OAuth 2.0 / OIDC token flows

Authorization code flow (most common for web apps)

User → App → Redirect to IdP /authorize
  → User authenticates + consents
  → IdP redirects back with authorization code
  → App exchanges code for tokens (POST /token)
  → IdP returns: access_token + id_token + refresh_token

Detection-relevant: The code-to-token exchange happens server-side. A replayed authorization code (AADSTS54005 in Entra ID) indicates code interception.

Installs
3
First Seen
Sep 16, 2026