identity-providers
Installation
SKILL.md
Identity Providers — cross-vendor authentication mechanics
This skill encodes how modern authentication protocols actually work at the level needed to detect abuse. It is vendor-neutral — specific platform telemetry lives in entra-id, okta-identity, and active-directory.
1. OAuth 2.0 / OIDC token flows
Authorization code flow (most common for web apps)
User → App → Redirect to IdP /authorize
→ User authenticates + consents
→ IdP redirects back with authorization code
→ App exchanges code for tokens (POST /token)
→ IdP returns: access_token + id_token + refresh_token
Detection-relevant: The code-to-token exchange happens server-side. A replayed authorization code (AADSTS54005 in Entra ID) indicates code interception.